mirror of
https://github.com/edgebox-iot/edgeboxctl.git
synced 2026-09-24 05:41:43 +02:00
Compare commits
41
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9bbe3d9997 | ||
|
|
7996c552f8 | ||
|
|
dbc831e972 | ||
|
|
19acbcbaad | ||
|
|
1e0a5df370 | ||
|
|
7913be080d | ||
|
|
e80aaf7d18 | ||
|
|
b11034dd17 | ||
|
|
80fc8b40cd | ||
|
|
01f423ee84 | ||
|
|
a8b1da4b7c | ||
|
|
6ccd4a3299 | ||
|
|
42b1a34ca7 | ||
|
|
4bb343769f | ||
|
|
3bb6200b1c | ||
|
|
eae72b0a79 | ||
|
|
8be566afb9 | ||
|
|
9c2a0dbefe | ||
|
|
4e399f63ea | ||
|
|
e238e9d71d | ||
|
|
db56530311 | ||
|
|
319acbd0e1 | ||
|
|
f0047a7a0c | ||
|
|
5c736a1b85 | ||
|
|
ca7f4af7fe | ||
|
|
445bc41d0e | ||
|
|
8bf26a334c | ||
|
|
e009c1f55d | ||
|
|
284acb18a4 | ||
|
|
8d0de36cdd | ||
|
|
113785def4 | ||
|
|
df13bf705d | ||
|
|
335b7ec29e | ||
|
|
13275f80a5 | ||
|
|
04cdba7479 | ||
|
|
a66ff40e65 | ||
|
|
f7823b9e20 | ||
|
|
ece500c342 | ||
|
|
161ec76eb9 | ||
|
|
d9720a48c9 | ||
|
|
1ba5a8f506 |
@@ -13,11 +13,11 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@v2
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: ^1.15
|
go-version: '1.20.2'
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v4
|
||||||
- name: Build
|
- name: Build
|
||||||
run: make build
|
run: make build
|
||||||
- name: Test
|
- name: Test
|
||||||
|
|||||||
@@ -21,3 +21,6 @@ main
|
|||||||
# Build
|
# Build
|
||||||
|
|
||||||
/bin
|
/bin
|
||||||
|
|
||||||
|
# Logs from executed scripts
|
||||||
|
/scripts/output.log
|
||||||
|
|||||||
Vendored
+236
@@ -0,0 +1,236 @@
|
|||||||
|
{
|
||||||
|
"version": "2.0.0",
|
||||||
|
"tasks": [
|
||||||
|
{
|
||||||
|
"label": "Build",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
|
||||||
|
},
|
||||||
|
"group": {
|
||||||
|
"kind": "build",
|
||||||
|
"isDefault": true
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build All",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-all"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build Prod",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-prod"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build Cloud",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-cloud"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build ARM64",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-arm64"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build ARMHF",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-armhf"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Build AMD64",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["build-amd64"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"group": "build",
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Clean",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["clean"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Test",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["test"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Test with Coverage",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["test-with-coverage"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Run",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["run"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install Prod",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install-prod"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install Cloud",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install-cloud"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install ARM64",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install-arm64"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install ARMHF",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install-armhf"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Install AMD64",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["install-amd64"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Start",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["start"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Stop",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["stop"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Restart",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["restart"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Status",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["status"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"label": "Logs",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "make",
|
||||||
|
"args": ["log"],
|
||||||
|
"options": {
|
||||||
|
"cwd": "${workspaceFolder}"
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Changelog
|
||||||
|
|
||||||
|
## [1.4.0] - 23-09-2026
|
||||||
|
|
||||||
|
* Added dashboard-managed SSH public-key access.
|
||||||
|
* Validates ED25519 public keys and reports their SHA256 fingerprints.
|
||||||
|
* Atomically installs or removes only the marked Edgebox key while preserving all other authorized keys.
|
||||||
|
* Never generates, reads, stores, logs, or returns SSH private keys.
|
||||||
|
|
||||||
|
## [1.3.2] - 08-12-2024
|
||||||
|
|
||||||
|
* Fix to Browser Dev feature:
|
||||||
|
* Checking browser dev url when internet_accessible was checking the incorrect path. This is now fixed.
|
||||||
|
|
||||||
|
## [1.3.1] - 08-12-2024
|
||||||
|
|
||||||
|
* Fixes to Browser Dev feature:
|
||||||
|
* Now edgeboxctl also fetches or generates the browser dev environment url and saves it into an option both when starting, and every time the browser dev status is fetched.
|
||||||
|
|
||||||
|
## [1.3.0] - 05-12-2024
|
||||||
|
|
||||||
|
* Added Edgebox Browser Development Environment Feature Support
|
||||||
|
* Added tasks for handling browser development environment into tasks.go
|
||||||
|
* Added executable tasks to ExecuteTask and scheduled ones to ExecuteSchedules
|
||||||
|
* Other bug fixes and improvements.
|
||||||
|
|
||||||
|
### Missing Past Releases
|
||||||
|
|
||||||
|
Release notes for past versions are not available in this file. Please refer to the [GitHub releases](https://hithub.com/edgebox-iot/edgeboxctl/releases) for more information. Feel free to contribute to this file by adding missing release notes.
|
||||||
+3
-5
@@ -1,11 +1,9 @@
|
|||||||
FROM golang:latest
|
FROM golang:1.20.2
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
COPY ./ /app
|
COPY ./ /app
|
||||||
|
|
||||||
RUN go mod download
|
RUN go install github.com/githubnemo/CompileDaemon@latest
|
||||||
|
|
||||||
RUN go get github.com/githubnemo/CompileDaemon
|
ENTRYPOINT CompileDaemon --build="make build" --command=./bin/edgeboxctl-$(go env GOOS)-$(go env GOARCH)
|
||||||
|
|
||||||
ENTRYPOINT CompileDaemon --build="make build" --command=./bin/edgeboxctl
|
|
||||||
|
|||||||
@@ -1,35 +1,114 @@
|
|||||||
PROJECT?=github.com/edgebox-iot/edgeboxctl
|
.DEFAULT_GOAL := build
|
||||||
|
|
||||||
|
PROJECT ?= github.com/edgebox-iot/edgeboxctl
|
||||||
RELEASE ?= dev
|
RELEASE ?= dev
|
||||||
COMMIT := $(shell git rev-parse --short HEAD)
|
COMMIT := $(shell git rev-parse --short HEAD)
|
||||||
BUILD_DATE := $(shell date -u '+%Y-%m-%d_%H:%M:%S')
|
BUILD_DATE := $(shell date -u '+%Y-%m-%d_%H:%M:%S')
|
||||||
BUILD_DIR = bin
|
BUILD_DIR = bin
|
||||||
|
GOOS := $(shell go env GOOS)
|
||||||
|
GOARCH := $(shell go env GOARCH)
|
||||||
|
|
||||||
|
|
||||||
build-all:
|
build-all:
|
||||||
|
@echo "\n🏗️ Building all architectures for ${RELEASE} mode"
|
||||||
|
@echo "🟡 This will build all supported architectures and release combinations. It can take a while...\n"
|
||||||
|
|
||||||
GOOS=linux GOARCH=amd64 make build
|
GOOS=linux GOARCH=amd64 make build
|
||||||
GOOS=linux GOARCH=arm make build
|
GOOS=linux GOARCH=arm make build
|
||||||
|
|
||||||
|
@echo "\n🟢 All builds completed and available at ./bin/ \n"
|
||||||
|
|
||||||
build-prod:
|
build-prod:
|
||||||
GOOS=linux GOARCH=arm RELEASE=prod make build
|
GOOS=linux GOARCH=arm RELEASE=prod make build
|
||||||
|
|
||||||
build-cloud:
|
build-cloud:
|
||||||
GOOS=linux GOARCH=amd64 RELEASE=cloud make build
|
GOOS=linux GOARCH=amd64 RELEASE=cloud make build
|
||||||
|
|
||||||
|
build-arm64:
|
||||||
|
GOOS=linux GOARCH=arm64 RELEASE=prod make build
|
||||||
|
|
||||||
|
build-armhf:
|
||||||
|
GOOS=linux GOARCH=arm RELEASE=prod make build
|
||||||
|
|
||||||
|
build-amd64:
|
||||||
|
GOOS=linux GOARCH=amd64 RELEASE=prod make build
|
||||||
|
|
||||||
|
|
||||||
build:
|
build:
|
||||||
@echo "Building ${GOOS}-${GOARCH}"
|
@echo "\n🏗️ Building edgeboxctl (${RELEASE} release) on ${GOOS} (${GOARCH})"
|
||||||
|
@echo "📦 Binary will be saved in ./${BUILD_DIR}/edgeboxctl-${GOOS}-${GOARCH}\n"
|
||||||
|
|
||||||
GOOS=${GOOS} GOARCH=${GOARCH} go build \
|
GOOS=${GOOS} GOARCH=${GOARCH} go build \
|
||||||
-trimpath -ldflags "-s -w -X ${PROJECT}/internal/diagnostics.Version=${RELEASE} \
|
-trimpath -ldflags "-s -w -X ${PROJECT}/internal/diagnostics.Version=${RELEASE} \
|
||||||
-X ${PROJECT}/internal/diagnostics.Commit=${COMMIT} \
|
-X ${PROJECT}/internal/diagnostics.Commit=${COMMIT} \
|
||||||
-X ${PROJECT}/internal/diagnostics.BuildDate=${BUILD_DATE}" \
|
-X ${PROJECT}/internal/diagnostics.BuildDate=${BUILD_DATE}" \
|
||||||
-o bin/edgeboxctl-${GOOS}-${GOARCH} ${PROJECT}/cmd/edgeboxctl
|
-o bin/edgeboxctl-${GOOS}-${GOARCH} ${PROJECT}/cmd/edgeboxctl
|
||||||
cp ./bin/edgeboxctl-${GOOS}-${GOARCH} ./bin/edgeboxctl
|
|
||||||
|
@echo "\n🟢 Build task completed\n"
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
|
@echo "🧹 Cleaning build directory and go cache\n"
|
||||||
|
|
||||||
rm -rf ${BUILD_DIR}
|
rm -rf ${BUILD_DIR}
|
||||||
go clean
|
go clean
|
||||||
|
|
||||||
|
@echo "\n🟢 Clean task completed\n"
|
||||||
|
|
||||||
test:
|
test:
|
||||||
go test -tags=unit -timeout=600s -v ./...
|
go test -tags=unit -timeout=600s -v ./...
