this post was submitted on 06 Feb 2025
12 points (92.9% liked)

Linux

49711 readers
721 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 

My work has given me a remote windows desktop to use, that I access using AWS.

Through this windows desktop (accessed via a chrome web-browser), I can SSH into a compute node to do work.

I dont actually need this virtual desktop, I'd rather just SSH from my local machine directly to the compute node, using the remote desktop's network without having to spawn the desktop itself.

Ive been reading up about SSM agents[0] as a solution, but am unsure if I have the priveledges to do this myself.

https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-getting-started-enable-ssh-connections.html#ssh-connections-enable

Is this something I can easily do using the AWS credentials that I have?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 5 points 23 hours ago (1 children)

Maybe ask your work before you get fired?

[–] [email protected] 0 points 22 hours ago* (last edited 22 hours ago) (1 children)

I have, but the IT dept either willfully misinterprets my request, or does not actually know. No judgement from my side, as I am also uncertain.

My plan is to find a solution that complies with their security standards (i.e. through AWS's authentication spec), but allows me a VPN/SSH style passthrough.

[–] [email protected] 2 points 21 hours ago* (last edited 21 hours ago) (1 children)

Maybe ask them to provide you with a Linux cli only bastion? Then you've got a lot of options, it costs almost nothing, and it's even better security wise.

My plan is to find a solution that complies with their security standards (i.e. through AWS's authentication spec)

I think SSO is your best bet, if you use identity center.

[–] lordnikon 2 points 17 hours ago (1 children)

Most likely using workspaces and the reason for it is to stop the very thing they are trying to do to keep data from directly leaking out of their network. If they had a Linux desktop workspace if they opened the ssh port on the workspace Eni you could do that but that would send up all kinds of security alerts.

[–] [email protected] 1 points 17 hours ago (1 children)

I'm not sure what you use by workspaces, I haven't touched windows in a while.

Wouldn't a bastion with SSO do the same thing? In both cases OP needs to pass AWS based security checks in order to ssh from the bastion instance. And both options can be locked down by enterprise standards.

[–] lordnikon 2 points 16 hours ago

Workspaces is an AWS service that creates desktops that can be used via a workspace client or through the web browser like guacamole project. It's main feature is the data stays in AWS not on local hardware.