From 30b66773938d2579a624c71f5a09aa39d922ef1f Mon Sep 17 00:00:00 2001 From: wheelz Date: Tue, 29 Sep 2026 22:55:01 +0000 Subject: [PATCH] Add wheelz user Termix key bootstrap --- README.md | 20 +++++ create-wheelz-user-termix-key.sh | 136 +++++++++++++++++++++++++++++++ 2 files changed, 156 insertions(+) create mode 100644 create-wheelz-user-termix-key.sh diff --git a/README.md b/README.md index 3898b94..2f6c34b 100644 --- a/README.md +++ b/README.md @@ -61,6 +61,26 @@ chmod +x install-docker.sh The old `Docker-Install.sh` filename still exists as a compatibility wrapper. +## Wheelz user + Termix SSH key + +Create/update the `wheelz` Linux user, prompt for a password, install the Termix public SSH key, and add the user to the sudo/wheel admin group when present: + +```bash +curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash +``` + +If you are not already root and the host has sudo: + +```bash +curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | sudo bash +``` + +Skip sudo/admin group membership: + +```bash +curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash -s -- --no-sudo +``` + ## PatchMon enrollment Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`. diff --git a/create-wheelz-user-termix-key.sh b/create-wheelz-user-termix-key.sh new file mode 100644 index 0000000..fa0d817 --- /dev/null +++ b/create-wheelz-user-termix-key.sh @@ -0,0 +1,136 @@ +#!/usr/bin/env bash +set -euo pipefail + +USER_NAME="wheelz" +PUBLIC_KEY="ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGFa4vhR/sd2s+Qod60qq1XtyN504BPKL/T+c/Kax7MY termix@docker-test-1" +ADD_SUDO=1 + +usage() { + cat <<'EOF' +Usage: create-wheelz-user-termix-key.sh [options] + +Creates the wheelz Linux user if missing, prompts for a password, and installs +Wheelz's Termix SSH public key into /home/wheelz/.ssh/authorized_keys. + +Options: + --user USER Username to create/update. Default: wheelz + --no-sudo Do not add the user to the sudo/admin group + -h, --help Show this help + +Run as root, or with sudo: + curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash +EOF +} + +while [[ $# -gt 0 ]]; do + case "$1" in + --user) + USER_NAME="${2:-}" + shift 2 + ;; + --no-sudo) + ADD_SUDO=0 + shift + ;; + -h|--help) + usage + exit 0 + ;; + *) + echo "Unknown option: $1" >&2 + usage >&2 + exit 2 + ;; + esac +done + +if [[ "$(id -u)" -ne 0 ]]; then + echo "ERROR: run as root, or use: curl ... | sudo bash" >&2 + exit 1 +fi + +if [[ -z "$USER_NAME" ]]; then + echo "ERROR: username cannot be empty" >&2 + exit 1 +fi + +if ! command -v useradd >/dev/null 2>&1; then + echo "ERROR: useradd command not found" >&2 + exit 1 +fi + +log() { printf '[Wheelz-User] %s\n' "$*"; } + +if id "$USER_NAME" >/dev/null 2>&1; then + log "User $USER_NAME already exists; keeping existing account." +else + log "Creating user $USER_NAME with home directory and /bin/bash shell." + useradd -m -s /bin/bash "$USER_NAME" +fi + +# Prompt through the controlling terminal so this works even when the script is piped from curl. +if [[ ! -r /dev/tty || ! -w /dev/tty ]]; then + echo "ERROR: no interactive terminal available for password prompt" >&2 + exit 1 +fi + +while true; do + printf 'Enter password for %s: ' "$USER_NAME" > /dev/tty + IFS= read -r -s PASS1 < /dev/tty + printf '\nConfirm password for %s: ' "$USER_NAME" > /dev/tty + IFS= read -r -s PASS2 < /dev/tty + printf '\n' > /dev/tty + + if [[ -z "$PASS1" ]]; then + echo "Password cannot be empty." > /dev/tty + continue + fi + if [[ "$PASS1" != "$PASS2" ]]; then + echo "Passwords did not match. Try again." > /dev/tty + continue + fi + break +done + +printf '%s:%s\n' "$USER_NAME" "$PASS1" | chpasswd +unset PASS1 PASS2 +log "Password set for $USER_NAME." + +HOME_DIR="$(getent passwd "$USER_NAME" | cut -d: -f6)" +if [[ -z "$HOME_DIR" || ! -d "$HOME_DIR" ]]; then + echo "ERROR: could not determine home directory for $USER_NAME" >&2 + exit 1 +fi + +SSH_DIR="$HOME_DIR/.ssh" +AUTH_KEYS="$SSH_DIR/authorized_keys" +mkdir -p "$SSH_DIR" +touch "$AUTH_KEYS" +chmod 700 "$SSH_DIR" +chmod 600 "$AUTH_KEYS" + +KEY_NO_COMMENT="$(awk '{print $1" "$2}' <<<"$PUBLIC_KEY")" +if awk -v key="$KEY_NO_COMMENT" 'BEGIN{found=0} {line=$1" "$2; if (line==key) found=1} END{exit found?0:1}' "$AUTH_KEYS"; then + log "Termix public key already present in $AUTH_KEYS." +else + printf '%s\n' "$PUBLIC_KEY" >> "$AUTH_KEYS" + log "Installed Termix public key in $AUTH_KEYS." +fi + +chown -R "$USER_NAME:$USER_NAME" "$SSH_DIR" +chmod 700 "$SSH_DIR" +chmod 600 "$AUTH_KEYS" + +if [[ "$ADD_SUDO" -eq 1 ]]; then + if getent group sudo >/dev/null 2>&1; then + usermod -aG sudo "$USER_NAME" + log "Added $USER_NAME to sudo group." + elif getent group wheel >/dev/null 2>&1; then + usermod -aG wheel "$USER_NAME" + log "Added $USER_NAME to wheel group." + else + log "No sudo/wheel group found; skipped admin group membership." + fi +fi + +log "Done. Test with: ssh $USER_NAME@"