|
||||||
|
|
||||||
test-with-coverage:
|
test-with-coverage:
|
||||||
go test -tags=unit -timeout=600s -v ./... -coverprofile=coverage.out
|
go test -tags=unit -timeout=600s -v ./... -coverprofile=coverage.out
|
||||||
|
|
||||||
|
run:
|
||||||
|
@echo "\n🚀 Running edgeboxctl\n"
|
||||||
|
./bin/edgeboxctl-${GOOS}-${GOARCH}
|
||||||
|
|
||||||
|
install:
|
||||||
|
@echo "📦 Installing edgeboxctl service (${RELEASE}) for ${GOOS} (${GOARCH})\n"
|
||||||
|
|
||||||
|
@echo "�🚧 Stopping edgeboxctl service if it is running"
|
||||||
|
sudo systemctl stop edgeboxctl || true
|
||||||
|
|
||||||
|
@echo "\n🗑️ Removing old edgeboxctl binary and service"
|
||||||
|
sudo rm -rf /usr/local/bin/edgeboxctl /usr/local/sbin/edgeboctl /lib/systemd/system/edgeboxctl.service
|
||||||
|
|
||||||
|
@echo "\n🚚 Copying edgeboxctl binary to /usr/local/bin"
|
||||||
|
sudo cp ./bin/edgeboxctl-${GOOS}-${GOARCH} /usr/local/bin/edgeboxctl
|
||||||
|
sudo cp ./bin/edgeboxctl-${GOOS}-${GOARCH} /usr/local/sbin/edgeboxctl
|
||||||
|
|
||||||
|
@echo "\n🚚 Copying edgeboxctl service to /lib/systemd/system"
|
||||||
|
sudo cp ./edgeboxctl.service /lib/systemd/system/edgeboxctl.service
|
||||||
|
sudo systemctl daemon-reload
|
||||||
|
|
||||||
|
@echo "\n 🚀 To start edgeboxctl run: make start"
|
||||||
|
@echo "🟢 Edgeboxctl installed successfully\n"
|
||||||
|
|
||||||
|
install-prod: build-prod install
|
||||||
|
install-cloud: build-cloud install
|
||||||
|
install-arm64: build-arm64 install
|
||||||
|
install-armhf: build-armhf install
|
||||||
|
install-amd64: build-amd64 install
|
||||||
|
|
||||||
|
start:
|
||||||
|
@echo "\n 🚀 Starting edgeboxctl service\n"
|
||||||
|
systemctl start edgeboxctl
|
||||||
|
@echo "\n 🟢 Edgebox service started\n"
|
||||||
|
|
||||||
|
stop:
|
||||||
|
@echo "\n✋ Stopping edgeboxctl service\n"
|
||||||
|
systemctl stop edgeboxctl
|
||||||
|
@echo "\n 🟢 Edgebox service stopped\n"
|
||||||
|
|
||||||
|
restart:
|
||||||
|
@echo "\n💫 Restarting edgeboxctl service\n"
|
||||||
|
systemctl restart edgeboxctl
|
||||||
|
@echo "\n 🟢 Edgebox service restarted\n"
|
||||||
|
|
||||||
|
status:
|
||||||
|
@echo "\nℹ️ edgeboxctl Service Info:\n"
|
||||||
|
systemctl status edgeboxctl
|
||||||
|
|
||||||
|
log:
|
||||||
|
@echo "\n📰 edgeboxctl service logs:\n"
|
||||||
|
journalctl -fu edgeboxctl
|
||||||
|
|||||||
@@ -8,7 +8,7 @@
|
|||||||
<h3 align="center">Edgebox Control Module</h3>
|
<h3 align="center">Edgebox Control Module</h3>
|
||||||
|
|
||||||
<p align="center">
|
<p align="center">
|
||||||
A System Control module written in Go. Its resonsability is to configure dependencies and perform system tasks, automatically in a schedule, or by command.
|
A System Control module written in Go. Its responsibility is to configure dependencies and perform system tasks, automatically on a schedule, or on demand.
|
||||||
<br />
|
<br />
|
||||||
<br />
|
<br />
|
||||||
<a href="https://github.com/github_username/edgeboxctl/issues">Report Bug</a>
|
<a href="https://github.com/github_username/edgeboxctl/issues">Report Bug</a>
|
||||||
@@ -38,8 +38,6 @@
|
|||||||
<!-- ABOUT THE PROJECT -->
|
<!-- ABOUT THE PROJECT -->
|
||||||
## About The Project
|
## About The Project
|
||||||
|
|
||||||
[![Edgebox Screen Shot][product-screenshot]](https://edgebox.co)
|
|
||||||
|
|
||||||
Edgebox is an easy to configure and use system. It brings powerful features that go alongside or can even completely replace various services that you already use in the day-to-day.
|
Edgebox is an easy to configure and use system. It brings powerful features that go alongside or can even completely replace various services that you already use in the day-to-day.
|
||||||
|
|
||||||
|
|
||||||
@@ -58,18 +56,17 @@ To get a local copy up and running follow these simple steps.
|
|||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
If you're installing this to run natively in the system, you better be doing it inside of the [Development Virtual Machine](https://github.com/edgebox-iot/devm). This software can do destructive action in the system is is running. You've been warned.
|
If you're running for development purposes, a docker container suffices, so make sure you have:
|
||||||
|
|
||||||
If you're running for development purposes, a Docker container suffices, so make sure you have:
|
* docker
|
||||||
* Docker
|
* docker compose (docker-compose-v2 package)
|
||||||
* Docker Compose
|
|
||||||
```sh
|
|
||||||
sudo apt-get install docker docker-compose
|
|
||||||
```
|
|
||||||
|
|
||||||
Check the following links for more info on [Docker](https://www.docker.com/) and [Docker Compose](https://docs.docker.com/compose/).
|
Check the following links for more info on [Docker](https://www.docker.com/) and [Docker Compose](https://docs.docker.com/compose/).
|
||||||
|
|
||||||
Aditionally, edgeboxctl needs the following bash commands available wherever it runs:
|
**Note:** If you don't have `docker compose` available, install it with: `sudo apt-get install docker-compose-v2`
|
||||||
|
|
||||||
|
Aditionally, `edgeboxctl` needs the following bash commands available wherever it runs:
|
||||||
|
|
||||||
* `arm-linux-gnueabi-gcc` (`sudo apt-get install gcc-arm*`)
|
* `arm-linux-gnueabi-gcc` (`sudo apt-get install gcc-arm*`)
|
||||||
* `sh`
|
* `sh`
|
||||||
* `rm`
|
* `rm`
|
||||||
@@ -84,10 +81,10 @@ Aditionally, edgeboxctl needs the following bash commands available wherever it
|
|||||||
```sh
|
```sh
|
||||||
git clone https://github.com/edgebox-iot/edgeboxctl.git
|
git clone https://github.com/edgebox-iot/edgeboxctl.git
|
||||||
```
|
```
|
||||||
2. Run Docker-Compose
|
2. Run Docker Compose
|
||||||
```sh
|
|
||||||
docker-compose up
|
|
||||||
```
|
```
|
||||||
|
docker compose up
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -121,4 +118,4 @@ Contributions are what make the open source community such an amazing place to b
|
|||||||
<!-- LICENSE -->
|
<!-- LICENSE -->
|
||||||
## License
|
## License
|
||||||
|
|
||||||
Distributed under the MIT License. See `LICENSE` for more information.
|
Distributed under the Elastic License 2.0. See `LICENSE` for more information.
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Edgebox Control Module Service
|
||||||
|
ConditionPathExists=/home/system/
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
User=root
|
||||||
|
Group=root
|
||||||
|
LimitNOFILE=1024
|
||||||
|
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=10
|
||||||
|
startLimitIntervalSec=60
|
||||||
|
|
||||||
|
WorkingDirectory=/home/system/components/edgeboxctl
|
||||||
|
ExecStart=edgeboxctl --name=edgebox-cloud
|
||||||
|
|
||||||
|
# make sure log directory exists and owned by syslog
|
||||||
|
PermissionsStartOnly=true
|
||||||
|
ExecStartPre=/bin/mkdir -p /var/log/edgeboxctl
|
||||||
|
ExecStartPre=/bin/chown root:root /var/log/edgeboxctl
|
||||||
|
ExecStartPre=/bin/chmod 755 /var/log/edgeboxctl
|
||||||
|
StandardOutput=syslog
|
||||||
|
StandardError=syslog
|
||||||
|
SyslogIdentifier=edgeboxctl
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -8,6 +8,7 @@ require (
|
|||||||
github.com/dustin/go-humanize v1.0.0 // indirect
|
github.com/dustin/go-humanize v1.0.0 // indirect
|
||||||
github.com/go-ole/go-ole v1.2.5 // indirect
|
github.com/go-ole/go-ole v1.2.5 // indirect
|
||||||
github.com/go-sql-driver/mysql v1.5.0
|
github.com/go-sql-driver/mysql v1.5.0
|
||||||
|
github.com/go-yaml/yaml v2.1.0+incompatible // indirect
|
||||||
github.com/joho/godotenv v1.3.0
|
github.com/joho/godotenv v1.3.0
|
||||||
github.com/mattn/go-sqlite3 v1.14.7 // indirect
|
github.com/mattn/go-sqlite3 v1.14.7 // indirect
|
||||||
github.com/shirou/gopsutil v3.21.4+incompatible // indirect
|
github.com/shirou/gopsutil v3.21.4+incompatible // indirect
|
||||||
|
|||||||
@@ -11,6 +11,8 @@ github.com/go-ole/go-ole v1.2.5 h1:t4MGB5xEDZvXI+0rMjjsfBsD7yAgp/s9ZDkL1JndXwY=
|
|||||||
github.com/go-ole/go-ole v1.2.5/go.mod h1:pprOEPIfldk/42T2oK7lQ4v4JSDwmV0As9GaiUsvbm0=
|
github.com/go-ole/go-ole v1.2.5/go.mod h1:pprOEPIfldk/42T2oK7lQ4v4JSDwmV0As9GaiUsvbm0=
|
||||||
github.com/go-sql-driver/mysql v1.5.0 h1:ozyZYNQW3x3HtqT1jira07DN2PArx2v7/mN66gGcHOs=
|
github.com/go-sql-driver/mysql v1.5.0 h1:ozyZYNQW3x3HtqT1jira07DN2PArx2v7/mN66gGcHOs=
|
||||||
github.com/go-sql-driver/mysql v1.5.0/go.mod h1:DCzpHaOWr8IXmIStZouvnhqoel9Qv2LBy8hT2VhHyBg=
|
github.com/go-sql-driver/mysql v1.5.0/go.mod h1:DCzpHaOWr8IXmIStZouvnhqoel9Qv2LBy8hT2VhHyBg=
|
||||||
|
github.com/go-yaml/yaml v2.1.0+incompatible h1:RYi2hDdss1u4YE7GwixGzWwVo47T8UQwnTLB6vQiq+o=
|
||||||
|
github.com/go-yaml/yaml v2.1.0+incompatible/go.mod h1:w2MrLa16VYP0jy6N7M5kHaCkaLENm+P+Tv+MfurjSw0=
|
||||||
github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI=
|
github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI=
|
||||||
github.com/joho/godotenv v1.3.0 h1:Zjp+RcGpHhGlrMbJzXTrZZPrWj+1vfm90La1wgB6Bhc=
|
github.com/joho/godotenv v1.3.0 h1:Zjp+RcGpHhGlrMbJzXTrZZPrWj+1vfm90La1wgB6Bhc=
|
||||||
github.com/joho/godotenv v1.3.0/go.mod h1:7hK45KPybAkOC6peb+G5yklZfMxEjkZhHbwpqxOKXbg=
|
github.com/joho/godotenv v1.3.0/go.mod h1:7hK45KPybAkOC6peb+G5yklZfMxEjkZhHbwpqxOKXbg=
|
||||||
|
|||||||
@@ -0,0 +1,28 @@
|
|||||||
|
package backups
|
||||||
|
|
||||||
|
// import (
|
||||||
|
// "fmt"
|
||||||
|
// "os"
|
||||||
|
// "path/filepath"
|
||||||
|
