From 674ead35089b33d545e63761e223b10c7b248f9d Mon Sep 17 00:00:00 2001 From: Anirudh Oppiliappan Date: Mon, 27 Jul 2026 11:42:29 +0300 Subject: [PATCH] appview: log source IPs on the git-over-ssh proxy The nginx stream proxy forwarding :22 to the knot had no logging, so we had no visibility into who was connecting. Add a stream access log capturing source IP + connection metadata to /var/log/nginx/ssh-proxy.log. SSH is an encrypted tunnel, so git paths/commands inside the session are not visible at this layer -- only connection-level metadata. Co-Authored-By: Claude Opus 4.8 (1M context) --- hosts/appview/services/nginx.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/hosts/appview/services/nginx.nix b/hosts/appview/services/nginx.nix index 5f5b722..5231080 100644 --- a/hosts/appview/services/nginx.nix +++ b/hosts/appview/services/nginx.nix @@ -66,6 +66,14 @@ ''; streamConfig = '' + # Log source IPs hitting the git-over-ssh proxy. SSH is an encrypted + # tunnel, so we can only see connection metadata here (source IP, + # bytes, duration) -- not the git paths/commands inside the session. + log_format ssh_proxy '$remote_addr [$time_local] ' + 'proto=$protocol status=$status ' + 'sent=$bytes_sent recv=$bytes_received ' + 'duration=$session_time upstream=$upstream_addr'; + upstream knot-sailor { server 85.9.211.103:22; } @@ -74,6 +82,7 @@ listen 22; listen [::]:22; proxy_pass knot-sailor; + access_log /var/log/nginx/ssh-proxy.log ssh_proxy; } ''; -- 2.51.2