Remove wrongly-specced opp-dm.py and dev-dm.py; dm.py is the headless DM tool
This commit is contained in:
Executable
+86
@@ -0,0 +1,86 @@
|
||||
#!/usr/bin/env python3
|
||||
"""onboard-driver.py — bl-side OTP onboarding driver.
|
||||
|
||||
Runs INSIDE the node's netns (via netvm-exec.sh). Reads the identifier
|
||||
(line 1) and OTP code (line 2, submit step only) from stdin — never argv.
|
||||
|
||||
onboard-driver.py --node muse --service muse --id-type email --step initiate [--dry-run]
|
||||
onboard-driver.py --node muse --service muse --id-type email --step submit
|
||||
|
||||
Exit codes: 0 = step done, 2 = APPROVAL_NEEDED (code sent, awaiting OTP),
|
||||
1 = failed. The identifier/code are passed to the local signin script as
|
||||
argv (transient, same trust domain — bl is operator infrastructure);
|
||||
they never cross a network boundary except inside the already-encrypted
|
||||
VM->bl SSH stdin pipe.
|
||||
|
||||
Part of the cred onboarding module (front-door repo, docs/CRED-MODULE.md).
|
||||
"""
|
||||
import argparse
|
||||
import json
|
||||
import subprocess
|
||||
import sys
|
||||
import urllib.request
|
||||
|
||||
SIGNIN = "/home/super/Projects/NetVM/bin/muse-signin.py"
|
||||
CDP_PORTS = {"muse": "9410", "pip": "9420"}
|
||||
|
||||
|
||||
def cdp_ok(port):
|
||||
try:
|
||||
ts = json.load(urllib.request.urlopen(
|
||||
"http://127.0.0.1:%s/json/list" % port, timeout=5))
|
||||
return any(t.get("type") == "page" for t in ts)
|
||||
except Exception:
|
||||
return False
|
||||
|
||||
|
||||
def main():
|
||||
p = argparse.ArgumentParser()
|
||||
p.add_argument("--node", required=True)
|
||||
p.add_argument("--service", required=True)
|
||||
p.add_argument("--id-type", required=True)
|
||||
p.add_argument("--step", required=True, choices=["initiate", "submit"])
|
||||
p.add_argument("--dry-run", action="store_true")
|
||||
args = p.parse_args()
|
||||
|
||||
lines = sys.stdin.read().splitlines()
|
||||
identifier = lines[0].strip() if lines else ""
|
||||
code = lines[1].strip() if len(lines) > 1 else ""
|
||||
|
||||
if args.service != "muse" or args.id_type != "email":
|
||||
print("ERROR: unsupported service/id_type "
|
||||
"(muse+email only for now)", file=sys.stderr)
|
||||
return 1
|
||||
port = CDP_PORTS.get(args.node)
|
||||
if not port:
|
||||
print("ERROR: unknown node", file=sys.stderr)
|
||||
return 1
|
||||
|
||||
if args.dry_run:
|
||||
# Walk the chain without sending anything: netns + CDP + page.
|
||||
if cdp_ok(port):
|
||||
print("dry-run ok: node=%s cdp=%s reachable, page present"
|
||||
% (args.node, port))
|
||||
return 0
|
||||
print("ERROR: CDP unreachable on %s" % port, file=sys.stderr)
|
||||
return 1
|
||||
|
||||
if not identifier:
|
||||
print("ERROR: no identifier on stdin", file=sys.stderr)
|
||||
return 1
|
||||
|
||||
cmd = [sys.executable, SIGNIN, "--email", identifier]
|
||||
if args.step == "submit":
|
||||
if not code:
|
||||
print("ERROR: no code on stdin", file=sys.stderr)
|
||||
return 1
|
||||
cmd += ["--otp", code]
|
||||
r = subprocess.run(cmd, capture_output=True, text=True, timeout=220)
|
||||
# Propagate the signin script's contract: 2 = OTP prompt reached.
|
||||
sys.stdout.write(r.stdout)
|
||||
sys.stderr.write(r.stderr)
|
||||
return r.returncode
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user