// "strings"
|
||||||
|
|
||||||
|
// "github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
||||||
|
// "github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
// "github.com/shirou/gopsutil/disk"
|
||||||
|
// )
|
||||||
|
|
||||||
|
// Repository : Struct representing the backup repository of a device in the system
|
||||||
|
type Repository struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
FileCount int64 `json:"file_count"`
|
||||||
|
Size string `json:"size"`
|
||||||
|
Snapshots []Snapshot `json:"snapshots"`
|
||||||
|
Status string `json:"status"`
|
||||||
|
// UsageStat UsageStat `json:"usage_stat"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Snapshot : Struct representing a single snapshot in the backup repository
|
||||||
|
type Snapshot struct {
|
||||||
|
ID string `json:"id"`
|
||||||
|
time string `json:"time"`
|
||||||
|
}
|
||||||
+293
-20
@@ -9,7 +9,9 @@ import (
|
|||||||
|
|
||||||
"github.com/joho/godotenv"
|
"github.com/joho/godotenv"
|
||||||
|
|
||||||
|
"github.com/edgebox-iot/edgeboxctl/internal/system"
|
||||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
"github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
||||||
)
|
)
|
||||||
|
|
||||||
// EdgeApp : Struct representing an EdgeApp in the system
|
// EdgeApp : Struct representing an EdgeApp in the system
|
||||||
@@ -17,11 +19,15 @@ type EdgeApp struct {
|
|||||||
ID string `json:"id"`
|
ID string `json:"id"`
|
||||||
Name string `json:"name"`
|
Name string `json:"name"`
|
||||||
Description string `json:"description"`
|
Description string `json:"description"`
|
||||||
|
Experimental bool `json:"experimental"`
|
||||||
Status EdgeAppStatus `json:"status"`
|
Status EdgeAppStatus `json:"status"`
|
||||||
Services []EdgeAppService `json:"services"`
|
Services []EdgeAppService `json:"services"`
|
||||||
InternetAccessible bool `json:"internet_accessible"`
|
InternetAccessible bool `json:"internet_accessible"`
|
||||||
NetworkURL string `json:"network_url"`
|
NetworkURL string `json:"network_url"`
|
||||||
InternetURL string `json:"internet_url"`
|
InternetURL string `json:"internet_url"`
|
||||||
|
Options []EdgeAppOption `json:"options"`
|
||||||
|
NeedsConfig bool `json:"needs_config"`
|
||||||
|
Login EdgeAppLogin `json:"login"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// MaybeEdgeApp : Boolean flag for validation of edgeapp existance
|
// MaybeEdgeApp : Boolean flag for validation of edgeapp existance
|
||||||
@@ -42,9 +48,30 @@ type EdgeAppService struct {
|
|||||||
IsRunning bool `json:"is_running"`
|
IsRunning bool `json:"is_running"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type EdgeAppOption struct {
|
||||||
|
Key string `json:"key"`
|
||||||
|
Value string `json:"value"`
|
||||||
|
DefaultValue string `json:"default_value"`
|
||||||
|
Format string `json:"format"`
|
||||||
|
Description string `json:"description"`
|
||||||
|
IsSecret bool `json:"is_secret"`
|
||||||
|
IsInstallLocked bool `json:"is_install_locked"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type EdgeAppLogin struct {
|
||||||
|
Enabled bool `json:"enabled"`
|
||||||
|
Username string `json:"username"`
|
||||||
|
Password string `json:"password"`
|
||||||
|
}
|
||||||
|
|
||||||
const configFilename = "/edgebox-compose.yml"
|
const configFilename = "/edgebox-compose.yml"
|
||||||
const envFilename = "/edgebox.env"
|
const envFilename = "/edgebox.env"
|
||||||
|
const optionsTemplateFilename = "/edgeapp.template.env"
|
||||||
|
const optionsEnvFilename = "/edgeapp.env"
|
||||||
|
const authEnvFilename = "/auth.env"
|
||||||
const runnableFilename = "/.run"
|
const runnableFilename = "/.run"
|
||||||
|
const appdataFoldername = "/appdata"
|
||||||
|
const postInstallFilename = "/edgebox-postinstall.done"
|
||||||
const myEdgeAppServiceEnvFilename = "/myedgeapp.env"
|
const myEdgeAppServiceEnvFilename = "/myedgeapp.env"
|
||||||
const defaultContainerOperationSleepTime time.Duration = time.Second * 10
|
const defaultContainerOperationSleepTime time.Duration = time.Second * 10
|
||||||
|
|
||||||
@@ -62,6 +89,8 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
|||||||
|
|
||||||
edgeAppName := ID
|
edgeAppName := ID
|
||||||
edgeAppDescription := ""
|
edgeAppDescription := ""
|
||||||
|
edgeAppExperimental := false
|
||||||
|
edgeAppOptions := []EdgeAppOption{}
|
||||||
|
|
||||||
edgeAppEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + envFilename)
|
edgeAppEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + envFilename)
|
||||||
|
|
||||||
@@ -74,8 +103,108 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
|||||||
if edgeAppEnv["EDGEAPP_DESCRIPTION"] != "" {
|
if edgeAppEnv["EDGEAPP_DESCRIPTION"] != "" {
|
||||||
edgeAppDescription = edgeAppEnv["EDGEAPP_DESCRIPTION"]
|
edgeAppDescription = edgeAppEnv["EDGEAPP_DESCRIPTION"]
|
||||||
}
|
}
|
||||||
|
if edgeAppEnv["EDGEAPP_EXPERIMENTAL"] == "true" {
|
||||||
|
edgeAppExperimental = true
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
needsConfig := false
|
||||||
|
hasFilledOptions := false
|
||||||
|
edgeAppOptionsTemplate, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + optionsTemplateFilename)
|
||||||
|
if err != nil {
|
||||||
|
log.Println("Error loading options template file for edgeapp " + edgeAppName)
|
||||||
|
} else {
|
||||||
|
// Try to read the edgeAppOptionsEnv file
|
||||||
|
edgeAppOptionsEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + optionsEnvFilename)
|
||||||
|
if err != nil {
|
||||||
|
log.Println("Error loading options env file for edgeapp " + edgeAppName)
|
||||||
|
} else {
|
||||||
|
hasFilledOptions = true
|
||||||
|
}
|
||||||
|
|
||||||
|
for key, value := range edgeAppOptionsTemplate {
|
||||||
|
|
||||||
|
optionFilledValue := ""
|
||||||
|
if hasFilledOptions {
|
||||||
|
// Check if key exists in edgeAppOptionsEnv
|
||||||
|
optionFilledValue = edgeAppOptionsEnv[key]
|
||||||
|
}
|
||||||
|
|
||||||
|
format := ""
|
||||||
|
defaultValue := ""
|
||||||
|
description := ""
|
||||||
|
installLocked := false
|
||||||
|
|
||||||
|
// Parse value to separate by | and get the format, installLocked, description and default value
|
||||||
|
// Format is the first element
|
||||||
|
// InstallLocked is the second element
|
||||||
|
// Description is the third element
|
||||||
|
// Default value is the fourth element
|
||||||
|
|
||||||
|
valueSlices := strings.Split(value, "|")
|
||||||
|
if len(valueSlices) > 0 {
|
||||||
|
format = valueSlices[0]
|
||||||
|
}
|
||||||
|
if len(valueSlices) > 1 {
|
||||||
|
installLocked = valueSlices[1] == "true"
|
||||||
|
}
|
||||||
|
if len(valueSlices) > 2 {
|
||||||
|
description = valueSlices[2]
|
||||||
|
}
|
||||||
|
if len(valueSlices) > 3 {
|
||||||
|
defaultValue = valueSlices[3]
|
||||||
|
}
|
||||||
|
|
||||||
|
// // If value contains ">|", then get everything that is to the right of it as the description
|
||||||
|
// // and get everything between "<>" as the format
|
||||||
|
// if strings.Contains(value, ">|") {
|
||||||
|
// description = strings.Split(value, ">|")[1]
|
||||||
|
// // Check if description has default value. That would be everything that is to the right of the last "|"
|
||||||
|
// if strings.Contains(description, "|") {
|
||||||
|
// defaultValue = strings.Split(description, "|")[1]
|
||||||
|
// description = strings.Split(description, "|")[0]
|
||||||
|
// }
|
||||||
|
|
||||||
|
// value = strings.Split(value, ">|")[0]
|
||||||
|
// // Remove the initial < from value
|
||||||
|
// value = strings.TrimPrefix(value, "<")
|
||||||
|
// } else {
|
||||||
|
// // Trim initial < and final > from value
|
||||||
|
// value = strings.TrimPrefix(value, "<")
|
||||||
|
// value = strings.TrimSuffix(value, ">")
|
||||||
|
// }
|
||||||
|
|
||||||
|
isSecret := false
|
||||||
|
|
||||||
|
// Check if the lowercased key string contains the letters "pass", "secret", "key"
|
||||||
|
lowercaseKey := strings.ToLower(key)
|
||||||
|
// check if lowercaseInput contains "pass", "key", or "secret", or "token"
|
||||||
|
if strings.Contains(lowercaseKey, "pass") ||
|
||||||
|
strings.Contains(lowercaseKey, "key") ||
|
||||||
|
strings.Contains(lowercaseKey, "secret") ||
|
||||||
|
strings.Contains(lowercaseKey, "token") {
|
||||||
|
isSecret = true
|
||||||
|
}
|
||||||
|
|
||||||
|
currentOption := EdgeAppOption{
|
||||||
|
Key: key,
|
||||||
|
Value: optionFilledValue,
|
||||||
|
DefaultValue: defaultValue,
|
||||||
|
Description: description,
|
||||||
|
Format: format,
|
||||||
|
IsSecret: isSecret,
|
||||||
|
IsInstallLocked: installLocked,
|
||||||
|
}
|
||||||
|
edgeAppOptions = append(edgeAppOptions, currentOption)
|
||||||
|
|
||||||
|
if optionFilledValue == "" {
|
||||||
|
needsConfig = true
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
edgeAppInternetAccessible := false
|
edgeAppInternetAccessible := false
|
||||||
edgeAppInternetURL := ""
|
edgeAppInternetURL := ""
|
||||||
|
|
||||||
@@ -89,16 +218,36 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
edgeAppBasicAuthEnabled := false
|
||||||
|
edgeAppBasicAuthUsername := ""
|
||||||
|
edgeAppBasicAuthPassword := ""
|
||||||
|
|
||||||
|
edgeAppAuthEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + authEnvFilename)
|
||||||
|
if err != nil {
|
||||||
|
log.Println("No auth.env file found. Login status is disabled.")
