mirror of
https://github.com/edgebox-iot/edgeboxctl.git
synced 2026-09-24 05:41:43 +02:00
Compare commits
43
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9bbe3d9997 | ||
|
|
7996c552f8 | ||
|
|
dbc831e972 | ||
|
|
19acbcbaad | ||
|
|
1e0a5df370 | ||
|
|
7913be080d | ||
|
|
e80aaf7d18 | ||
|
|
b11034dd17 | ||
|
|
80fc8b40cd | ||
|
|
01f423ee84 | ||
|
|
a8b1da4b7c | ||
|
|
6ccd4a3299 | ||
|
|
42b1a34ca7 | ||
|
|
4bb343769f | ||
|
|
3bb6200b1c | ||
|
|
eae72b0a79 | ||
|
|
8be566afb9 | ||
|
|
9c2a0dbefe | ||
|
|
4e399f63ea | ||
|
|
e238e9d71d | ||
|
|
db56530311 | ||
|
|
319acbd0e1 | ||
|
|
f0047a7a0c | ||
|
|
5c736a1b85 | ||
|
|
ca7f4af7fe | ||
|
|
445bc41d0e | ||
|
|
8bf26a334c | ||
|
|
e009c1f55d | ||
|
|
284acb18a4 | ||
|
|
8d0de36cdd | ||
|
|
113785def4 | ||
|
|
df13bf705d | ||
|
|
335b7ec29e | ||
|
|
13275f80a5 | ||
|
|
04cdba7479 | ||
|
|
a66ff40e65 | ||
|
|
f7823b9e20 | ||
|
|
ece500c342 | ||
|
|
161ec76eb9 | ||
|
|
d9720a48c9 | ||
|
|
1ba5a8f506 | ||
|
|
25d5ca74f8 | ||
|
|
d62cb57222 |
@@ -0,0 +1,10 @@
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: "gomod"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
- package-ecosystem: "github-actions"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
@@ -13,16 +13,16 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v2
|
||||
uses: actions/setup-go@v5
|
||||
with:
|
||||
go-version: ^1.15
|
||||
go-version: '1.20.2'
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@v4
|
||||
- name: Build
|
||||
run: make build
|
||||
- name: Test
|
||||
run: make test-with-coverage
|
||||
- uses: codecov/codecov-action@v1
|
||||
with:
|
||||
token: ${{ secrets.CODECOV_TOKEN }}
|
||||
files: coverage.out
|
||||
# - uses: codecov/codecov-action@v1
|
||||
# with:
|
||||
# token: ${{ secrets.CODECOV_TOKEN }}
|
||||
# files: coverage.out
|
||||
|
||||
@@ -21,3 +21,6 @@ main
|
||||
# Build
|
||||
|
||||
/bin
|
||||
|
||||
# Logs from executed scripts
|
||||
/scripts/output.log
|
||||
|
||||
Vendored
+236
@@ -0,0 +1,236 @@
|
||||
{
|
||||
"version": "2.0.0",
|
||||
"tasks": [
|
||||
{
|
||||
"label": "Build",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
|
||||
},
|
||||
"group": {
|
||||
"kind": "build",
|
||||
"isDefault": true
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build All",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-all"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build Prod",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-prod"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build Cloud",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-cloud"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build ARM64",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-arm64"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build ARMHF",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-armhf"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Build AMD64",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["build-amd64"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"group": "build",
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Clean",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["clean"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Test",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["test"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Test with Coverage",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["test-with-coverage"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Run",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["run"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install Prod",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install-prod"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install Cloud",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install-cloud"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install ARM64",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install-arm64"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install ARMHF",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install-armhf"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Install AMD64",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["install-amd64"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Start",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["start"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Stop",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["stop"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Restart",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["restart"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Status",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["status"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
},
|
||||
{
|
||||
"label": "Logs",
|
||||
"type": "shell",
|
||||
"command": "make",
|
||||
"args": ["log"],
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}"
|
||||
},
|
||||
"problemMatcher": []
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
# Changelog
|
||||
|
||||
## [1.4.0] - 23-09-2026
|
||||
|
||||
* Added dashboard-managed SSH public-key access.
|
||||
* Validates ED25519 public keys and reports their SHA256 fingerprints.
|
||||
* Atomically installs or removes only the marked Edgebox key while preserving all other authorized keys.
|
||||
* Never generates, reads, stores, logs, or returns SSH private keys.
|
||||
|
||||
## [1.3.2] - 08-12-2024
|
||||
|
||||
* Fix to Browser Dev feature:
|
||||
* Checking browser dev url when internet_accessible was checking the incorrect path. This is now fixed.
|
||||
|
||||
## [1.3.1] - 08-12-2024
|
||||
|
||||
* Fixes to Browser Dev feature:
|
||||
* Now edgeboxctl also fetches or generates the browser dev environment url and saves it into an option both when starting, and every time the browser dev status is fetched.
|
||||
|
||||
## [1.3.0] - 05-12-2024
|
||||
|
||||
* Added Edgebox Browser Development Environment Feature Support
|
||||
* Added tasks for handling browser development environment into tasks.go
|
||||
* Added executable tasks to ExecuteTask and scheduled ones to ExecuteSchedules
|
||||
* Other bug fixes and improvements.
|
||||
|
||||
### Missing Past Releases
|
||||
|
||||
Release notes for past versions are not available in this file. Please refer to the [GitHub releases](https://hithub.com/edgebox-iot/edgeboxctl/releases) for more information. Feel free to contribute to this file by adding missing release notes.
|
||||
+3
-5
@@ -1,11 +1,9 @@
|
||||
FROM golang:latest
|
||||
FROM golang:1.20.2
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY ./ /app
|
||||
|
||||
RUN go mod download
|
||||
RUN go install github.com/githubnemo/CompileDaemon@latest
|
||||
|
||||
RUN go get github.com/githubnemo/CompileDaemon
|
||||
|
||||
ENTRYPOINT CompileDaemon --build="make build" --command=./bin/edgeboxctl
|
||||
ENTRYPOINT CompileDaemon --build="make build" --command=./bin/edgeboxctl-$(go env GOOS)-$(go env GOARCH)
|
||||
|
||||
@@ -1,35 +1,114 @@
|
||||
PROJECT?=github.com/edgebox-iot/edgeboxctl
|
||||
.DEFAULT_GOAL := build
|
||||
|
||||
PROJECT ?= github.com/edgebox-iot/edgeboxctl
|
||||
RELEASE ?= dev
|
||||
COMMIT := $(shell git rev-parse --short HEAD)
|
||||
BUILD_DATE := $(shell date -u '+%Y-%m-%d_%H:%M:%S')
|
||||
BUILD_DIR = bin
|
||||
GOOS := $(shell go env GOOS)
|
||||
GOARCH := $(shell go env GOARCH)
|
||||
|
||||
|
||||
build-all:
|
||||
@echo "\n🏗️ Building all architectures for ${RELEASE} mode"
|
||||
@echo "🟡 This will build all supported architectures and release combinations. It can take a while...\n"
|
||||
|
||||
GOOS=linux GOARCH=amd64 make build
|
||||
GOOS=linux GOARCH=arm make build
|
||||
|
||||
@echo "\n🟢 All builds completed and available at ./bin/ \n"
|
||||
|
||||
build-prod:
|
||||
GOOS=linux GOARCH=arm RELEASE=prod make build
|
||||
|
||||
build-cloud:
|
||||
GOOS=linux GOARCH=amd64 RELEASE=cloud make build
|
||||
|
||||
build-arm64:
|
||||
GOOS=linux GOARCH=arm64 RELEASE=prod make build
|
||||
|
||||
build-armhf:
|
||||
GOOS=linux GOARCH=arm RELEASE=prod make build
|
||||
|
||||
build-amd64:
|
||||
GOOS=linux GOARCH=amd64 RELEASE=prod make build
|
||||
|
||||
|
||||
build:
|
||||
@echo "Building ${GOOS}-${GOARCH}"
|
||||
@echo "\n🏗️ Building edgeboxctl (${RELEASE} release) on ${GOOS} (${GOARCH})"
|
||||
@echo "📦 Binary will be saved in ./${BUILD_DIR}/edgeboxctl-${GOOS}-${GOARCH}\n"
|
||||
|
||||
GOOS=${GOOS} GOARCH=${GOARCH} go build \
|
||||
-trimpath -ldflags "-s -w -X ${PROJECT}/internal/diagnostics.Version=${RELEASE} \
|
||||
-X ${PROJECT}/internal/diagnostics.Commit=${COMMIT} \
|
||||
-X ${PROJECT}/internal/diagnostics.BuildDate=${BUILD_DATE}" \
|
||||
-o bin/edgeboxctl-${GOOS}-${GOARCH} ${PROJECT}/cmd/edgeboxctl
|
||||
cp ./bin/edgeboxctl-${GOOS}-${GOARCH} ./bin/edgeboxctl
|
||||
|
||||
@echo "\n🟢 Build task completed\n"
|
||||
|
||||
clean:
|
||||
@echo "🧹 Cleaning build directory and go cache\n"
|
||||
|
||||
rm -rf ${BUILD_DIR}
|
||||
go clean
|
||||
|
||||
@echo "\n🟢 Clean task completed\n"
|
||||
|
||||
test:
|
||||
go test -tags=unit -timeout=600s -v ./...
