Use PatchMon FQDN for enrollment

This commit is contained in:
2026-09-29 16:58:43 +00:00
parent 8357693c06
commit 8ad89fddda
2 changed files with 77 additions and 4 deletions
+3 -2
View File
@@ -63,7 +63,7 @@ The old `Docker-Install.sh` filename still exists as a compatibility wrapper.
## PatchMon enrollment
Enroll a Linux host into PatchMon. By default this uses the PatchMon LXC at `http://192.168.20.232:3000` and the `direct-host` enrollment type.
Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`.
Recommended interactive one-liner. It prompts for the PatchMon auto-enrollment token key and secret:
@@ -86,10 +86,11 @@ curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/pat
Useful options:
```text
--server URL PatchMon base URL. Default: http://192.168.20.232:3000
--server URL PatchMon base URL. Default: https://patchmon.wheelz.lab
--type TYPE direct-host or proxmox-lxc. Default: direct-host
--friendly-name NAME Friendly name to report to PatchMon
--force Ask PatchMon's generated installer to force/reinstall when supported
--no-caddy-ca Do not install the Wheelz/Caddy internal CA before enrollment
--print-script Download and print the generated PatchMon script instead of running it
-y, --yes Non-interactive mode
```
+74 -2
View File
@@ -2,12 +2,14 @@
set -Eeuo pipefail
SCRIPT_NAME="$(basename "$0")"
PATCHMON_SERVER="${PATCHMON_SERVER:-http://192.168.20.232:3000}"
PATCHMON_SERVER="${PATCHMON_SERVER:-https://patchmon.wheelz.lab}"
CADDY_CA_INSTALL_URL="${CADDY_CA_INSTALL_URL:-https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-caddy-local-ca.sh}"
ENROLL_TYPE="${PATCHMON_ENROLL_TYPE:-direct-host}"
TOKEN_KEY="${PATCHMON_AUTO_ENROLL_KEY:-}"
TOKEN_SECRET="${PATCHMON_AUTO_ENROLL_SECRET:-}"
FRIENDLY_NAME_VALUE="${FRIENDLY_NAME:-}"
FORCE_INSTALL="false"
INSTALL_CADDY_CA="true"
PRINT_ONLY="false"
YES="false"
@@ -20,12 +22,13 @@ Usage:
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/patchmon-enroll.sh | sudo bash -s -- [options]
Options:
--server URL PatchMon base URL. Default: http://192.168.20.232:3000
--server URL PatchMon base URL. Default: https://patchmon.wheelz.lab
--type TYPE Enrollment type: direct-host or proxmox-lxc. Default: direct-host
--token-key KEY PatchMon auto-enrollment token key. Can also use PATCHMON_AUTO_ENROLL_KEY.
--token-secret SECRET PatchMon auto-enrollment token secret. Can also use PATCHMON_AUTO_ENROLL_SECRET.
--friendly-name NAME Friendly name to report to PatchMon.
--force Ask PatchMon's generated installer to force/reinstall when supported.
--no-caddy-ca Do not install the Wheelz/Caddy internal CA before enrollment.
--print-script Download and print the generated PatchMon script instead of running it.
-y, --yes Non-interactive. Fail if token values are missing instead of prompting.
-h, --help Show this help.
@@ -71,6 +74,60 @@ prompt_secret() {
printf '%s' "$value"
}
install_caddy_ca_if_needed() {
if [[ "$INSTALL_CADDY_CA" != "true" ]]; then
return 0
fi
case "$PATCHMON_SERVER" in
https://patchmon.wheelz.lab|https://patchmon.wheelz.lab/*)
log "Installing/updating Wheelz Caddy local root CA before contacting PatchMon"
curl -fsSL "$CADDY_CA_INSTALL_URL" | bash
;;
*)
log "Skipping Caddy CA install because PatchMon server is not patchmon.wheelz.lab"
;;
esac
}
normalize_agent_config() {
local cfg="/etc/patchmon/config.yml"
[[ -f "$cfg" ]] || return 0
log "Normalizing local PatchMon agent config to canonical FQDN"
python3 - "$cfg" "$PATCHMON_SERVER" <<'PY'
from pathlib import Path
import re
import sys
p = Path(sys.argv[1])
server = sys.argv[2].rstrip('/')
s = p.read_text()
s = re.sub(r'^patchmon_server:.*$', f'patchmon_server: {server}', s, flags=re.M)
if 'skip_ssl_verify:' in s:
s = re.sub(r'^skip_ssl_verify:.*$', 'skip_ssl_verify: false', s, flags=re.M)
else:
s += '\nskip_ssl_verify: false\n'
p.write_text(s)
PY
}
normalize_generated_script() {
local generated_script="$1"
log "Normalizing generated PatchMon installer to use: $PATCHMON_SERVER"
python3 - "$generated_script" "$PATCHMON_SERVER" <<'PY'
from pathlib import Path
import re
import sys
p = Path(sys.argv[1])
server = sys.argv[2].rstrip('/')
s = p.read_text()
# PatchMon may generate installers using its internal/raw-IP origin even when the
# wrapper contacted the canonical FQDN. Force the generated installer itself to
# enroll/configure the agent against the FQDN.
s = re.sub(r'export PATCHMON_URL="[^"]+"', f'export PATCHMON_URL="{server}"', s)
s = s.replace('http://192.168.20.232:3000', server)
p.write_text(s)
PY
}
while [[ $# -gt 0 ]]; do
case "$1" in
--server)
@@ -102,6 +159,10 @@ while [[ $# -gt 0 ]]; do
FORCE_INSTALL="true"
shift
;;
--no-caddy-ca)
INSTALL_CADDY_CA="false"
shift
;;
--print-script)
PRINT_ONLY="true"
shift
@@ -145,6 +206,10 @@ if [[ "$PRINT_ONLY" != "true" && "$(id -u)" -ne 0 ]]; then
fail "This script must be run as root because PatchMon's generated installer installs a system agent. Use sudo."
fi
if [[ "$PRINT_ONLY" != "true" ]]; then
install_caddy_ca_if_needed
fi
query="type=$(urlencode "$ENROLL_TYPE")&force=$(urlencode "$FORCE_INSTALL")&token_key=$(urlencode "$TOKEN_KEY")&token_secret=$(urlencode "$TOKEN_SECRET")"
script_url="${PATCHMON_SERVER}/api/v1/auto-enrollment/script?${query}"
tmp_script="$(mktemp /tmp/patchmon-enroll.XXXXXX.sh)"
@@ -161,6 +226,7 @@ if ! head -n 1 "$tmp_script" | grep -q '^#!'; then
sed -n '1,10p' "$tmp_script" >&2
fail "Unexpected response from PatchMon enrollment endpoint"
fi
normalize_generated_script "$tmp_script"
chmod 700 "$tmp_script"
if [[ "$PRINT_ONLY" == "true" ]]; then
@@ -175,6 +241,12 @@ else
sh "$tmp_script"
fi
normalize_agent_config
if command -v systemctl >/dev/null 2>&1 && systemctl list-unit-files 'patchmon-agent.service' --no-legend 2>/dev/null | grep -q .; then
log "Restarting PatchMon agent after config normalization"
systemctl restart patchmon-agent || warn "patchmon-agent restart failed; check service logs"
fi
log "Verifying local PatchMon agent service"
if command -v systemctl >/dev/null 2>&1; then
if systemctl list-unit-files 'patchmon*' --no-legend 2>/dev/null | grep -q .; then