Fix proxmox LXC PatchMon enrollment CA handling
This commit is contained in:
+55
-3
@@ -154,9 +154,8 @@ s = s.replace(
|
|||||||
' error "Failed to install agent (exit: $install_exit_code)"',
|
' error "Failed to install agent (exit: $install_exit_code)"',
|
||||||
' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"',
|
' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"',
|
||||||
)
|
)
|
||||||
# The auto-enrollment script pipes a second, nested agent installer directly to
|
# Direct-host generated installers and proxmox-lxc generated installers use
|
||||||
# sh. That nested installer can still contain PatchMon's internal/raw-IP URL, so
|
# different nested install shapes. Normalize both.
|
||||||
# intercept it, rewrite it to the canonical FQDN, then execute it.
|
|
||||||
old_nested = ''' # Download and execute installation script
|
old_nested = ''' # Download and execute installation script
|
||||||
install_exit_code=0
|
install_exit_code=0
|
||||||
install_output=$(curl $CURL_FLAGS \\
|
install_output=$(curl $CURL_FLAGS \\
|
||||||
@@ -180,6 +179,59 @@ new_nested = ''' # Download, normalize, and execute installation script
|
|||||||
rm -f "$nested_install_script"
|
rm -f "$nested_install_script"
|
||||||
'''
|
'''
|
||||||
s = s.replace(old_nested, new_nested)
|
s = s.replace(old_nested, new_nested)
|
||||||
|
|
||||||
|
# PatchMon's proxmox-lxc generated installer downloads a nested installer inside
|
||||||
|
# each container with `pct exec ... sh -c`. The containers also need the local
|
||||||
|
# Caddy CA before HTTPS calls to patchmon.wheelz.lab work. Inject a host-side CA
|
||||||
|
# push/update step and normalize the nested script inside the container before
|
||||||
|
# running it.
|
||||||
|
old_lxc_install = ''' # Download and execute in separate steps to avoid stdin issues with piping
|
||||||
|
# Pass CURL_FLAGS as environment variable to container
|
||||||
|
# Use sh -c for POSIX compatibility (Alpine uses ash, not bash)
|
||||||
|
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
|
||||||
|
export CURL_FLAGS='$CURL_FLAGS'
|
||||||
|
cd /tmp
|
||||||
|
curl \\$CURL_FLAGS \\
|
||||||
|
-H \\"X-API-ID: $api_id\\" \\
|
||||||
|
-H \\"X-API-KEY: $api_key\\" \\
|
||||||
|
-o patchmon-install.sh \\
|
||||||
|
'$install_url' && \\
|
||||||
|
sh patchmon-install.sh && \\
|
||||||
|
rm -f patchmon-install.sh
|
||||||
|
" 2>&1 </dev/null) || install_exit_code=$?
|
||||||
|
'''
|
||||||
|
new_lxc_install = ''' # Install/trust the Wheelz Caddy root CA inside the LXC before the nested
|
||||||
|
# installer contacts https://patchmon.wheelz.lab. Minimal containers may
|
||||||
|
# not trust the host's CA bundle.
|
||||||
|
ca_push_output=""
|
||||||
|
if [[ -f "/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt" ]]; then
|
||||||
|
ca_push_output=$(timeout 30 pct exec "$vmid" -- sh -c "mkdir -p /usr/local/share/ca-certificates" 2>&1 </dev/null || true)
|
||||||
|
ca_push_output="$ca_push_output
|
||||||
|
$(timeout 30 pct push "$vmid" /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt 2>&1 || true)"
|
||||||
|
ca_push_output="$ca_push_output
|
||||||
|
$(timeout 60 pct exec "$vmid" -- sh -c "command -v update-ca-certificates >/dev/null 2>&1 && update-ca-certificates || true" 2>&1 </dev/null || true)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Download and execute in separate steps to avoid stdin issues with piping.
|
||||||
|
# Normalize the nested installer inside the container before running it.
|
||||||
|
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
|
||||||
|
export CURL_FLAGS='$CURL_FLAGS'
|
||||||
|
export CURL_CA_BUNDLE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
|
||||||
|
export SSL_CERT_FILE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
|
||||||
|
cd /tmp
|
||||||
|
curl \\$CURL_FLAGS --cacert /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt \\
|
||||||
|
-H \\"X-API-ID: $api_id\\" \\
|
||||||
|
-H \\"X-API-KEY: $api_key\\" \\
|
||||||
|
-o patchmon-install.sh \\
|
||||||
|
'$install_url' && \\
|
||||||
|
sed -i 's#http://192.168.20.232:3000#$PATCHMON_URL#g' patchmon-install.sh && \\
|
||||||
|
sh patchmon-install.sh && \\
|
||||||
|
rm -f patchmon-install.sh
|
||||||
|
" 2>&1 </dev/null) || install_exit_code=$?
|
||||||
|
install_output="$ca_push_output
|
||||||
|
$install_output"
|
||||||
|
'''
|
||||||
|
s = s.replace(old_lxc_install, new_lxc_install)
|
||||||
p.write_text(s)
|
p.write_text(s)
|
||||||
PY
|
PY
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user