|
||||
|
||||
test-with-coverage:
|
||||
go test -tags=unit -timeout=600s -v ./... -coverprofile=coverage.out
|
||||
|
||||
run:
|
||||
@echo "\n🚀 Running edgeboxctl\n"
|
||||
./bin/edgeboxctl-${GOOS}-${GOARCH}
|
||||
|
||||
install:
|
||||
@echo "📦 Installing edgeboxctl service (${RELEASE}) for ${GOOS} (${GOARCH})\n"
|
||||
|
||||
@echo "�🚧 Stopping edgeboxctl service if it is running"
|
||||
sudo systemctl stop edgeboxctl || true
|
||||
|
||||
@echo "\n🗑️ Removing old edgeboxctl binary and service"
|
||||
sudo rm -rf /usr/local/bin/edgeboxctl /usr/local/sbin/edgeboctl /lib/systemd/system/edgeboxctl.service
|
||||
|
||||
@echo "\n🚚 Copying edgeboxctl binary to /usr/local/bin"
|
||||
sudo cp ./bin/edgeboxctl-${GOOS}-${GOARCH} /usr/local/bin/edgeboxctl
|
||||
sudo cp ./bin/edgeboxctl-${GOOS}-${GOARCH} /usr/local/sbin/edgeboxctl
|
||||
|
||||
@echo "\n🚚 Copying edgeboxctl service to /lib/systemd/system"
|
||||
sudo cp ./edgeboxctl.service /lib/systemd/system/edgeboxctl.service
|
||||
sudo systemctl daemon-reload
|
||||
|
||||
@echo "\n 🚀 To start edgeboxctl run: make start"
|
||||
@echo "🟢 Edgeboxctl installed successfully\n"
|
||||
|
||||
install-prod: build-prod install
|
||||
install-cloud: build-cloud install
|
||||
install-arm64: build-arm64 install
|
||||
install-armhf: build-armhf install
|
||||
install-amd64: build-amd64 install
|
||||
|
||||
start:
|
||||
@echo "\n 🚀 Starting edgeboxctl service\n"
|
||||
systemctl start edgeboxctl
|
||||
@echo "\n 🟢 Edgebox service started\n"
|
||||
|
||||
stop:
|
||||
@echo "\n✋ Stopping edgeboxctl service\n"
|
||||
systemctl stop edgeboxctl
|
||||
@echo "\n 🟢 Edgebox service stopped\n"
|
||||
|
||||
restart:
|
||||
@echo "\n💫 Restarting edgeboxctl service\n"
|
||||
systemctl restart edgeboxctl
|
||||
@echo "\n 🟢 Edgebox service restarted\n"
|
||||
|
||||
status:
|
||||
@echo "\nℹ️ edgeboxctl Service Info:\n"
|
||||
systemctl status edgeboxctl
|
||||
|
||||
log:
|
||||
@echo "\n📰 edgeboxctl service logs:\n"
|
||||
journalctl -fu edgeboxctl
|
||||
|
||||
@@ -1,21 +1,3 @@
|
||||
|
||||
<!-- PROJECT SHIELDS -->
|
||||
<!--
|
||||
*** Using markdown "reference style" links for readability.
|
||||
*** Reference links are enclosed in brackets [ ] instead of parentheses ( ).
|
||||
*** See the bottom of this document for the declaration of the reference variables
|
||||
*** for contributors-url, forks-url, etc. This is an optional, concise syntax you may use.
|
||||
*** https://www.markdownguide.org/basic-syntax/#reference-style-links
|
||||
-->
|
||||
[![Contributors][contributors-shield]][contributors-url]
|
||||
[![Forks][forks-shield]][forks-url]
|
||||
[![Stargazers][stars-shield]][stars-url]
|
||||
[![Issues][issues-shield]][issues-url]
|
||||
[![MIT License][license-shield]][license-url]
|
||||
[![LinkedIn][linkedin-shield]][linkedin-url]
|
||||
|
||||
|
||||
|
||||
<!-- PROJECT LOGO -->
|
||||
<br />
|
||||
<p align="center">
|
||||
@@ -26,9 +8,7 @@
|
||||
<h3 align="center">Edgebox Control Module</h3>
|
||||
|
||||
<p align="center">
|
||||
A System Control module written in Go. Its resonsability is to configure dependencies and perform system tasks, automatically in a schedule, or by command.
|
||||
<br />
|
||||
<a href="https://github.com/github_username/edgeboxctl"><strong>Explore the docs »</strong></a>
|
||||
A System Control module written in Go. Its responsibility is to configure dependencies and perform system tasks, automatically on a schedule, or on demand.
|
||||
<br />
|
||||
<br />
|
||||
<a href="https://github.com/github_username/edgeboxctl/issues">Report Bug</a>
|
||||
@@ -58,9 +38,7 @@
|
||||
<!-- ABOUT THE PROJECT -->
|
||||
## About The Project
|
||||
|
||||
[![Edgebox Screen Shot][product-screenshot]](https://edgebox.co)
|
||||
|
||||
Edgebox is a small box that connects alongside your home internet router. It brings powerful features that go alongside or can even completely replace various services that you already use in the day-to-day.
|
||||
Edgebox is an easy to configure and use system. It brings powerful features that go alongside or can even completely replace various services that you already use in the day-to-day.
|
||||
|
||||
|
||||
### Built With
|
||||
@@ -78,18 +56,17 @@ To get a local copy up and running follow these simple steps.
|
||||
|
||||
### Prerequisites
|
||||
|
||||
If you're installing this to run natively in the system, you better be doing it inside of the [Development Virtual Machine](https://github.com/edgebox-iot/devm). This software can do destructive action in the system is is running. You've been warned.
|
||||
If you're running for development purposes, a docker container suffices, so make sure you have:
|
||||
|
||||
If you're running for development purposes, a Docker container suffices, so make sure you have:
|
||||
* Docker
|
||||
* Docker Compose
|
||||
```sh
|
||||
sudo apt-get install docker docker-compose
|
||||
```
|
||||
* docker
|
||||
* docker compose (docker-compose-v2 package)
|
||||
|
||||
Check the following links for more info on [Docker](https://www.docker.com/) and [Docker Compose](https://docs.docker.com/compose/).
|
||||
|
||||
Aditionally, edgeboxctl needs the following bash commands available wherever it runs:
|
||||
**Note:** If you don't have `docker compose` available, install it with: `sudo apt-get install docker-compose-v2`
|
||||
|
||||
Aditionally, `edgeboxctl` needs the following bash commands available wherever it runs:
|
||||
|
||||
* `arm-linux-gnueabi-gcc` (`sudo apt-get install gcc-arm*`)
|
||||
* `sh`
|
||||
* `rm`
|
||||
@@ -104,10 +81,10 @@ Aditionally, edgeboxctl needs the following bash commands available wherever it
|
||||
```sh
|
||||
git clone https://github.com/edgebox-iot/edgeboxctl.git
|
||||
```
|
||||
2. Run Docker-Compose
|
||||
```sh
|
||||
docker-compose up
|
||||
2. Run Docker Compose
|
||||
|
||||
```
|
||||
docker compose up
|
||||
|
||||
|
||||
|
||||
@@ -141,20 +118,4 @@ Contributions are what make the open source community such an amazing place to b
|
||||
<!-- LICENSE -->
|
||||
## License
|
||||
|
||||
Distributed under the MIT License. See `LICENSE` for more information.
|
||||
|
||||
|
||||
<!-- MARKDOWN LINKS & IMAGES -->
|
||||
<!-- https://www.markdownguide.org/basic-syntax/#reference-style-links -->
|
||||
[contributors-shield]: https://img.shields.io/github/contributors/edgebox-iot/edgeboxctl.svg?style=flat-square
|
||||
[contributors-url]: https://github.com/edgebox-iot/edgeboxctl/graphs/contributors
|
||||
[forks-shield]: https://img.shields.io/github/forks/edgebox-iot/edgeboxctl.svg?style=flat-square
|
||||
[forks-url]: https://github.com/edgebox-iot/edgeboxctl/network/members
|
||||
[stars-shield]: https://img.shields.io/github/stars/edgebox-iot/edgeboxctl.svg?style=flat-square
|
||||
[stars-url]: https://github.com/edgebox-iot/edgeboxctl/stargazers
|
||||
[issues-shield]: https://img.shields.io/github/issues/edgebox-iot/edgeboxctl.svg?style=flat-square
|
||||
[issues-url]: https://github.com/edgebox-iot/edgeboxctl/issues
|
||||
[license-shield]: https://img.shields.io/github/license/edgebox-iot/edgeboxctl.svg?style=flat-square
|
||||
[license-url]: https://github.com/edgebox-iot/edgeboxctl/blob/master/LICENSE.txt
|
||||
[linkedin-shield]: https://img.shields.io/badge/-LinkedIn-black.svg?style=flat-square&logo=linkedin&colorB=555
|
||||
[linkedin-url]: https://linkedin.com/in/edgebox-iot
|
||||
Distributed under the Elastic License 2.0. See `LICENSE` for more information.
