# =========================================================================== # OSM taxiway bastion — broker mode, self-contained OSM export box # =========================================================================== # Deploy on the host that holds your osm-maps directory (region/planet PBF + # export-icao-geojson.sh). A backend connects over SSH as `agent` and may run # ONLY the three whitelisted taxiway commands (see allowed-commands.list); every # request is validated and exec'd shell-free by bastion-broker. # # Backend side (its own .env / config): # host = agent@ # port = 6770 (whatever you publish below) # auth = a private key whose *.pub is dropped in docker-data/bastion/users.d/ # # Setup: # 1. Drop the backend's agent public key: # mkdir -p docker-data/bastion/users.d # cp /path/to/agent.pub docker-data/bastion/users.d/backend.pub # 2. Make the osm-maps dir writable by the bastion's `agent` user (export writes # -taxiways.geojson + work/ intermediates there): # AGENT_UID=$(docker run --rm blaxsoftware/bastion:latest id -u agent) # chown -R "$AGENT_UID" /srv/osm-maps # 3. Ensure the osm-maps dir contains export-icao-geojson.sh + the region PBF. # 4. docker compose up -d --build # 5. Test from a host holding the agent key: # ssh -p 6770 agent@ taxiways-list # ssh -p 6770 agent@ taxiways-export EDDF # minutes # ssh -p 6770 agent@ taxiways-cat EDDF | base64 -d | head # ssh -p 6770 agent@ 'rm -rf /' # → refused (exit 126) # =========================================================================== services: osm-taxiways-bastion: build: . image: blaxsoftware/bastion-osm-taxiways:latest container_name: osm-taxiways-bastion restart: unless-stopped volumes: # THE osm-maps dir — the only real host data reachable. Must contain the # region PBF + export-icao-geojson.sh, and be writable by the agent user. # Mount at exactly /osm-maps (the wrappers hardcode that path — sshd does # not propagate container env into a ForceCommand session). Point the LEFT # side at wherever your osm-maps dir actually lives. - /srv/osm-maps:/osm-maps # Broker allowlist — re-read every request (live edits, no restart). - ./allowed-commands.list:/etc/bastion/allowed-commands.list:ro # Authorized clients — one *.pub per identity (read live). - ./docker-data/bastion/users.d:/etc/bastion/users.d # Persist the SSH host identity across rebuilds (bind mount, never a named # volume — `down -v` would change the host key and clients would refuse it). - ./docker-data/bastion/keys:/etc/ssh/keys ports: # Bind to an internal interface / front with a VPN if you don't want the # taxiway bastion on the public internet. - "6770:22"