Add identity-audit-check.sh and box identity-audit action
identity-audit-check.sh: proper script replacing the identity-audit-watch cron inline SSH one-liner. Reads a bl-local cache of the VM audit JSON (bl cannot SSH to VM; VM hourly audit should push to var/identity-audit.json). Exits 0 clean, 1 on drift, 2 if cache missing. box-ctl.py: new identity-audit action returning drift as JSON.
This commit is contained in:
@@ -697,6 +697,21 @@ def act_relay_health():
|
||||
out(all_healthy, relays=results, healthy=all_healthy)
|
||||
|
||||
|
||||
def act_identity_audit():
|
||||
"""Run identity-audit-check.sh and return drift as JSON."""
|
||||
audit("identity-audit")
|
||||
script = BIN / "identity-audit-check.sh"
|
||||
r = subprocess.run([str(script)], capture_output=True, text=True, timeout=60)
|
||||
if r.returncode == 2:
|
||||
fail("AUDIT_UNAVAILABLE", (r.stderr or r.stdout).strip()[:500])
|
||||
drift = []
|
||||
for line in r.stdout.strip().split("\n"):
|
||||
if line.startswith("DRIFT: "):
|
||||
drift.append(line[len("DRIFT: "):])
|
||||
clean = r.returncode == 0
|
||||
out(clean, drift=drift, clean=clean)
|
||||
|
||||
|
||||
|
||||
def act_cdp_latency():
|
||||
"""Run cdp-latency-check.sh and return per-node latency JSON."""
|
||||
@@ -1131,6 +1146,7 @@ fleet:
|
||||
watchdog-alerts
|
||||
relay-health
|
||||
cdp-latency
|
||||
identity-audit VM identity audit drift check
|
||||
|
||||
timer actions:
|
||||
timer-list
|
||||
@@ -1363,6 +1379,10 @@ def main(argv):
|
||||
act_watchdog_alerts()
|
||||
elif action == "relay-health":
|
||||
act_relay_health()
|
||||
elif action == "identity-audit":
|
||||
if rest:
|
||||
fail("BAD_ARGS", "usage: identity-audit")
|
||||
act_identity_audit()
|
||||
elif action == "cdp-latency":
|
||||
act_cdp_latency()
|
||||
elif action == "chrome-errors":
|
||||
|
||||
Reference in New Issue
Block a user