|
||||
|
||||
+3
-2
@@ -1,3 +1,4 @@
|
||||
codecov:
|
||||
require_ci_to_pass: no
|
||||
|
||||
comment: false
|
||||
github_checks:
|
||||
annotations: false
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
[Unit]
|
||||
Description=Edgebox Control Module Service
|
||||
ConditionPathExists=/home/system/
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
LimitNOFILE=1024
|
||||
|
||||
Restart=on-failure
|
||||
RestartSec=10
|
||||
startLimitIntervalSec=60
|
||||
|
||||
WorkingDirectory=/home/system/components/edgeboxctl
|
||||
ExecStart=edgeboxctl --name=edgebox-cloud
|
||||
|
||||
# make sure log directory exists and owned by syslog
|
||||
PermissionsStartOnly=true
|
||||
ExecStartPre=/bin/mkdir -p /var/log/edgeboxctl
|
||||
ExecStartPre=/bin/chown root:root /var/log/edgeboxctl
|
||||
ExecStartPre=/bin/chmod 755 /var/log/edgeboxctl
|
||||
StandardOutput=syslog
|
||||
StandardError=syslog
|
||||
SyslogIdentifier=edgeboxctl
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -8,6 +8,7 @@ require (
|
||||
github.com/dustin/go-humanize v1.0.0 // indirect
|
||||
github.com/go-ole/go-ole v1.2.5 // indirect
|
||||
github.com/go-sql-driver/mysql v1.5.0
|
||||
github.com/go-yaml/yaml v2.1.0+incompatible // indirect
|
||||
github.com/joho/godotenv v1.3.0
|
||||
github.com/mattn/go-sqlite3 v1.14.7 // indirect
|
||||
github.com/shirou/gopsutil v3.21.4+incompatible // indirect
|
||||
|
||||
@@ -11,6 +11,8 @@ github.com/go-ole/go-ole v1.2.5 h1:t4MGB5xEDZvXI+0rMjjsfBsD7yAgp/s9ZDkL1JndXwY=
|
||||
github.com/go-ole/go-ole v1.2.5/go.mod h1:pprOEPIfldk/42T2oK7lQ4v4JSDwmV0As9GaiUsvbm0=
|
||||
github.com/go-sql-driver/mysql v1.5.0 h1:ozyZYNQW3x3HtqT1jira07DN2PArx2v7/mN66gGcHOs=
|
||||
github.com/go-sql-driver/mysql v1.5.0/go.mod h1:DCzpHaOWr8IXmIStZouvnhqoel9Qv2LBy8hT2VhHyBg=
|
||||
github.com/go-yaml/yaml v2.1.0+incompatible h1:RYi2hDdss1u4YE7GwixGzWwVo47T8UQwnTLB6vQiq+o=
|
||||
github.com/go-yaml/yaml v2.1.0+incompatible/go.mod h1:w2MrLa16VYP0jy6N7M5kHaCkaLENm+P+Tv+MfurjSw0=
|
||||
github.com/google/renameio v0.1.0/go.mod h1:KWCgfxg9yswjAJkECMjeO8J8rahYeXnNhOm40UhjYkI=
|
||||
github.com/joho/godotenv v1.3.0 h1:Zjp+RcGpHhGlrMbJzXTrZZPrWj+1vfm90La1wgB6Bhc=
|
||||
github.com/joho/godotenv v1.3.0/go.mod h1:7hK45KPybAkOC6peb+G5yklZfMxEjkZhHbwpqxOKXbg=
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
package backups
|
||||
|
||||
// import (
|
||||
// "fmt"
|
||||
// "os"
|
||||
// "path/filepath"
|
||||
// "strings"
|
||||
|
||||
// "github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
||||
// "github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||
// "github.com/shirou/gopsutil/disk"
|
||||
// )
|
||||
|
||||
// Repository : Struct representing the backup repository of a device in the system
|
||||
type Repository struct {
|
||||
ID string `json:"id"`
|
||||
FileCount int64 `json:"file_count"`
|
||||
Size string `json:"size"`
|
||||
Snapshots []Snapshot `json:"snapshots"`
|
||||
Status string `json:"status"`
|
||||
// UsageStat UsageStat `json:"usage_stat"`
|
||||
}
|
||||
|
||||
// Snapshot : Struct representing a single snapshot in the backup repository
|
||||
type Snapshot struct {
|
||||
ID string `json:"id"`
|
||||
time string `json:"time"`
|
||||
}
|
||||
+295
-22
@@ -6,10 +6,12 @@ import (
|
||||
"os"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
|
||||
"github.com/joho/godotenv"
|
||||
|
||||
"github.com/edgebox-iot/edgeboxctl/internal/system"
|
||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||
"github.com/edgebox-iot/edgeboxctl/internal/diagnostics"
|
||||
)
|
||||
|
||||
// EdgeApp : Struct representing an EdgeApp in the system
|
||||
@@ -17,11 +19,15 @@ type EdgeApp struct {
|
||||
ID string `json:"id"`
|
||||
Name string `json:"name"`
|
||||
Description string `json:"description"`
|
||||
Experimental bool `json:"experimental"`
|
||||
Status EdgeAppStatus `json:"status"`
|
||||
Services []EdgeAppService `json:"services"`
|
||||
InternetAccessible bool `json:"internet_accessible"`
|
||||
NetworkURL string `json:"network_url"`
|
||||
InternetURL string `json:"internet_url"`
|
||||
Options []EdgeAppOption `json:"options"`
|
||||
NeedsConfig bool `json:"needs_config"`
|
||||
Login EdgeAppLogin `json:"login"`
|
||||
}
|
||||
|
||||
// MaybeEdgeApp : Boolean flag for validation of edgeapp existance
|
||||
@@ -42,9 +48,30 @@ type EdgeAppService struct {
|
||||
IsRunning bool `json:"is_running"`
|
||||
}
|
||||
|
||||
type EdgeAppOption struct {
|
||||
Key string `json:"key"`
|
||||
Value string `json:"value"`
|
||||
DefaultValue string `json:"default_value"`
|
||||
Format string `json:"format"`
|
||||
Description string `json:"description"`
|
||||
IsSecret bool `json:"is_secret"`
|
||||
IsInstallLocked bool `json:"is_install_locked"`
|
||||
}
|
||||
|
||||
type EdgeAppLogin struct {
|
||||
Enabled bool `json:"enabled"`
|
||||
Username string `json:"username"`
|
||||
Password string `json:"password"`
|
||||
}
|
||||
|
||||
const configFilename = "/edgebox-compose.yml"
|
||||
const envFilename = "/edgebox.env"
|
||||
const optionsTemplateFilename = "/edgeapp.template.env"
|
||||
const optionsEnvFilename = "/edgeapp.env"
|
||||
const authEnvFilename = "/auth.env"
|
||||
const runnableFilename = "/.run"
|
||||
const appdataFoldername = "/appdata"
|
||||
const postInstallFilename = "/edgebox-postinstall.done"
|
||||
const myEdgeAppServiceEnvFilename = "/myedgeapp.env"
|
||||
const defaultContainerOperationSleepTime time.Duration = time.Second * 10
|
||||
|
||||
@@ -62,6 +89,8 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
||||
|
||||
edgeAppName := ID
|
||||
edgeAppDescription := ""
|
||||
edgeAppExperimental := false
|
||||
edgeAppOptions := []EdgeAppOption{}
|
||||
|
||||
edgeAppEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + envFilename)
|
||||
|
||||
@@ -74,8 +103,108 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
||||
if edgeAppEnv["EDGEAPP_DESCRIPTION"] != "" {
|
||||
edgeAppDescription = edgeAppEnv["EDGEAPP_DESCRIPTION"]
|
||||
}
|
||||
if edgeAppEnv["EDGEAPP_EXPERIMENTAL"] == "true" {
|
||||
edgeAppExperimental = true
|
||||
}
|
||||
}
|
||||
|
||||
needsConfig := false
|
||||
hasFilledOptions := false
|
||||
edgeAppOptionsTemplate, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + optionsTemplateFilename)
|
||||
if err != nil {
|
||||
log.Println("Error loading options template file for edgeapp " + edgeAppName)
|
||||
} else {
|
||||
// Try to read the edgeAppOptionsEnv file
|
||||
edgeAppOptionsEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + optionsEnvFilename)
|
||||
if err != nil {
|
||||
log.Println("Error loading options env file for edgeapp " + edgeAppName)
|
||||
} else {
|
||||
hasFilledOptions = true
|
||||
}
|
||||
|
||||
for key, value := range edgeAppOptionsTemplate {
|
||||
|
||||
optionFilledValue := ""
|
||||
if hasFilledOptions {
|
||||
// Check if key exists in edgeAppOptionsEnv
|
||||
optionFilledValue = edgeAppOptionsEnv[key]
|
||||
}
|
||||
|
||||
format := ""
|
||||
defaultValue := ""
|
||||
description := ""
|
||||
installLocked := false
|
||||
|
||||
// Parse value to separate by | and get the format, installLocked, description and default value
|
||||
// Format is the first element
|
||||
// InstallLocked is the second element
|
||||
// Description is the third element
|
||||
// Default value is the fourth element
|
||||
|
||||
valueSlices := strings.Split(value, "|")
|
||||
if len(valueSlices) > 0 {
|
||||
format = valueSlices[0]
|
||||
}
|
||||
if len(valueSlices) > 1 {
|
||||
installLocked = valueSlices[1] == "true"
|
||||
}
|
||||
if len(valueSlices) > 2 {
|
||||
description = valueSlices[2]
|
||||
}
|
||||
if len(valueSlices) > 3 {
|
||||
defaultValue = valueSlices[3]
|
||||
}
|
||||
|
||||
// // If value contains ">|", then get everything that is to the right of it as the description
|
||||
// // and get everything between "<>" as the format
|
||||
// if strings.Contains(value, ">|") {
|
||||
// description = strings.Split(value, ">|")[1]
|
||||
// // Check if description has default value. That would be everything that is to the right of the last "|"
|
||||
// if strings.Contains(description, "|") {
|
||||
// defaultValue = strings.Split(description, "|")[1]
|
||||
// description = strings.Split(description, "|")[0]
|
||||
// }
|
||||
|
||||
// value = strings.Split(value, ">|")[0]
|
||||
// // Remove the initial < from value
|
||||
// value = strings.TrimPrefix(value, "<")
|
||||
// } else {
|
||||
// // Trim initial < and final > from value
|
||||
// value = strings.TrimPrefix(value, "<")
|
||||
// value = strings.TrimSuffix(value, ">")
|
||||
// }
|
||||
|
||||
isSecret := false
|
||||
|
||||
// Check if the lowercased key string contains the letters "pass", "secret", "key"
|
||||
lowercaseKey := strings.ToLower(key)
|
||||
// check if lowercaseInput contains "pass", "key", or "secret", or "token"
|
||||
if strings.Contains(lowercaseKey, "pass") ||
|
||||
strings.Contains(lowercaseKey, "key") ||
|
||||
strings.Contains(lowercaseKey, "secret") ||
|
||||
strings.Contains(lowercaseKey, "token") {
|
||||
isSecret = true
|
||||
}
|
||||
|
||||
currentOption := EdgeAppOption{
|
||||
Key: key,
|
||||
Value: optionFilledValue,
|
||||
DefaultValue: defaultValue,
|
||||
Description: description,
|
||||
Format: format,
|
||||
IsSecret: isSecret,
|
||||
IsInstallLocked: installLocked,
|
||||
}
|
||||
edgeAppOptions = append(edgeAppOptions, currentOption)
|
||||
|
||||
if optionFilledValue == "" {
|
||||
needsConfig = true
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
edgeAppInternetAccessible := false
|
||||
edgeAppInternetURL := ""
|
||||
|
||||
@@ -89,16 +218,36 @@ func GetEdgeApp(ID string) MaybeEdgeApp {
|
||||
}
|
||||
}
|
||||
|
||||
edgeAppBasicAuthEnabled := false
|
||||
edgeAppBasicAuthUsername := ""
|
||||
edgeAppBasicAuthPassword := ""
|
||||
|
||||
edgeAppAuthEnv, err := godotenv.Read(utils.GetPath(utils.EdgeAppsPath) + ID + authEnvFilename)
|
||||
if err != nil {
|
||||
log.Println("No auth.env file found. Login status is disabled.")
