Add wheelz user Termix key bootstrap
This commit is contained in:
@@ -61,6 +61,26 @@ chmod +x install-docker.sh
|
|||||||
|
|
||||||
The old `Docker-Install.sh` filename still exists as a compatibility wrapper.
|
The old `Docker-Install.sh` filename still exists as a compatibility wrapper.
|
||||||
|
|
||||||
|
## Wheelz user + Termix SSH key
|
||||||
|
|
||||||
|
Create/update the `wheelz` Linux user, prompt for a password, install the Termix public SSH key, and add the user to the sudo/wheel admin group when present:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash
|
||||||
|
```
|
||||||
|
|
||||||
|
If you are not already root and the host has sudo:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | sudo bash
|
||||||
|
```
|
||||||
|
|
||||||
|
Skip sudo/admin group membership:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash -s -- --no-sudo
|
||||||
|
```
|
||||||
|
|
||||||
## PatchMon enrollment
|
## PatchMon enrollment
|
||||||
|
|
||||||
Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`.
|
Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`.
|
||||||
|
|||||||
@@ -0,0 +1,136 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
USER_NAME="wheelz"
|
||||||
|
PUBLIC_KEY="ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGFa4vhR/sd2s+Qod60qq1XtyN504BPKL/T+c/Kax7MY termix@docker-test-1"
|
||||||
|
ADD_SUDO=1
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
cat <<'EOF'
|
||||||
|
Usage: create-wheelz-user-termix-key.sh [options]
|
||||||
|
|
||||||
|
Creates the wheelz Linux user if missing, prompts for a password, and installs
|
||||||
|
Wheelz's Termix SSH public key into /home/wheelz/.ssh/authorized_keys.
|
||||||
|
|
||||||
|
Options:
|
||||||
|
--user USER Username to create/update. Default: wheelz
|
||||||
|
--no-sudo Do not add the user to the sudo/admin group
|
||||||
|
-h, --help Show this help
|
||||||
|
|
||||||
|
Run as root, or with sudo:
|
||||||
|
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
while [[ $# -gt 0 ]]; do
|
||||||
|
case "$1" in
|
||||||
|
--user)
|
||||||
|
USER_NAME="${2:-}"
|
||||||
|
shift 2
|
||||||
|
;;
|
||||||
|
--no-sudo)
|
||||||
|
ADD_SUDO=0
|
||||||
|
shift
|
||||||
|
;;
|
||||||
|
-h|--help)
|
||||||
|
usage
|
||||||
|
exit 0
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "Unknown option: $1" >&2
|
||||||
|
usage >&2
|
||||||
|
exit 2
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
if [[ "$(id -u)" -ne 0 ]]; then
|
||||||
|
echo "ERROR: run as root, or use: curl ... | sudo bash" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -z "$USER_NAME" ]]; then
|
||||||
|
echo "ERROR: username cannot be empty" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! command -v useradd >/dev/null 2>&1; then
|
||||||
|
echo "ERROR: useradd command not found" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
log() { printf '[Wheelz-User] %s\n' "$*"; }
|
||||||
|
|
||||||
|
if id "$USER_NAME" >/dev/null 2>&1; then
|
||||||
|
log "User $USER_NAME already exists; keeping existing account."
|
||||||
|
else
|
||||||
|
log "Creating user $USER_NAME with home directory and /bin/bash shell."
|
||||||
|
useradd -m -s /bin/bash "$USER_NAME"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Prompt through the controlling terminal so this works even when the script is piped from curl.
|
||||||
|
if [[ ! -r /dev/tty || ! -w /dev/tty ]]; then
|
||||||
|
echo "ERROR: no interactive terminal available for password prompt" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
while true; do
|
||||||
|
printf 'Enter password for %s: ' "$USER_NAME" > /dev/tty
|
||||||
|
IFS= read -r -s PASS1 < /dev/tty
|
||||||
|
printf '\nConfirm password for %s: ' "$USER_NAME" > /dev/tty
|
||||||
|
IFS= read -r -s PASS2 < /dev/tty
|
||||||
|
printf '\n' > /dev/tty
|
||||||
|
|
||||||
|
if [[ -z "$PASS1" ]]; then
|
||||||
|
echo "Password cannot be empty." > /dev/tty
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if [[ "$PASS1" != "$PASS2" ]]; then
|
||||||
|
echo "Passwords did not match. Try again." > /dev/tty
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
break
|
||||||
|
done
|
||||||
|
|
||||||
|
printf '%s:%s\n' "$USER_NAME" "$PASS1" | chpasswd
|
||||||
|
unset PASS1 PASS2
|
||||||
|
log "Password set for $USER_NAME."
|
||||||
|
|
||||||
|
HOME_DIR="$(getent passwd "$USER_NAME" | cut -d: -f6)"
|
||||||
|
if [[ -z "$HOME_DIR" || ! -d "$HOME_DIR" ]]; then
|
||||||
|
echo "ERROR: could not determine home directory for $USER_NAME" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
SSH_DIR="$HOME_DIR/.ssh"
|
||||||
|
AUTH_KEYS="$SSH_DIR/authorized_keys"
|
||||||
|
mkdir -p "$SSH_DIR"
|
||||||
|
touch "$AUTH_KEYS"
|
||||||
|
chmod 700 "$SSH_DIR"
|
||||||
|
chmod 600 "$AUTH_KEYS"
|
||||||
|
|
||||||
|
KEY_NO_COMMENT="$(awk '{print $1" "$2}' <<<"$PUBLIC_KEY")"
|
||||||
|
if awk -v key="$KEY_NO_COMMENT" 'BEGIN{found=0} {line=$1" "$2; if (line==key) found=1} END{exit found?0:1}' "$AUTH_KEYS"; then
|
||||||
|
log "Termix public key already present in $AUTH_KEYS."
|
||||||
|
else
|
||||||
|
printf '%s\n' "$PUBLIC_KEY" >> "$AUTH_KEYS"
|
||||||
|
log "Installed Termix public key in $AUTH_KEYS."
|
||||||
|
fi
|
||||||
|
|
||||||
|
chown -R "$USER_NAME:$USER_NAME" "$SSH_DIR"
|
||||||
|
chmod 700 "$SSH_DIR"
|
||||||
|
chmod 600 "$AUTH_KEYS"
|
||||||
|
|
||||||
|
if [[ "$ADD_SUDO" -eq 1 ]]; then
|
||||||
|
if getent group sudo >/dev/null 2>&1; then
|
||||||
|
usermod -aG sudo "$USER_NAME"
|
||||||
|
log "Added $USER_NAME to sudo group."
|
||||||
|
elif getent group wheel >/dev/null 2>&1; then
|
||||||
|
usermod -aG wheel "$USER_NAME"
|
||||||
|
log "Added $USER_NAME to wheel group."
|
||||||
|
else
|
||||||
|
log "No sudo/wheel group found; skipped admin group membership."
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Done. Test with: ssh $USER_NAME@<host>"
|
||||||
Reference in New Issue
Block a user