Page MenuHomePhabricator

Move away from rssh in fundraising environment
Closed, ResolvedPublic


We currently use rssh to restrict connections for backups and some data copies in the fundraising rig. We have been using the stretch package on buster. Since we have shifted off of stretch and wish to clean it from the rig, we need to find an alternative to use for this.

Please investigate the options and shift the current rssh usage to a new method.

Event Timeline

We already use openssh's built in sftp server and chroot where applicable. For rsync, after a whole bunch of research and testing a reasonable way to handle this is with script that runs via openssh's ForceCommand. This is similar to rrsync which is bundled with rsync, but without it's additional layer of filesystem access controls. We would also like to support unison. To that end I wrote nopeshell.

Jgreen triaged this task as Medium priority.
Jgreen moved this task from Triage to In Progress on the fundraising-tech-ops board.
Jgreen moved this task from In Progress to Done on the fundraising-tech-ops board.