From 11e63117ca7979883d33c310ff1aa99a261e56a2 Mon Sep 17 00:00:00 2001 From: wheelz Date: Tue, 29 Sep 2026 20:53:47 +0000 Subject: [PATCH] Fix proxmox LXC PatchMon enrollment CA handling --- patchmon-enroll.sh | 58 +++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 55 insertions(+), 3 deletions(-) diff --git a/patchmon-enroll.sh b/patchmon-enroll.sh index bc4aceb..eabdb58 100755 --- a/patchmon-enroll.sh +++ b/patchmon-enroll.sh @@ -154,9 +154,8 @@ s = s.replace( ' error "Failed to install agent (exit: $install_exit_code)"', ' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"', ) -# The auto-enrollment script pipes a second, nested agent installer directly to -# sh. That nested installer can still contain PatchMon's internal/raw-IP URL, so -# intercept it, rewrite it to the canonical FQDN, then execute it. +# Direct-host generated installers and proxmox-lxc generated installers use +# different nested install shapes. Normalize both. old_nested = ''' # Download and execute installation script install_exit_code=0 install_output=$(curl $CURL_FLAGS \\ @@ -180,6 +179,59 @@ new_nested = ''' # Download, normalize, and execute installation script rm -f "$nested_install_script" ''' s = s.replace(old_nested, new_nested) + +# PatchMon's proxmox-lxc generated installer downloads a nested installer inside +# each container with `pct exec ... sh -c`. The containers also need the local +# Caddy CA before HTTPS calls to patchmon.wheelz.lab work. Inject a host-side CA +# push/update step and normalize the nested script inside the container before +# running it. +old_lxc_install = ''' # Download and execute in separate steps to avoid stdin issues with piping + # Pass CURL_FLAGS as environment variable to container + # Use sh -c for POSIX compatibility (Alpine uses ash, not bash) + install_output=$(timeout 180 pct exec "$vmid" -- sh -c " + export CURL_FLAGS='$CURL_FLAGS' + cd /tmp + curl \\$CURL_FLAGS \\ + -H \\"X-API-ID: $api_id\\" \\ + -H \\"X-API-KEY: $api_key\\" \\ + -o patchmon-install.sh \\ + '$install_url' && \\ + sh patchmon-install.sh && \\ + rm -f patchmon-install.sh + " 2>&1 &1 &1 || true)" + ca_push_output="$ca_push_output +$(timeout 60 pct exec "$vmid" -- sh -c "command -v update-ca-certificates >/dev/null 2>&1 && update-ca-certificates || true" 2>&1 &1