Fix proxmox LXC PatchMon enrollment CA handling
This commit is contained in:
+55
-3
@@ -154,9 +154,8 @@ s = s.replace(
|
||||
' error "Failed to install agent (exit: $install_exit_code)"',
|
||||
' printf "%s\\n" "$install_output" >&2\n error "Failed to install agent (exit: $install_exit_code)"',
|
||||
)
|
||||
# The auto-enrollment script pipes a second, nested agent installer directly to
|
||||
# sh. That nested installer can still contain PatchMon's internal/raw-IP URL, so
|
||||
# intercept it, rewrite it to the canonical FQDN, then execute it.
|
||||
# Direct-host generated installers and proxmox-lxc generated installers use
|
||||
# different nested install shapes. Normalize both.
|
||||
old_nested = ''' # Download and execute installation script
|
||||
install_exit_code=0
|
||||
install_output=$(curl $CURL_FLAGS \\
|
||||
@@ -180,6 +179,59 @@ new_nested = ''' # Download, normalize, and execute installation script
|
||||
rm -f "$nested_install_script"
|
||||
'''
|
||||
s = s.replace(old_nested, new_nested)
|
||||
|
||||
# PatchMon's proxmox-lxc generated installer downloads a nested installer inside
|
||||
# each container with `pct exec ... sh -c`. The containers also need the local
|
||||
# Caddy CA before HTTPS calls to patchmon.wheelz.lab work. Inject a host-side CA
|
||||
# push/update step and normalize the nested script inside the container before
|
||||
# running it.
|
||||
old_lxc_install = ''' # Download and execute in separate steps to avoid stdin issues with piping
|
||||
# Pass CURL_FLAGS as environment variable to container
|
||||
# Use sh -c for POSIX compatibility (Alpine uses ash, not bash)
|
||||
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
|
||||
export CURL_FLAGS='$CURL_FLAGS'
|
||||
cd /tmp
|
||||
curl \\$CURL_FLAGS \\
|
||||
-H \\"X-API-ID: $api_id\\" \\
|
||||
-H \\"X-API-KEY: $api_key\\" \\
|
||||
-o patchmon-install.sh \\
|
||||
'$install_url' && \\
|
||||
sh patchmon-install.sh && \\
|
||||
rm -f patchmon-install.sh
|
||||
" 2>&1 </dev/null) || install_exit_code=$?
|
||||
'''
|
||||
new_lxc_install = ''' # Install/trust the Wheelz Caddy root CA inside the LXC before the nested
|
||||
# installer contacts https://patchmon.wheelz.lab. Minimal containers may
|
||||
# not trust the host's CA bundle.
|
||||
ca_push_output=""
|
||||
if [[ -f "/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt" ]]; then
|
||||
ca_push_output=$(timeout 30 pct exec "$vmid" -- sh -c "mkdir -p /usr/local/share/ca-certificates" 2>&1 </dev/null || true)
|
||||
ca_push_output="$ca_push_output
|
||||
$(timeout 30 pct push "$vmid" /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt 2>&1 || true)"
|
||||
ca_push_output="$ca_push_output
|
||||
$(timeout 60 pct exec "$vmid" -- sh -c "command -v update-ca-certificates >/dev/null 2>&1 && update-ca-certificates || true" 2>&1 </dev/null || true)"
|
||||
fi
|
||||
|
||||
# Download and execute in separate steps to avoid stdin issues with piping.
|
||||
# Normalize the nested installer inside the container before running it.
|
||||
install_output=$(timeout 180 pct exec "$vmid" -- sh -c "
|
||||
export CURL_FLAGS='$CURL_FLAGS'
|
||||
export CURL_CA_BUNDLE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
|
||||
export SSL_CERT_FILE=\"/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt\"
|
||||
cd /tmp
|
||||
curl \\$CURL_FLAGS --cacert /usr/local/share/ca-certificates/wheelz-caddy-local-root.crt \\
|
||||
-H \\"X-API-ID: $api_id\\" \\
|
||||
-H \\"X-API-KEY: $api_key\\" \\
|
||||
-o patchmon-install.sh \\
|
||||
'$install_url' && \\
|
||||
sed -i 's#http://192.168.20.232:3000#$PATCHMON_URL#g' patchmon-install.sh && \\
|
||||
sh patchmon-install.sh && \\
|
||||
rm -f patchmon-install.sh
|
||||
" 2>&1 </dev/null) || install_exit_code=$?
|
||||
install_output="$ca_push_output
|
||||
$install_output"
|
||||
'''
|
||||
s = s.replace(old_lxc_install, new_lxc_install)
|
||||
p.write_text(s)
|
||||
PY
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user