mirror of
https://github.com/edgebox-iot/edgeboxctl.git
synced 2026-09-24 05:41:43 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9bbe3d9997 | ||
|
|
7996c552f8 | ||
|
|
dbc831e972 | ||
|
|
19acbcbaad | ||
|
|
1e0a5df370 | ||
|
|
7913be080d |
@@ -13,7 +13,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@v4
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: '1.20.2'
|
go-version: '1.20.2'
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Changelog
|
||||||
|
|
||||||
|
## [1.4.0] - 23-09-2026
|
||||||
|
|
||||||
|
* Added dashboard-managed SSH public-key access.
|
||||||
|
* Validates ED25519 public keys and reports their SHA256 fingerprints.
|
||||||
|
* Atomically installs or removes only the marked Edgebox key while preserving all other authorized keys.
|
||||||
|
* Never generates, reads, stores, logs, or returns SSH private keys.
|
||||||
|
|
||||||
|
## [1.3.2] - 08-12-2024
|
||||||
|
|
||||||
|
* Fix to Browser Dev feature:
|
||||||
|
* Checking browser dev url when internet_accessible was checking the incorrect path. This is now fixed.
|
||||||
|
|
||||||
|
## [1.3.1] - 08-12-2024
|
||||||
|
|
||||||
|
* Fixes to Browser Dev feature:
|
||||||
|
* Now edgeboxctl also fetches or generates the browser dev environment url and saves it into an option both when starting, and every time the browser dev status is fetched.
|
||||||
|
|
||||||
|
## [1.3.0] - 05-12-2024
|
||||||
|
|
||||||
|
* Added Edgebox Browser Development Environment Feature Support
|
||||||
|
* Added tasks for handling browser development environment into tasks.go
|
||||||
|
* Added executable tasks to ExecuteTask and scheduled ones to ExecuteSchedules
|
||||||
|
* Other bug fixes and improvements.
|
||||||
|
|
||||||
|
### Missing Past Releases
|
||||||
|
|
||||||
|
Release notes for past versions are not available in this file. Please refer to the [GitHub releases](https://hithub.com/edgebox-iot/edgeboxctl/releases) for more information. Feel free to contribute to this file by adding missing release notes.
|
||||||
@@ -67,7 +67,7 @@ run:
|
|||||||
install:
|
install:
|
||||||
@echo "📦 Installing edgeboxctl service (${RELEASE}) for ${GOOS} (${GOARCH})\n"
|
@echo "📦 Installing edgeboxctl service (${RELEASE}) for ${GOOS} (${GOARCH})\n"
|
||||||
|
|
||||||
@echo "🚧 Stopping edgeboxctl service if it is running"
|
@echo "�🚧 Stopping edgeboxctl service if it is running"
|
||||||
sudo systemctl stop edgeboxctl || true
|
sudo systemctl stop edgeboxctl || true
|
||||||
|
|
||||||
@echo "\n🗑️ Removing old edgeboxctl binary and service"
|
@echo "\n🗑️ Removing old edgeboxctl binary and service"
|
||||||
|
|||||||
@@ -59,10 +59,12 @@ To get a local copy up and running follow these simple steps.
|
|||||||
If you're running for development purposes, a docker container suffices, so make sure you have:
|
If you're running for development purposes, a docker container suffices, so make sure you have:
|
||||||
|
|
||||||
* docker
|
* docker
|
||||||
* docker compose
|
* docker compose (docker-compose-v2 package)
|
||||||
|
|
||||||
Check the following links for more info on [Docker](https://www.docker.com/) and [Docker Compose](https://docs.docker.com/compose/).
|
Check the following links for more info on [Docker](https://www.docker.com/) and [Docker Compose](https://docs.docker.com/compose/).
|
||||||
|
|
||||||
|
**Note:** If you don't have `docker compose` available, install it with: `sudo apt-get install docker-compose-v2`
|
||||||
|
|
||||||
Aditionally, `edgeboxctl` needs the following bash commands available wherever it runs:
|
Aditionally, `edgeboxctl` needs the following bash commands available wherever it runs:
|
||||||
|
|
||||||
* `arm-linux-gnueabi-gcc` (`sudo apt-get install gcc-arm*`)
|
* `arm-linux-gnueabi-gcc` (`sudo apt-get install gcc-arm*`)
|
||||||
@@ -79,10 +81,10 @@ Aditionally, `edgeboxctl` needs the following bash commands available wherever i
|
|||||||
```sh
|
```sh
|
||||||
git clone https://github.com/edgebox-iot/edgeboxctl.git
|
git clone https://github.com/edgebox-iot/edgeboxctl.git
|
||||||
```
|
```
|
||||||
2. Run Docker-Compose
|
2. Run Docker Compose
|
||||||
```sh
|
|
||||||
docker-compose up
|
|
||||||
```
|
```
|
||||||
|
docker compose up
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -489,7 +489,7 @@ func GetEdgeAppServices(ID string) []EdgeAppService {
|
|||||||
// Check if the service is actually running
|
// Check if the service is actually running
|
||||||
if shouldBeRunning {
|
if shouldBeRunning {
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
||||||
cmdResult := utils.Exec(wsPath, "docker-compose", cmdArgs)
|
cmdResult := utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
if cmdResult != "" {
|
if cmdResult != "" {
|
||||||
isRunning = true
|
isRunning = true
|
||||||
}
|
}
|
||||||
@@ -511,7 +511,7 @@ func RunEdgeApp(ID string) EdgeAppStatus {
|
|||||||
for _, service := range services {
|
for _, service := range services {
|
||||||
|
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "start", service.ID}
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "start", service.ID}
|
||||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
}
|
}
|
||||||
|
|
||||||
// Wait for it to settle up before continuing...
|
// Wait for it to settle up before continuing...
|
||||||
@@ -529,7 +529,7 @@ func StopEdgeApp(ID string) EdgeAppStatus {
|
|||||||
for _, service := range services {
|
for _, service := range services {
|
||||||
|
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "stop", service.ID}
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "stop", service.ID}
|
||||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
}
|
}
|
||||||
|
|
||||||
// Wait for it to settle up before continuing...
|
// Wait for it to settle up before continuing...