|
||||||
|
} else {
|
||||||
|
if edgeAppAuthEnv["USERNAME"] != "" && edgeAppAuthEnv["PASSWORD"] != "" {
|
||||||
|
edgeAppBasicAuthEnabled = true
|
||||||
|
edgeAppBasicAuthUsername = edgeAppAuthEnv["USERNAME"]
|
||||||
|
edgeAppBasicAuthPassword = edgeAppAuthEnv["PASSWORD"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
result = MaybeEdgeApp{
|
result = MaybeEdgeApp{
|
||||||
EdgeApp: EdgeApp{
|
EdgeApp: EdgeApp{
|
||||||
ID: ID,
|
ID: ID,
|
||||||
Name: edgeAppName,
|
Name: edgeAppName,
|
||||||
Description: edgeAppDescription,
|
Description: edgeAppDescription,
|
||||||
|
Experimental: edgeAppExperimental,
|
||||||
Status: GetEdgeAppStatus(ID),
|
Status: GetEdgeAppStatus(ID),
|
||||||
Services: GetEdgeAppServices(ID),
|
Services: GetEdgeAppServices(ID),
|
||||||
InternetAccessible: edgeAppInternetAccessible,
|
InternetAccessible: edgeAppInternetAccessible,
|
||||||
NetworkURL: ID + ".edgebox.local",
|
NetworkURL: ID + "." + system.GetHostname() + ".local",
|
||||||
InternetURL: edgeAppInternetURL,
|
InternetURL: edgeAppInternetURL,
|
||||||
|
Options: edgeAppOptions,
|
||||||
|
NeedsConfig: needsConfig,
|
||||||
|
Login: EdgeAppLogin{edgeAppBasicAuthEnabled, edgeAppBasicAuthUsername, edgeAppBasicAuthPassword},
|
||||||
|
|
||||||
},
|
},
|
||||||
Valid: true,
|
Valid: true,
|
||||||
}
|
}
|
||||||
@@ -122,21 +271,53 @@ func IsEdgeAppInstalled(ID string) bool {
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func writeAppRunnableFiles(ID string) bool {
|
||||||
|
edgeAppPath := utils.GetPath(utils.EdgeAppsPath)
|
||||||
|
_, err := os.Stat(edgeAppPath + ID + runnableFilename)
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
_, err := os.Create(edgeAppPath + ID + runnableFilename)
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal("Runnable file for EdgeApp could not be created!")
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check the block default apps option
|
||||||
|
blockDefaultAppsOption := utils.ReadOption("DASHBOARD_BLOCK_DEFAULT_APPS_PUBLIC_ACCESS")
|
||||||
|
if blockDefaultAppsOption != "yes" {
|
||||||
|
// Create myedgeapp.env file with default network URL
|
||||||
|
envFilePath := edgeAppPath + ID + myEdgeAppServiceEnvFilename
|
||||||
|
|
||||||
|
var networkURL string
|
||||||
|
domainName := utils.ReadOption("DOMAIN_NAME")
|
||||||
|
|
||||||
|
if domainName != "" {
|
||||||
|
networkURL = ID + "." + domainName
|
||||||
|
} else if diagnostics.GetReleaseVersion() == diagnostics.CLOUD_VERSION {
|
||||||
|
cluster := utils.ReadOption("CLUSTER")
|
||||||
|
username := utils.ReadOption("USERNAME")
|
||||||
|
if cluster != "" && username != "" {
|
||||||
|
networkURL = username + "-" + ID + "." + cluster
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
networkURL = ID + "." + system.GetHostname() + ".local" // default
|
||||||
|
}
|
||||||
|
|
||||||
|
env, _ := godotenv.Unmarshal("INTERNET_URL=" + networkURL)
|
||||||
|
err = godotenv.Write(env, envFilePath)
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("Error creating myedgeapp.env file: %s", err)
|
||||||
|
// result = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
func SetEdgeAppInstalled(ID string) bool {
|
func SetEdgeAppInstalled(ID string) bool {
|
||||||
|
|
||||||
result := true
|
result := true
|
||||||
edgeAppPath := utils.GetPath(utils.EdgeAppsPath)
|
|
||||||
|
|
||||||
_, err := os.Stat(edgeAppPath + ID + runnableFilename)
|
if writeAppRunnableFiles(ID) {
|
||||||
if os.IsNotExist(err) {
|
|
||||||
|
|
||||||
_, err := os.Create(edgeAppPath + ID + runnableFilename)
|
|
||||||
result = true
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal("Runnable file for EdgeApp could not be created!")
|
|
||||||
result = false
|
|
||||||
}
|
|
||||||
|
|
||||||
buildFrameworkContainers()
|
buildFrameworkContainers()
|
||||||
|
|
||||||
@@ -151,13 +332,63 @@ func SetEdgeAppInstalled(ID string) bool {
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func SetEdgeAppNotInstalled(ID string) bool {
|
func SetEdgeAppBulkInstalled(IDs []string) bool {
|
||||||
|
|
||||||
result := true
|
result := true
|
||||||
|
|
||||||
|
for _, ID := range IDs {
|
||||||
|
writeAppRunnableFiles(ID)
|
||||||
|
}
|
||||||
|
|
||||||
|
buildFrameworkContainers()
|
||||||
|
|
||||||
|
return result
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
func SetEdgeAppNotInstalled(ID string) bool {
|
||||||
|
|
||||||
|
// Stop the app first
|
||||||
|
StopEdgeApp(ID)
|
||||||
|
|
||||||
|
// Now remove any files
|
||||||
|
result := true
|
||||||
|
|
||||||
err := os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + runnableFilename)
|
err := os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + runnableFilename)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
result = false
|
result = false
|
||||||
log.Fatal(err)
|
log.Println(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + authEnvFilename)
|
||||||
|
if err != nil {
|
||||||
|
result = false
|
||||||
|
log.Println(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.RemoveAll(utils.GetPath(utils.EdgeAppsPath) + ID + appdataFoldername)
|
||||||
|
if err != nil {
|
||||||
|
result = false
|
||||||
|
log.Println(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + myEdgeAppServiceEnvFilename)
|
||||||
|
if err != nil {
|
||||||
|
result = false
|
||||||
|
log.Println(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + optionsEnvFilename)
|
||||||
|
if err != nil {
|
||||||
|
result = false
|
||||||
|
log.Println(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + postInstallFilename)
|
||||||
|
if err != nil {
|
||||||
|
result = false
|
||||||
|
log.Println(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
buildFrameworkContainers()
|
buildFrameworkContainers()
|
||||||
@@ -246,12 +477,24 @@ func GetEdgeAppServices(ID string) []EdgeAppService {
|
|||||||
var edgeAppServices []EdgeAppService
|
var edgeAppServices []EdgeAppService
|
||||||
|
|
||||||
for _, serviceID := range serviceSlices {
|
for _, serviceID := range serviceSlices {
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
shouldBeRunning := false
|
||||||
cmdResult := utils.Exec(wsPath, "docker-compose", cmdArgs)
|
|
||||||
isRunning := false
|
isRunning := false
|
||||||
if cmdResult != "" {
|
|
||||||
isRunning = true
|
// Is service "runnable" when .run lockfile in the app folder
|
||||||
|
_, err := os.Stat(utils.GetPath(utils.EdgeAppsPath) + ID + runnableFilename)
|
||||||
|
if !os.IsNotExist(err) {
|
||||||
|
shouldBeRunning = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Check if the service is actually running
|
||||||
|
if shouldBeRunning {
|
||||||
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
||||||
|
cmdResult := utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
|
if cmdResult != "" {
|
||||||
|
isRunning = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
edgeAppServices = append(edgeAppServices, EdgeAppService{ID: serviceID, IsRunning: isRunning})
|
edgeAppServices = append(edgeAppServices, EdgeAppService{ID: serviceID, IsRunning: isRunning})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -268,7 +511,7 @@ func RunEdgeApp(ID string) EdgeAppStatus {
|
|||||||
for _, service := range services {
|
for _, service := range services {
|
||||||
|
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "start", service.ID}
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "start", service.ID}
|
||||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
}
|
}
|
||||||
|
|
||||||
// Wait for it to settle up before continuing...
|
// Wait for it to settle up before continuing...
|
||||||
@@ -286,7 +529,7 @@ func StopEdgeApp(ID string) EdgeAppStatus {
|
|||||||
for _, service := range services {
|
for _, service := range services {
|
||||||
|
|
||||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "stop", service.ID}
|
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "stop", service.ID}
|
||||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||||
}
|
}
|
||||||
|
|
||||||
// Wait for it to settle up before continuing...
|
// Wait for it to settle up before continuing...
