feat(protocol): implement unified protocol_muse package, wheel caching, and rebuild recovery
This commit is contained in:
@@ -42,13 +42,21 @@ needs_provisioning() { [ ! -f "$SENTINEL" ]; }
|
||||
|
||||
restore_ssh_keys() {
|
||||
# Key restoration: rebuilds may wipe ~/.ssh. Restore from persistent store if present.
|
||||
if [ ! -f "$HOME/.ssh/vm_to_gcp" ] && [ -f "$HOME/workspace/.ssh-keys/vm_to_gcp" ]; then
|
||||
log "restoring ~/.ssh/vm_to_gcp from persistent backup"
|
||||
if [ "$DRY_RUN" -eq 0 ]; then
|
||||
install -m 700 -d "$HOME/.ssh"
|
||||
install -m 600 "$HOME/workspace/.ssh-keys/vm_to_gcp" "$HOME/.ssh/vm_to_gcp"
|
||||
install -m 700 -d "$HOME/.ssh" 2>/dev/null || true
|
||||
for keyname in vm_to_gcp id_frontdoor; do
|
||||
if [ ! -f "$HOME/.ssh/$keyname" ]; then
|
||||
if [ -f "$HOME/workspace/.ssh-keys/$keyname" ]; then
|
||||
log "restoring ~/.ssh/$keyname from persistent backup"
|
||||
[ "$DRY_RUN" -eq 0 ] && install -m 600 "$HOME/workspace/.ssh-keys/$keyname" "$HOME/.ssh/$keyname"
|
||||
elif [ -f "$HOME/workspace/.ssh-keys/vm_to_gcp" ]; then
|
||||
log "linking ~/.ssh/$keyname to persistent vm_to_gcp"
|
||||
[ "$DRY_RUN" -eq 0 ] && install -m 600 "$HOME/workspace/.ssh-keys/vm_to_gcp" "$HOME/.ssh/$keyname"
|
||||
elif [ -f "$HOME/workspace/.ssh-keys/id_frontdoor" ]; then
|
||||
log "linking ~/.ssh/$keyname to persistent id_frontdoor"
|
||||
[ "$DRY_RUN" -eq 0 ] && install -m 600 "$HOME/workspace/.ssh-keys/id_frontdoor" "$HOME/.ssh/$keyname"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
provision_critical() {
|
||||
@@ -115,6 +123,22 @@ provision_critical() {
|
||||
/home/muse/.ssh/authorized_keys 2>/dev/null || true
|
||||
fi
|
||||
|
||||
# 6. Restore /root/.ssh/authorized_keys across rebuilds
|
||||
install -m 700 -d /root/.ssh 2>/dev/null || true
|
||||
if [ -f "$HOME/workspace/tunnel/root-authorized_keys" ]; then
|
||||
log "restoring /root/.ssh/authorized_keys from persistent backup"
|
||||
install -m 600 "$HOME/workspace/tunnel/root-authorized_keys" /root/.ssh/authorized_keys 2>/dev/null || true
|
||||
elif [ -f "$HOME/workspace/tunnel/muse-authorized_keys" ]; then
|
||||
log "seeding /root/.ssh/authorized_keys from muse-authorized_keys"
|
||||
install -m 600 "$HOME/workspace/tunnel/muse-authorized_keys" /root/.ssh/authorized_keys 2>/dev/null || true
|
||||
fi
|
||||
if [ -f "/home/hatch/.ssh/authorized_keys" ]; then
|
||||
log "merging /home/hatch/.ssh/authorized_keys into /root/.ssh/authorized_keys"
|
||||
cat /home/hatch/.ssh/authorized_keys >> /root/.ssh/authorized_keys 2>/dev/null || true
|
||||
sort -u /root/.ssh/authorized_keys -o /root/.ssh/authorized_keys 2>/dev/null || true
|
||||
chmod 600 /root/.ssh/authorized_keys 2>/dev/null || true
|
||||
fi
|
||||
|
||||
touch "$SENTINEL"
|
||||
log "critical provisioning complete"
|
||||
}
|
||||
@@ -150,6 +174,11 @@ provision_deferred() {
|
||||
cp -r "$HOME/workspace/nvim/"* /opt/nvim/ 2>/dev/null || true
|
||||
ln -sf /opt/nvim/bin/nvim /usr/local/bin/nvim 2>/dev/null || true
|
||||
fi
|
||||
local wheel_dir="$HOME/workspace/wheels"
|
||||
if [ -d "$wheel_dir" ] && ls "$wheel_dir"/*.whl >/dev/null 2>&1; then
|
||||
log "installing cached python wheels from $wheel_dir"
|
||||
python3 -m pip install --no-index --find-links="$wheel_dir" protocol_muse 2>/dev/null || true
|
||||
fi
|
||||
) >/dev/null 2>&1 &
|
||||
disown 2>/dev/null || true
|
||||
}
|
||||
@@ -178,7 +207,12 @@ ensure_gcp_tunnel() {
|
||||
log "gcp tunnel supervisor already running"
|
||||
exit 0
|
||||
fi
|
||||
if [ ! -f "$HOME/.ssh/vm_to_gcp" ]; then
|
||||
if [ ! -f "$HOME/.ssh/vm_to_gcp" ] && [ -f "$HOME/.ssh/id_frontdoor" ]; then
|
||||
ln -sf "$HOME/.ssh/id_frontdoor" "$HOME/.ssh/vm_to_gcp"
|
||||
elif [ ! -f "$HOME/.ssh/id_frontdoor" ] && [ -f "$HOME/.ssh/vm_to_gcp" ]; then
|
||||
ln -sf "$HOME/.ssh/vm_to_gcp" "$HOME/.ssh/id_frontdoor"
|
||||
fi
|
||||
if [ ! -f "$HOME/.ssh/vm_to_gcp" ] && [ ! -f "$HOME/.ssh/id_frontdoor" ]; then
|
||||
log "WARNING: ~/.ssh/vm_to_gcp missing — cannot start gcp tunnel supervisor"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user