LazySSH – A jump-host SSH server that starts machines on-demand
github.com
github.com
- Create an EC2 instance in a private subnet, and assign the AmazonSSMManagedInstanceCore IAM role to it
- Install the AWS CLI tools on your desktop
- Add a function to your .bash_profile like this:
function jumphost() {
JUMP_ID=$(aws ec2 describe-instances --filter "Name=tag:Name,Values=my-jumphost-name" --query "Reservations[].Instances[].InstanceId[]")
echo "Starting jumphost..."
aws ec2 start-instances --instance-ids $JUMP_ID
sleep 30
aws ssm start-session --target $JUMP_ID
}
Then just run "jumphost" from your terminal and boom, SSH'ed in via the magic of SSM.Bonus points: add a cronjob to your jumphost to shutdown every X hours in case you forget ;-)
Super tiny downside to your approach: you'll be paying for storage of that instance while shut down, I guess. But that's probably peanuts.
---
as an aside: `function name()` is redundant; the `function name {` syntax is a bashism, `name() {` is the posix syntax
and you may find `aws ec2 wait instance-running` handy instead of the sleep: https://docs.aws.amazon.com/cli/latest/reference/ec2/wait/in...
I submitted this elsewhere myself, and added a little extra blurb, so I'll just quote it here:
> This is very much a ‘release early’ type thing. I’ve mostly been testing with it, and not yet seriously using it.
> Besides the cases mentioned in the readme, I also want to use this to automate on-demand Nix builders, because Nix only understands SSH for remote builders. Locally I run Mac, and I sometimes need to do a Nix build for Linux. Similarly at work, we have a build server that I want to do ARM builds on, so I can eventually deploy on t4g.* EC2 instances.
> Any way, hope this is useful to others.
I've been thinking of the same thing for a while now but I was thinking of utilizing containers instead of virtual machines.
It would be sweet to have a jump box that creates an isolated container for every user that logs in. The container could just be torn down on logoff.
Thinking, we can make dialing the provider responsibility. I didn't want to block the goroutine there, but it could just spawn another temporary one for dialing.
Then the manager can be generic over ReadWriter, and optionally try if whatever it has is also Closer.
Beyond that, I think Docker talks gRPC?
P.S.: Note that I made this AGPL. If you planned on creating some sort of product out of this, best start fresh from the golang.org/x/crypto. Might even be simpler in the end, because I feel like a big part of lazyssh is management of resources, which in Docker is (probably) local, cheap and almost instant.
ssh foo@ubuntu20-16G-100G-8c.project-a
I like this idea! I wonder how much of it is compatible with how LazySSH works right now. It’s not really on my list of things, though.
Since the container could be used by multiple team members, I had an external scripts to tear down after 30min of inactivity.
>LazySSH is an SSH server that acts as a jump host only, and dynamically starts temporary virtual machines.
>If you find yourself briefly starting a virtual machine just to SSH into it and try something out, LazySSH is an attempt to automate that flow via just the ssh command. LazySSH starts the machine for you when you connect, and shuts it down (some time after) you disconnect.
I would love for a capability like this to be extended to physical machines. I have a dozen SuperMicro servers with IPMI interfaces, an HP server with fully licensed ILO, and a Dell server with a BMC. Being able to control when these go on/off would be very nice.