|
||||||
@@ -296,6 +539,36 @@ func StopEdgeApp(ID string) EdgeAppStatus {
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// StopAllEdgeApps: Stops all EdgeApps and returns a count of how many were stopped
|
||||||
|
func StopAllEdgeApps() int {
|
||||||
|
edgeApps := GetEdgeApps()
|
||||||
|
appCount := 0
|
||||||
|
for _, edgeApp := range edgeApps {
|
||||||
|
StopEdgeApp(edgeApp.ID)
|
||||||
|
appCount++
|
||||||
|
}
|
||||||
|
|
||||||
|
return appCount
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
// StartAllEdgeApps: Starts all EdgeApps and returns a count of how many were started
|
||||||
|
func StartAllEdgeApps() int {
|
||||||
|
edgeApps := GetEdgeApps()
|
||||||
|
appCount := 0
|
||||||
|
for _, edgeApp := range edgeApps {
|
||||||
|
RunEdgeApp(edgeApp.ID)
|
||||||
|
appCount++
|
||||||
|
}
|
||||||
|
|
||||||
|
return appCount
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
func RestartEdgeAppsService() {
|
||||||
|
buildFrameworkContainers()
|
||||||
|
}
|
||||||
|
|
||||||
// EnableOnline : Write environment file and rebuild the necessary containers. Rebuilds containers in project (in case of change only)
|
// EnableOnline : Write environment file and rebuild the necessary containers. Rebuilds containers in project (in case of change only)
|
||||||
func EnableOnline(ID string, InternetURL string) MaybeEdgeApp {
|
func EnableOnline(ID string, InternetURL string) MaybeEdgeApp {
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package storage
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"strconv"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
@@ -73,12 +74,13 @@ const (
|
|||||||
DISK_TYPE_SDA DeviceIdentifier = "sda"
|
DISK_TYPE_SDA DeviceIdentifier = "sda"
|
||||||
DISK_TYPE_MCBLK DeviceIdentifier = "mmcblk0"
|
DISK_TYPE_MCBLK DeviceIdentifier = "mmcblk0"
|
||||||
DISK_TYPE_VDA DeviceIdentifier = "vda"
|
DISK_TYPE_VDA DeviceIdentifier = "vda"
|
||||||
|
MIN_DISK_SIZE int = 1048576 // 1GB in bytes
|
||||||
)
|
)
|
||||||
|
|
||||||
func GetDeviceIdentifier(release_version diagnostics.ReleaseVersion) DeviceIdentifier {
|
func GetDeviceIdentifier(release_version diagnostics.ReleaseVersion) DeviceIdentifier {
|
||||||
switch release_version {
|
switch release_version {
|
||||||
case diagnostics.CLOUD_VERSION:
|
case diagnostics.CLOUD_VERSION:
|
||||||
return DISK_TYPE_VDA
|
return DISK_TYPE_SDA
|
||||||
case diagnostics.PROD_VERSION:
|
case diagnostics.PROD_VERSION:
|
||||||
return DISK_TYPE_MCBLK
|
return DISK_TYPE_MCBLK
|
||||||
}
|
}
|
||||||
@@ -134,7 +136,13 @@ func GetDevices(release_version diagnostics.ReleaseVersion) []Device {
|
|||||||
currentDevice.InUse = currentDeviceInUseFlag
|
currentDevice.InUse = currentDeviceInUseFlag
|
||||||
currentDeviceInUseFlag = false
|
currentDeviceInUseFlag = false
|
||||||
currentPartitions = []Partition{}
|
currentPartitions = []Partition{}
|
||||||
devices = append(devices, currentDevice)
|
size, err := strconv.Atoi(currentDevice.Size)
|
||||||
|
if err != nil {
|
||||||
|
size = 0
|
||||||
|
}
|
||||||
|
if size > MIN_DISK_SIZE {
|
||||||
|
devices = append(devices, currentDevice)
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
firstDevice = false
|
firstDevice = false
|
||||||
}
|
}
|
||||||
@@ -193,8 +201,22 @@ func GetDevices(release_version diagnostics.ReleaseVersion) []Device {
|
|||||||
currentDevice.Status.Description = "Not configured"
|
currentDevice.Status.Description = "Not configured"
|
||||||
}
|
}
|
||||||
currentDevice.InUse = currentDeviceInUseFlag
|
currentDevice.InUse = currentDeviceInUseFlag
|
||||||
devices = append([]Device{currentDevice}, devices...) // Prepending the first device...
|
|
||||||
|
|
||||||
|
fmt.Println("Secondary Storage Devices Found: ", len(devices))
|
||||||
|
fmt.Println("Main Storage Device size: ", currentDevice.Size)
|
||||||
|
|
||||||
|
// only append device if size > 1GB
|
||||||
|
if currentDevice.Size != "" && currentDevice.Size != "0" {
|
||||||
|
// Convert size to int
|
||||||
|
// Convert string to int
|
||||||
|
size, err := strconv.Atoi(currentDevice.Size)
|
||||||
|
if err != nil {
|
||||||
|
size = 0
|
||||||
|
}
|
||||||
|
if size > MIN_DISK_SIZE {
|
||||||
|
devices = append([]Device{currentDevice}, devices...) // Prepending the first device...
|
||||||
|
}
|
||||||
|
}
|
||||||
devices = getDevicesSpaceUsage(devices)
|
devices = getDevicesSpaceUsage(devices)
|
||||||
|
|
||||||
return devices
|
return devices
|
||||||
|
|||||||
@@ -4,13 +4,29 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
|
"log"
|
||||||
|
"os"
|
||||||
|
"io"
|
||||||
|
"errors"
|
||||||
|
"os/exec"
|
||||||
|
"bufio"
|
||||||
|
"path/filepath"
|
||||||
|
"io/ioutil"
|
||||||
|
"encoding/json"
|
||||||
|
|
||||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
|
||||||
"github.com/joho/godotenv"
|
"github.com/joho/godotenv"
|
||||||
"github.com/shirou/gopsutil/host"
|
"github.com/shirou/gopsutil/host"
|
||||||
|
"github.com/go-yaml/yaml"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
type cloudflaredTunnelJson struct {
|
||||||
|
AccountTag string `json:"AccountTag"`
|
||||||
|
TunnelSecret string `json:"TunnelSecret"`
|
||||||
|
TunnelID string `json:"TunnelID"`
|
||||||
|
}
|
||||||
|
|
||||||
// GetUptimeInSeconds: Returns a value (as string) of the total system uptime
|
// GetUptimeInSeconds: Returns a value (as string) of the total system uptime
|
||||||
func GetUptimeInSeconds() string {
|
func GetUptimeInSeconds() string {
|
||||||
uptime, _ := host.Uptime()
|
uptime, _ := host.Uptime()
|
||||||
@@ -78,6 +94,22 @@ func SetupCloudOptions() {
|
|||||||
utils.WriteOption("EMAIL", cloudEnv["EMAIL"])
|
utils.WriteOption("EMAIL", cloudEnv["EMAIL"])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if cloudEnv["USERNAME"] != "" {
|
||||||
|
utils.WriteOption("USERNAME", cloudEnv["USERNAME"])
|
||||||
|
}
|
||||||
|
|
||||||
|
if cloudEnv["CLUSTER"] != "" {
|
||||||
|
utils.WriteOption("CLUSTER", cloudEnv["CLUSTER"])
|
||||||
|
}
|
||||||
|
|
||||||
|
if cloudEnv["CLUSTER_IP"] != "" {
|
||||||
|
utils.WriteOption("CLUSTER_IP", cloudEnv["CLUSTER_IP"])
|
||||||
|
}
|
||||||
|
|
||||||
|
if cloudEnv["CLUSTER_SSH_PORT"] != "" {
|
||||||
|
utils.WriteOption("CLUSTER_SSH_PORT", cloudEnv["CLUSTER_SSH_PORT"])
|
||||||
|
}
|
||||||
|
|
||||||
if cloudEnv["EDGEBOXIO_API_TOKEN"] != "" {
|
if cloudEnv["EDGEBOXIO_API_TOKEN"] != "" {
|
||||||
utils.WriteOption("EDGEBOXIO_API_TOKEN", cloudEnv["EDGEBOXIO_API_TOKEN"])
|
utils.WriteOption("EDGEBOXIO_API_TOKEN", cloudEnv["EDGEBOXIO_API_TOKEN"])
|
||||||
}
|
}
|
||||||
@@ -85,3 +117,484 @@ func SetupCloudOptions() {
|
|||||||
// In the end of this operation takes place, remove the env file as to not overwrite any options once they are set.
|
// In the end of this operation takes place, remove the env file as to not overwrite any options once they are set.
|
||||||
utils.Exec("/", "rm", []string{cloudEnvFileLocationPath})
|
utils.Exec("/", "rm", []string{cloudEnvFileLocationPath})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func StartSystemLogger() {
|
||||||
|
fmt.Println("Starting system logger")
|
||||||
|
loggerPath := utils.GetPath(utils.LoggerPath)
|
||||||
|
utils.Exec(loggerPath, "make", []string{"start"})
|
||||||
|
}
|
||||||
|
|
||||||
|
// UpdateSystemLoggerServices: Updates the services.txt file with the services that are currently running
|
||||||
|
func UpdateSystemLoggerServices(services []string) {
|
||||||
|
fmt.Println("Updating system logger services:")
|
||||||
|
fmt.Println(services)
|
||||||
|
loggerPath := utils.GetPath(utils.LoggerPath)
|
||||||
|
|
||||||
|
utils.Exec(loggerPath, "bash", []string{"-c", "rm services.txt && touch services.txt"})
|
||||||
|
|
||||||
|
for _, service := range services {
|
||||||
|
fmt.Println("Adding " + service + " to services.txt")
|
||||||
|
utils.Exec(loggerPath, "bash", []string{"-c", "echo " + service + " >> services.txt"})
|
||||||
|
}
|
||||||
|
|
||||||
|
// Add empty line at the end of file (best practice)
|
||||||
|
utils.Exec(loggerPath, "bash", []string{"-c", "echo '' >> services.txt"})
|
||||||
|
}
|
||||||
|
|
||||||
|
// StartWs: Starts the webserver service for Edgeapps
|
||||||
|
func StartWs() {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
fmt.Println("Starting WS")
|
||||||
|
cmdargs := []string{"-b"}
|
||||||
|
utils.Exec(wsPath, "./ws", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
// StartService: Starts a service
|
||||||
|
func StartService(serviceID string) {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
fmt.Println("Starting" + serviceID + "service")
|
||||||
|
cmdargs := []string{"start", serviceID}
|
||||||
|
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
// StopService: Stops a service
|
||||||
|
func StopService(serviceID string) {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
fmt.Println("Stopping" + serviceID + "service")
|
||||||
|
cmdargs := []string{"stop", "cloudflared"}
|
||||||
|
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
// RestartService: Restarts a service
|
||||||
|
func RestartService(serviceID string) {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
fmt.Println("Restarting" + serviceID + "service")
|
||||||
|
cmdargs := []string{"restart", serviceID}
|
||||||
|
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
// GetServiceStatus: Returns the status output of a service
|
||||||
|
func GetServiceStatus(serviceID string) string {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
cmdargs := []string{"status", serviceID}
|
||||||
|
return utils.Exec(wsPath, "systemctl", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
func CreateBackupsPasswordFile(password string) {
|
||||||
|
// Create a password file for backups
|
||||||
|
backupPasswordFile := utils.GetPath(utils.BackupPasswordFileLocation)
|
||||||
|
backupPasswordFileDir := filepath.Dir(backupPasswordFile)
|
||||||
|
|
||||||
|
if _, err := os.Stat(backupPasswordFileDir); os.IsNotExist(err) {
|
||||||
|
os.MkdirAll(backupPasswordFileDir, 0755)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Write the password to the file, overriting an existing file
|
||||||
|
err := ioutil.WriteFile(backupPasswordFile, []byte(password), 0644)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// CreateTunnel: Creates a tunnel via cloudflared, needs to be authenticated first
|
||||||
|
func CreateTunnel(configDestination string) {
|
||||||
|
fmt.Println("Creating Tunnel for Edgebox.")
|
||||||
|
cmd := exec.Command("sh", "/home/system/components/edgeboxctl/scripts/cloudflared_tunnel_create.sh")
|
||||||
|
stdout, err := cmd.StdoutPipe()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
scanner := bufio.NewScanner(stdout)
|
||||||
|
err = cmd.Start()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
for scanner.Scan() {
|
||||||
|
fmt.Println(scanner.Text())
|
||||||
|
text := scanner.Text()
|
||||||
|
fmt.Println(text)
|
||||||
|
}
|
||||||
|
if scanner.Err() != nil {
|
||||||
|
cmd.Process.Kill()
|
||||||
|
cmd.Wait()
|
||||||
|
panic(scanner.Err())
|
||||||
|
}
|
||||||
|
|
||||||
|
// This also needs to be executed in root and non root variants
|
||||||
|
fmt.Println("Reading cloudflared folder to get the JSON file.")
