Use PatchMon FQDN for enrollment
This commit is contained in:
@@ -63,7 +63,7 @@ The old `Docker-Install.sh` filename still exists as a compatibility wrapper.
|
||||
|
||||
## PatchMon enrollment
|
||||
|
||||
Enroll a Linux host into PatchMon. By default this uses the PatchMon LXC at `http://192.168.20.232:3000` and the `direct-host` enrollment type.
|
||||
Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`.
|
||||
|
||||
Recommended interactive one-liner. It prompts for the PatchMon auto-enrollment token key and secret:
|
||||
|
||||
@@ -86,10 +86,11 @@ curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/pat
|
||||
Useful options:
|
||||
|
||||
```text
|
||||
--server URL PatchMon base URL. Default: http://192.168.20.232:3000
|
||||
--server URL PatchMon base URL. Default: https://patchmon.wheelz.lab
|
||||
--type TYPE direct-host or proxmox-lxc. Default: direct-host
|
||||
--friendly-name NAME Friendly name to report to PatchMon
|
||||
--force Ask PatchMon's generated installer to force/reinstall when supported
|
||||
--no-caddy-ca Do not install the Wheelz/Caddy internal CA before enrollment
|
||||
--print-script Download and print the generated PatchMon script instead of running it
|
||||
-y, --yes Non-interactive mode
|
||||
```
|
||||
|
||||
+74
-2
@@ -2,12 +2,14 @@
|
||||
set -Eeuo pipefail
|
||||
|
||||
SCRIPT_NAME="$(basename "$0")"
|
||||
PATCHMON_SERVER="${PATCHMON_SERVER:-http://192.168.20.232:3000}"
|
||||
PATCHMON_SERVER="${PATCHMON_SERVER:-https://patchmon.wheelz.lab}"
|
||||
CADDY_CA_INSTALL_URL="${CADDY_CA_INSTALL_URL:-https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-caddy-local-ca.sh}"
|
||||
ENROLL_TYPE="${PATCHMON_ENROLL_TYPE:-direct-host}"
|
||||
TOKEN_KEY="${PATCHMON_AUTO_ENROLL_KEY:-}"
|
||||
TOKEN_SECRET="${PATCHMON_AUTO_ENROLL_SECRET:-}"
|
||||
FRIENDLY_NAME_VALUE="${FRIENDLY_NAME:-}"
|
||||
FORCE_INSTALL="false"
|
||||
INSTALL_CADDY_CA="true"
|
||||
PRINT_ONLY="false"
|
||||
YES="false"
|
||||
|
||||
@@ -20,12 +22,13 @@ Usage:
|
||||
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/patchmon-enroll.sh | sudo bash -s -- [options]
|
||||
|
||||
Options:
|
||||
--server URL PatchMon base URL. Default: http://192.168.20.232:3000
|
||||
--server URL PatchMon base URL. Default: https://patchmon.wheelz.lab
|
||||
--type TYPE Enrollment type: direct-host or proxmox-lxc. Default: direct-host
|
||||
--token-key KEY PatchMon auto-enrollment token key. Can also use PATCHMON_AUTO_ENROLL_KEY.
|
||||
--token-secret SECRET PatchMon auto-enrollment token secret. Can also use PATCHMON_AUTO_ENROLL_SECRET.
|
||||
--friendly-name NAME Friendly name to report to PatchMon.
|
||||
--force Ask PatchMon's generated installer to force/reinstall when supported.
|
||||
--no-caddy-ca Do not install the Wheelz/Caddy internal CA before enrollment.
|
||||
--print-script Download and print the generated PatchMon script instead of running it.
|
||||
-y, --yes Non-interactive. Fail if token values are missing instead of prompting.
|
||||
-h, --help Show this help.