|
||||
} else {
|
||||
if edgeAppAuthEnv["USERNAME"] != "" && edgeAppAuthEnv["PASSWORD"] != "" {
|
||||
edgeAppBasicAuthEnabled = true
|
||||
edgeAppBasicAuthUsername = edgeAppAuthEnv["USERNAME"]
|
||||
edgeAppBasicAuthPassword = edgeAppAuthEnv["PASSWORD"]
|
||||
}
|
||||
}
|
||||
|
||||
result = MaybeEdgeApp{
|
||||
EdgeApp: EdgeApp{
|
||||
ID: ID,
|
||||
Name: edgeAppName,
|
||||
Description: edgeAppDescription,
|
||||
Experimental: edgeAppExperimental,
|
||||
Status: GetEdgeAppStatus(ID),
|
||||
Services: GetEdgeAppServices(ID),
|
||||
InternetAccessible: edgeAppInternetAccessible,
|
||||
NetworkURL: ID + ".edgebox.local",
|
||||
NetworkURL: ID + "." + system.GetHostname() + ".local",
|
||||
InternetURL: edgeAppInternetURL,
|
||||
Options: edgeAppOptions,
|
||||
NeedsConfig: needsConfig,
|
||||
Login: EdgeAppLogin{edgeAppBasicAuthEnabled, edgeAppBasicAuthUsername, edgeAppBasicAuthPassword},
|
||||
|
||||
},
|
||||
Valid: true,
|
||||
}
|
||||
@@ -122,22 +271,54 @@ func IsEdgeAppInstalled(ID string) bool {
|
||||
|
||||
}
|
||||
|
||||
func writeAppRunnableFiles(ID string) bool {
|
||||
edgeAppPath := utils.GetPath(utils.EdgeAppsPath)
|
||||
_, err := os.Stat(edgeAppPath + ID + runnableFilename)
|
||||
if os.IsNotExist(err) {
|
||||
_, err := os.Create(edgeAppPath + ID + runnableFilename)
|
||||
if err != nil {
|
||||
log.Fatal("Runnable file for EdgeApp could not be created!")
|
||||
return false
|
||||
}
|
||||
|
||||
// Check the block default apps option
|
||||
blockDefaultAppsOption := utils.ReadOption("DASHBOARD_BLOCK_DEFAULT_APPS_PUBLIC_ACCESS")
|
||||
if blockDefaultAppsOption != "yes" {
|
||||
// Create myedgeapp.env file with default network URL
|
||||
envFilePath := edgeAppPath + ID + myEdgeAppServiceEnvFilename
|
||||
|
||||
var networkURL string
|
||||
domainName := utils.ReadOption("DOMAIN_NAME")
|
||||
|
||||
if domainName != "" {
|
||||
networkURL = ID + "." + domainName
|
||||
} else if diagnostics.GetReleaseVersion() == diagnostics.CLOUD_VERSION {
|
||||
cluster := utils.ReadOption("CLUSTER")
|
||||
username := utils.ReadOption("USERNAME")
|
||||
if cluster != "" && username != "" {
|
||||
networkURL = username + "-" + ID + "." + cluster
|
||||
}
|
||||
} else {
|
||||
networkURL = ID + "." + system.GetHostname() + ".local" // default
|
||||
}
|
||||
|
||||
env, _ := godotenv.Unmarshal("INTERNET_URL=" + networkURL)
|
||||
err = godotenv.Write(env, envFilePath)
|
||||
if err != nil {
|
||||
log.Printf("Error creating myedgeapp.env file: %s", err)
|
||||
// result = false
|
||||
}
|
||||
}
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
func SetEdgeAppInstalled(ID string) bool {
|
||||
|
||||
result := true
|
||||
edgeAppPath := utils.GetPath(utils.EdgeAppsPath)
|
||||
|
||||
_, err := os.Stat(edgeAppPath + ID + runnableFilename)
|
||||
if os.IsNotExist(err) {
|
||||
|
||||
_, err := os.Create(edgeAppPath + ID + runnableFilename)
|
||||
result = true
|
||||
|
||||
if err != nil {
|
||||
log.Fatal("Runnable file for EdgeApp could not be created!")
|
||||
result = false
|
||||
}
|
||||
|
||||
if writeAppRunnableFiles(ID) {
|
||||
|
||||
buildFrameworkContainers()
|
||||
|
||||
} else {
|
||||
@@ -151,13 +332,63 @@ func SetEdgeAppInstalled(ID string) bool {
|
||||
|
||||
}
|
||||
|
||||
func SetEdgeAppNotInstalled(ID string) bool {
|
||||
func SetEdgeAppBulkInstalled(IDs []string) bool {
|
||||
|
||||
result := true
|
||||
|
||||
for _, ID := range IDs {
|
||||
writeAppRunnableFiles(ID)
|
||||
}
|
||||
|
||||
buildFrameworkContainers()
|
||||
|
||||
return result
|
||||
|
||||
}
|
||||
|
||||
|
||||
func SetEdgeAppNotInstalled(ID string) bool {
|
||||
|
||||
// Stop the app first
|
||||
StopEdgeApp(ID)
|
||||
|
||||
// Now remove any files
|
||||
result := true
|
||||
|
||||
err := os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + runnableFilename)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Fatal(err)
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + authEnvFilename)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
err = os.RemoveAll(utils.GetPath(utils.EdgeAppsPath) + ID + appdataFoldername)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + myEdgeAppServiceEnvFilename)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + optionsEnvFilename)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
err = os.Remove(utils.GetPath(utils.EdgeAppsPath) + ID + postInstallFilename)
|
||||
if err != nil {
|
||||
result = false
|
||||
log.Println(err)
|
||||
}
|
||||
|
||||
buildFrameworkContainers()
|
||||
@@ -246,12 +477,24 @@ func GetEdgeAppServices(ID string) []EdgeAppService {
|
||||
var edgeAppServices []EdgeAppService
|
||||
|
||||
for _, serviceID := range serviceSlices {
|
||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
||||
cmdResult := utils.Exec(wsPath, "docker-compose", cmdArgs)
|
||||
shouldBeRunning := false
|
||||
isRunning := false
|
||||
if cmdResult != "" {
|
||||
isRunning = true
|
||||
|
||||
// Is service "runnable" when .run lockfile in the app folder
|
||||
_, err := os.Stat(utils.GetPath(utils.EdgeAppsPath) + ID + runnableFilename)
|
||||
if !os.IsNotExist(err) {
|
||||
shouldBeRunning = true
|
||||
}
|
||||
|
||||
// Check if the service is actually running
|
||||
if shouldBeRunning {
|
||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "exec", "-T", serviceID, "echo", "'Service Check'"}
|
||||
cmdResult := utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||
if cmdResult != "" {
|
||||
isRunning = true
|
||||
}
|
||||
}
|
||||
|
||||
edgeAppServices = append(edgeAppServices, EdgeAppService{ID: serviceID, IsRunning: isRunning})
|
||||
}
|
||||
|
||||
@@ -268,7 +511,7 @@ func RunEdgeApp(ID string) EdgeAppStatus {
|
||||
for _, service := range services {
|
||||
|
||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "start", service.ID}
|
||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
||||
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||
}
|
||||
|
||||
// Wait for it to settle up before continuing...
|
||||
@@ -286,7 +529,7 @@ func StopEdgeApp(ID string) EdgeAppStatus {
|
||||
for _, service := range services {
|
||||
|
||||
cmdArgs = []string{"-f", wsPath + "/docker-compose.yml", "stop", service.ID}
|
||||
utils.Exec(wsPath, "docker-compose", cmdArgs)
|
||||
utils.Exec(wsPath, "docker", append([]string{"compose"}, cmdArgs...))
|
||||
}
|
||||
|
||||
// Wait for it to settle up before continuing...
|
||||
@@ -296,6 +539,36 @@ func StopEdgeApp(ID string) EdgeAppStatus {
|
||||
|
||||
}
|
||||
|
||||
// StopAllEdgeApps: Stops all EdgeApps and returns a count of how many were stopped
|
||||
func StopAllEdgeApps() int {
|
||||
edgeApps := GetEdgeApps()
|
||||
appCount := 0
|
||||
for _, edgeApp := range edgeApps {
|
||||
StopEdgeApp(edgeApp.ID)
|
||||
appCount++
|
||||
}
|
||||
|
||||
return appCount
|
||||
|
||||
}
|
||||
|
||||
// StartAllEdgeApps: Starts all EdgeApps and returns a count of how many were started
|
||||
func StartAllEdgeApps() int {
|
||||
edgeApps := GetEdgeApps()
|
||||
appCount := 0
|
||||
for _, edgeApp := range edgeApps {
|
||||
RunEdgeApp(edgeApp.ID)
|
||||
appCount++
|
||||
}
|
||||
|
||||
return appCount
|
||||
|
||||
}
|
||||
|
||||
func RestartEdgeAppsService() {
|
||||
buildFrameworkContainers()
|
||||
}
|
||||
|
||||
// EnableOnline : Write environment file and rebuild the necessary containers. Rebuilds containers in project (in case of change only)
|
||||
func EnableOnline(ID string, InternetURL string) MaybeEdgeApp {
|
||||
|
||||
|
||||
@@ -2,6 +2,7 @@ package storage
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strconv"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
@@ -73,12 +74,13 @@ const (
|
||||
DISK_TYPE_SDA DeviceIdentifier = "sda"
|
||||
DISK_TYPE_MCBLK DeviceIdentifier = "mmcblk0"
|
||||
DISK_TYPE_VDA DeviceIdentifier = "vda"
|
||||
MIN_DISK_SIZE int = 1048576 // 1GB in bytes
|
||||
)
|
||||
|
||||
func GetDeviceIdentifier(release_version diagnostics.ReleaseVersion) DeviceIdentifier {
|
||||
switch release_version {
|
||||
case diagnostics.CLOUD_VERSION:
|
||||
return DISK_TYPE_VDA
|
||||
return DISK_TYPE_SDA
|
||||
case diagnostics.PROD_VERSION:
|
||||
return DISK_TYPE_MCBLK
|
||||
}
|
||||
@@ -134,7 +136,13 @@ func GetDevices(release_version diagnostics.ReleaseVersion) []Device {
|
||||
currentDevice.InUse = currentDeviceInUseFlag
|
||||
currentDeviceInUseFlag = false
|
||||
currentPartitions = []Partition{}
|
||||
devices = append(devices, currentDevice)
|
||||
size, err := strconv.Atoi(currentDevice.Size)
|
||||
if err != nil {
|
||||
size = 0
|
||||
}
|
||||
if size > MIN_DISK_SIZE {
|
||||
devices = append(devices, currentDevice)
|
||||
}
|
||||
} else {
|
||||
firstDevice = false
|
||||
}
|
||||
@@ -193,8 +201,22 @@ func GetDevices(release_version diagnostics.ReleaseVersion) []Device {
|
||||
currentDevice.Status.Description = "Not configured"
|
||||
}
|
||||
currentDevice.InUse = currentDeviceInUseFlag
|
||||
devices = append([]Device{currentDevice}, devices...) // Prepending the first device...
