Skip to main content
Most integration surprises on an ssh lane are an assumption carried over from sshd. This page is the list of them. An end-hop is a complete SSH server for the paths it implements, not a drop-in sshd. It authenticates certificates, resolves accounts, spawns processes and honours login shells the way sshd does. It does not read sshd_config, does not invoke PAM, and does not implement most of what an OpenSSH deployment accumulates.

sshd_config mapping

Start here, because it shows which parts of an ssh lane are a rename of something you already know and which parts are genuinely new. The left column is what capabilities_allowed accepts; see Configuration. The capabilities this design inspects are the ones OpenSSH cannot name. There is no keyword separating shell from exec, and none that treats a file operation as a statement — the closest control is ForceCommand, which replaces what runs rather than judging it. That is the gap this lane fills. AcceptEnv is the one keyword that is already default-deny, and it narrows by variable name, which is exactly how an env_set guardrail matches. This design does not copy that default — an omitted capabilities_allowed admits env. A deployment that wants OpenSSH’s answer writes the list without env.

Assumptions to drop

What a session gets

So .profile and audit rules behave:
  • USER, LOGNAME, HOME, SHELL, PATH, plus TERM when a pty was allocated, and any env variables that passed the guardrails.
  • SSH_CONNECTION and SSH_CLIENT.
  • The Sidecar’s own environment is never inherited — it holds the Sidecar’s configuration and possibly its credentials.
  • An interactive session runs <shell> -l, so profile files are sourced. A command runs <shell> -c, so they are not. Same split as sshd.
  • Supplementary groups are applied in the child, setgroups → setgid → setuid, before exec.

Not implemented

Naming any of the first four in capabilities_allowed fails at load, because the config would be asking for something this version cannot do. Refusing the request at runtime instead would leave an operator believing a capability is on when it is not.

Where it is stricter

Not everything on this page is a subtraction. The last two rows are the point of the lane. The rest of this page is the price.

Next

Host Configuration

The accounts, groups and shells that have to be in place before any of this applies.

Configuration

Every attribute, the full capability surface, and what each one can carry.