|
||||||
|
|||||||
@@ -0,0 +1,217 @@
|
|||||||
|
package tasks
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/binary"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
sshDirectory = "/root/.ssh"
|
||||||
|
managedSSHComment = "edgebox-dashboard-managed"
|
||||||
|
)
|
||||||
|
|
||||||
|
type sshAccessResult struct {
|
||||||
|
Status string `json:"status"`
|
||||||
|
PublicKey string `json:"public_key,omitempty"`
|
||||||
|
Fingerprint string `json:"fingerprint,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func taskEnableSSHAccess(args taskEnableSSHAccessArgs) (string, error) {
|
||||||
|
if err := verifyRootSSHAccess(); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
publicKey, fingerprint, err := parseSSHEd25519PublicKey(args.PublicKey)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(sshDirectory, publicKey); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.WriteOption("SSH_ACCESS_ENABLED", "true")
|
||||||
|
utils.WriteOption("SSH_PUBLIC_KEY", publicKey)
|
||||||
|
utils.WriteOption("SSH_KEY_FINGERPRINT", fingerprint)
|
||||||
|
|
||||||
|
result, err := json.Marshal(sshAccessResult{
|
||||||
|
Status: "enabled",
|
||||||
|
PublicKey: publicKey,
|
||||||
|
Fingerprint: fingerprint,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
return string(result), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func taskDisableSSHAccess() (string, error) {
|
||||||
|
if err := reconcileManagedSSHKey(sshDirectory, ""); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.WriteOption("SSH_ACCESS_ENABLED", "false")
|
||||||
|
utils.DeleteOption("SSH_PUBLIC_KEY")
|
||||||
|
utils.DeleteOption("SSH_KEY_FINGERPRINT")
|
||||||
|
|
||||||
|
result, err := json.Marshal(sshAccessResult{Status: "disabled"})
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
return string(result), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseSSHEd25519PublicKey(input string) (string, string, error) {
|
||||||
|
trimmed := strings.TrimSpace(input)
|
||||||
|
if trimmed == "" || strings.ContainsAny(trimmed, "\r\n") {
|
||||||
|
return "", "", fmt.Errorf("provide exactly one SSH public key")
|
||||||
|
}
|
||||||
|
|
||||||
|
fields := strings.Fields(trimmed)
|
||||||
|
if len(fields) < 2 || len(fields) > 3 || fields[0] != "ssh-ed25519" {
|
||||||
|
return "", "", fmt.Errorf("only one ssh-ed25519 public key is supported")
|
||||||
|
}
|
||||||
|
|
||||||
|
keyBlob, err := base64.StdEncoding.DecodeString(fields[1])
|
||||||
|
if err != nil || !validEd25519KeyBlob(keyBlob) {
|
||||||
|
return "", "", fmt.Errorf("invalid ssh-ed25519 public key")
|
||||||
|
}
|
||||||
|
|
||||||
|
digest := sha256.Sum256(keyBlob)
|
||||||
|
publicKey := "ssh-ed25519 " + base64.StdEncoding.EncodeToString(keyBlob) + " " + managedSSHComment
|
||||||
|
fingerprint := "SHA256:" + base64.RawStdEncoding.EncodeToString(digest[:])
|
||||||
|
|
||||||
|
return publicKey, fingerprint, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func validEd25519KeyBlob(blob []byte) bool {
|
||||||
|
if len(blob) < 4 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
typeLength := int(binary.BigEndian.Uint32(blob[:4]))
|
||||||
|
if typeLength != len("ssh-ed25519") || len(blob) < 4+typeLength+4 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if string(blob[4:4+typeLength]) != "ssh-ed25519" {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
keyLengthOffset := 4 + typeLength
|
||||||
|
keyLength := int(binary.BigEndian.Uint32(blob[keyLengthOffset : keyLengthOffset+4]))
|
||||||
|
return keyLength == 32 && len(blob) == keyLengthOffset+4+keyLength
|
||||||
|
}
|
||||||
|
|
||||||
|
func reconcileManagedSSHKey(directory string, publicKey string) error {
|
||||||
|
if info, err := os.Lstat(directory); err == nil {
|
||||||
|
if info.Mode()&os.ModeSymlink != 0 || !info.IsDir() {
|
||||||
|
return fmt.Errorf("SSH directory is not a regular directory")
|
||||||
|
}
|
||||||
|
} else if !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("inspect SSH directory: %w", err)
|
||||||
|
} else if err := os.MkdirAll(directory, 0700); err != nil {
|
||||||
|
return fmt.Errorf("create SSH directory: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := os.Chmod(directory, 0700); err != nil {
|
||||||
|
return fmt.Errorf("secure SSH directory: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||||
|
if info, err := os.Lstat(authorizedKeysPath); err == nil && info.Mode()&os.ModeSymlink != 0 {
|
||||||
|
return fmt.Errorf("authorized_keys must not be a symbolic link")
|
||||||
|
} else if err != nil && !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("inspect authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
existing, err := os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil && !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("read authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
lines := strings.Split(string(existing), "\n")
|
||||||
|
kept := make([]string, 0, len(lines)+1)
|
||||||
|
for _, line := range lines {
|
||||||
|
if strings.TrimSpace(line) == "" || isManagedSSHKey(line) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
kept = append(kept, line)
|
||||||
|
}
|
||||||
|
if publicKey != "" {
|
||||||
|
kept = append(kept, publicKey)
|
||||||
|
}
|
||||||
|
|
||||||
|
contents := ""
|
||||||
|
if len(kept) > 0 {
|
||||||
|
contents = strings.Join(kept, "\n") + "\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
temporary, err := os.CreateTemp(directory, ".authorized_keys-*")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("create authorized_keys temporary file: %w", err)
|
||||||
|
}
|
||||||
|
temporaryPath := temporary.Name()
|
||||||
|
defer os.Remove(temporaryPath)
|
||||||
|
|
||||||
|
if err := temporary.Chmod(0600); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("secure authorized_keys temporary file: %w", err)
|
||||||
|
}
|
||||||
|
if _, err := temporary.WriteString(contents); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("write authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := temporary.Sync(); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("sync authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := temporary.Close(); err != nil {
|
||||||
|
return fmt.Errorf("close authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := os.Rename(temporaryPath, authorizedKeysPath); err != nil {
|
||||||
|
return fmt.Errorf("replace authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func isManagedSSHKey(line string) bool {
|
||||||
|
fields := strings.Fields(line)
|
||||||
|
return len(fields) == 3 && fields[2] == managedSSHComment
|
||||||
|
}
|
||||||
|
|
||||||
|
func verifyRootSSHAccess() error {
|
||||||
|
sshdPath, err := exec.LookPath("sshd")
|
||||||
|
if err != nil {
|
||||||
|
sshdPath = "/usr/sbin/sshd"
|
||||||
|
if _, statErr := os.Stat(sshdPath); statErr != nil {
|
||||||
|
