NetVM: 1:1 profile:node mapping — hashed iface names, netvm-enter + netvm-chrome launcher

This commit is contained in:
Antigravity Agent
2026-10-03 00:43:08 -04:00
parent 218a527623
commit b86b6fa4b5
8 changed files with 84 additions and 46 deletions
+3 -1
View File
@@ -32,7 +32,9 @@ sudo tee "$SUDOERS_FILE" > /dev/null << SUDOERS
# NetVM operator lifecycle access — managed by netvm-provision-edge.sh. Named zz- so it sorts last: in sudoers the LAST matching entry wins, and this must beat any blanket (ALL) grant.
# Lets the operator user bring node egress up/down and read topology.
# WireGuard configs in /etc/netvm stay root-only; these scripts never print them.
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh, $REPO/bin/netvm-enter.sh *
# let the display env survive sudo for browser launches inside the netns
Defaults!$REPO/bin/netvm-enter.sh env_keep+="DISPLAY WAYLAND_DISPLAY XDG_RUNTIME_DIR XAUTHORITY"
SUDOERS
sudo chmod 440 "$SUDOERS_FILE"
sudo visudo -c -f "$SUDOERS_FILE" > /dev/null && echo "ok: sudoers valid"