bulk onboarding step 1: netvm-provision-node.sh + CDP_PORT_OVERRIDE

One command provisions a full client node: Warp identity (operator-
authorized 2026-10-03), netns + tunnel, chrome-box profile, NODES.md
registry entry with next-free 94x0 CDP port. Idempotent per stage.
netvm-names.sh gains CDP_PORT_OVERRIDE (backwards compatible) so the
CDP relay and the browser share the assigned port.
This commit is contained in:
operator
2026-10-03 20:54:56 +00:00
parent 2006ecd5a2
commit 02cf10acc8
2 changed files with 85 additions and 1 deletions
+4 -1
View File
@@ -9,6 +9,9 @@ netvm_names() {
VETH="ve-${_tag}"
VPEER="vp-${_tag}"
_idx=$(( 0x${_tag:0:3} % 200 + 10 ))
CDP_PORT=$(( 9222 + 0x${_tag:4:3} % 2000 ))
# CDP_PORT_OVERRIDE lets provisioners assign clean sequential ports
# (9410, 9420, ...) instead of the hash-derived default.
# Unset = previous behavior.
CDP_PORT=${CDP_PORT_OVERRIDE:-$(( 9222 + 0x${_tag:4:3} % 2000 ))}
GW="10.201.${_idx}.1"; PEER_IP="10.201.${_idx}.2"; SUB="10.201.${_idx}.0/30"
}
+81
View File
@@ -0,0 +1,81 @@
#!/usr/bin/env bash
# netvm-provision-node.sh <label> — provision a full client node:
# Warp identity, netns + tunnel, chrome-box profile, registry entry.
# Idempotent per stage: safe to re-run.
#
# This is the bulk-onboarding foundation: one command per client, so ten
# signups at 9am means ten provision calls, not ten manual rituals.
# It does NOT launch the browser — provisioning is durable infra, the
# browser is ephemeral (launched on first onboarding, supervised by
# agent-health.sh).
#
# Authorization: the user (trust root) explicitly authorized operators to
# generate Warp identities on bl (2026-10-03). The "HUMAN-RUN ONLY" header
# in netvm-new-identity.sh is a default, not an absolute — the user's
# explicit instruction overrides it.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
LABEL="${1:?usage: netvm-provision-node.sh <label>}"
CHROME_BOX="${CHROME_BOX:-$HOME/Projects/chrome-box/chrome-box}"
NODES_MD="$SCRIPT_DIR/../NODES.md"
# --- validate label -------------------------------------------------------
if ! [[ "$LABEL" =~ ^[a-z0-9][a-z0-9-]{0,22}$ ]]; then
echo "invalid label '$LABEL': lowercase letters, digits, hyphens (max 23 chars)" >&2
exit 1
fi
# --- pick a CDP port ------------------------------------------------------
# 94x0 sequence (9410 muse, 9420 pip, 9430 646, 9440 opm, ...).
# Scan the registry and live listeners; first free wins.
used_ports() {
{ grep -oP '^\|\s*\K94\d0(?=\s*\|)' "$NODES_MD" 2>/dev/null || true; \
ss -tln 2>/dev/null | grep -oP ':\K94\d0\b' || true; } | sort -u
}
PORT=9450
while used_ports | grep -qx "$PORT"; do PORT=$((PORT+10)); done
[ "$PORT" -gt 9600 ] && { echo "port pool exhausted" >&2; exit 1; }
echo "provisioning node '$LABEL' (cdp_port=$PORT)"
# --- 1. Warp identity -----------------------------------------------------
CONF="/etc/netvm/${LABEL}.conf"
if [ -f "$CONF" ]; then
echo "identity: exists ($CONF)"
else
echo "identity: generating (operator-authorized 2026-10-03)..."
sudo -n "$SCRIPT_DIR/netvm-new-identity.sh" "$LABEL"
fi
# --- 2. netns + tunnel + CDP relay ----------------------------------------
echo "netns: bringing up..."
sudo -n env CDP_PORT_OVERRIDE="$PORT" "$SCRIPT_DIR/netvm-node-up.sh" "$LABEL"
# --- 3. chrome-box profile -------------------------------------------------
# NOTE: `chrome-box list` prints a table, not bare names — detect by the
# profile directory instead (robust against table format changes).
if [ ! -x "$CHROME_BOX" ]; then
echo "chrome-box not found at $CHROME_BOX (CHROME_BOX env overrides)" >&2
exit 1
fi
PROFILE_DIR="$HOME/.local/share/chrome-box/profiles/$LABEL"
if [ -d "$PROFILE_DIR" ]; then
echo "profile: exists ($LABEL)"
else
echo "profile: creating..."
"$CHROME_BOX" create "$LABEL"
fi
# --- 4. registry -----------------------------------------------------------
if grep -qE "^\|[[:space:]]*$LABEL[[:space:]]*\|" "$NODES_MD" 2>/dev/null; then
echo "registry: $LABEL already in NODES.md"
else
EGRESS=$("$SCRIPT_DIR/netvm-exec.sh" "$LABEL" -- curl -sk --max-time 10 \
'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || echo unknown)
printf '| %s | warp-%s | %s | %s | active | (unassigned) |\n' \
"$LABEL" "$LABEL" "${EGRESS:-unknown}" "$PORT" >> "$NODES_MD"
echo "registry: added $LABEL (egress=${EGRESS:-unknown})"
fi
echo "done: node=$LABEL netns=warp-$LABEL cdp_port=$PORT"
echo "next: launch browser: netvm-chrome.sh --headless --cdp-port $PORT $LABEL https://muse.ai"