return fmt.Errorf("OpenSSH server is not installed")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output, err := exec.Command(sshdPath, "-T").Output()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("could not verify the effective SSH server configuration")
|
||||||
|
}
|
||||||
|
|
||||||
|
settings := string(output)
|
||||||
|
if !strings.Contains(settings, "pubkeyauthentication yes") {
|
||||||
|
return fmt.Errorf("SSH public-key authentication is disabled")
|
||||||
|
}
|
||||||
|
if strings.Contains(settings, "permitrootlogin no") {
|
||||||
|
return fmt.Errorf("SSH root login is disabled")
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,111 @@
|
|||||||
|
package tasks
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/binary"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func testPublicKey(t *testing.T) string {
|
||||||
|
t.Helper()
|
||||||
|
blob := make([]byte, 4+len("ssh-ed25519")+4+32)
|
||||||
|
binary.BigEndian.PutUint32(blob[:4], uint32(len("ssh-ed25519")))
|
||||||
|
copy(blob[4:], "ssh-ed25519")
|
||||||
|
offset := 4 + len("ssh-ed25519")
|
||||||
|
binary.BigEndian.PutUint32(blob[offset:offset+4], 32)
|
||||||
|
for index := 0; index < 32; index++ {
|
||||||
|
blob[offset+4+index] = byte(index + 1)
|
||||||
|
}
|
||||||
|
return "ssh-ed25519 " + base64.StdEncoding.EncodeToString(blob) + " workstation"
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseSSHEd25519PublicKey(t *testing.T) {
|
||||||
|
publicKey, fingerprint, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if !strings.HasSuffix(publicKey, " "+managedSSHComment) {
|
||||||
|
t.Fatalf("public key does not have managed marker: %q", publicKey)
|
||||||
|
}
|
||||||
|
if !strings.HasPrefix(fingerprint, "SHA256:") {
|
||||||
|
t.Fatalf("unexpected fingerprint: %q", fingerprint)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseSSHEd25519PublicKeyRejectsUnsafeInput(t *testing.T) {
|
||||||
|
inputs := []string{
|
||||||
|
"",
|
||||||
|
"-----BEGIN OPENSSH PRIVATE KEY-----",
|
||||||
|
testPublicKey(t) + "\n" + testPublicKey(t),
|
||||||
|
"command=whoami " + testPublicKey(t),
|
||||||
|
"ssh-rsa AAAA invalid",
|
||||||
|
}
|
||||||
|
for _, input := range inputs {
|
||||||
|
if _, _, err := parseSSHEd25519PublicKey(input); err == nil {
|
||||||
|
t.Fatalf("expected input to be rejected: %q", input)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReconcileManagedSSHKeyPreservesUnrelatedKeys(t *testing.T) {
|
||||||
|
directory := t.TempDir()
|
||||||
|
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||||
|
original := "# operator key\nssh-ed25519 AAAAoperator operator\n"
|
||||||
|
if err := os.WriteFile(authorizedKeysPath, []byte(original), 0644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
publicKey, _, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
contents, err := os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if strings.Count(string(contents), managedSSHComment) != 1 {
|
||||||
|
t.Fatalf("managed key is not idempotent: %s", contents)
|
||||||
|
}
|
||||||
|
if !strings.Contains(string(contents), original) {
|
||||||
|
t.Fatalf("unrelated content was changed: %s", contents)
|
||||||
|
}
|
||||||
|
if info, err := os.Stat(authorizedKeysPath); err != nil || info.Mode().Perm() != 0600 {
|
||||||
|
t.Fatalf("authorized_keys mode is not 0600: %v, %v", info, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(directory, ""); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
contents, err = os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if string(contents) != original {
|
||||||
|
t.Fatalf("disable changed unrelated content: %q", contents)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReconcileManagedSSHKeyRejectsSymlink(t *testing.T) {
|
||||||
|
directory := t.TempDir()
|
||||||
|
target := filepath.Join(directory, "target")
|
||||||
|
if err := os.WriteFile(target, []byte("preserve me"), 0600); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := os.Symlink(target, filepath.Join(directory, "authorized_keys")); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(directory, ""); err == nil {
|
||||||
|
t.Fatal("expected symlink to be rejected")
|
||||||
|
}
|
||||||
|
}
|
||||||
+153
-99
@@ -1,16 +1,16 @@
|
|||||||
package tasks
|
package tasks
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bufio"
|
||||||
"database/sql"
|
"database/sql"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
"log"
|
"log"
|
||||||
"strconv"
|
|
||||||
"time"
|
|
||||||
"os/exec"
|
|
||||||
"strings"
|
|
||||||
"os"
|
"os"
|
||||||
"bufio"
|
"os/exec"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
"github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
||||||
"github.com/edgebox-iot/edgeboxctl/internal/edgeapps"
|
"github.com/edgebox-iot/edgeboxctl/internal/edgeapps"
|
||||||
@@ -18,6 +18,8 @@ import (
|
|||||||
"github.com/edgebox-iot/edgeboxctl/internal/system"
|
"github.com/edgebox-iot/edgeboxctl/internal/system"
|
||||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
|
||||||
|
"github.com/joho/godotenv"
|
||||||
|
|
||||||
_ "github.com/go-sql-driver/mysql" // Mysql Driver
|
_ "github.com/go-sql-driver/mysql" // Mysql Driver
|
||||||
_ "github.com/mattn/go-sqlite3" // SQlite Driver
|
_ "github.com/mattn/go-sqlite3" // SQlite Driver
|
||||||
)
|
)
|
||||||
@@ -75,7 +77,7 @@ type taskSetEdgeAppOptionsArgs struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type taskSetEdgeAppBasicAuthArgs struct {
|
type taskSetEdgeAppBasicAuthArgs struct {
|
||||||
ID string `json:"id"`
|
ID string `json:"id"`
|
||||||
Login TaskBasicAuth `json:"login"`
|
Login TaskBasicAuth `json:"login"`
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -97,10 +99,10 @@ type taskEnablePublicDashboardArgs struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type taskSetupBackupsArgs struct {
|
type taskSetupBackupsArgs struct {
|
||||||
Service string `json:"service"`
|
Service string `json:"service"`
|
||||||
AccessKeyID string `json:"access_key_id"`
|
AccessKeyID string `json:"access_key_id"`
|
||||||
SecretAccessKey string `json:"secret_access_key"`
|
SecretAccessKey string `json:"secret_access_key"`
|
||||||
RepositoryName string `json:"repository_name"`
|
RepositoryName string `json:"repository_name"`
|
||||||
RepositoryPassword string `json:"repository_password"`
|
RepositoryPassword string `json:"repository_password"`
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -112,6 +114,9 @@ type taskSetBrowserDevPasswordArgs struct {
|
|||||||
Password string `json:"password"`
|
Password string `json:"password"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type taskEnableSSHAccessArgs struct {
|
||||||
|
PublicKey string `json:"public_key"`
|
||||||
|
}
|
||||||
|
|
||||||
const STATUS_CREATED int = 0
|
const STATUS_CREATED int = 0
|
||||||
const STATUS_EXECUTING int = 1
|
const STATUS_EXECUTING int = 1
|
||||||
@@ -272,7 +277,7 @@ func ExecuteTask(task Task) Task {
|
|||||||
log.Println("Stopping Cloudflare Tunnel...")
