feat(netvm): add waypipe support and cgroup/netns wrapping for chromebox

This commit is contained in:
Antigravity Agent
2026-10-05 13:41:05 -04:00
parent 4b92277686
commit ab7d1215e0
3 changed files with 51 additions and 8 deletions
+29 -1
View File
@@ -6,8 +6,15 @@ SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
. "$SCRIPT_DIR/netvm-names.sh"
netvm_names "${1:?usage: netvm-node-up.sh <node>}"
CONF="/etc/netvm/${NODE}.conf"
STAGE_CONF="/tmp/netvm-stage-${NODE}.conf"
if [ ! -f "$CONF" ] && [ -f "$STAGE_CONF" ]; then
mkdir -p /etc/netvm 2>/dev/null || true
install -m 600 -o root -g root "$STAGE_CONF" "$CONF"
rm -f "$STAGE_CONF"
fi
[ -f "$CONF" ] || { echo "missing $CONF (human: netvm-new-identity.sh $NODE)"; exit 1; }
chmod 600 "$CONF"
# let the operator user stat (not read) identities: 711 dir, 600 files
chmod 711 /etc/netvm 2>/dev/null || true
nsexec() { ip netns exec "$NETNS" "$@"; }
@@ -100,4 +107,25 @@ else
fi
EGRESS=$(nsexec curl -sk --max-time 15 'https://1.1.1.1/cdn-cgi/trace' 2>/dev/null | grep -oP '^ip=\K.*' || true)
fi
echo "node=$NODE netns=$NETNS ifaces=$WG/$VETH egress=${EGRESS:-unknown}"
if [ -z "$EGRESS" ]; then
echo "ERROR: Egress check failed for node '$NODE' (warp interface down or unroutable). Aborting." >&2
EMAIL_ALERT="/home/super/Projects/email-alert/email-alert"
if [ -x "$EMAIL_ALERT" ]; then
"$EMAIL_ALERT" send --priority high --subject "NetVM Alert: Node '$NODE' Egress Failed" "WireGuard WARP tunnel for node '$NODE' failed egress verification. Execution aborted to protect IP isolation." || true
fi
exit 1
fi
REAL_USER="${SUDO_USER:-$USER}"
REAL_HOME=$(eval echo "~$REAL_USER")
AUDIT_DIR="$REAL_HOME/.local/share/chrome-box"
mkdir -p "$AUDIT_DIR" 2>/dev/null || true
chown "$REAL_USER:" "$AUDIT_DIR" 2>/dev/null || true
TIMESTAMP=$(date -u +"%Y-%m-%dT%H:%M:%SZ")
python3 -c "import json; print(json.dumps({'timestamp': '$TIMESTAMP', 'event': 'node_up', 'node': '$NODE', 'netns': '$NETNS', 'veth_ip': '$PEER_IP', 'cdp_port': $CDP_PORT, 'egress_ip': '$EGRESS', 'user': '$REAL_USER'}))" >> "$AUDIT_DIR/audit.jsonl" 2>/dev/null || true
chown "$REAL_USER:" "$AUDIT_DIR/audit.jsonl" 2>/dev/null || true
echo "node=$NODE netns=$NETNS ifaces=$WG/$VETH egress=$EGRESS"