Configuration
Bifröst will be configured in the YAML language.
By default, the configuration is taken from the following location:
- Linux:
/etc/engity/bifroest/configuration.yaml - macOS:
/Library/Application Support/Engity/Bifroest/configuration.yaml - Windows:
C:\ProgramData\Engity\Bifroest\configuration.yaml
This location can be changed by the --configuration=<path> flag when executing:
bifroest run --configuration=/my/config.yaml
Properties
ssh
Defines how the SSH connections itself will behave.
session
Defines where and how the sessions inside Bifröst are handled.
flows
[]Flow
Defines which flows are evaluated for user sessions.
auditlog
Defines named audit logs that flows can use for security-relevant actions. If omitted or empty, it contains one disabled audit log named default.
housekeeping
Defines how Bifröst will clean up its sessions and connections.
alternatives
Defines how the imp (if needed) behaves to help to bridge context boundaries, for example to enable port-forwarding into an OCI container.
startMessage
string Core = ""
If defined this message will be displayed in the log files of Bifröst on startup.
Examples
-
Simple:
1 2 3 4 5 6 7 8 9 10 11 12 13 14
ssh: addresses: [ ":22" ] # ... session: type: fs # ... flows: - name: local # ... housekeeping: # ... alternatives: # ... startMessage: "" -
Local-account host configuration
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
## Host service for an existing local account on Linux, Windows or macOS. ## Local authentication uses the platform default. flows: - name: local authorization: type: local environment: type: local name: "{{.authorization.user.name}}" ## If you only want to allow user with group "ssh" to log in, uncomment the following lines: ## Unix only: Windows users have no primary group. #loginAllowed: | # {{ or # (.authorization.user.group.name | eq "ssh" ) # (.authorization.user.groups | firstMatching `{{.name | eq "ssh" }}` ) # }} -
Docker environment with OpenID Connect authorization
This example is using the Docker environment with OpenID Connection authorization.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
flows: - name: docker authorization: type: oidcDeviceAuth issuer: https://login.microsoftonline.com/my-great-tenant-uuid/v2.0 clientId: my-great-client-uuid clientSecret: very-secret-secret scopes: - openid - email - profile - offline_access environment: type: docker image: alpine