|
log.Println("Stopping Cloudflare Tunnel...")
|
||||||
taskResult := taskStopTunnel()
|
taskResult := taskStopTunnel()
|
||||||
task.Result = sql.NullString{String: taskResult, Valid: true}
|
task.Result = sql.NullString{String: taskResult, Valid: true}
|
||||||
|
|
||||||
case "disable_tunnel":
|
case "disable_tunnel":
|
||||||
|
|
||||||
log.Println("Disabling Cloudflare Tunnel...")
|
log.Println("Disabling Cloudflare Tunnel...")
|
||||||
@@ -287,7 +292,7 @@ func ExecuteTask(task Task) Task {
|
|||||||
log.Printf("Error reading arguments or start_shell task: %s", err)
|
log.Printf("Error reading arguments or start_shell task: %s", err)
|
||||||
} else {
|
} else {
|
||||||
taskResult := taskStartShell(args)
|
taskResult := taskStartShell(args)
|
||||||
task.Result = sql.NullString{String: taskResult, Valid: true}
|
task.Result = sql.NullString{String: taskResult, Valid: true}
|
||||||
}
|
}
|
||||||
|
|
||||||
case "stop_shell":
|
case "stop_shell":
|
||||||
@@ -448,7 +453,7 @@ func ExecuteTask(task Task) Task {
|
|||||||
|
|
||||||
log.Println("Updating Edgebox System...")
|
log.Println("Updating Edgebox System...")
|
||||||
is_updating := utils.ReadOption("UPDATING_SYSTEM")
|
is_updating := utils.ReadOption("UPDATING_SYSTEM")
|
||||||
if is_updating == "true" {
|
if is_updating == "true" {
|
||||||
log.Println("Edgebox update was running... Probably system restarted. Finishing update...")
|
log.Println("Edgebox update was running... Probably system restarted. Finishing update...")
|
||||||
utils.WriteOption("UPDATING_SYSTEM", "false")
|
utils.WriteOption("UPDATING_SYSTEM", "false")
|
||||||
task.Result = sql.NullString{String: "{result: true}", Valid: true}
|
task.Result = sql.NullString{String: "{result: true}", Valid: true}
|
||||||
@@ -482,6 +487,27 @@ func ExecuteTask(task Task) Task {
|
|||||||
taskResult := taskDeactivateBrowserDev()
|
taskResult := taskDeactivateBrowserDev()
|
||||||
task.Result = sql.NullString{String: taskResult, Valid: true}
|
task.Result = sql.NullString{String: taskResult, Valid: true}
|
||||||
|
|
||||||
|
case "enable_ssh_access":
|
||||||
|
log.Println("Installing dashboard-managed SSH public key...")
|
||||||
|
var args taskEnableSSHAccessArgs
|
||||||
|
if err := json.Unmarshal([]byte(task.Args.String), &args); err != nil {
|
||||||
|
task.Result = sql.NullString{String: "invalid SSH access task arguments", Valid: false}
|
||||||
|
} else if taskResult, err := taskEnableSSHAccess(args); err != nil {
|
||||||
|
log.Printf("Error enabling SSH access: %s", err)
|
||||||
|
task.Result = sql.NullString{String: err.Error(), Valid: false}
|
||||||
|
} else {
|
||||||
|
task.Result = sql.NullString{String: taskResult, Valid: true}
|
||||||
|
}
|
||||||
|
|
||||||
|
case "disable_ssh_access":
|
||||||
|
log.Println("Removing dashboard-managed SSH public key...")
|
||||||
|
if taskResult, err := taskDisableSSHAccess(); err != nil {
|
||||||
|
log.Printf("Error disabling SSH access: %s", err)
|
||||||
|
task.Result = sql.NullString{String: err.Error(), Valid: false}
|
||||||
|
} else {
|
||||||
|
task.Result = sql.NullString{String: taskResult, Valid: true}
|
||||||
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
@@ -505,7 +531,11 @@ func ExecuteTask(task Task) Task {
|
|||||||
|
|
||||||
} else {
|
} else {
|
||||||
fmt.Println("Error executing task with result: " + task.Result.String)
|
fmt.Println("Error executing task with result: " + task.Result.String)
|
||||||
_, err = statement.Exec(STATUS_ERROR, "Error", formatedDatetime, strconv.Itoa(task.ID)) // Execute SQL Statement with Error info
|
errorResult := task.Result.String
|
||||||
|
if errorResult == "" {
|
||||||
|
errorResult = "Error"
|
||||||
|
}
|
||||||
|
_, err = statement.Exec(STATUS_ERROR, errorResult, formatedDatetime, strconv.Itoa(task.ID)) // Execute SQL Statement with Error info
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal(err.Error())
|
log.Fatal(err.Error())
|
||||||
}
|
}
|
||||||
@@ -531,7 +561,9 @@ func ExecuteSchedules(tick int) {
|
|||||||
log.Println("Fetching Browser Dev Environment Information")
|
log.Println("Fetching Browser Dev Environment Information")
|
||||||
taskGetBrowserDevPassword()
|
taskGetBrowserDevPassword()
|
||||||
taskGetBrowserDevStatus()
|
taskGetBrowserDevStatus()
|
||||||
|
|
||||||
|
taskCheckSystemUpdates()
|
||||||
|
|
||||||
ip := taskGetSystemIP()
|
ip := taskGetSystemIP()
|
||||||
log.Println("System IP is: " + ip)
|
log.Println("System IP is: " + ip)
|
||||||
|
|
||||||
@@ -561,8 +593,6 @@ func ExecuteSchedules(tick int) {
|
|||||||
log.Println(taskGetEdgeApps())
|
log.Println(taskGetEdgeApps())
|
||||||
taskUpdateSystemLoggerServices()
|
taskUpdateSystemLoggerServices()
|
||||||
taskRecoverFromUpdate()
|
taskRecoverFromUpdate()
|
||||||
taskCheckSystemUpdates()
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if tick%5 == 0 {
|
if tick%5 == 0 {
|
||||||
@@ -571,6 +601,10 @@ func ExecuteSchedules(tick int) {
|
|||||||
log.Println(taskGetStorageDevices())
|
log.Println(taskGetStorageDevices())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if tick%15 == 0 {
|
||||||
|
taskGetBrowserDevStatus()
|
||||||
|
}
|
||||||
|
|
||||||
if tick%30 == 0 {
|
if tick%30 == 0 {
|
||||||
// Executing every 30 ticks
|
// Executing every 30 ticks
|
||||||
log.Println(taskGetEdgeApps())
|
log.Println(taskGetEdgeApps())
|
||||||
@@ -593,7 +627,7 @@ func ExecuteSchedules(tick int) {
|
|||||||
} else {
|
} else {
|
||||||
|
|
||||||
log.Println("Last backup is " + fmt.Sprint(secondsSinceLastBackup) + " seconds old (less than 1 hour ago), skipping auto backup...")