|
||||
|
||||
fmt.Println("Secondary Storage Devices Found: ", len(devices))
|
||||
fmt.Println("Main Storage Device size: ", currentDevice.Size)
|
||||
|
||||
// only append device if size > 1GB
|
||||
if currentDevice.Size != "" && currentDevice.Size != "0" {
|
||||
// Convert size to int
|
||||
// Convert string to int
|
||||
size, err := strconv.Atoi(currentDevice.Size)
|
||||
if err != nil {
|
||||
size = 0
|
||||
}
|
||||
if size > MIN_DISK_SIZE {
|
||||
devices = append([]Device{currentDevice}, devices...) // Prepending the first device...
|
||||
}
|
||||
}
|
||||
devices = getDevicesSpaceUsage(devices)
|
||||
|
||||
return devices
|
||||
|
||||
@@ -4,13 +4,29 @@ import (
|
||||
"fmt"
|
||||
"strconv"
|
||||
"strings"
|
||||
"log"
|
||||
"os"
|
||||
"io"
|
||||
"errors"
|
||||
"os/exec"
|
||||
"bufio"
|
||||
"path/filepath"
|
||||
"io/ioutil"
|
||||
"encoding/json"
|
||||
|
||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||
|
||||
"github.com/joho/godotenv"
|
||||
"github.com/shirou/gopsutil/host"
|
||||
"github.com/go-yaml/yaml"
|
||||
)
|
||||
|
||||
type cloudflaredTunnelJson struct {
|
||||
AccountTag string `json:"AccountTag"`
|
||||
TunnelSecret string `json:"TunnelSecret"`
|
||||
TunnelID string `json:"TunnelID"`
|
||||
}
|
||||
|
||||
// GetUptimeInSeconds: Returns a value (as string) of the total system uptime
|
||||
func GetUptimeInSeconds() string {
|
||||
uptime, _ := host.Uptime()
|
||||
@@ -78,6 +94,22 @@ func SetupCloudOptions() {
|
||||
utils.WriteOption("EMAIL", cloudEnv["EMAIL"])
|
||||
}
|
||||
|
||||
if cloudEnv["USERNAME"] != "" {
|
||||
utils.WriteOption("USERNAME", cloudEnv["USERNAME"])
|
||||
}
|
||||
|
||||
if cloudEnv["CLUSTER"] != "" {
|
||||
utils.WriteOption("CLUSTER", cloudEnv["CLUSTER"])
|
||||
}
|
||||
|
||||
if cloudEnv["CLUSTER_IP"] != "" {
|
||||
utils.WriteOption("CLUSTER_IP", cloudEnv["CLUSTER_IP"])
|
||||
}
|
||||
|
||||
if cloudEnv["CLUSTER_SSH_PORT"] != "" {
|
||||
utils.WriteOption("CLUSTER_SSH_PORT", cloudEnv["CLUSTER_SSH_PORT"])
|
||||
}
|
||||
|
||||
if cloudEnv["EDGEBOXIO_API_TOKEN"] != "" {
|
||||
utils.WriteOption("EDGEBOXIO_API_TOKEN", cloudEnv["EDGEBOXIO_API_TOKEN"])
|
||||
}
|
||||
@@ -85,3 +117,484 @@ func SetupCloudOptions() {
|
||||
// In the end of this operation takes place, remove the env file as to not overwrite any options once they are set.
|
||||
utils.Exec("/", "rm", []string{cloudEnvFileLocationPath})
|
||||
}
|
||||
|
||||
func StartSystemLogger() {
|
||||
fmt.Println("Starting system logger")
|
||||
loggerPath := utils.GetPath(utils.LoggerPath)
|
||||
utils.Exec(loggerPath, "make", []string{"start"})
|
||||
}
|
||||
|
||||
// UpdateSystemLoggerServices: Updates the services.txt file with the services that are currently running
|
||||
func UpdateSystemLoggerServices(services []string) {
|
||||
fmt.Println("Updating system logger services:")
|
||||
fmt.Println(services)
|
||||
loggerPath := utils.GetPath(utils.LoggerPath)
|
||||
|
||||
utils.Exec(loggerPath, "bash", []string{"-c", "rm services.txt && touch services.txt"})
|
||||
|
||||
for _, service := range services {
|
||||
fmt.Println("Adding " + service + " to services.txt")
|
||||
utils.Exec(loggerPath, "bash", []string{"-c", "echo " + service + " >> services.txt"})
|
||||
}
|
||||
|
||||
// Add empty line at the end of file (best practice)
|
||||
utils.Exec(loggerPath, "bash", []string{"-c", "echo '' >> services.txt"})
|
||||
}
|
||||
|
||||
// StartWs: Starts the webserver service for Edgeapps
|
||||
func StartWs() {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
fmt.Println("Starting WS")
|
||||
cmdargs := []string{"-b"}
|
||||
utils.Exec(wsPath, "./ws", cmdargs)
|
||||
}
|
||||
|
||||
// StartService: Starts a service
|
||||
func StartService(serviceID string) {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
fmt.Println("Starting" + serviceID + "service")
|
||||
cmdargs := []string{"start", serviceID}
|
||||
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||
}
|
||||
|
||||
// StopService: Stops a service
|
||||
func StopService(serviceID string) {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
fmt.Println("Stopping" + serviceID + "service")
|
||||
cmdargs := []string{"stop", "cloudflared"}
|
||||
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||
}
|
||||
|
||||
// RestartService: Restarts a service
|
||||
func RestartService(serviceID string) {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
fmt.Println("Restarting" + serviceID + "service")
|
||||
cmdargs := []string{"restart", serviceID}
|
||||
utils.Exec(wsPath, "systemctl", cmdargs)
|
||||
}
|
||||
|
||||
// GetServiceStatus: Returns the status output of a service
|
||||
func GetServiceStatus(serviceID string) string {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
cmdargs := []string{"status", serviceID}
|
||||
return utils.Exec(wsPath, "systemctl", cmdargs)
|
||||
}
|
||||
|
||||
func CreateBackupsPasswordFile(password string) {
|
||||
// Create a password file for backups
|
||||
backupPasswordFile := utils.GetPath(utils.BackupPasswordFileLocation)
|
||||
backupPasswordFileDir := filepath.Dir(backupPasswordFile)
|
||||
|
||||
if _, err := os.Stat(backupPasswordFileDir); os.IsNotExist(err) {
|
||||
os.MkdirAll(backupPasswordFileDir, 0755)
|
||||
}
|
||||
|
||||
// Write the password to the file, overriting an existing file
|
||||
err := ioutil.WriteFile(backupPasswordFile, []byte(password), 0644)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
}
|
||||
|
||||
// CreateTunnel: Creates a tunnel via cloudflared, needs to be authenticated first
|
||||
func CreateTunnel(configDestination string) {
|
||||
fmt.Println("Creating Tunnel for Edgebox.")
|
||||
cmd := exec.Command("sh", "/home/system/components/edgeboxctl/scripts/cloudflared_tunnel_create.sh")
|
||||
stdout, err := cmd.StdoutPipe()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
scanner := bufio.NewScanner(stdout)
|
||||
err = cmd.Start()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
for scanner.Scan() {
|
||||
fmt.Println(scanner.Text())
|
||||
text := scanner.Text()
|
||||
fmt.Println(text)
|
||||
}
|
||||
if scanner.Err() != nil {
|
||||
cmd.Process.Kill()
|
||||
cmd.Wait()
|
||||
panic(scanner.Err())
|
||||
}
|
||||
|
||||
// This also needs to be executed in root and non root variants
|
||||
fmt.Println("Reading cloudflared folder to get the JSON file.")
|
||||
isRoot := false
|
||||
dir := "/home/system/.cloudflared/"
|
||||
dir2 := "/root/.cloudflared/"
|
||||
files, err := os.ReadDir(dir)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
var jsonFile os.DirEntry
|
||||
for _, file := range files {
|
||||
// check if file has json extension
|
||||
if filepath.Ext(file.Name()) == ".json" {
|
||||
fmt.Println("Non-Root JSON file found: " + file.Name())
|
||||
jsonFile = file
|
||||
}
|
||||
}
|
||||
|
||||
// If the files are not in the home folder, try the root folder
|
||||
if jsonFile == nil {
|
||||
files, err = os.ReadDir(dir2)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
for _, file := range files {
|
||||
// check if file has json extension
|
||||
if filepath.Ext(file.Name()) == ".json" {
|
||||
fmt.Println("Root JSON file found: " + file.Name())
|
||||
jsonFile = file
|
||||
isRoot = true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if jsonFile == nil {
|
||||
panic("No JSON file found in directory")
|
||||
}
|
||||
|
||||
fmt.Println("Reading JSON file.")
|
||||
targetDir := "/home/system/.cloudflared/"
|
||||
if isRoot {
|
||||
targetDir = "/root/.cloudflared/"
|
||||
}
|
||||
|
||||
jsonFilePath := filepath.Join(targetDir, jsonFile.Name())
|
||||
jsonBytes, err := ioutil.ReadFile(jsonFilePath)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
fmt.Println("Parsing JSON file.")
