{"repo":"cloudposse/bastion","free":true,"listed":false,"github":"https://github.com/cloudposse/bastion","clone":"git clone https://github.com/cloudposse/bastion.git","description":"🔒Secure Bastion implemented as Docker Container running Alpine Linux with Google Authenticator & DUO MFA support","language":"Shell","stars":674,"topics":["bastion","docker","dockerfile","alpine","linux","openssh","mfa","duo","google-authenticator","slack"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"This is a secure/locked-down bastion implemented as a Docker Container. It uses Alpine Linux as the base image and ships with support for Google Authenticator & DUO MFA support. It was designed to be used on Kubernetes together with GitHub Authorized Keys to provide secure remote access to production clusters. MFA Setup & Usage Here's a demo of what a user experiences when setting up Google Authenticator for the first time. When using Duo as the MFA provider, this becomes even more magical because Duo supports automatic Push notifications to your mobile device. Just approve the request on your mobile phone (e.g. with a thumb press on iOS) when prompted. Slack Notifications Here's what it looks like when someone connects to the bastion if Slack notifications are enabled. We recommend using Slack notifications for self-reporting. Any time a user accesses production systems, they should reply to the slack notification to justify their remote access. A \"buddy\" should approve the login by adding a reaction (e.g. ✅). If no one approves the login, it should trigger an incident response to track down the unauthorized access. Usage Running Refer to the Environment Variables section below to tune how the bastion operates. Building Testing Run basic connection tests Configuration Recommendations Do not allow root (or sudo ) access to this container as doing so would allow remote users to manipulate audit-logs in /var/log/sudo-io Use the bastion as a \"jump host\" for accessing other inter","default_branch":null,"files":null,"tree":[],"storefront":"/r/cloudposse","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cloudposse/bastion/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}