Sets up secure remote access to your Zo Computer so you can connect from anywhere
This file will be included in a user request. If it is, and the user has provided the necessary inputs, Zo should interpret this as the current task at hand and use its tools to carry out the task until completion. Zo should not ask for user confirmation to continue if it has all required parameters to execute this function. Zo should effectively treat the inclusion of this file as a user request to "run" this task.
This document codifies the procedure for setting up an SSH server (sshd) as a managed user service on Zo Computer, allowing secure remote shell access to the machine. The setup includes configuring authentication (either SSH keys or password), installing necessary packages, configuring sshd, and registering the service to run persistently with automatic restarts.
key) The user's SSH public key content to add to authorized_keys - strongly prefer this method and show the user how to create a keypair on their host system, whether that is a mac or a windows machine. Prefer to have them create a new identity vs using an existing identity. give them the correct commands to create a keypair and have it added to their system.password) The password to set for the root user accountConfigure authentication based on the chosen method:
If using public key authentication:
echo "<public_key_content>" >> /root/.ssh/authorized_keys
chmod 600 /root/.ssh/authorized_keys
Replace <public_key_content> with the actual SSH public key provided by the user.
If using password authentication:
echo "root:<password>" | chpasswd
Replace <password> with the password provided by the user.
Create or update sshd configuration file at /etc/ssh/sshd_config with the following settings:
cat > /etc/ssh/sshd_config << 'EOF'
# Port will be set via command-line flag (-p)
Protocol 2
# Authentication
PermitRootLogin yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
PasswordAuthentication <password_auth_setting>
PermitEmptyPasswords no
ChallengeResponseAuthentication no
# Security
X11Forwarding no
PrintMotd no
AcceptEnv LANG LC_*
# Logging
SyslogFacility AUTH
LogLevel INFO
# Subsystems
Subsystem sftp /usr/lib/openssh/sftp-server
EOF
Replace <password_auth_setting> with yes if using password authentication, or no if using key-only authentication.
Choose an available port for the SSH service (recommend using a port in the 20000-30000 range to avoid conflicts). DO NOT use port 22:
# Check if port is available (should return no output if free)
netstat -tuln | grep :<chosen_port>
If port 22222 is already in use, increment to 22223, 22224, etc. until you find a free port.
Register the sshd service using the register_user_service tool:
register_user_service(
label="sshd",
protocol="tcp",
local_port=<chosen_port>,
entrypoint="/usr/sbin/sshd -D -p <chosen_port>"
)
Replace <chosen_port> with the port number selected in step 3.
The service will:
-D flag prevents backgrounding)-p flag)ts1.zocomputer.io:10991)Verify the service is running:
# Check service logs for successful startup
cat /dev/shm/sshd.log
cat /dev/shm/sshd_err.log
# Verify sshd process is running
ps aux | grep sshd | grep -v grep
# Test local connectivity
nc -zv localhost <chosen_port>
Retrieve the public TCP address from the service registration response (format: ts1.zocomputer.io:<port>).
/etc/ssh/sshd_config with appropriate security settingsAfter each successful run of this procedure, communicate to the user:
ts1.zocomputer.io:10991)ssh -p <public_port> root@<public_host>ssh -p <public_port> root@<public_host> (they will be prompted for the password)Suggest to the user that they can create a convenient SSH shortcut on their personal computer by adding an entry to their ~/.ssh/config file:
Host myzo
HostName <public_host>
Port <public_port>
User root
ServerAliveInterval 30
ServerAliveCountMax 3
IdentityFile ~/.ssh/<users_key_file>
Replace the placeholders:
<public_host> with the actual hostname (e.g., ts1.zocomputer.io)<public_port> with the actual port number<users_key_file> with their SSH private key filename (e.g., id_ed25519 or id_rsa)After adding this entry, they can simply connect with:
ssh myzo
The ServerAliveInterval and ServerAliveCountMax settings help keep the connection alive and detect dropped connections more reliably.
Now that SSH access is configured, inform the user they have several options for leveraging this connection:
Development Tools:
File Transfer:
scp or rsync for command-line file transfersOther Possibilities:
Ask the user: "What would you like to do with your SSH connection?" This helps guide them toward the next configuration steps based on their specific needs.
/dev/shm/sshd.log and /dev/shm/sshd_err.logupdate_user_service tooldelete_user_service tool with the service_id/etc/ssh/sshd_config require service restart to take effect-D flag is required for sshd to run in the foreground (managed services expect foreground processes)authorized_keysPasswordAuthentication no if you're using key-based auth only/dev/shm/sshd.log for unauthorized access attemptsapt-get update && apt-get upgrade -y openssh-serverThis document will be maintained and updated as SSH configuration needs evolve, but will always reflect the core action of establishing a secure, managed SSH server service on Zo Computer.