|
||||
var data cloudflaredTunnelJson
|
||||
err = json.Unmarshal(jsonBytes, &data)
|
||||
if err != nil {
|
||||
log.Printf("Error reading tunnel JSON file: %s", err)
|
||||
}
|
||||
|
||||
fmt.Println("Tunnel ID is:" + data.TunnelID)
|
||||
|
||||
// create the config.yml file with the following content in each line:
|
||||
// "url": "http://localhost:80"
|
||||
// "tunnel": "<TunnelID>"
|
||||
// "credentials-file": "/root/.cloudflared/<tunnelID>.json"
|
||||
|
||||
file := configDestination
|
||||
f, err := os.Create(file)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
defer f.Close()
|
||||
|
||||
_, err = f.WriteString("url: http://localhost:80\ntunnel: " + data.TunnelID + "\ncredentials-file: " + jsonFilePath)
|
||||
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
}
|
||||
|
||||
// DeleteTunnel: Deletes a tunnel via cloudflared, this does not remove the service
|
||||
func DeleteTunnel() {
|
||||
fmt.Println("Deleting possible previous tunnel.")
|
||||
|
||||
// Configure the service and start it
|
||||
cmd := exec.Command("sh", "/home/system/components/edgeboxctl/scripts/cloudflared_tunnel_delete.sh")
|
||||
stdout, err := cmd.StdoutPipe()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
scanner := bufio.NewScanner(stdout)
|
||||
err = cmd.Start()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
for scanner.Scan() {
|
||||
fmt.Println(scanner.Text())
|
||||
text := scanner.Text()
|
||||
fmt.Println(text)
|
||||
}
|
||||
if scanner.Err() != nil {
|
||||
cmd.Process.Kill()
|
||||
cmd.Wait()
|
||||
panic(scanner.Err())
|
||||
}
|
||||
}
|
||||
|
||||
// InstallTunnelService: Installs the tunnel service
|
||||
func InstallTunnelService(config string) {
|
||||
fmt.Println("Installing cloudflared service.")
|
||||
cmd := exec.Command("cloudflared", "--config", config, "service", "install")
|
||||
cmd.Start()
|
||||
cmd.Wait()
|
||||
}
|
||||
|
||||
// RemoveTunnelService: Removes the tunnel service
|
||||
func RemoveTunnelService() {
|
||||
wsPath := utils.GetPath(utils.WsPath)
|
||||
fmt.Println("Removing possibly previous service install.")
|
||||
cmd := exec.Command("cloudflared", "service", "uninstall")
|
||||
cmd.Start()
|
||||
cmd.Wait()
|
||||
|
||||
fmt.Println("Removing cloudflared files")
|
||||
cmdargs := []string{"-rf", "/home/system/.cloudflared"}
|
||||
utils.Exec(wsPath, "rm", cmdargs)
|
||||
cmdargs = []string{"-rf", "/etc/cloudflared/config.yml"}
|
||||
utils.Exec(wsPath, "rm", cmdargs)
|
||||
cmdargs = []string{"-rf", "/root/.cloudflared/cert.pem"}
|
||||
utils.Exec(wsPath, "rm", cmdargs)
|
||||
}
|
||||
|
||||
func CopyDir(src string, dest string) error {
|
||||
srcInfo, err := os.Stat(src)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if !srcInfo.IsDir() {
|
||||
return fmt.Errorf("%s is not a directory", src)
|
||||
}
|
||||
|
||||
err = os.MkdirAll(dest, srcInfo.Mode())
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
items, err := ioutil.ReadDir(src)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
for _, item := range items {
|
||||
srcPath := filepath.Join(src, item.Name())
|
||||
destPath := filepath.Join(dest, item.Name())
|
||||
|
||||
if item.IsDir() {
|
||||
err = CopyDir(srcPath, destPath)
|
||||
if err != nil {
|
||||
fmt.Printf("error copying directory %s to %s: %s\n", srcPath, destPath, err.Error())
|
||||
}
|
||||
} else {
|
||||
err = CopyFile(srcPath, destPath)
|
||||
if err != nil {
|
||||
fmt.Printf("error copying file %s to %s: %s\n", srcPath, destPath, err.Error())
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func CopyFile(src string, dest string) error {
|
||||
srcFile, err := os.Open(src)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer srcFile.Close()
|
||||
|
||||
destFile, err := os.Create(dest)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer destFile.Close()
|
||||
|
||||
_, err = io.Copy(destFile, srcFile)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
err = destFile.Sync()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
srcInfo, err := os.Stat(src)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
err = os.Chmod(dest, srcInfo.Mode())
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func CheckUpdates() {
|
||||
fmt.Println("Checking for Edgebox System Updates.")
|
||||
|
||||
// Configure the service and start it
|
||||
cmd := exec.Command("sh", "/home/system/components/updater/run.sh", "--check")
|
||||
stdout, err := cmd.StdoutPipe()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
scanner := bufio.NewScanner(stdout)
|
||||
err = cmd.Start()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
for scanner.Scan() {
|
||||
// fmt.Println(scanner.Text())
|
||||
text := scanner.Text()
|
||||
fmt.Println(text)
|
||||
}
|
||||
if scanner.Err() != nil {
|
||||
cmd.Process.Kill()
|
||||
cmd.Wait()
|
||||
fmt.Println("Error running updates check.")
|
||||
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||
return
|
||||
}
|
||||
|
||||
// Read targets.env file into JSON list structure
|
||||
targets := []string{}
|
||||
targetsFile, err := os.Open("/home/system/components/updater/targets.env")
|
||||
if err != nil {
|
||||
fmt.Println("No targets.env file found. Skipping.")
|
||||
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||
return
|
||||
}
|
||||
defer targetsFile.Close()
|
||||
scanner = bufio.NewScanner(targetsFile)
|
||||
for scanner.Scan() {
|
||||
text := scanner.Text()
|
||||
// text line should look like: {"target": "<target>", "version": "<version>"}
|
||||
target := strings.Split(text, "=")
|
||||
newText := "{\"target\": \"" + strings.Replace(target[0], "_VERSION", "", -1) + "\", \"version\": \"" + target[1] + "\"}"
|
||||
targets = append(targets, newText)
|
||||
}
|
||||
if scanner.Err() != nil {
|
||||
fmt.Println("Error reading update targets file.")
|
||||
utils.WriteOption("SYSTEM_UPDATES", "[]")
|
||||
return
|
||||
}
|
||||
|
||||
// convert targets to string
|
||||
targetsString := strings.Join(targets, ",")
|
||||
targetsString = "[" + targetsString + "]"
|
||||
|
||||
fmt.Println(targetsString)
|
||||
|
||||
// Write option with targets
|
||||
utils.WriteOption("SYSTEM_UPDATES", targetsString)
|
||||
}
|
||||
|
||||
func ApplyUpdates() {
|
||||
fmt.Println("Applying Edgebox System Updates.")
|
||||
|
||||
utils.WriteOption("UPDATING_SYSTEM", "true")
|
||||
|
||||
// Configure the service and start it
|
||||
cmd := exec.Command("sh", "/home/system/components/updater/run.sh", "--update")
|
||||
stdout, err := cmd.StdoutPipe()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
scanner := bufio.NewScanner(stdout)
|
||||
err = cmd.Start()
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
for scanner.Scan() {
|
||||
fmt.Println(scanner.Text())
|
||||
text := scanner.Text()
|
||||
fmt.Println(text)
|
||||
}
|
||||
if scanner.Err() != nil {
|
||||
cmd.Process.Kill()
|
||||
cmd.Wait()
|
||||
panic(scanner.Err())
|
||||
}
|
||||
|
||||
// If the system did not yet restart, set updating system to false
|
||||
utils.WriteOption("UPDATING_SYSTEM", "false")
|
||||
}
|
||||
|
||||
func FetchBrowserDevPasswordFromFile() (string, error) {
|
||||
fmt.Println("Executing FetchBrowserDevPasswordFromFile")
|
||||
|
||||
// Read the "password" entry on the yaml file
|
||||
// Read the yaml file in system.GetPath(BrowserDevPasswordFileLocation)
|
||||
yamlFile, err := ioutil.ReadFile(utils.GetPath(utils.BrowserDevPasswordFileLocation))
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
// Parse the yaml file and get the "password" entry
|
||||
var yamlFileMap yaml.MapSlice
|
||||
err = yaml.Unmarshal(yamlFile, &yamlFileMap)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
for _, item := range yamlFileMap {
|
||||
key, value := item.Key, item.Value
|
||||
if key == "password" {
|
||||
if pwString, ok := value.(string); ok {
|
||||
return pwString, nil
|
||||
} else {
|
||||
return "", errors.New("password value is not a string")
|
||||
}
|
||||
}
|
||||
}
|
||||
return "", errors.New("password key not found")
|
||||
}
|
||||
|
||||
func SetBrowserDevPasswordFile(password string) error {
|
||||
// Get current password from file
|
||||
currentPassword, err := FetchBrowserDevPasswordFromFile()
|
||||
if err != nil {
|
||||
fmt.Println("Error fetching current password from file.")
|
||||
return err
|
||||
}
|
||||
|
||||
// Write the new password on the file using ReplaceTextInFile
|
||||
err = ReplaceTextInFile(utils.GetPath(utils.BrowserDevPasswordFileLocation), currentPassword, password)
|
||||
if err != nil {
|
||||
fmt.Println("Error writing new password to file.")