|
log.Println("Last backup is " + fmt.Sprint(secondsSinceLastBackup) + " seconds old (less than 1 hour ago), skipping auto backup...")
|
||||||
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
@@ -634,17 +668,17 @@ func taskSetupBackups(args taskSetupBackupsArgs) string {
|
|||||||
service_found := false
|
service_found := false
|
||||||
|
|
||||||
switch args.Service {
|
switch args.Service {
|
||||||
case "s3":
|
case "s3":
|
||||||
service_url = "s3.amazonaws.com/"
|
service_url = "s3.amazonaws.com/"
|
||||||
service_found = true
|
service_found = true
|
||||||
case "b2":
|
case "b2":
|
||||||
service_url = ""
|
service_url = ""
|
||||||
key_id_name = "B2_ACCOUNT_ID"
|
key_id_name = "B2_ACCOUNT_ID"
|
||||||
key_secret_name = "B2_ACCOUNT_KEY"
|
key_secret_name = "B2_ACCOUNT_KEY"
|
||||||
service_found = true
|
service_found = true
|
||||||
case "wasabi":
|
case "wasabi":
|
||||||
service_found = true
|
service_found = true
|
||||||
service_url = "s3.wasabisys.com/"
|
service_url = "s3.wasabisys.com/"
|
||||||
}
|
}
|
||||||
|
|
||||||
if !service_found {
|
if !service_found {
|
||||||
@@ -657,14 +691,14 @@ func taskSetupBackups(args taskSetupBackupsArgs) string {
|
|||||||
os.Setenv(key_secret_name, args.SecretAccessKey)
|
os.Setenv(key_secret_name, args.SecretAccessKey)
|
||||||
|
|
||||||
fmt.Println("Creating restic password file")
|
fmt.Println("Creating restic password file")
|
||||||
|
|
||||||
system.CreateBackupsPasswordFile(args.RepositoryPassword)
|
system.CreateBackupsPasswordFile(args.RepositoryPassword)
|
||||||
|
|
||||||
fmt.Println("Initializing restic repository")
|
fmt.Println("Initializing restic repository")
|
||||||
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
||||||
|
|
||||||
cmdArgs := []string{"-r", args.Service + ":" + service_url + args.RepositoryName + ":" + repo_location, "init", "--password-file", utils.GetPath(utils.BackupPasswordFileLocation), "--verbose=3"}
|
cmdArgs := []string{"-r", args.Service + ":" + service_url + args.RepositoryName + ":" + repo_location, "init", "--password-file", utils.GetPath(utils.BackupPasswordFileLocation), "--verbose=3"}
|
||||||
|
|
||||||
result := utils.ExecAndStream(repo_location, "restic", cmdArgs)
|
result := utils.ExecAndStream(repo_location, "restic", cmdArgs)
|
||||||
|
|
||||||
utils.WriteOption("BACKUP_IS_WORKING", "0")
|
utils.WriteOption("BACKUP_IS_WORKING", "0")
|
||||||
@@ -693,9 +727,9 @@ func taskSetupBackups(args taskSetupBackupsArgs) string {
|
|||||||
|
|
||||||
// Populate Stats right away
|
// Populate Stats right away
|
||||||
taskGetBackupStatus()
|
taskGetBackupStatus()
|
||||||
|
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskRemoveBackups() string {
|
func taskRemoveBackups() string {
|
||||||
@@ -704,12 +738,12 @@ func taskRemoveBackups() string {
|
|||||||
|
|
||||||
// ... This deletes the restic repository
|
// ... This deletes the restic repository
|
||||||
// cmdArgs := []string{"-r", "s3:https://s3.amazonaws.com/edgebox-backups:/home/system/components/apps/", "forget", "latest", "--password-file", utils.GetPath(utils.BackupPasswordFileLocation), "--verbose=3"}
|
// cmdArgs := []string{"-r", "s3:https://s3.amazonaws.com/edgebox-backups:/home/system/components/apps/", "forget", "latest", "--password-file", utils.GetPath(utils.BackupPasswordFileLocation), "--verbose=3"}
|
||||||
|
|
||||||
utils.WriteOption("BACKUP_STATUS", "")
|
utils.WriteOption("BACKUP_STATUS", "")
|
||||||
utils.WriteOption("BACKUP_IS_WORKING", "0")
|
utils.WriteOption("BACKUP_IS_WORKING", "0")
|
||||||
|
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskBackup() string {
|
func taskBackup() string {
|
||||||
@@ -729,14 +763,14 @@ func taskBackup() string {
|
|||||||
service_found := false
|
service_found := false
|
||||||
|
|
||||||
switch backup_service {
|
switch backup_service {
|
||||||
case "s3":
|
case "s3":
|
||||||
service_found = true
|
service_found = true
|
||||||
case "b2":
|
case "b2":
|
||||||
key_id_name = "B2_ACCOUNT_ID"
|
key_id_name = "B2_ACCOUNT_ID"
|
||||||
key_secret_name = "B2_ACCOUNT_KEY"
|
key_secret_name = "B2_ACCOUNT_KEY"
|
||||||
service_found = true
|
service_found = true
|
||||||
case "wasabi":
|
case "wasabi":
|
||||||
service_found = true
|
service_found = true
|
||||||
}
|
}
|
||||||
|
|
||||||
if !service_found {
|
if !service_found {
|
||||||
@@ -750,7 +784,6 @@ func taskBackup() string {
|
|||||||
fmt.Println(key_secret_name)
|
fmt.Println(key_secret_name)
|
||||||
os.Setenv(key_secret_name, backup_repository_secret_access_key)
|
os.Setenv(key_secret_name, backup_repository_secret_access_key)
|
||||||
|
|
||||||
|
|
||||||
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
||||||
|
|
||||||
// ... This backs up the restic repository
|
// ... This backs up the restic repository
|
||||||
@@ -772,7 +805,7 @@ func taskBackup() string {
|
|||||||
utils.WriteOption("BACKUP_STATUS", "working")
|
utils.WriteOption("BACKUP_STATUS", "working")
|
||||||
taskGetBackupStatus()
|
taskGetBackupStatus()
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskRestoreBackup() string {
|
func taskRestoreBackup() string {
|
||||||
@@ -792,14 +825,14 @@ func taskRestoreBackup() string {
|
|||||||
service_found := false
|
service_found := false
|
||||||
|
|
||||||
switch backup_service {
|
switch backup_service {
|
||||||
case "s3":
|
