NetVM: agent-friendly exec primitive (local + fleet)
This commit is contained in:
Executable
+13
@@ -0,0 +1,13 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# netvm-exec.sh <node> -- <cmd> [args...] — run a command inside the node's
|
||||||
|
# netns as the invoking user. The agent-friendly primitive for "do X in the
|
||||||
|
# node's network": egress tests, automation, debugging.
|
||||||
|
# (The node must be up; see netvm-node-up.sh / netvm-fleet.sh up.)
|
||||||
|
set -euo pipefail
|
||||||
|
NETVM_BIN="$(cd "$(dirname "$0")" && pwd)"
|
||||||
|
NODE="${1:?usage: netvm-exec.sh <node> -- <cmd> [args...]}"; shift
|
||||||
|
[ "${1:-}" = "--" ] && shift
|
||||||
|
[ $# -gt 0 ] || { echo "usage: netvm-exec.sh <node> -- <cmd> [args...]"; exit 1; }
|
||||||
|
[ -f "/etc/netvm/${NODE}.conf" ] || { echo "no warp identity for '$NODE' (human: netvm-new-identity.sh $NODE)"; exit 1; }
|
||||||
|
ip netns list 2>/dev/null | grep -q "^warp-${NODE}" || { echo "node '$NODE' is not up (netvm-node-up.sh $NODE)"; exit 1; }
|
||||||
|
exec sudo -n "$NETVM_BIN/netvm-enter.sh" "$NODE" "$(id -u)" "$(id -g)" "$HOME" -- "$@"
|
||||||
+11
-1
@@ -38,7 +38,7 @@ run_on() { # <node> <remote-command...>
|
|||||||
ssh -o BatchMode=yes -o ConnectTimeout=15 "${OPERATOR_USER}@${ip}" "$@"
|
ssh -o BatchMode=yes -o ConnectTimeout=15 "${OPERATOR_USER}@${ip}" "$@"
|
||||||
}
|
}
|
||||||
|
|
||||||
cmd="${1:?usage: netvm-fleet.sh topology|up <node>|down <node>|ssh <node>}"
|
cmd="${1:?usage: netvm-fleet.sh topology|up <node>|down <node>|ssh <node>|exec <node> -- <cmd>|cdp <node>}"
|
||||||
case "$cmd" in
|
case "$cmd" in
|
||||||
topology)
|
topology)
|
||||||
for n in $(nodes); do
|
for n in $(nodes); do
|
||||||
@@ -55,5 +55,15 @@ case "$cmd" in
|
|||||||
ip=$(tail_ip "$node") || { echo "unknown tailnet node: $node"; exit 1; }
|
ip=$(tail_ip "$node") || { echo "unknown tailnet node: $node"; exit 1; }
|
||||||
exec ssh "${OPERATOR_USER}@${ip}"
|
exec ssh "${OPERATOR_USER}@${ip}"
|
||||||
;;
|
;;
|
||||||
|
exec)
|
||||||
|
node="${2:?usage: netvm-fleet.sh exec <node> -- <cmd> [args...]}"
|
||||||
|
shift 2
|
||||||
|
[ "${1:-}" = "--" ] && shift
|
||||||
|
run_on "$node" "sudo -n \$HOME/Projects/NetVM/bin/netvm-exec.sh ${node} -- $*"
|
||||||
|
;;
|
||||||
|
cdp)
|
||||||
|
node="${2:?usage: netvm-fleet.sh cdp <node>}"
|
||||||
|
run_on "$node" "\$HOME/Projects/NetVM/bin/netvm-cdp.sh ${node}"
|
||||||
|
;;
|
||||||
*) echo "unknown command: $cmd"; exit 1 ;;
|
*) echo "unknown command: $cmd"; exit 1 ;;
|
||||||
esac
|
esac
|
||||||
|
|||||||
Reference in New Issue
Block a user