Deploy Ladill Hosting / deploy (push) Successful in 45s
SECURITY: the browser terminal ran an unconfined login shell as the account's system user, so customers could browse the whole host (/var/www, other tenants, /etc). Run it inside a jailkit chroot instead: a vetted, sudo-scoped launcher (/usr/local/sbin/ladill-jailsh) enters a private mount namespace, bind-mounts ONLY that user's home into /home/jail, and chroots as the user. They can no longer see anything outside their own home. Provisioning committed in deployment/ (setup-terminal-jail.sh + ladill-jailsh) so it is reproducible. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41 lines
1.9 KiB
Bash
Executable File
41 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Provision the jailkit chroot used by the control-panel browser terminal so the
|
|
# customer shell is confined to its own home (cannot see /var/www, other tenants,
|
|
# /etc, or secrets). Idempotent; run as root on each hosting node.
|
|
set -Eeuo pipefail
|
|
|
|
JAIL=/home/jail
|
|
|
|
echo "==> Installing jailkit"
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
command -v jk_init >/dev/null 2>&1 || apt-get install -y jailkit
|
|
|
|
echo "==> Building jail tree at $JAIL"
|
|
jk_init -j "$JAIL" uidbasics netbasics basicshell interactiveshell extendedshell editors netutils terminfo || true
|
|
jk_cp -j "$JAIL" /usr/bin/id /usr/bin/whoami /usr/bin/find /usr/bin/grep /usr/bin/less \
|
|
/usr/bin/head /usr/bin/tail /usr/bin/du /usr/bin/df /usr/bin/wc /usr/bin/clear /usr/bin/sed /usr/bin/awk || true
|
|
|
|
# Terminal definitions (xterm*) for a usable TTY.
|
|
mkdir -p "$JAIL/usr/share/terminfo"
|
|
cp -rn /usr/share/terminfo/x "$JAIL/usr/share/terminfo/" 2>/dev/null || true
|
|
|
|
# Non-listable jail /home (each session bind-mounts only its own home here).
|
|
install -d -o root -g root -m 711 "$JAIL/home"
|
|
install -d -m 1777 "$JAIL/tmp"
|
|
|
|
echo "==> Syncing hosting users into the jail passwd/group (for name resolution)"
|
|
while IFS=: read -r name _ uid gid _ home shell; do
|
|
[ "$uid" -ge 1000 ] 2>/dev/null || continue
|
|
[ -d "/home/$name" ] || continue
|
|
grep -q "^$name:" "$JAIL/etc/passwd" || getent passwd "$name" >> "$JAIL/etc/passwd"
|
|
grep -q "^$name:" "$JAIL/etc/group" || getent group "$name" >> "$JAIL/etc/group"
|
|
done < <(getent passwd)
|
|
|
|
echo "==> Installing the jailed-shell launcher + scoped sudoers"
|
|
install -o root -g root -m 755 "$(dirname "$0")/ladill-jailsh" /usr/local/sbin/ladill-jailsh
|
|
echo 'www-data ALL=(root) NOPASSWD: /usr/local/sbin/ladill-jailsh *' > /etc/sudoers.d/ladill-jailsh
|
|
chmod 440 /etc/sudoers.d/ladill-jailsh
|
|
visudo -cf /etc/sudoers.d/ladill-jailsh
|
|
|
|
echo "==> Done. Customer terminals now run jailed in $JAIL."
|