|
||||||
|
isRoot := false
|
||||||
|
dir := "/home/system/.cloudflared/"
|
||||||
|
dir2 := "/root/.cloudflared/"
|
||||||
|
files, err := os.ReadDir(dir)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
var jsonFile os.DirEntry
|
||||||
|
for _, file := range files {
|
||||||
|
// check if file has json extension
|
||||||
|
if filepath.Ext(file.Name()) == ".json" {
|
||||||
|
fmt.Println("Non-Root JSON file found: " + file.Name())
|
||||||
|
jsonFile = file
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// If the files are not in the home folder, try the root folder
|
||||||
|
if jsonFile == nil {
|
||||||
|
files, err = os.ReadDir(dir2)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
for _, file := range files {
|
||||||
|
// check if file has json extension
|
||||||
|
if filepath.Ext(file.Name()) == ".json" {
|
||||||
|
fmt.Println("Root JSON file found: " + file.Name())
|
||||||
|
jsonFile = file
|
||||||
|
isRoot = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if jsonFile == nil {
|
||||||
|
panic("No JSON file found in directory")
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Println("Reading JSON file.")
|
||||||
|
targetDir := "/home/system/.cloudflared/"
|
||||||
|
if isRoot {
|
||||||
|
targetDir = "/root/.cloudflared/"
|
||||||
|
}
|
||||||
|
|
||||||
|
jsonFilePath := filepath.Join(targetDir, jsonFile.Name())
|
||||||
|
jsonBytes, err := ioutil.ReadFile(jsonFilePath)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Println("Parsing JSON file.")
|
||||||
|
var data cloudflaredTunnelJson
|
||||||
|
err = json.Unmarshal(jsonBytes, &data)
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("Error reading tunnel JSON file: %s", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Println("Tunnel ID is:" + data.TunnelID)
|
||||||
|
|
||||||
|
// create the config.yml file with the following content in each line:
|
||||||
|
// "url": "http://localhost:80"
|
||||||
|
// "tunnel": "<TunnelID>"
|
||||||
|
// "credentials-file": "/root/.cloudflared/<tunnelID>.json"
|
||||||
|
|
||||||
|
file := configDestination
|
||||||
|
f, err := os.Create(file)
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
defer f.Close()
|
||||||
|
|
||||||
|
_, err = f.WriteString("url: http://localhost:80\ntunnel: " + data.TunnelID + "\ncredentials-file: " + jsonFilePath)
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// DeleteTunnel: Deletes a tunnel via cloudflared, this does not remove the service
|
||||||
|
func DeleteTunnel() {
|
||||||
|
fmt.Println("Deleting possible previous tunnel.")
|
||||||
|
|
||||||
|
// Configure the service and start it
|
||||||
|
cmd := exec.Command("sh", "/home/system/components/edgeboxctl/scripts/cloudflared_tunnel_delete.sh")
|
||||||
|
stdout, err := cmd.StdoutPipe()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
scanner := bufio.NewScanner(stdout)
|
||||||
|
err = cmd.Start()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
for scanner.Scan() {
|
||||||
|
fmt.Println(scanner.Text())
|
||||||
|
text := scanner.Text()
|
||||||
|
fmt.Println(text)
|
||||||
|
}
|
||||||
|
if scanner.Err() != nil {
|
||||||
|
cmd.Process.Kill()
|
||||||
|
cmd.Wait()
|
||||||
|
panic(scanner.Err())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// InstallTunnelService: Installs the tunnel service
|
||||||
|
func InstallTunnelService(config string) {
|
||||||
|
fmt.Println("Installing cloudflared service.")
|
||||||
|
cmd := exec.Command("cloudflared", "--config", config, "service", "install")
|
||||||
|
cmd.Start()
|
||||||
|
cmd.Wait()
|
||||||
|
}
|
||||||
|
|
||||||
|
// RemoveTunnelService: Removes the tunnel service
|
||||||
|
func RemoveTunnelService() {
|
||||||
|
wsPath := utils.GetPath(utils.WsPath)
|
||||||
|
fmt.Println("Removing possibly previous service install.")
|
||||||
|
cmd := exec.Command("cloudflared", "service", "uninstall")
|
||||||
|
cmd.Start()
|
||||||
|
cmd.Wait()
|
||||||
|
|
||||||
|
fmt.Println("Removing cloudflared files")
|
||||||
|
cmdargs := []string{"-rf", "/home/system/.cloudflared"}
|
||||||
|
utils.Exec(wsPath, "rm", cmdargs)
|
||||||
|
cmdargs = []string{"-rf", "/etc/cloudflared/config.yml"}
|
||||||
|
utils.Exec(wsPath, "rm", cmdargs)
|
||||||
|
cmdargs = []string{"-rf", "/root/.cloudflared/cert.pem"}
|
||||||
|
utils.Exec(wsPath, "rm", cmdargs)
|
||||||
|
}
|
||||||
|
|
||||||
|
func CopyDir(src string, dest string) error {
|
||||||
|
srcInfo, err := os.Stat(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if !srcInfo.IsDir() {
|
||||||
|
return fmt.Errorf("%s is not a directory", src)
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.MkdirAll(dest, srcInfo.Mode())
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
items, err := ioutil.ReadDir(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, item := range items {
|
||||||
|
srcPath := filepath.Join(src, item.Name())
|
||||||
|
destPath := filepath.Join(dest, item.Name())
|
||||||
|
|
||||||
|
if item.IsDir() {
|
||||||
|
err = CopyDir(srcPath, destPath)
|
||||||
|
if err != nil {
|
||||||
|
fmt.Printf("error copying directory %s to %s: %s\n", srcPath, destPath, err.Error())
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
err = CopyFile(srcPath, destPath)
|
||||||
|
if err != nil {
|
||||||
|
fmt.Printf("error copying file %s to %s: %s\n", srcPath, destPath, err.Error())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func CopyFile(src string, dest string) error {
|
||||||
|
srcFile, err := os.Open(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer srcFile.Close()
|
||||||
|
|
||||||
|
destFile, err := os.Create(dest)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer destFile.Close()
|
||||||
|
|
||||||
|
_, err = io.Copy(destFile, srcFile)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
err = destFile.Sync()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
srcInfo, err := os.Stat(src)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
err = os.Chmod(dest, srcInfo.Mode())
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func CheckUpdates() {
|
||||||
|
fmt.Println("Checking for Edgebox System Updates.")
|
||||||
|
|
||||||
|
// Configure the service and start it
|
||||||
|
cmd := exec.Command("sh", "/home/system/components/updater/run.sh", "--check")
|
||||||
|
stdout, err := cmd.StdoutPipe()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
scanner := bufio.NewScanner(stdout)
|
||||||
|
err = cmd.Start()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
for scanner.Scan() {
|
||||||
|
// fmt.Println(scanner.Text())
|
||||||
|
text := scanner.Text()
|
||||||
|
fmt.Println(text)
|
||||||
|
}
|
||||||
|
if scanner.Err() != nil {
|
||||||
|
cmd.Process.Kill()
|
||||||
|
cmd.Wait()
|
||||||
|
fmt.Println("Error running updates check.")
|
||||||
|
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Read targets.env file into JSON list structure
|
||||||
|
targets := []string{}
|
||||||
|
targetsFile, err := os.Open("/home/system/components/updater/targets.env")
|
||||||
|
if err != nil {
|
||||||
|
fmt.Println("No targets.env file found. Skipping.")
|
||||||
|
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer targetsFile.Close()
|
||||||
|
scanner = bufio.NewScanner(targetsFile)
|
||||||
|
for scanner.Scan() {
|
||||||
|
text := scanner.Text()
|
||||||
|
// text line should look like: {"target": "<target>", "version": "<version>"}
|
||||||
|
target := strings.Split(text, "=")
|
||||||
|
newText := "{\"target\": \"" + strings.Replace(target[0], "_VERSION", "", -1) + "\", \"version\": \"" + target[1] + "\"}"
|
||||||
|
targets = append(targets, newText)
|
||||||
|
}
|
||||||
|
if scanner.Err() != nil {
|
||||||
|
fmt.Println("Error reading update targets file.")
|
||||||
|
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// convert targets to string
|
||||||
|
targetsString := strings.Join(targets, ",")
|
||||||
|
targetsString = "[" + targetsString + "]"
|
||||||
|
|
||||||
|
fmt.Println(targetsString)
|
||||||
|
|
||||||
|
// Write option with targets
|
||||||
|
utils.WriteOption("SYSTEM_UPDATES", targetsString)
|
||||||
|
}
|
||||||
|
|
||||||
|
func ApplyUpdates() {
|
||||||
|
fmt.Println("Applying Edgebox System Updates.")
|
||||||
|
|
||||||
|
utils.WriteOption("UPDATING_SYSTEM", "true")
|
||||||
|
|
||||||
|
// Configure the service and start it
|
||||||
|
cmd := exec.Command("sh", "/home/system/components/updater/run.sh", "--update")
|
||||||
|
stdout, err := cmd.StdoutPipe()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
scanner := bufio.NewScanner(stdout)
|
||||||
|
err = cmd.Start()
|
||||||
|
if err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
for scanner.Scan() {
|
||||||
|
fmt.Println(scanner.Text())
|
||||||
|
text := scanner.Text()
|
||||||
|
fmt.Println(text)
|
||||||
|
}
|
||||||
|
if scanner.Err() != nil {
|
||||||
|
cmd.Process.Kill()
|
||||||
|
cmd.Wait()
|
||||||
|
panic(scanner.Err())
|
||||||
|
}
|
||||||
|
|
||||||
|
// If the system did not yet restart, set updating system to false
|
||||||
|
utils.WriteOption("UPDATING_SYSTEM", "false")
|
||||||
|
}
|
||||||
|
|
||||||
|
func FetchBrowserDevPasswordFromFile() (string, error) {
|
||||||
|
fmt.Println("Executing FetchBrowserDevPasswordFromFile")
|
||||||
|
|
||||||
|
// Read the "password" entry on the yaml file
|
||||||
|
// Read the yaml file in system.GetPath(BrowserDevPasswordFileLocation)
|
||||||
|
yamlFile, err := ioutil.ReadFile(utils.GetPath(utils.BrowserDevPasswordFileLocation))
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Parse the yaml file and get the "password" entry
|
||||||
|
var yamlFileMap yaml.MapSlice
|
||||||
|
err = yaml.Unmarshal(yamlFile, &yamlFileMap)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, item := range yamlFileMap {
|
||||||
|
key, value := item.Key, item.Value
|
||||||
|
if key == "password" {
|
||||||
|
if pwString, ok := value.(string); ok {
|
||||||
|
return pwString, nil
|
||||||
|
} else {
|
||||||
|
return "", errors.New("password value is not a string")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return "", errors.New("password key not found")
|
||||||
|
}
|
||||||
|
|
||||||
|
func SetBrowserDevPasswordFile(password string) error {
|
||||||
|
// Get current password from file
|
||||||
|
currentPassword, err := FetchBrowserDevPasswordFromFile()
|
||||||
|
if err != nil {
|
||||||
|
fmt.Println("Error fetching current password from file.")
