Sign inSign up

cdupuis/sbx-kit-github-yubikey

By cdupuis

•Updated 8 days ago

Sandbox Kit
0

147

cdupuis/sbx-kit-github-yubikey repository overview

Digest

sha256:5241ceb01153…

Size

1.6 kB

Schema

v3

Pushed

8 days ago

Specificationspec.yaml

MIXIN

Prepares a sandbox for GitHub git over the forwarded host ssh-agent (YubiKey PIV slot 9a, served by docker-piv-agent). The private key and PIN never enter the sandbox — each git network op makes the HOST YubiKey blink for a tap, which the human approves. Pairs with host-side ssh-agent forwarding (the daemon's SSH_AUTH_SOCK at startup). What it does: - network-policy runtime: allow GitHub SSH egress. sbx egress is a TLS-intercepting HTTP(S) proxy, so raw SSH on port 22 is closed at kex by default; this opens it (also covers ssh.github.com:443 for the 443 fallback). - lifecycle startup (idempotent; runs on every boot): accept GitHub's host key on first use (a non-TTY agent can't answer the interactive yes/no prompt), and rewrite any HTTPS github URL to SSH so all git traffic routes through the forwarded agent.


CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/lifecycle@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit cdupuis/sbx-kit-github-yubikey:1.0.0

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠
No overview available
This repository doesn't have an overview