|
||||
@@ -71,6 +74,60 @@ prompt_secret() {
|
||||
printf '%s' "$value"
|
||||
}
|
||||
|
||||
install_caddy_ca_if_needed() {
|
||||
if [[ "$INSTALL_CADDY_CA" != "true" ]]; then
|
||||
return 0
|
||||
fi
|
||||
case "$PATCHMON_SERVER" in
|
||||
https://patchmon.wheelz.lab|https://patchmon.wheelz.lab/*)
|
||||
log "Installing/updating Wheelz Caddy local root CA before contacting PatchMon"
|
||||
curl -fsSL "$CADDY_CA_INSTALL_URL" | bash
|
||||
;;
|
||||
*)
|
||||
log "Skipping Caddy CA install because PatchMon server is not patchmon.wheelz.lab"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
normalize_agent_config() {
|
||||
local cfg="/etc/patchmon/config.yml"
|
||||
[[ -f "$cfg" ]] || return 0
|
||||
log "Normalizing local PatchMon agent config to canonical FQDN"
|
||||
python3 - "$cfg" "$PATCHMON_SERVER" <<'PY'
|
||||
from pathlib import Path
|
||||
import re
|
||||
import sys
|
||||
p = Path(sys.argv[1])
|
||||
server = sys.argv[2].rstrip('/')
|
||||
s = p.read_text()
|
||||
s = re.sub(r'^patchmon_server:.*$', f'patchmon_server: {server}', s, flags=re.M)
|
||||
if 'skip_ssl_verify:' in s:
|
||||
s = re.sub(r'^skip_ssl_verify:.*$', 'skip_ssl_verify: false', s, flags=re.M)
|
||||
else:
|
||||
s += '\nskip_ssl_verify: false\n'
|
||||
p.write_text(s)
|
||||
PY
|
||||
}
|
||||
|
||||
normalize_generated_script() {
|
||||
local generated_script="$1"
|
||||
log "Normalizing generated PatchMon installer to use: $PATCHMON_SERVER"
|
||||
python3 - "$generated_script" "$PATCHMON_SERVER" <<'PY'
|
||||
from pathlib import Path
|
||||
import re
|
||||
import sys
|
||||
p = Path(sys.argv[1])
|
||||
server = sys.argv[2].rstrip('/')
|
||||
s = p.read_text()
|
||||
# PatchMon may generate installers using its internal/raw-IP origin even when the
|
||||
# wrapper contacted the canonical FQDN. Force the generated installer itself to
|
||||
# enroll/configure the agent against the FQDN.
|
||||
s = re.sub(r'export PATCHMON_URL="[^"]+"', f'export PATCHMON_URL="{server}"', s)
|
||||
s = s.replace('http://192.168.20.232:3000', server)
|
||||
p.write_text(s)
|
||||
PY
|
||||
}
|
||||
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
--server)
|
||||
@@ -102,6 +159,10 @@ while [[ $# -gt 0 ]]; do
|
||||
FORCE_INSTALL="true"
|
||||
shift
|
||||
;;
|
||||
--no-caddy-ca)
|
||||
INSTALL_CADDY_CA="false"
|
||||
shift
|
||||
;;
|
||||
--print-script)
|
||||
PRINT_ONLY="true"
|
||||
shift
|
||||
@@ -145,6 +206,10 @@ if [[ "$PRINT_ONLY" != "true" && "$(id -u)" -ne 0 ]]; then
|
||||
fail "This script must be run as root because PatchMon's generated installer installs a system agent. Use sudo."
|
||||
fi
|
||||
|
||||
if [[ "$PRINT_ONLY" != "true" ]]; then
|
||||
install_caddy_ca_if_needed
|
||||
fi
|
||||
|
||||
query="type=$(urlencode "$ENROLL_TYPE")&force=$(urlencode "$FORCE_INSTALL")&token_key=$(urlencode "$TOKEN_KEY")&token_secret=$(urlencode "$TOKEN_SECRET")"
|
||||
script_url="${PATCHMON_SERVER}/api/v1/auto-enrollment/script?${query}"
|
||||
tmp_script="$(mktemp /tmp/patchmon-enroll.XXXXXX.sh)"
|
||||
@@ -161,6 +226,7 @@ if ! head -n 1 "$tmp_script" | grep -q '^#!'; then
|
||||
sed -n '1,10p' "$tmp_script" >&2
|
||||
fail "Unexpected response from PatchMon enrollment endpoint"
|
||||
fi
|
||||
normalize_generated_script "$tmp_script"
|
||||
chmod 700 "$tmp_script"
|
||||
|
||||
if [[ "$PRINT_ONLY" == "true" ]]; then
|
||||
@@ -175,6 +241,12 @@ else
|
||||
sh "$tmp_script"
|
||||
fi
|
||||
|
||||
normalize_agent_config
|
||||
if command -v systemctl >/dev/null 2>&1 && systemctl list-unit-files 'patchmon-agent.service' --no-legend 2>/dev/null | grep -q .; then
|
||||
log "Restarting PatchMon agent after config normalization"
|
||||
systemctl restart patchmon-agent || warn "patchmon-agent restart failed; check service logs"
|
||||
fi
|
||||
|
||||
log "Verifying local PatchMon agent service"
|
||||
if command -v systemctl >/dev/null 2>&1; then
|
||||
if systemctl list-unit-files 'patchmon*' --no-legend 2>/dev/null | grep -q .; then
|
||||
|
||||
Reference in New Issue
Block a user