AWS bastion ssh from docker: `ssh_exchange_identification: Connection closed by remote host`

Viewed 160

I am trying to ssh into a AWS bastion instance from a Docker container.
So far I have a Docker image:

FROM amazon/aws-cli

RUN yum update -y && yum install jq openssh-clients unzip -y

RUN curl "https://s3.amazonaws.com/session-manager-downloads/plugin/latest/mac/sessionmanager-bundle.zip" -o "sessionmanager-bundle.zip"
RUN unzip sessionmanager-bundle.zip
RUN ./sessionmanager-bundle/install -i /usr/local/sessionmanagerplugin -b /usr/local/bin/session-manager-plugin
RUN rm -rf ./sessionmanager-bundle
RUN rm ./sessionmanager-bundle.zip

COPY ./script/db-connect-container db-connect
COPY ./script/bash-colors bash-colors

ENTRYPOINT /aws/db-connect

And a script:

#!/usr/bin/env bash

source bash-colors

echo -e "Using ${blue}${AWS_PROFILE}${nc} AWS profile"

###########       Generating temporary SSH key      ###########
echo -e "${green}>>${nc} Generating temporary SSH key"
rm -f -- bastion_ssh_key
rm -f -- bastion_ssh_key.pub
ssh-keygen -t rsa -f bastion_ssh_key -N ''
###############################################################

###########       Finding Bastion instance ID       ###########
BASTION_INSTANCE_ID=`aws ec2 describe-instances --filters Name=tag:Name,Values=hercules-db-bastion-${ENV} | jq -r ".Reservations[0].Instances[0].InstanceId"`
echo -e "${green}>>${nc} Found bastion instance id: ${blue}$BASTION_INSTANCE_ID${nc}"
###############################################################

###########       Finding RDS instance address      ###########
RDS_INSTANCE_ADDRESS=`aws rds describe-db-instances --db-instance-identifier=hercules-${ENV} --max-items=1 | jq -r ".DBInstances[0].Endpoint.Address"`
echo -e "${green}>>${nc} Found RDS instance: ${blue}${RDS_INSTANCE_ADDRESS}${nc}"
###############################################################

###########       Uploading SSH key to bastion      ###########
echo -e "${green}>>${nc} Pushing generated key to the bastion instance"
aws ec2-instance-connect send-ssh-public-key \
  --instance-id ${BASTION_INSTANCE_ID} \
  --instance-os-user ec2-user \
  --ssh-public-key file://bastion_ssh_key.pub \
  --region eu-west-3
###############################################################

###########       Connecting to the instance        ###########
echo -e "${green}>>${nc} Connecting to the instance"
ssh ec2-user@${BASTION_INSTANCE_ID} \
  -i bastion_ssh_key \
  -vvv \
  -g \
  -L ${PORT}:${RDS_INSTANCE_ADDRESS}:5432 \
  -o "IdentitiesOnly=yes" \
  -o ProxyCommand="aws ssm start-session --target %h --document AWS-StartSSHSession --parameters portNumber=%p --region=eu-west-3"
###############################################################

Running the above with:

docker build -f ./docker/Dockerfile-db-connect -t aws-db-connect .
docker run \
  --rm \
  -it \
  -v ~/.aws:/root/.aws \
  -e AWS_PROFILE \
  -e ENV \
  -e PORT \
  -p ${PORT}:${PORT} \
  aws-db-connect

Everything works fine up to the actual ssh command:

OpenSSH_7.4p1, OpenSSL 1.0.2k-fips  26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 58: Applying options for *
debug1: Executing proxy command: exec aws ssm start-session --target i-0a1f5364f78fb18b8 --document AWS-StartSSHSession --parameters portNumber=22 --region=eu-west-3
debug1: permanently_set_uid: 0/0
debug1: SELinux support disabled
debug1: permanently_drop_suid: 0
debug1: identity file /bastion_ssh_key type 1
debug1: key_load_public: No such file or directory
debug1: identity file /bastion_ssh_key-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.4
ssh_exchange_identification: Connection closed by remote host

I am a little bit lost as exactly the same thing works perfectly on my host:

OpenSSH_8.1p1, LibreSSL 2.7.3
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 47: Applying options for *
debug1: Executing proxy command: exec aws ssm start-session --target i-XXXXX --document AWS-StartSSHSession --parameters portNumber=22 --region=eu-west-3
debug1: identity file bastion_ssh_key type 0
debug1: identity file bastion_ssh_key-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.1
debug1: kex_exchange_identification: banner line 0: 
.....

Any idea what am I missing?

0 Answers
Related