Read host keys from environment variables

Philipp Marek philipp at marek.priv.at
Tue Aug 11 20:09:45 AEST 2026


Hi Darren,

thanks for the (immediate) answer!

>> for use in containers it would be nice to pull SSH host keys from
>> environment variables.
> 
> Well for one thing, on many systems environment variables are visible
> to every other user on the system, which seems like  a really bad
> attribute to have for the secret which is the only thing preventing
> someone from MITMing your connection.

Right.

_In containers_ there is no other user,
and passing secrets via the environment seems to be a normal usecase[1].


>> I saw "HostKeyAgent", but providing a unix-socket to a different
>> container running an agent
> 
> You could maybe cook something up with HostKeyAgent to an ssh-agent in
> the same container.  This works to load a key from an environment
> variable:
> 
> $ ssh-keygen -f tmp-key -t ed25519
> $ key=$(cat tmp-key)
> $ echo "$key" | ssh-add /dev/stdin
> 
> so you could in theory plumb an environment variable through to a host
> key available to sshd.  That sounds like a bad idea, though.

Hmmm, I guess I'll try that.

One point I see here is that in case someone breaks into the container,
there's now a nicely defined API to fetch the host keys from,
whereas with (ASAP removed) environment variables
the memory contents of PID 1 need to be investigated,
which sounds a bit harder to do from a minimal installation with no 
tools.


Thanks!


Ad 1: 
https://kubernetes.io/docs/tasks/inject-data-application/distribute-credentials-secure/#define-container-environment-variables-using-secret-data


More information about the openssh-unix-dev mailing list