Make PatchMon enrollment trust Caddy CA explicitly
This commit is contained in:
+21
-1
@@ -4,6 +4,7 @@ set -Eeuo pipefail
|
||||
SCRIPT_NAME="$(basename "$0")"
|
||||
PATCHMON_SERVER="${PATCHMON_SERVER:-https://patchmon.wheelz.lab}"
|
||||
CADDY_CA_INSTALL_URL="${CADDY_CA_INSTALL_URL:-https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-caddy-local-ca.sh}"
|
||||
CADDY_CA_CERT_PATH="${CADDY_CA_CERT_PATH:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}"
|
||||
ENROLL_TYPE="${PATCHMON_ENROLL_TYPE:-direct-host}"
|
||||
TOKEN_KEY="${PATCHMON_AUTO_ENROLL_KEY:-}"
|
||||
TOKEN_SECRET="${PATCHMON_AUTO_ENROLL_SECRET:-}"
|
||||
@@ -89,6 +90,17 @@ install_caddy_ca_if_needed() {
|
||||
esac
|
||||
}
|
||||
|
||||
curl_patchmon() {
|
||||
local -a trust_args=()
|
||||
if [[ -f "$CADDY_CA_CERT_PATH" ]]; then
|
||||
# Use the exact Wheelz/Caddy root CA for PatchMon calls. Some minimal
|
||||
# Proxmox/Debian installs update the system store but curl still fails in
|
||||
# the same one-liner; this makes enrollment deterministic.
|
||||
trust_args=(--cacert "$CADDY_CA_CERT_PATH")
|
||||
fi
|
||||
curl "${trust_args[@]}" "$@"
|
||||
}
|
||||
|
||||
normalize_agent_config() {
|
||||
local cfg="/etc/patchmon/config.yml"
|
||||
[[ -f "$cfg" ]] || return 0
|
||||
@@ -124,6 +136,14 @@ s = p.read_text()
|
||||
# enroll/configure the agent against the FQDN.
|
||||
s = re.sub(r'export PATCHMON_URL="[^"]+"', f'export PATCHMON_URL="{server}"', s)
|
||||
s = s.replace('http://192.168.20.232:3000', server)
|
||||
# Make curl inside PatchMon's generated script trust the Wheelz/Caddy root even
|
||||
# on minimal hosts where the CA bundle refresh is not picked up immediately.
|
||||
if 'CURL_CA_BUNDLE=' not in s:
|
||||
s = s.replace(
|
||||
f'export PATCHMON_URL="{server}"',
|
||||
f'export PATCHMON_URL="{server}"\nexport CURL_CA_BUNDLE="${{CURL_CA_BUNDLE:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}}"\nexport SSL_CERT_FILE="${{SSL_CERT_FILE:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}}"',
|
||||
1,
|
||||
)
|
||||
# PatchMon's generated auto-enroll script captures the real agent-install
|
||||
# output, but by default only prints a generic "Failed to install agent" line.
|
||||
# Make failures actionable for one-liner installs.
|
||||
@@ -250,7 +270,7 @@ cleanup() { rm -f "$tmp_script"; }
|
||||
trap cleanup EXIT
|
||||
|
||||
log "Downloading PatchMon generated enrollment script"
|
||||
if ! curl -fsSL "$script_url" -o "$tmp_script"; then
|
||||
if ! curl_patchmon -fsSL "$script_url" -o "$tmp_script"; then
|
||||
fail "Failed to download PatchMon enrollment script. Check server URL, token, allowed IP range, and network access."
|
||||
fi
|
||||
|
||||
|
||||
Reference in New Issue
Block a user