Fix proxmox LXC PatchMon enrollment CA handling

This commit is contained in:
2026-09-29 20:53:47 +00:00
parent 131f901a58
commit 11e63117ca
+55 -3
View File
@@ -154,9 +154,8 @@ s = s.replace(
' error "Failed to install agent (exit: $install_exit_code)"', ' error "Failed to install agent (exit: $install_exit_code)"',
' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"', ' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"',
) )
# The auto-enrollment script pipes a second, nested agent installer directly to # Direct-host generated installers and proxmox-lxc generated installers use
# sh. That nested installer can still contain PatchMon's internal/raw-IP URL, so # different nested install shapes. Normalize both.
# intercept it, rewrite it to the canonical FQDN, then execute it.
old_nested = ''' # Download and execute installation script old_nested = ''' # Download and execute installation script
install_exit_code=0 install_exit_code=0
install_output=$(curl $CURL_FLAGS \\ install_output=$(curl $CURL_FLAGS \\
@@ -180,6 +179,59 @@ new_nested = ''' # Download, normalize, and execute installation script
rm -f "$nested_install_script" rm -f "$nested_install_script"
''' '''
s = s.replace(old_nested, new_nested) s = s.replace(old_nested, new_nested)
# PatchMon's proxmox-lxc generated installer downloads a nested installer inside
# each container with `pct exec ... sh -c`. The containers also need the local
# Caddy CA before HTTPS calls to patchmon.wheelz.lab work. Inject a host-side CA
# push/update step and normalize the nested script inside the container before
# running it.
old_lxc_install = ''' # Download and execute in separate steps to avoid stdin issues with piping
# Pass CURL_FLAGS as environment variable to container
# Use sh -c for POSIX compatibility (Alpine uses ash, not bash)
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
export CURL_FLAGS='$CURL_FLAGS'
cd /tmp
curl \\$CURL_FLAGS \\
-H \\"X-API-ID: $api_id\\" \\
-H \\"X-API-KEY: $api_key\\" \\
-o patchmon-install.sh \\
'$install_url' && \\
sh patchmon-install.sh && \\
rm -f patchmon-install.sh
" 2>&1 </dev/null) || install_exit_code=$?
'''
new_lxc_install = ''' # Install/trust the Wheelz Caddy root CA inside the LXC before the nested
# installer contacts https://patchmon.wheelz.lab. Minimal containers may
# not trust the host's CA bundle.
ca_push_output=""
if [[ -f "/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt" ]]; then
ca_push_output=$(timeout 30 pct exec "$vmid" -- sh -c "mkdir -p /usr/local/share/ca-certificates" 2>&1 </dev/null || true)
ca_push_output="$ca_push_output
$(timeout 30 pct push "$vmid" /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt 2>&1 || true)"
ca_push_output="$ca_push_output
$(timeout 60 pct exec "$vmid" -- sh -c "command -v update-ca-certificates >/dev/null 2>&1 && update-ca-certificates || true" 2>&1 </dev/null || true)"
fi
# Download and execute in separate steps to avoid stdin issues with piping.
# Normalize the nested installer inside the container before running it.
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
export CURL_FLAGS='$CURL_FLAGS'
export CURL_CA_BUNDLE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
export SSL_CERT_FILE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
cd /tmp
curl \\$CURL_FLAGS --cacert /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt \\
-H \\"X-API-ID: $api_id\\" \\
-H \\"X-API-KEY: $api_key\\" \\
-o patchmon-install.sh \\
'$install_url' && \\
sed -i 's#http://192.168.20.232:3000#$PATCHMON_URL#g' patchmon-install.sh && \\
sh patchmon-install.sh && \\
rm -f patchmon-install.sh
" 2>&1 </dev/null) || install_exit_code=$?
install_output="$ca_push_output
$install_output"
'''
s = s.replace(old_lxc_install, new_lxc_install)
p.write_text(s) p.write_text(s)
PY PY
} }