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func ReplaceTextInFile(filePath string, oldText string, newText string) error {
|
||||
// Open the file for reading
|
||||
file, err := os.OpenFile(filePath, os.O_RDWR, 0644)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Read the file contents
|
||||
data, err := ioutil.ReadAll(file)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Close the file
|
||||
err = file.Close()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Replace the text in the file
|
||||
newData := strings.Replace(string(data), oldText, newText, -1)
|
||||
|
||||
// Write the new data back to the file
|
||||
err = ioutil.WriteFile(filePath, []byte(newData), 0644)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,217 @@
|
||||
package tasks
|
||||
|
||||
import (
|
||||
"crypto/sha256"
|
||||
"encoding/base64"
|
||||
"encoding/binary"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/edgebox-iot/edgeboxctl/internal/utils"
|
||||
)
|
||||
|
||||
const (
|
||||
sshDirectory = "/root/.ssh"
|
||||
managedSSHComment = "edgebox-dashboard-managed"
|
||||
)
|
||||
|
||||
type sshAccessResult struct {
|
||||
Status string `json:"status"`
|
||||
PublicKey string `json:"public_key,omitempty"`
|
||||
Fingerprint string `json:"fingerprint,omitempty"`
|
||||
}
|
||||
|
||||
func taskEnableSSHAccess(args taskEnableSSHAccessArgs) (string, error) {
|
||||
if err := verifyRootSSHAccess(); err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
publicKey, fingerprint, err := parseSSHEd25519PublicKey(args.PublicKey)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
if err := reconcileManagedSSHKey(sshDirectory, publicKey); err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
utils.WriteOption("SSH_ACCESS_ENABLED", "true")
|
||||
utils.WriteOption("SSH_PUBLIC_KEY", publicKey)
|
||||
utils.WriteOption("SSH_KEY_FINGERPRINT", fingerprint)
|
||||
|
||||
result, err := json.Marshal(sshAccessResult{
|
||||
Status: "enabled",
|
||||
PublicKey: publicKey,
|
||||
Fingerprint: fingerprint,
|
||||
})
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return string(result), nil
|
||||
}
|
||||
|
||||
func taskDisableSSHAccess() (string, error) {
|
||||
if err := reconcileManagedSSHKey(sshDirectory, ""); err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
utils.WriteOption("SSH_ACCESS_ENABLED", "false")
|
||||
utils.DeleteOption("SSH_PUBLIC_KEY")
|
||||
utils.DeleteOption("SSH_KEY_FINGERPRINT")
|
||||
|
||||
result, err := json.Marshal(sshAccessResult{Status: "disabled"})
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
return string(result), nil
|
||||
}
|
||||
|
||||
func parseSSHEd25519PublicKey(input string) (string, string, error) {
|
||||
trimmed := strings.TrimSpace(input)
|
||||
if trimmed == "" || strings.ContainsAny(trimmed, "\r\n") {
|
||||
return "", "", fmt.Errorf("provide exactly one SSH public key")
|
||||
}
|
||||
|
||||
fields := strings.Fields(trimmed)
|
||||
if len(fields) < 2 || len(fields) > 3 || fields[0] != "ssh-ed25519" {
|
||||
return "", "", fmt.Errorf("only one ssh-ed25519 public key is supported")
|
||||
}
|
||||
|
||||
keyBlob, err := base64.StdEncoding.DecodeString(fields[1])
|
||||
if err != nil || !validEd25519KeyBlob(keyBlob) {
|
||||
return "", "", fmt.Errorf("invalid ssh-ed25519 public key")
|
||||
}
|
||||
|
||||
digest := sha256.Sum256(keyBlob)
|
||||
publicKey := "ssh-ed25519 " + base64.StdEncoding.EncodeToString(keyBlob) + " " + managedSSHComment
|
||||
fingerprint := "SHA256:" + base64.RawStdEncoding.EncodeToString(digest[:])
|
||||
|
||||
return publicKey, fingerprint, nil
|
||||
}
|
||||
|
||||
func validEd25519KeyBlob(blob []byte) bool {
|
||||
if len(blob) < 4 {
|
||||
return false
|
||||
}
|
||||
|
||||
typeLength := int(binary.BigEndian.Uint32(blob[:4]))
|
||||
if typeLength != len("ssh-ed25519") || len(blob) < 4+typeLength+4 {
|
||||
return false
|
||||
}
|
||||
if string(blob[4:4+typeLength]) != "ssh-ed25519" {
|
||||
return false
|
||||
}
|
||||
|
||||
keyLengthOffset := 4 + typeLength
|
||||
keyLength := int(binary.BigEndian.Uint32(blob[keyLengthOffset : keyLengthOffset+4]))
|
||||
return keyLength == 32 && len(blob) == keyLengthOffset+4+keyLength
|
||||
}
|
||||
|
||||
func reconcileManagedSSHKey(directory string, publicKey string) error {
|
||||
if info, err := os.Lstat(directory); err == nil {
|
||||
if info.Mode()&os.ModeSymlink != 0 || !info.IsDir() {
|
||||
return fmt.Errorf("SSH directory is not a regular directory")
|
||||
}
|
||||
} else if !os.IsNotExist(err) {
|
||||
return fmt.Errorf("inspect SSH directory: %w", err)
|
||||
} else if err := os.MkdirAll(directory, 0700); err != nil {
|
||||
return fmt.Errorf("create SSH directory: %w", err)
|
||||
}
|
||||
|
||||
if err := os.Chmod(directory, 0700); err != nil {
|
||||
return fmt.Errorf("secure SSH directory: %w", err)
|
||||
}
|
||||
|
||||
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||
if info, err := os.Lstat(authorizedKeysPath); err == nil && info.Mode()&os.ModeSymlink != 0 {
|
||||
return fmt.Errorf("authorized_keys must not be a symbolic link")
|
||||
} else if err != nil && !os.IsNotExist(err) {
|
||||
return fmt.Errorf("inspect authorized_keys: %w", err)
|
||||
}
|
||||
|
||||
existing, err := os.ReadFile(authorizedKeysPath)
|
||||
if err != nil && !os.IsNotExist(err) {
|
||||
return fmt.Errorf("read authorized_keys: %w", err)
|
||||
}
|
||||
|
||||
lines := strings.Split(string(existing), "\n")
|
||||
kept := make([]string, 0, len(lines)+1)
|
||||
for _, line := range lines {
|
||||
if strings.TrimSpace(line) == "" || isManagedSSHKey(line) {
|
||||
continue
|
||||
}
|
||||
kept = append(kept, line)
|
||||
}
|
||||
if publicKey != "" {
|
||||
kept = append(kept, publicKey)
|
||||
}
|
||||
|
||||
contents := ""
|
||||
if len(kept) > 0 {
|
||||
contents = strings.Join(kept, "\n") + "\n"
|
||||
}
|
||||
|
||||
temporary, err := os.CreateTemp(directory, ".authorized_keys-*")
|
||||
if err != nil {
|
||||
return fmt.Errorf("create authorized_keys temporary file: %w", err)
|
||||
}
|
||||
temporaryPath := temporary.Name()
|
||||
defer os.Remove(temporaryPath)
|
||||
|
||||
if err := temporary.Chmod(0600); err != nil {
|
||||
temporary.Close()
|
||||
return fmt.Errorf("secure authorized_keys temporary file: %w", err)
|
||||
}
|
||||
if _, err := temporary.WriteString(contents); err != nil {
|
||||
temporary.Close()
|
||||
return fmt.Errorf("write authorized_keys: %w", err)
|
||||
}
|
||||
if err := temporary.Sync(); err != nil {
|
||||
temporary.Close()
|
||||
return fmt.Errorf("sync authorized_keys: %w", err)
|
||||
}
|
||||
if err := temporary.Close(); err != nil {
|
||||
return fmt.Errorf("close authorized_keys: %w", err)
|
||||
}
|
||||
if err := os.Rename(temporaryPath, authorizedKeysPath); err != nil {
|
||||
return fmt.Errorf("replace authorized_keys: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func isManagedSSHKey(line string) bool {
|
||||
fields := strings.Fields(line)
|
||||
return len(fields) == 3 && fields[2] == managedSSHComment
|
||||
}
|
||||
|
||||
func verifyRootSSHAccess() error {
|
||||
sshdPath, err := exec.LookPath("sshd")
|
||||
if err != nil {
|
||||
sshdPath = "/usr/sbin/sshd"
|
||||
if _, statErr := os.Stat(sshdPath); statErr != nil {
|
||||
return fmt.Errorf("OpenSSH server is not installed")
|
||||
}
|
||||
}
|
||||
|
||||
output, err := exec.Command(sshdPath, "-T").Output()
|
||||
if err != nil {
|
||||
return fmt.Errorf("could not verify the effective SSH server configuration")
|
||||
}
|
||||
|
||||
settings := string(output)
|
||||
if !strings.Contains(settings, "pubkeyauthentication yes") {
|
||||
return fmt.Errorf("SSH public-key authentication is disabled")
|
||||
}
|
||||
if strings.Contains(settings, "permitrootlogin no") {
|
||||
return fmt.Errorf("SSH root login is disabled")
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -0,0 +1,111 @@
|
||||
package tasks
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"encoding/binary"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func testPublicKey(t *testing.T) string {
|
||||
t.Helper()
|
||||
blob := make([]byte, 4+len("ssh-ed25519")+4+32)
|
||||
binary.BigEndian.PutUint32(blob[:4], uint32(len("ssh-ed25519")))
|
||||
copy(blob[4:], "ssh-ed25519")
|
||||
offset := 4 + len("ssh-ed25519")
|
||||
binary.BigEndian.PutUint32(blob[offset:offset+4], 32)
|
||||
for index := 0; index < 32; index++ {
|
||||
blob[offset+4+index] = byte(index + 1)
|
||||
}
|
||||
return "ssh-ed25519 " + base64.StdEncoding.EncodeToString(blob) + " workstation"
|
||||
}
|
||||
|
||||
func TestParseSSHEd25519PublicKey(t *testing.T) {
|
||||
publicKey, fingerprint, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.HasSuffix(publicKey, " "+managedSSHComment) {
|
||||
t.Fatalf("public key does not have managed marker: %q", publicKey)
|
||||
}
|
||||
if !strings.HasPrefix(fingerprint, "SHA256:") {
|
||||
t.Fatalf("unexpected fingerprint: %q", fingerprint)
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseSSHEd25519PublicKeyRejectsUnsafeInput(t *testing.T) {
|
||||
inputs := []string{
|
||||
"",
|
||||
"-----BEGIN OPENSSH PRIVATE KEY-----",
|
||||
testPublicKey(t) + "\n" + testPublicKey(t),
|
||||
"command=whoami " + testPublicKey(t),
|
||||
"ssh-rsa AAAA invalid",
|
||||
}
|
||||
for _, input := range inputs {
|
||||
if _, _, err := parseSSHEd25519PublicKey(input); err == nil {
|
||||
t.Fatalf("expected input to be rejected: %q", input)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestReconcileManagedSSHKeyPreservesUnrelatedKeys(t *testing.T) {
|
||||
directory := t.TempDir()
|
||||
authorizedKeysPath := filepath.Join(directory, "authorized_keys")
|
||||
original := "# operator key\nssh-ed25519 AAAAoperator operator\n"
|
||||
if err := os.WriteFile(authorizedKeysPath, []byte(original), 0644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
publicKey, _, err := parseSSHEd25519PublicKey(testPublicKey(t))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := reconcileManagedSSHKey(directory, publicKey); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
contents, err := os.ReadFile(authorizedKeysPath)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if strings.Count(string(contents), managedSSHComment) != 1 {
|
||||
t.Fatalf("managed key is not idempotent: %s", contents)
|
||||
}
|
||||
if !strings.Contains(string(contents), original) {
|
||||
t.Fatalf("unrelated content was changed: %s", contents)
|
||||
}
|
||||
if info, err := os.Stat(authorizedKeysPath); err != nil || info.Mode().Perm() != 0600 {
|
||||
t.Fatalf("authorized_keys mode is not 0600: %v, %v", info, err)
|
||||
}
|
||||
|
||||
if err := reconcileManagedSSHKey(directory, ""); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
contents, err = os.ReadFile(authorizedKeysPath)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if string(contents) != original {
|
||||
t.Fatalf("disable changed unrelated content: %q", contents)
|
||||
}
|
||||
}
|
||||
|
||||
func TestReconcileManagedSSHKeyRejectsSymlink(t *testing.T) {
|
||||
directory := t.TempDir()
|
||||
target := filepath.Join(directory, "target")
|
||||
if err := os.WriteFile(target, []byte("preserve me"), 0600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.Symlink(target, filepath.Join(directory, "authorized_keys")); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
if err := reconcileManagedSSHKey(directory, ""); err == nil {
|
||||
t.Fatal("expected symlink to be rejected")
|
||||
}
|
||||
}
|
||||
+1143
-17
File diff suppressed because it is too large
Load Diff
+102
-3
@@ -16,7 +16,7 @@ import (
|
||||
)
|
||||
|
||||
// ExecAndStream : Runs a terminal command, but streams progress instead of outputting. Ideal for long lived process that need to be logged.
