2026-10-03 00:05:14 -04:00
#!/usr/bin/env bash
# netvm-provision-edge.sh — prepare an edge device for operator-managed NetVM.
# Run ON the edge device as a user with sudo (interactive sudo is fine).
# Idempotent: safe to re-run. Every edge device provisioned this way looks
# identical, so the operator uses one command everywhere.
set -euo pipefail
OPERATOR_USER = " ${ OPERATOR_USER :- $( whoami) } "
REPO = " $HOME /Projects/NetVM "
2026-10-03 00:17:41 -04:00
SUDOERS_FILE = "/etc/sudoers.d/zz-netvm-operator"
2026-10-03 00:05:14 -04:00
echo " == NetVM edge provisioning (operator user: $OPERATOR_USER ) == "
# 1. prerequisites (best-effort install for the common missing piece: wg)
if ! " $REPO /bin/netvm-verify.sh " ; then
echo "-- installing missing packages --"
if command -v pacman >/dev/null 2>& 1; then
sudo pacman -S --noconfirm --needed wireguard-tools
elif command -v apt-get >/dev/null 2>& 1; then
sudo apt-get update && sudo apt-get install -y wireguard
else
echo "install wireguard-tools manually, then re-run" ; exit 1
fi
" $REPO /bin/netvm-verify.sh "
fi
# 2. repo must be here (sync over Tailscale first on non-laptop nodes)
[ -x " $REPO /bin/netvm-node-up.sh " ] || { echo " NetVM repo not at $REPO — sync it here first " ; exit 1; }
# 3. sudoers allowlist: exact lifecycle scripts only, never blanket root
sudo tee " $SUDOERS_FILE " > /dev/null << SUDOERS
2026-10-03 00:17:41 -04:00
# NetVM operator lifecycle access — managed by netvm-provision-edge.sh. Named zz- so it sorts last: in sudoers the LAST matching entry wins, and this must beat any blanket (ALL) grant.
2026-10-03 00:05:14 -04:00
# Lets the operator user bring node egress up/down and read topology.
# WireGuard configs in /etc/netvm stay root-only; these scripts never print them.
2026-10-03 00:43:08 -04:00
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh, $REPO/bin/netvm-enter.sh *
# let the display env survive sudo for browser launches inside the netns
Defaults!$REPO/bin/netvm-enter.sh env_keep+="DISPLAY WAYLAND_DISPLAY XDG_RUNTIME_DIR XAUTHORITY"
2026-10-03 00:05:14 -04:00
SUDOERS
sudo chmod 440 " $SUDOERS_FILE "
sudo visudo -c -f " $SUDOERS_FILE " > /dev/null && echo "ok: sudoers valid"
# 4. dir for human-placed WireGuard identities
sudo mkdir -p /etc/netvm
2026-10-03 01:06:00 -04:00
sudo chmod 711 /etc/netvm
2026-10-03 00:05:14 -04:00
echo "ok: /etc/netvm ready"
# 5. tailnet check
tailscale status >/dev/null 2>& 1 && echo "ok: tailscale up" || echo "NOTE: tailscale not up — run: tailscale up"
echo
echo "Done. Human next step: place this node's WireGuard config at"
echo " /etc/netvm/<node>.conf (root-owned, 0600; wgcf-generated)"
echo "Operator usage from anywhere on the tailnet:"
echo " ssh ${ OPERATOR_USER } @<tail-ip> 'sudo -n $REPO /bin/netvm-node-up.sh <node>' "