Make PatchMon enrollment trust Caddy CA explicitly

This commit is contained in:
2026-09-29 20:15:08 +00:00
parent 4a90f75cb2
commit 717585b519
+21 -1
View File
@@ -4,6 +4,7 @@ set -Eeuo pipefail
SCRIPT_NAME="$(basename "$0")"
PATCHMON_SERVER="${PATCHMON_SERVER:-https://patchmon.wheelz.lab}"
CADDY_CA_INSTALL_URL="${CADDY_CA_INSTALL_URL:-https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-caddy-local-ca.sh}"
CADDY_CA_CERT_PATH="${CADDY_CA_CERT_PATH:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}"
ENROLL_TYPE="${PATCHMON_ENROLL_TYPE:-direct-host}"
TOKEN_KEY="${PATCHMON_AUTO_ENROLL_KEY:-}"
TOKEN_SECRET="${PATCHMON_AUTO_ENROLL_SECRET:-}"
@@ -89,6 +90,17 @@ install_caddy_ca_if_needed() {
esac
}
curl_patchmon() {
local -a trust_args=()
if [[ -f "$CADDY_CA_CERT_PATH" ]]; then
# Use the exact Wheelz/Caddy root CA for PatchMon calls. Some minimal
# Proxmox/Debian installs update the system store but curl still fails in
# the same one-liner; this makes enrollment deterministic.
trust_args=(--cacert "$CADDY_CA_CERT_PATH")
fi
curl "${trust_args[@]}" "$@"
}
normalize_agent_config() {
local cfg="/etc/patchmon/config.yml"
[[ -f "$cfg" ]] || return 0
@@ -124,6 +136,14 @@ s = p.read_text()
# enroll/configure the agent against the FQDN.
s = re.sub(r'export PATCHMON_URL="[^"]+"', f'export PATCHMON_URL="{server}"', s)
s = s.replace('http://192.168.20.232:3000', server)
# Make curl inside PatchMon's generated script trust the Wheelz/Caddy root even
# on minimal hosts where the CA bundle refresh is not picked up immediately.
if 'CURL_CA_BUNDLE=' not in s:
s = s.replace(
f'export PATCHMON_URL="{server}"',
f'export PATCHMON_URL="{server}"\nexport CURL_CA_BUNDLE="${{CURL_CA_BUNDLE:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}}"\nexport SSL_CERT_FILE="${{SSL_CERT_FILE:-/usr/local/share/ca-certificates/wheelz-caddy-local-root.crt}}"',
1,
)
# PatchMon's generated auto-enroll script captures the real agent-install
# output, but by default only prints a generic "Failed to install agent" line.
# Make failures actionable for one-liner installs.
@@ -250,7 +270,7 @@ cleanup() { rm -f "$tmp_script"; }
trap cleanup EXIT
log "Downloading PatchMon generated enrollment script"
if ! curl -fsSL "$script_url" -o "$tmp_script"; then
if ! curl_patchmon -fsSL "$script_url" -o "$tmp_script"; then
fail "Failed to download PatchMon enrollment script. Check server URL, token, allowed IP range, and network access."
fi