NetVM: edge provisioning script (sudoers allowlist for operator)
This commit is contained in:
@@ -81,6 +81,7 @@ Tear down: sudo bin/netvm-node-down.sh <node>.
|
|||||||
- bin/netvm-node-up.sh <node> — bring up a node's egress.
|
- bin/netvm-node-up.sh <node> — bring up a node's egress.
|
||||||
- bin/netvm-node-down.sh <node> — tear a node's egress down.
|
- bin/netvm-node-down.sh <node> — tear a node's egress down.
|
||||||
- bin/netvm-topology.sh — print the live topology table.
|
- bin/netvm-topology.sh — print the live topology table.
|
||||||
|
- `bin/netvm-provision-edge.sh` — prepare an edge device (sudoers allowlist, deps, /etc/netvm); run on the node, once.
|
||||||
- NODES.md — the registry: node -> netns -> Warp identity -> egress IP.
|
- NODES.md — the registry: node -> netns -> Warp identity -> egress IP.
|
||||||
|
|
||||||
## Verification checklist
|
## Verification checklist
|
||||||
|
|||||||
Executable
+52
@@ -0,0 +1,52 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# netvm-provision-edge.sh — prepare an edge device for operator-managed NetVM.
|
||||||
|
# Run ON the edge device as a user with sudo (interactive sudo is fine).
|
||||||
|
# Idempotent: safe to re-run. Every edge device provisioned this way looks
|
||||||
|
# identical, so the operator uses one command everywhere.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
OPERATOR_USER="${OPERATOR_USER:-$(whoami)}"
|
||||||
|
REPO="$HOME/Projects/NetVM"
|
||||||
|
SUDOERS_FILE="/etc/sudoers.d/netvm-operator"
|
||||||
|
|
||||||
|
echo "== NetVM edge provisioning (operator user: $OPERATOR_USER) =="
|
||||||
|
|
||||||
|
# 1. prerequisites (best-effort install for the common missing piece: wg)
|
||||||
|
if ! "$REPO/bin/netvm-verify.sh"; then
|
||||||
|
echo "-- installing missing packages --"
|
||||||
|
if command -v pacman >/dev/null 2>&1; then
|
||||||
|
sudo pacman -S --noconfirm --needed wireguard-tools
|
||||||
|
elif command -v apt-get >/dev/null 2>&1; then
|
||||||
|
sudo apt-get update && sudo apt-get install -y wireguard
|
||||||
|
else
|
||||||
|
echo "install wireguard-tools manually, then re-run"; exit 1
|
||||||
|
fi
|
||||||
|
"$REPO/bin/netvm-verify.sh"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 2. repo must be here (sync over Tailscale first on non-laptop nodes)
|
||||||
|
[ -x "$REPO/bin/netvm-node-up.sh" ] || { echo "NetVM repo not at $REPO — sync it here first"; exit 1; }
|
||||||
|
|
||||||
|
# 3. sudoers allowlist: exact lifecycle scripts only, never blanket root
|
||||||
|
sudo tee "$SUDOERS_FILE" > /dev/null << SUDOERS
|
||||||
|
# NetVM operator lifecycle access — managed by netvm-provision-edge.sh.
|
||||||
|
# Lets the operator user bring node egress up/down and read topology.
|
||||||
|
# WireGuard configs in /etc/netvm stay root-only; these scripts never print them.
|
||||||
|
$OPERATOR_USER ALL=(root) NOPASSWD: $REPO/bin/netvm-node-up.sh *, $REPO/bin/netvm-node-down.sh *, $REPO/bin/netvm-topology.sh
|
||||||
|
SUDOERS
|
||||||
|
sudo chmod 440 "$SUDOERS_FILE"
|
||||||
|
sudo visudo -c -f "$SUDOERS_FILE" > /dev/null && echo "ok: sudoers valid"
|
||||||
|
|
||||||
|
# 4. dir for human-placed WireGuard identities
|
||||||
|
sudo mkdir -p /etc/netvm
|
||||||
|
sudo chmod 700 /etc/netvm
|
||||||
|
echo "ok: /etc/netvm ready"
|
||||||
|
|
||||||
|
# 5. tailnet check
|
||||||
|
tailscale status >/dev/null 2>&1 && echo "ok: tailscale up" || echo "NOTE: tailscale not up — run: tailscale up"
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "Done. Human next step: place this node's WireGuard config at"
|
||||||
|
echo " /etc/netvm/<node>.conf (root-owned, 0600; wgcf-generated)"
|
||||||
|
echo "Operator usage from anywhere on the tailnet:"
|
||||||
|
echo " ssh ${OPERATOR_USER}@<tail-ip> 'sudo -n $REPO/bin/netvm-node-up.sh <node>'"
|
||||||
Reference in New Issue
Block a user