|
||||
func ExecAndStream(path string, command string, args []string) {
|
||||
func ExecAndStream(path string, command string, args []string) string {
|
||||
|
||||
cmd := exec.Command(command, args...)
|
||||
|
||||
@@ -27,13 +27,17 @@ func ExecAndStream(path string, command string, args []string) {
|
||||
|
||||
err := cmd.Run()
|
||||
|
||||
outStr, errStr := string(stdoutBuf.Bytes()), string(stderrBuf.Bytes())
|
||||
|
||||
returnVal := outStr
|
||||
if err != nil {
|
||||
fmt.Printf("cmd.Run() failed with %s\n", err)
|
||||
returnVal = errStr
|
||||
}
|
||||
|
||||
outStr, errStr := string(stdoutBuf.Bytes()), string(stderrBuf.Bytes())
|
||||
fmt.Printf("\nout:\n%s\nerr:\n%s\n", outStr, errStr)
|
||||
|
||||
return returnVal
|
||||
}
|
||||
|
||||
// Exec : Runs a terminal Command, catches and logs errors, returns the result.
|
||||
@@ -100,11 +104,18 @@ func GetSQLiteFormattedDateTime(t time.Time) string {
|
||||
return formatedDatetime
|
||||
}
|
||||
|
||||
const BackupPasswordFileLocation string = "backupPasswordFileLocation"
|
||||
const CloudEnvFileLocation string = "cloudEnvFileLocation"
|
||||
const ApiEnvFileLocation string = "apiEnvFileLocation"
|
||||
const ApiPath string = "apiPath"
|
||||
const EdgeAppsPath string = "edgeAppsPath"
|
||||
const EdgeAppsBackupPath string = "edgeAppsBackupPath"
|
||||
const WsPath string = "wsPath"
|
||||
const BrowserDevPath string = "browserDevPath"
|
||||
const LoggerPath string = "loggerPath"
|
||||
const BrowserDevPasswordFileLocation string = "browserDevPasswordFileLocation"
|
||||
const BrowserDevProxyPath string = "browserDevProxyPath"
|
||||
|
||||
|
||||
// GetPath : Returns either the hardcoded path, or a overwritten value via .env file at project root. Register paths here for seamless working code between dev and prod environments ;)
|
||||
func GetPath(pathKey string) string {
|
||||
@@ -124,7 +135,7 @@ func GetPath(pathKey string) string {
|
||||
if env["CLOUD_ENV_FILE_LOCATION"] != "" {
|
||||
targetPath = env["CLOUD_ENV_FILE_LOCATION"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/edgeboxctl/cloud.env"
|
||||
targetPath = "/home/system/components/api/cloud.env"
|
||||
}
|
||||
|
||||
case ApiEnvFileLocation:
|
||||
@@ -151,6 +162,13 @@ func GetPath(pathKey string) string {
|
||||
targetPath = "/home/system/components/apps/"
|
||||
}
|
||||
|
||||
case EdgeAppsBackupPath:
|
||||
if env["EDGEAPPS_BACKUP_PATH"] != "" {
|
||||
targetPath = env["EDGEAPPS_BACKUP_PATH"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/backups/"
|
||||
}
|
||||
|
||||
case WsPath:
|
||||
|
||||
if env["WS_PATH"] != "" {
|
||||
@@ -159,6 +177,43 @@ func GetPath(pathKey string) string {
|
||||
targetPath = "/home/system/components/ws/"
|
||||
}
|
||||
|
||||
case BrowserDevPath:
|
||||
|
||||
if env["BROWSERDEV_PATH"] != "" {
|
||||
targetPath = env["BROWSERDEV_PATH"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/dev/"
|
||||
}
|
||||
|
||||
case LoggerPath:
|
||||
if env["LOGGER_PATH"] != "" {
|
||||
targetPath = env["LOGGER_PATH"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/logger/"
|
||||
}
|
||||
|
||||
case BackupPasswordFileLocation:
|
||||
|
||||
if env["BACKUP_PASSWORD_FILE_LOCATION"] != "" {
|
||||
targetPath = env["BACKUP_PASSWORD_FILE_LOCATION"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/backups/pw.txt"
|
||||
}
|
||||
|
||||
case BrowserDevPasswordFileLocation:
|
||||
if env["BROWSERDEV_PASSWORD_FILE_LOCATION"] != "" {
|
||||
targetPath = env["BROWSERDEV_PASSWORD_FILE_LOCATION"]
|
||||
} else {
|
||||
targetPath = "/root/.config/code-server/config.yaml"
|
||||
}
|
||||
|
||||
case BrowserDevProxyPath:
|
||||
if env["BROWSERDEV_PROXY_PATH"] != "" {
|
||||
targetPath = env["BROWSERDEV_PROXY_PATH"]
|
||||
} else {
|
||||
targetPath = "/home/system/components/dev/"
|
||||
}
|
||||
|
||||
default:
|
||||
|
||||
log.Printf("path_key %s nonexistant in GetPath().\n", pathKey)
|
||||
@@ -192,3 +247,47 @@ func WriteOption(optionKey string, optionValue string) {
|
||||
|
||||
db.Close()
|
||||
}
|
||||
|
||||
// ReadOption : Reads a key value pair option from the api shared database
|
||||
func ReadOption(optionKey string) string {
|
||||
|
||||
db, err := sql.Open("sqlite3", GetSQLiteDbConnectionDetails())
|
||||
|
||||
if err != nil {
|
||||
log.Fatal(err.Error())
|
||||
}
|
||||
|
||||
var optionValue string
|
||||
|
||||
err = db.QueryRow("SELECT value FROM option WHERE name = ?", optionKey).Scan(&optionValue)
|
||||
|
||||
if err != nil {
|
||||
log.Println(err.Error())
|
||||
}
|
||||
|
||||
db.Close()
|
||||
|
||||
return optionValue
|
||||
}
|
||||
|
||||
// DeleteOption : Deletes a key value pair option from the api shared database
|
||||
func DeleteOption(optionKey string) {
|
||||
|
||||
db, err := sql.Open("sqlite3", GetSQLiteDbConnectionDetails())
|
||||
|
||||
if err != nil {
|
||||
log.Fatal(err.Error())
|
||||
}
|
||||
|
||||
statement, err := db.Prepare("DELETE FROM option WHERE name = ?;") // Prepare SQL Statement
|
||||
if err != nil {
|
||||
log.Fatal(err.Error())
|
||||
}
|
||||
|
||||
_, err = statement.Exec(optionKey) // Execute SQL Statement
|
||||
if err != nil {
|
||||
log.Fatal(err.Error())
|
||||
}
|
||||
|
||||
db.Close()
|
||||
}
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
#!/usr/bin/env sh
|
||||
|
||||
echo "Starting script login"
|
||||
cloudflared tunnel login 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log &
|
||||
echo "sleeping 5 seconds"
|
||||
sleep 5
|
||||
Executable
+7
@@ -0,0 +1,7 @@
|
||||
#!/usr/bin/env sh
|
||||
|
||||
echo "Starting script create"
|
||||
# script -q -c "cloudflared tunnel login 2>&1 | tee /app/output.log" &
|
||||
cloudflared tunnel create edgebox 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log
|
||||
echo "sleeping 5 seconds"
|
||||
sleep 5
|
||||
Executable
+7
@@ -0,0 +1,7 @@
|
||||
#!/usr/bin/env sh
|
||||
|
||||
echo "Starting script delete"
|
||||
TUNNEL_ORIGIN_CERT=/home/system/.cloudflared/cert.pem
|
||||
cloudflared tunnel delete edgebox 2>&1 | tee /home/system/components/edgeboxctl/scripts/output.log &
|
||||
echo "sleeping 5 seconds"
|
||||
sleep 5
|
||||
Reference in New Issue
Block a user