case "s3":
|
||||||
service_found = true
|
service_found = true
|
||||||
case "b2":
|
case "b2":
|
||||||
key_id_name = "B2_ACCOUNT_ID"
|
key_id_name = "B2_ACCOUNT_ID"
|
||||||
key_secret_name = "B2_ACCOUNT_KEY"
|
key_secret_name = "B2_ACCOUNT_KEY"
|
||||||
service_found = true
|
service_found = true
|
||||||
case "wasabi":
|
case "wasabi":
|
||||||
service_found = true
|
service_found = true
|
||||||
}
|
}
|
||||||
|
|
||||||
if !service_found {
|
if !service_found {
|
||||||
@@ -813,7 +846,6 @@ func taskRestoreBackup() string {
|
|||||||
fmt.Println(key_secret_name)
|
fmt.Println(key_secret_name)
|
||||||
os.Setenv(key_secret_name, backup_repository_secret_access_key)
|
os.Setenv(key_secret_name, backup_repository_secret_access_key)
|
||||||
|
|
||||||
|
|
||||||
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
utils.WriteOption("BACKUP_IS_WORKING", "1")
|
||||||
|
|
||||||
fmt.Println("Stopping All EdgeApps")
|
fmt.Println("Stopping All EdgeApps")
|
||||||
@@ -822,8 +854,8 @@ func taskRestoreBackup() string {
|
|||||||
|
|
||||||
// Copy all files in /home/system/components/apps/ to a backup folder
|
// Copy all files in /home/system/components/apps/ to a backup folder
|
||||||
fmt.Println("Copying all files in /home/system/components/apps/ to a backup folder")
|
fmt.Println("Copying all files in /home/system/components/apps/ to a backup folder")
|
||||||
os.MkdirAll(utils.GetPath(utils.EdgeAppsBackupPath + "temp/"), 0777)
|
os.MkdirAll(utils.GetPath(utils.EdgeAppsBackupPath+"temp/"), 0777)
|
||||||
system.CopyDir(utils.GetPath(utils.EdgeAppsPath), utils.GetPath(utils.EdgeAppsBackupPath + "temp/"))
|
system.CopyDir(utils.GetPath(utils.EdgeAppsPath), utils.GetPath(utils.EdgeAppsBackupPath+"temp/"))
|
||||||
|
|
||||||
fmt.Println("Removing all files in /home/system/components/apps/")
|
fmt.Println("Removing all files in /home/system/components/apps/")
|
||||||
os.RemoveAll(utils.GetPath(utils.EdgeAppsPath))
|
os.RemoveAll(utils.GetPath(utils.EdgeAppsPath))
|
||||||
@@ -846,7 +878,7 @@ func taskRestoreBackup() string {
|
|||||||
if strings.Contains(result, "Fatal:") {
|
if strings.Contains(result, "Fatal:") {
|
||||||
// Copy all files from backup folder to /home/system/components/apps/
|
// Copy all files from backup folder to /home/system/components/apps/
|
||||||
os.MkdirAll(utils.GetPath(utils.EdgeAppsPath), 0777)
|
os.MkdirAll(utils.GetPath(utils.EdgeAppsPath), 0777)
|
||||||
system.CopyDir(utils.GetPath(utils.EdgeAppsBackupPath + "temp/"), utils.GetPath(utils.EdgeAppsPath))
|
system.CopyDir(utils.GetPath(utils.EdgeAppsBackupPath+"temp/"), utils.GetPath(utils.EdgeAppsPath))
|
||||||
|
|
||||||
fmt.Println("Error restoring backup: ")
|
fmt.Println("Error restoring backup: ")
|
||||||
utils.WriteOption("BACKUP_STATUS", "error")
|
utils.WriteOption("BACKUP_STATUS", "error")
|
||||||
@@ -857,7 +889,7 @@ func taskRestoreBackup() string {
|
|||||||
utils.WriteOption("BACKUP_STATUS", "working")
|
utils.WriteOption("BACKUP_STATUS", "working")
|
||||||
taskGetBackupStatus()
|
taskGetBackupStatus()
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskAutoBackup() string {
|
func taskAutoBackup() string {
|
||||||
@@ -870,7 +902,7 @@ func taskAutoBackup() string {
|
|||||||
return taskBackup()
|
return taskBackup()
|
||||||
} else {
|
} else {
|
||||||
fmt.Println("Backup status is not working... skipping")
|
fmt.Println("Backup status is not working... skipping")
|
||||||
return "{\"status\": \"skipped\"}"
|
return "{\"status\": \"skipped\"}"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -891,14 +923,14 @@ func taskGetBackupStatus() string {
|
|||||||
service_found := false
|
service_found := false
|
||||||
|
|
||||||
switch backup_service {
|
switch backup_service {
|
||||||
case "s3":
|
case "s3":
|
||||||
service_found = true
|
service_found = true
|
||||||
case "b2":
|
case "b2":
|
||||||
key_id_name = "B2_ACCOUNT_ID"
|
key_id_name = "B2_ACCOUNT_ID"
|
||||||
key_secret_name = "B2_ACCOUNT_KEY"
|
key_secret_name = "B2_ACCOUNT_KEY"
|
||||||
service_found = true
|
service_found = true
|
||||||
case "wasabi":
|
case "wasabi":
|
||||||
service_found = true
|
service_found = true
|
||||||
}
|
}
|
||||||
|
|
||||||
if !service_found {
|
if !service_found {
|
||||||
@@ -915,12 +947,12 @@ func taskGetBackupStatus() string {
|
|||||||
utils.WriteOption("BACKUP_STATS", utils.ExecAndStream(backup_repository_location, "restic", cmdArgs))
|
utils.WriteOption("BACKUP_STATS", utils.ExecAndStream(backup_repository_location, "restic", cmdArgs))
|
||||||
|
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskSetupTunnel(args taskSetupTunnelArgs) string {
|
func taskSetupTunnel(args taskSetupTunnelArgs) string {
|
||||||
fmt.Println("Executing taskSetupTunnel")
|
fmt.Println("Executing taskSetupTunnel")
|
||||||
wsPath := utils.GetPath(utils.WsPath)
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
|
||||||
// Stop a the service if it is running
|
// Stop a the service if it is running
|
||||||
system.StopService("cloudflared")
|
system.StopService("cloudflared")
|
||||||
@@ -989,14 +1021,14 @@ func taskSetupTunnel(args taskSetupTunnelArgs) string {
|
|||||||
system.CreateTunnel("/home/system/.cloudflared/config.yml")
|
system.CreateTunnel("/home/system/.cloudflared/config.yml")
|
||||||
|
|
||||||
fmt.Println("Creating DNS Routes for @ and *.")