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Write the new password on the file using ReplaceTextInFile
|
||||||
|
err = ReplaceTextInFile(utils.GetPath(utils.BrowserDevPasswordFileLocation), currentPassword, password)
|
||||||
|
if err != nil {
|
||||||
|
fmt.Println("Error writing new password to file.")
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func ReplaceTextInFile(filePath string, oldText string, newText string) error {
|
||||||
|
// Open the file for reading
|
||||||
|
file, err := os.OpenFile(filePath, os.O_RDWR, 0644)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Read the file contents
|
||||||
|
data, err := ioutil.ReadAll(file)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Close the file
|
||||||
|
err = file.Close()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// Replace the text in the file
|
||||||
|
newData := strings.Replace(string(data), oldText, newText, -1)
|
||||||
|
|
||||||
|
// Write the new data back to the file
|
||||||
|
err = ioutil.WriteFile(filePath, []byte(newData), 0644)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,217 @@
|
|||||||
|
package tasks
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/binary"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
sshDirectory = "/root/.ssh"
|
||||||
|
managedSSHComment = "edgebox-dashboard-managed"
|
||||||
|
)
|
||||||
|
|
||||||
|
type sshAccessResult struct {
|
||||||
|
Status string `json:"status"`
|
||||||
|
PublicKey string `json:"public_key,omitempty"`
|
||||||
|
Fingerprint string `json:"fingerprint,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func taskEnableSSHAccess(args taskEnableSSHAccessArgs) (string, error) {
|
||||||
|
if err := verifyRootSSHAccess(); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
publicKey, fingerprint, err := parseSSHEd25519PublicKey(args.PublicKey)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(sshDirectory, publicKey); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.WriteOption("SSH_ACCESS_ENABLED", "true")
|
||||||
|
utils.WriteOption("SSH_PUBLIC_KEY", publicKey)
|
||||||
|
utils.WriteOption("SSH_KEY_FINGERPRINT", fingerprint)
|
||||||
|
|
||||||
|
result, err := json.Marshal(sshAccessResult{
|
||||||
|
Status: "enabled",
|
||||||
|
PublicKey: publicKey,
|
||||||
|
Fingerprint: fingerprint,
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
return string(result), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func taskDisableSSHAccess() (string, error) {
|
||||||
|
if err := reconcileManagedSSHKey(sshDirectory, ""); err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
utils.WriteOption("SSH_ACCESS_ENABLED", "false")
|
||||||
|
utils.DeleteOption("SSH_PUBLIC_KEY")
|
||||||
|
utils.DeleteOption("SSH_KEY_FINGERPRINT")
|
||||||
|
|
||||||
|
result, err := json.Marshal(sshAccessResult{Status: "disabled"})
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
|
||||||
|
return string(result), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseSSHEd25519PublicKey(input string) (string, string, error) {
|
||||||
|
trimmed := strings.TrimSpace(input)
|
||||||
|
if trimmed == "" || strings.ContainsAny(trimmed, "\r\n") {
|
||||||
|
return "", "", fmt.Errorf("provide exactly one SSH public key")
|
||||||
|
}
|
||||||
|
|
||||||
|
fields := strings.Fields(trimmed)
|
||||||
|
if len(fields) < 2 || len(fields) > 3 || fields[0] != "ssh-ed25519" {
|
||||||
|
return "", "", fmt.Errorf("only one ssh-ed25519 public key is supported")
|
||||||
|
}
|
||||||
|
|
||||||
|
keyBlob, err := base64.StdEncoding.DecodeString(fields[1])
|
||||||
|
if err != nil || !validEd25519KeyBlob(keyBlob) {
|
||||||
|
return "", "", fmt.Errorf("invalid ssh-ed25519 public key")
|
||||||
|
}
|
||||||
|
|
||||||
|
digest := sha256.Sum256(keyBlob)
|
||||||
|
publicKey := "ssh-ed25519 " + base64.StdEncoding.EncodeToString(keyBlob) + " " + managedSSHComment
|
||||||
|
fingerprint := "SHA256:" + base64.RawStdEncoding.EncodeToString(digest[:])
|
||||||
|
|
||||||
|
return publicKey, fingerprint, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func validEd25519KeyBlob(blob []byte) bool {
|
||||||
|
if len(blob) < 4 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
typeLength := int(binary.BigEndian.Uint32(blob[:4]))
|
||||||
|
if typeLength != len("ssh-ed25519") || len(blob) < 4+typeLength+4 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if string(blob[4:4+typeLength]) != "ssh-ed25519" {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
keyLengthOffset := 4 + typeLength
|
||||||
|
keyLength := int(binary.BigEndian.Uint32(blob[keyLengthOffset : keyLengthOffset+4]))
|
||||||
|
return keyLength == 32 && len(blob) == keyLengthOffset+4+keyLength
|
||||||
|
}
|
||||||
|
|
||||||
|
func reconcileManagedSSHKey(directory string, publicKey string) error {
|
||||||
|
if info, err := os.Lstat(directory); err == nil {
|
||||||
|
if info.Mode()&os.ModeSymlink != 0 || !info.IsDir() {
|
||||||
|
return fmt.Errorf("SSH directory is not a regular directory")
|
||||||
|
}
|
||||||
|
} else if !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("inspect SSH directory: %w", err)
|
||||||
|
} else if err := os.MkdirAll(directory, 0700); err != nil {
|
||||||
|
return fmt.Errorf("create SSH directory: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := os.Chmod(directory, 0700); err != nil {
|
||||||
|
return fmt.Errorf("secure SSH directory: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||||
|
if info, err := os.Lstat(authorizedKeysPath); err == nil && info.Mode()&os.ModeSymlink != 0 {
|
||||||
|
return fmt.Errorf("authorized_keys must not be a symbolic link")
|
||||||
|
} else if err != nil && !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("inspect authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
existing, err := os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil && !os.IsNotExist(err) {
|
||||||
|
return fmt.Errorf("read authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
lines := strings.Split(string(existing), "\n")
|
||||||
|
kept := make([]string, 0, len(lines)+1)
|
||||||
|
for _, line := range lines {
|
||||||
|
if strings.TrimSpace(line) == "" || isManagedSSHKey(line) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
kept = append(kept, line)
|
||||||
|
}
|
||||||
|
if publicKey != "" {
|
||||||
|
kept = append(kept, publicKey)
|
||||||
|
}
|
||||||
|
|
||||||
|
contents := ""
|
||||||
|
if len(kept) > 0 {
|
||||||
|
contents = strings.Join(kept, "\n") + "\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
temporary, err := os.CreateTemp(directory, ".authorized_keys-*")
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("create authorized_keys temporary file: %w", err)
|
||||||
|
}
|
||||||
|
temporaryPath := temporary.Name()
|
||||||
|
defer os.Remove(temporaryPath)
|
||||||
|
|
||||||
|
if err := temporary.Chmod(0600); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("secure authorized_keys temporary file: %w", err)
|
||||||
|
}
|
||||||
|
if _, err := temporary.WriteString(contents); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("write authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := temporary.Sync(); err != nil {
|
||||||
|
temporary.Close()
|
||||||
|
return fmt.Errorf("sync authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := temporary.Close(); err != nil {
|
||||||
|
return fmt.Errorf("close authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
if err := os.Rename(temporaryPath, authorizedKeysPath); err != nil {
|
||||||
|
return fmt.Errorf("replace authorized_keys: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func isManagedSSHKey(line string) bool {
|
||||||
|
fields := strings.Fields(line)
|
||||||
|
return len(fields) == 3 && fields[2] == managedSSHComment
|
||||||
|
}
|
||||||
|
|
||||||
|
func verifyRootSSHAccess() error {
|
||||||
|
sshdPath, err := exec.LookPath("sshd")
|
||||||
|
if err != nil {
|
||||||
|
sshdPath = "/usr/sbin/sshd"
|
||||||
|
if _, statErr := os.Stat(sshdPath); statErr != nil {
|
||||||
|
return fmt.Errorf("OpenSSH server is not installed")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
output, err := exec.Command(sshdPath, "-T").Output()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("could not verify the effective SSH server configuration")
|
||||||
|
}
|
||||||
|
|
||||||
|
settings := string(output)
|
||||||
|
if !strings.Contains(settings, "pubkeyauthentication yes") {
|
||||||
|
return fmt.Errorf("SSH public-key authentication is disabled")
|
||||||
|
}
|
||||||
|
if strings.Contains(settings, "permitrootlogin no") {
|
||||||
|
return fmt.Errorf("SSH root login is disabled")
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,111 @@
|
|||||||
|
package tasks
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/binary"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func testPublicKey(t *testing.T) string {
|
||||||
|
t.Helper()
|
||||||
|
blob := make([]byte, 4+len("ssh-ed25519")+4+32)
|
||||||
|
binary.BigEndian.PutUint32(blob[:4], uint32(len("ssh-ed25519")))
|
||||||
|
copy(blob[4:], "ssh-ed25519")
|
||||||
|
offset := 4 + len("ssh-ed25519")
|
||||||
|
binary.BigEndian.PutUint32(blob[offset:offset+4], 32)
|
||||||
|
for index := 0; index < 32; index++ {
|
||||||
|
blob[offset+4+index] = byte(index + 1)
|
||||||
|
}
|
||||||
|
return "ssh-ed25519 " + base64.StdEncoding.EncodeToString(blob) + " workstation"
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseSSHEd25519PublicKey(t *testing.T) {
|
||||||
|
publicKey, fingerprint, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if !strings.HasSuffix(publicKey, " "+managedSSHComment) {
|
||||||
|
t.Fatalf("public key does not have managed marker: %q", publicKey)
|
||||||
|
}
|
||||||
|
if !strings.HasPrefix(fingerprint, "SHA256:") {
|
||||||
|
t.Fatalf("unexpected fingerprint: %q", fingerprint)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseSSHEd25519PublicKeyRejectsUnsafeInput(t *testing.T) {
|
||||||
|
inputs := []string{
|
||||||
|
"",
|
||||||
|
"-----BEGIN OPENSSH PRIVATE KEY-----",
|
||||||
|
testPublicKey(t) + "\n" + testPublicKey(t),
|
||||||
|
"command=whoami " + testPublicKey(t),
|
||||||
|
"ssh-rsa AAAA invalid",
|
||||||
|
}
|
||||||
|
for _, input := range inputs {
|
||||||
|
if _, _, err := parseSSHEd25519PublicKey(input); err == nil {
|
||||||
|
t.Fatalf("expected input to be rejected: %q", input)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReconcileManagedSSHKeyPreservesUnrelatedKeys(t *testing.T) {
|
||||||
|
directory := t.TempDir()
|
||||||
|
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||||
|
original := "# operator key\nssh-ed25519 AAAAoperator operator\n"
|
||||||
|
if err := os.WriteFile(authorizedKeysPath, []byte(original), 0644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
publicKey, _, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
contents, err := os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if strings.Count(string(contents), managedSSHComment) != 1 {
|
||||||
|
t.Fatalf("managed key is not idempotent: %s", contents)
|
||||||
|
}
|
||||||
|
if !strings.Contains(string(contents), original) {
|
||||||
|
t.Fatalf("unrelated content was changed: %s", contents)
|
||||||
|
}
|
||||||
|
if info, err := os.Stat(authorizedKeysPath); err != nil || info.Mode().Perm() != 0600 {
|
||||||
|
t.Fatalf("authorized_keys mode is not 0600: %v, %v", info, err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(directory, ""); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
contents, err = os.ReadFile(authorizedKeysPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if string(contents) != original {
|
||||||
|
t.Fatalf("disable changed unrelated content: %q", contents)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReconcileManagedSSHKeyRejectsSymlink(t *testing.T) {
|
||||||
|
directory := t.TempDir()
|
||||||
|
target := filepath.Join(directory, "target")
|
||||||
|
if err := os.WriteFile(target, []byte("preserve me"), 0600); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := os.Symlink(target, filepath.Join(directory, "authorized_keys")); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := reconcileManagedSSHKey(directory, ""); err == nil {
|
||||||
|
t.Fatal("expected symlink to be rejected")
|
||||||
|
}
|
||||||
|
}
|
||||||
+1143
-17
File diff suppressed because it is too large
Load Diff
+102
-3
@@ -16,7 +16,7 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
// ExecAndStream : Runs a terminal command, but streams progress instead of outputting. Ideal for long lived process that need to be logged.
