Phase 4: end-to-end SSH tests (OpenSSH + Dropbear containers)

#24 · closed · 0 comments

View on GitHub ↗

vdemeester

Current tests are unit-level (`internal/engine`, `internal/authkeys`) plus `praetorian check` scripted simulation. This issue covers true end-to-end validation against real SSH servers — deliberately deferred from v1. ## Goal Prove that, end-to-end, a real SSH server invokes `praetorian run <alias>` via a `command=` directive and that allowed commands succeed while denied commands fail — across server implementations. ## Tasks - [ ] **OpenSSH e2e** - [ ] containerized `sshd` with `AuthorizedKeysFile` mapping a test key to `command="praetorian run <alias>"` - [ ] fixtures: test keypair + `config.hcl` - [ ] assert ALLOW: e.g. `ssh ... git-upload-pack '/srv/git/repo.git'` succeeds - [ ] assert DENY: e.g. `ssh ... rm -rf /` exits non-zero with `praetorian: denied` - [ ] assert injection inertness: `ssh ... 'borg serve; rm -rf /'` is denied (no shell) - [ ] **Dropbear e2e** (Alpine/embedded compatibility) - [ ] same matrix against Dropbear's `authorized_keys` `command=` support - [ ] **Real `SSH_ORIGINAL_COMMAND` coverage**: git push/fetch, rsync, scp, borg serve, nix-store --serve, nc jump - [ ] **CI**: dedicated workflow/job (containers), kept separate from the fast unit lane - [ ] **Docs**: how to run e2e locally ## Notes - Lives outside the unit test lane so the main CI stays fast. - Out of scope (documented as "use an unrestricted FIDO2 key"): interactive sessions, kitty kitten ssh, piped/redirected commands.

Comments