|
fmt.Println("Creating DNS Routes for @ and *.")
|
||||||
cmd = exec.Command("cloudflared", "tunnel", "route", "dns", "-f" ,"edgebox", "*." + args.DomainName)
|
cmd = exec.Command("cloudflared", "tunnel", "route", "dns", "-f", "edgebox", "*."+args.DomainName)
|
||||||
cmd.Start()
|
cmd.Start()
|
||||||
err = cmd.Wait()
|
err = cmd.Wait()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal(err)
|
log.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
cmd = exec.Command("cloudflared", "tunnel", "route", "dns", "-f" ,"edgebox", args.DomainName)
|
cmd = exec.Command("cloudflared", "tunnel", "route", "dns", "-f", "edgebox", args.DomainName)
|
||||||
cmd.Start()
|
cmd.Start()
|
||||||
err = cmd.Wait()
|
err = cmd.Wait()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -1026,23 +1058,23 @@ func taskSetupTunnel(args taskSetupTunnelArgs) string {
|
|||||||
fmt.Println("Finished running async")
|
fmt.Println("Finished running async")
|
||||||
}()
|
}()
|
||||||
|
|
||||||
return "{\"url\": \"" + url + "\"}"
|
return "{\"url\": \"" + url + "\"}"
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskStartTunnel() string {
|
func taskStartTunnel() string {
|
||||||
fmt.Println("Executing taskStartTunnel")
|
fmt.Println("Executing taskStartTunnel")
|
||||||
|
|
||||||
// Read tunnel status to check if cloudflare is configured
|
// Read tunnel status to check if cloudflare is configured
|
||||||
tunnelStatus := utils.ReadOption("TUNNEL_STATUS")
|
tunnelStatus := utils.ReadOption("TUNNEL_STATUS")
|
||||||
if tunnelStatus != "" {
|
if tunnelStatus != "" {
|
||||||
// Only start cloudflared if we have a tunnel configured
|
// Only start cloudflared if we have a tunnel configured
|
||||||
system.StartService("cloudflared")
|
system.StartService("cloudflared")
|
||||||
domainName := utils.ReadOption("DOMAIN_NAME")
|
domainName := utils.ReadOption("DOMAIN_NAME")
|
||||||
status := "{\"status\": \"connected\", \"domain\": \"" + domainName + "\"}"
|
status := "{\"status\": \"connected\", \"domain\": \"" + domainName + "\"}"
|
||||||
utils.WriteOption("TUNNEL_STATUS", status)
|
utils.WriteOption("TUNNEL_STATUS", status)
|
||||||
}
|
}
|
||||||
|
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
}
|
}
|
||||||
|
|
||||||
func taskStopTunnel() string {
|
func taskStopTunnel() string {
|
||||||
@@ -1104,7 +1136,7 @@ func taskStartShell(args taskStartShellArgs) string {
|
|||||||
|
|
||||||
go func() {
|
go func() {
|
||||||
fmt.Println("Running shell async")
|
fmt.Println("Running shell async")
|
||||||
|
|
||||||
// cmd.Wait()
|
// cmd.Wait()
|
||||||
|
|
||||||
// Keep retrying to calculate timeout to know when to kill the process
|
// Keep retrying to calculate timeout to know when to kill the process
|
||||||
@@ -1146,11 +1178,14 @@ func taskGetBrowserDevStatus() string {
|
|||||||
utils.GetPath(utils.WsPath),
|
utils.GetPath(utils.WsPath),
|
||||||
"sh",
|
"sh",
|
||||||
[]string{"-c", "systemctl --quiet is-active code-server@root && echo 'active' || echo 'inactive'"},
|
[]string{"-c", "systemctl --quiet is-active code-server@root && echo 'active' || echo 'inactive'"},
|
||||||
)
|
)
|
||||||
if browserDevStatus == "active" {
|
if browserDevStatus == "active" {
|
||||||
fmt.Println("Browser Dev Environment is running")
|
fmt.Println("Browser Dev Environment is running")
|
||||||
utils.WriteOption("BROWSERDEV_STATUS", "running")
|
utils.WriteOption("BROWSERDEV_STATUS", "running")
|
||||||
|
taskGetBrowserDevUrl()
|
||||||
|
|
||||||
return "{\"status\": \"running\"}"
|
return "{\"status\": \"running\"}"
|
||||||
|
|
||||||
} else {
|
} else {
|
||||||
fmt.Println("Browser Dev Environment is not running")
|
fmt.Println("Browser Dev Environment is not running")
|
||||||
utils.WriteOption("BROWSERDEV_STATUS", "not_running")
|
utils.WriteOption("BROWSERDEV_STATUS", "not_running")
|
||||||
@@ -1158,6 +1193,24 @@ func taskGetBrowserDevStatus() string {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func taskGetBrowserDevUrl() string {
|
||||||
|
url := ""
|
||||||
|
myEdgeAppServiceEnv, err := godotenv.Read(utils.GetPath(utils.BrowserDevPath) + "myedgeapp.env")
|
||||||
|
if err != nil {
|
||||||
|
log.Println("No myedge.app environment file found. Status is Network-Only")
|
||||||
|
url = "http://dev." + system.GetHostname() + ".local"
|
||||||
|
} else {
|
||||||
|
if myEdgeAppServiceEnv["INTERNET_URL"] != "" {
|
||||||
|
url = "https://" + myEdgeAppServiceEnv["INTERNET_URL"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Println("Browser Dev Url: " + url)
|
||||||
|
|
||||||
|
utils.WriteOption("BROWSERDEV_URL", url)
|
||||||
|
return url
|
||||||
|
}
|
||||||
|
|
||||||
func taskActivateBrowserDev() string {
|
func taskActivateBrowserDev() string {
|
||||||
fmt.Println("Executing taskActivateBrowserDev")
|
fmt.Println("Executing taskActivateBrowserDev")
|
||||||
wsPath := utils.GetPath(utils.WsPath)
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
@@ -1170,6 +1223,10 @@ func taskActivateBrowserDev() string {
|
|||||||
system.StartWs()
|
system.StartWs()
|
||||||
// Write control option for API
|
// Write control option for API
|
||||||
utils.WriteOption("BROWSERDEV_STATUS", "running")
|
utils.WriteOption("BROWSERDEV_STATUS", "running")
|
||||||
|
|
||||||
|
// Write and refresh the dev environment password option
|
||||||
|
taskGetBrowserDevPassword()
|
||||||
|
|
||||||
return "{\"status\": \"ok\"}"
|
return "{\"status\": \"ok\"}"
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1180,7 +1237,7 @@ func taskDeactivateBrowserDev() string {
|
|||||||
// Remove the run file
|
// Remove the run file
|
||||||
os.Remove(utils.GetPath(utils.BrowserDevProxyPath) + ".run")