|
// ExecAndStream : Runs a terminal command, but streams progress instead of outputting. Ideal for long lived process that need to be logged.
|
||||||
func ExecAndStream(path string, command string, args []string) {
|
func ExecAndStream(path string, command string, args []string) string {
|
||||||
|
|
||||||
cmd := exec.Command(command, args...)
|
cmd := exec.Command(command, args...)
|
||||||
|
|
||||||
@@ -27,13 +27,17 @@ func ExecAndStream(path string, command string, args []string) {
|
|||||||
|
|
||||||
err := cmd.Run()
|
err := cmd.Run()
|
||||||
|
|
||||||
|
outStr, errStr := string(stdoutBuf.Bytes()), string(stderrBuf.Bytes())
|
||||||
|
|
||||||
|
returnVal := outStr
|
||||||
if err != nil {
|
if err != nil {
|
||||||
fmt.Printf("cmd.Run() failed with %s\n", err)
|
fmt.Printf("cmd.Run() failed with %s\n", err)
|
||||||
|
returnVal = errStr
|
||||||
}
|
}
|
||||||
|
|
||||||
outStr, errStr := string(stdoutBuf.Bytes()), string(stderrBuf.Bytes())
|
|
||||||
fmt.Printf("\nout:\n%s\nerr:\n%s\n", outStr, errStr)
|
fmt.Printf("\nout:\n%s\nerr:\n%s\n", outStr, errStr)
|
||||||
|
|
||||||
|
return returnVal
|
||||||
}
|
}
|
||||||
|
|
||||||
// Exec : Runs a terminal Command, catches and logs errors, returns the result.
|
// Exec : Runs a terminal Command, catches and logs errors, returns the result.
|
||||||
@@ -100,11 +104,18 @@ func GetSQLiteFormattedDateTime(t time.Time) string {
|
|||||||
return formatedDatetime
|
return formatedDatetime
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const BackupPasswordFileLocation string = "backupPasswordFileLocation"
|
||||||
const CloudEnvFileLocation string = "cloudEnvFileLocation"
|
const CloudEnvFileLocation string = "cloudEnvFileLocation"
|
||||||
const ApiEnvFileLocation string = "apiEnvFileLocation"
|
const ApiEnvFileLocation string = "apiEnvFileLocation"
|
||||||
const ApiPath string = "apiPath"
|
const ApiPath string = "apiPath"
|
||||||
const EdgeAppsPath string = "edgeAppsPath"
|
const EdgeAppsPath string = "edgeAppsPath"
|
||||||
|
const EdgeAppsBackupPath string = "edgeAppsBackupPath"
|
||||||
const WsPath string = "wsPath"
|
const WsPath string = "wsPath"
|
||||||
|
const BrowserDevPath string = "browserDevPath"
|
||||||
|
const LoggerPath string = "loggerPath"
|
||||||
|
const BrowserDevPasswordFileLocation string = "browserDevPasswordFileLocation"
|
||||||
|
const BrowserDevProxyPath string = "browserDevProxyPath"
|
||||||
|
|
||||||
|
|
||||||
// GetPath : Returns either the hardcoded path, or a overwritten value via .env file at project root. Register paths here for seamless working code between dev and prod environments ;)
|
// GetPath : Returns either the hardcoded path, or a overwritten value via .env file at project root. Register paths here for seamless working code between dev and prod environments ;)
|
||||||
func GetPath(pathKey string) string {
|
func GetPath(pathKey string) string {
|
||||||
@@ -124,7 +135,7 @@ func GetPath(pathKey string) string {
|
|||||||
if env["CLOUD_ENV_FILE_LOCATION"] != "" {
|
if env["CLOUD_ENV_FILE_LOCATION"] != "" {
|
||||||
targetPath = env["CLOUD_ENV_FILE_LOCATION"]
|
targetPath = env["CLOUD_ENV_FILE_LOCATION"]
|
||||||
} else {
|
} else {
|
||||||
targetPath = "/home/system/components/edgeboxctl/cloud.env"
|
targetPath = "/home/system/components/api/cloud.env"
|
||||||
}
|
}
|
||||||
|
|
||||||
case ApiEnvFileLocation:
|
case ApiEnvFileLocation:
|
||||||
@@ -151,6 +162,13 @@ func GetPath(pathKey string) string {
|
|||||||
targetPath = "/home/system/components/apps/"
|
targetPath = "/home/system/components/apps/"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
case EdgeAppsBackupPath:
|
||||||
|
if env["EDGEAPPS_BACKUP_PATH"] != "" {
|
||||||
|
targetPath = env["EDGEAPPS_BACKUP_PATH"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/backups/"
|
||||||
|
}
|
||||||
|
|
||||||
case WsPath:
|
case WsPath:
|
||||||
|
|
||||||
if env["WS_PATH"] != "" {
|
if env["WS_PATH"] != "" {
|
||||||
@@ -159,6 +177,43 @@ func GetPath(pathKey string) string {
|
|||||||
targetPath = "/home/system/components/ws/"
|
targetPath = "/home/system/components/ws/"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
case BrowserDevPath:
|
||||||
|
|
||||||
|
if env["BROWSERDEV_PATH"] != "" {
|
||||||
|
targetPath = env["BROWSERDEV_PATH"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/dev/"
|
||||||
|
}
|
||||||
|
|
||||||
|
case LoggerPath:
|
||||||
|
if env["LOGGER_PATH"] != "" {
|
||||||
|
targetPath = env["LOGGER_PATH"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/logger/"
|
||||||
|
}
|
||||||
|
|
||||||
|
case BackupPasswordFileLocation:
|
||||||
|
|
||||||
|
if env["BACKUP_PASSWORD_FILE_LOCATION"] != "" {
|
||||||
|
targetPath = env["BACKUP_PASSWORD_FILE_LOCATION"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/backups/pw.txt"
|
||||||
|
}
|
||||||
|
|
||||||
|
case BrowserDevPasswordFileLocation:
|
||||||
|
if env["BROWSERDEV_PASSWORD_FILE_LOCATION"] != "" {
|
||||||
|
targetPath = env["BROWSERDEV_PASSWORD_FILE_LOCATION"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/root/.config/code-server/config.yaml"
|
||||||
|
}
|
||||||
|
|
||||||
|
case BrowserDevProxyPath:
|
||||||
|
if env["BROWSERDEV_PROXY_PATH"] != "" {
|
||||||
|
targetPath = env["BROWSERDEV_PROXY_PATH"]
|
||||||
|
} else {
|
||||||
|
targetPath = "/home/system/components/dev/"
|
||||||
|
}
|
||||||
|
|
||||||
default:
|
default:
|
||||||
|
|
||||||
log.Printf("path_key %s nonexistant in GetPath().\n", pathKey)
|
log.Printf("path_key %s nonexistant in GetPath().\n", pathKey)
|
||||||
@@ -192,3 +247,47 @@ func WriteOption(optionKey string, optionValue string) {
|
|||||||
|
|
||||||
db.Close()
|
db.Close()
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ReadOption : Reads a key value pair option from the api shared database
|
||||||
|
func ReadOption(optionKey string) string {
|
||||||
|
|
||||||
|
db, err := sql.Open("sqlite3", GetSQLiteDbConnectionDetails())
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal(err.Error())
|
||||||
|
}
|
||||||
|
|
||||||
|
var optionValue string
|
||||||
|
|
||||||
|
err = db.QueryRow("SELECT value FROM option WHERE name = ?", optionKey).Scan(&optionValue)
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
log.Println(err.Error())
|
||||||
|
}
|
||||||
|
|
||||||
|
db.Close()
|
||||||
|
|
||||||
|
return optionValue
|
||||||
|
}
|
||||||
|
|
||||||
|
// DeleteOption : Deletes a key value pair option from the api shared database
|
||||||
|
func DeleteOption(optionKey string) {
|
||||||
|
|
||||||
|
db, err := sql.Open("sqlite3", GetSQLiteDbConnectionDetails())
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal(err.Error())
|
||||||
|
}
|
||||||
|
|
||||||
|
statement, err := db.Prepare("DELETE FROM option WHERE name = ?;") // Prepare SQL Statement
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal(err.Error())
|
||||||
|
}
|
||||||
|
|
||||||
|
_, err = statement.Exec(optionKey) // Execute SQL Statement
|
||||||
|
if err != nil {
|
||||||
|
log.Fatal(err.Error())
|
||||||
|
}
|
||||||
|
|
||||||
|
db.Close()
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
#!/usr/bin/env sh
|
||||||
|
|
||||||
|
echo "Starting script login"
|
||||||
|
cloudflared tunnel login 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log &
|
||||||
|
echo "sleeping 5 seconds"
|
||||||
|
sleep 5
|
||||||
Executable
+7
@@ -0,0 +1,7 @@
|
|||||||
|
#!/usr/bin/env sh
|
||||||
|
|
||||||
|
echo "Starting script create"
|
||||||
|
# script -q -c "cloudflared tunnel login 2>&1 | tee /app/output.log" &
|
||||||
|
cloudflared tunnel create edgebox 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log
|
||||||
|
echo "sleeping 5 seconds"
|
||||||
|
sleep 5
|
||||||
Executable
+7
@@ -0,0 +1,7 @@
|
|||||||
|
#!/usr/bin/env sh
|
||||||
|
|
||||||
|
echo "Starting script delete"
|
||||||
|
TUNNEL_ORIGIN_CERT=/home/system/.cloudflared/cert.pem
|
||||||
|
cloudflared tunnel delete edgebox 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log &
|
||||||
|
echo "sleeping 5 seconds"
|
||||||
|
sleep 5
|
||||||
Reference in New Issue
Block a user