No Description

Fabian Peter Hammerle b7360e83a3 compose example: added explanation for not using named volumes 5 years ago
docker 1a50342b76 docker: fix umount when busy 5 years ago
examples b7360e83a3 compose example: added explanation for not using named volumes 5 years ago
src d6fe4ab5b6 fix rgpgfs_strncpy_without_suffix when max_len << len(src) / len(suffix); 5 years ago
tests a31c36f687 added unit tests for rgpgfs_fs_mkdirs; docker ignore binaries in src/ & tests/ 5 years ago
.dockerignore a31c36f687 added unit tests for rgpgfs_fs_mkdirs; docker ignore binaries in src/ & tests/ 5 years ago
.gitignore d6fe4ab5b6 fix rgpgfs_strncpy_without_suffix when max_len << len(src) / len(suffix); 5 years ago
Dockerfile a31c36f687 added unit tests for rgpgfs_fs_mkdirs; docker ignore binaries in src/ & tests/ 5 years ago
Makefile a31c36f687 added unit tests for rgpgfs_fs_mkdirs; docker ignore binaries in src/ & tests/ 5 years ago
README.md 4dd6395f92 added example: rsync-sshd/docker-compose.yml 5 years ago
docker-compose.yml 4dd6395f92 added example: rsync-sshd/docker-compose.yml 5 years ago

README.md

rgpgfs 💾 🔐

PoC: PGP/GPG-enciphered view of plain directories

Mounting & unmounting does not require setuid, sudo, root ...

Build

Run make after installing libfuse and gpgme.

Debian / Ubuntu

apt-get install libfuse3-dev libgpgme-dev
make

Docker 🐳

docker build --target build -t rgpgfs .

Usage

rgpgfs -r [fingerprint] [mountpoint]
# or
rgpgfs --recipient=[fingerprint] [mountpoint]
# or
rgpgfs -o recipient=[fingerprint] [mountpoint]

rgpgfs will refuse to encrypt with untrusted keys. See gpg -k [fingerprint].

Example

Mount encrypted view of / in ~/rgpgfs:

$ rgpgfs --recipient 1234567890ABCDEF1234567890ABCDEF12345678 ~/rgpgfs

$ ls -1 ~/rgpfs/var/log/syslog.*
/home/me/rgpgfs/var/log/syslog.gpg
/home/me/rgpgfs/var/log/syslog.1.gpg
/home/me/rgpgfs/var/log/syslog.2.gz.gpg
/home/me/rgpgfs/var/log/syslog.3.gz.gpg

$ gpg --decrypt --for-your-eyes-only /home/me/rgpgfs/var/log/syslog.gpg | wc -l
gpg: encrypted with 4096-bit RSA key, ID 89ABCDEF12345678, created 2019-03-30
      "someone <someone@somewhere.me>"
3141

Change source directory

rgpgfs -o modules=subdir -o subdir=/source/dir /mount/point

Docker 🐳

Mount an enciphered view of named volume plain-data at /mnt/rgpgfs:

docker run --rm \
    --device /dev/fuse --cap-add SYS_ADMIN \
    -e RECIPIENT=1234567890ABCDEF1234567890ABCDEF12345678 \
    -v plain-data:/plain:ro \
    -v /mnt/rgpgfs:/encrypted:shared \
    fphammerle/rgpgfs

Interactively:

host$ mkdir /mnt/rgpgfs && chmod a+rwx /mnt/rgpgfs
host$ docker run --rm -it \
    -v plain-data:/plain:ro \
    -v /mnt/rgpgfs:/enc:shared \
    --device /dev/fuse --cap-add SYS_ADMIN \
    fphammerle/rgpgfs ash
container$ ls /plain
example.txt
container$ gpg --recv-keys 1234567890ABCDEF1234567890ABCDEF12345678
container$ gpg --edit-key 1234567890ABCDEF1234567890ABCDEF12345678
container gpg> trust
container gpg> 5
container gpg> quit
container$ rgpgfs -o allow_other,modules=subdir,subdir=/plain,recipient=12345678 /enc
container$ ls /enc
example.txt.gpg
# meanwhile in another shell:
host$ ls /mnt/rgpgfs
example.txt.gpg

When AppArmor is enabled you may need to add --security-opt apparmor:unconfined.

You may need to disable user namespace remapping for containers (dockerd option --userns-remap) due to https://github.com/moby/moby/issues/36472 .

Docker Compose 🐙

  1. Adapt paths & recipient in docker-compose.yml
  2. docker-compose up

Serve encrypted data via rsync ssh server

See examples/rsync-sshd