|
os.Remove(utils.GetPath(utils.BrowserDevProxyPath) + ".run")
|
||||||
system.StartWs()
|
system.StartWs()
|
||||||
|
|
||||||
utils.Exec(wsPath, "systemctl", []string{"stop", "code-server@root"})
|
utils.Exec(wsPath, "systemctl", []string{"stop", "code-server@root"})
|
||||||
utils.WriteOption("BROWSERDEV_STATUS", "not_running")
|
utils.WriteOption("BROWSERDEV_STATUS", "not_running")
|
||||||
|
|
||||||
@@ -1189,15 +1246,14 @@ func taskDeactivateBrowserDev() string {
|
|||||||
|
|
||||||
func taskGetBrowserDevPassword() string {
|
func taskGetBrowserDevPassword() string {
|
||||||
fmt.Println("Executing taskGetBrowserDevPassword")
|
fmt.Println("Executing taskGetBrowserDevPassword")
|
||||||
password := utils.ReadOption("BROWSERDEV_PASSWORD")
|
|
||||||
if password == "" {
|
password, err := system.FetchBrowserDevPasswordFromFile()
|
||||||
password, err := system.FetchBrowserDevPasswordFromFile()
|
if err == nil {
|
||||||
if err == nil {
|
utils.WriteOption("BROWSERDEV_PASSWORD", password)
|
||||||
utils.WriteOption("BROWSERDEV_PASSWORD", password)
|
} else {
|
||||||
} else {
|
fmt.Println("Error fetching browser dev password from file: " + err.Error())
|
||||||
fmt.Println("Error fetching browser dev password from file: " + err.Error())
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return password
|
return password
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1272,7 +1328,6 @@ func taskSetEdgeAppOptions(args taskSetEdgeAppOptionsArgs) string {
|
|||||||
// Id is the edgeapp id
|
// Id is the edgeapp id
|
||||||
appID := args.ID
|
appID := args.ID
|
||||||
|
|
||||||
|
|
||||||
// Open the file to write the options,
|
// Open the file to write the options,
|
||||||
// it is an env file in /home/system/components/apps/<app_id>/edgeapp.env
|
// it is an env file in /home/system/components/apps/<app_id>/edgeapp.env
|
||||||
|
|
||||||
@@ -1303,7 +1358,7 @@ func taskSetEdgeAppOptions(args taskSetEdgeAppOptionsArgs) string {
|
|||||||
log.Printf("Error writing option to edgeapp.env file: %s", err)
|
log.Printf("Error writing option to edgeapp.env file: %s", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Close the file
|
// Close the file
|
||||||
err = edgeappEnvFile.Close()
|
err = edgeappEnvFile.Close()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -1323,7 +1378,6 @@ func taskSetEdgeAppBasicAuth(args taskSetEdgeAppBasicAuthArgs) string {
|
|||||||
// Id is the edgeapp id
|
// Id is the edgeapp id
|
||||||
appID := args.ID
|
appID := args.ID
|
||||||
|
|
||||||
|
|
||||||
// Open the file to write the options,
|
// Open the file to write the options,
|
||||||
// it is an env file in /home/system/components/apps/<app_id>/auth.env
|
// it is an env file in /home/system/components/apps/<app_id>/auth.env
|
||||||
|
|
||||||
@@ -1351,7 +1405,7 @@ func taskSetEdgeAppBasicAuth(args taskSetEdgeAppBasicAuthArgs) string {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
log.Printf("Error writing credentials to auth.env file: %s", err)
|
log.Printf("Error writing credentials to auth.env file: %s", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Close the file
|
// Close the file
|
||||||
err = edgeappAuthEnvFile.Close()
|
err = edgeappAuthEnvFile.Close()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -1456,7 +1510,7 @@ func taskRecoverFromUpdate() string {
|
|||||||
filteredTasks = append(filteredTasks, task)
|
filteredTasks = append(filteredTasks, task)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// If tasks is not empty, Get the last task
|
// If tasks is not empty, Get the last task
|
||||||
if len(filteredTasks) > 0 {
|
if len(filteredTasks) > 0 {
|
||||||
lastTask := filteredTasks[len(filteredTasks)-1]
|
lastTask := filteredTasks[len(filteredTasks)-1]
|
||||||
@@ -1497,7 +1551,7 @@ func taskUpdateSystemLoggerServices() string {
|
|||||||
|
|
||||||
input = append(input, "edgeboxctl")
|
input = append(input, "edgeboxctl")
|
||||||
input = append(input, "tunnel")
|
input = append(input, "tunnel")
|
||||||
|
|
||||||
// Run the system logger
|
// Run the system logger
|
||||||
system.UpdateSystemLoggerServices(input)
|
system.UpdateSystemLoggerServices(input)
|
||||||
|
|
||||||
|
|||||||
@@ -111,6 +111,7 @@ const ApiPath string = "apiPath"
|
|||||||
const EdgeAppsPath string = "edgeAppsPath"
|
const EdgeAppsPath string = "edgeAppsPath"
|
||||||
const EdgeAppsBackupPath string = "edgeAppsBackupPath"
|
const EdgeAppsBackupPath string = "edgeAppsBackupPath"
|
||||||
const WsPath string = "wsPath"
|
const WsPath string = "wsPath"
|
||||||
|
const BrowserDevPath string = "browserDevPath"
|
||||||
const LoggerPath string = "loggerPath"
|
const LoggerPath string = "loggerPath"
|
||||||
const BrowserDevPasswordFileLocation string = "browserDevPasswordFileLocation"
|
const BrowserDevPasswordFileLocation string = "browserDevPasswordFileLocation"
|
||||||
const BrowserDevProxyPath string = "browserDevProxyPath"
|
const BrowserDevProxyPath string = "browserDevProxyPath"
|
||||||
@@ -176,6 +177,14 @@ func GetPath(pathKey string) string {
|
|||||||
targetPath = "/home/system/components/ws/"
|
targetPath = "/home/system/components/ws/"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
case BrowserDevPath:
|
||||||
|
|
||||||
|
if env["BROWSERDEV_PATH"] != "" {
|
||||||
|
targetPath = env["BROWSERDEV_PATH"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/dev/"
|
||||||
|
}
|
||||||
|
|
||||||
case LoggerPath:
|
case LoggerPath:
|
||||||
if env["LOGGER_PATH"] != "" {
|
if env["LOGGER_PATH"] != "" {
|
||||||
targetPath = env["LOGGER_PATH"]
|
targetPath = env["LOGGER_PATH"]
|
||||||
|
|||||||
Reference in New Issue
Block a user