diff --git a/agent/linux/install.sh b/agent/linux/install.sh index 5f37979..a776960 100644 --- a/agent/linux/install.sh +++ b/agent/linux/install.sh @@ -6,16 +6,30 @@ # curl -fsSL https://homelab.example.lan/agent/linux/install.sh | \ # sudo API_URL=https://homelab.example.lan API_TOKEN=hlm_xxx bash # +# If Homelab Manager is served with a self-signed certificate, also pass +# API_INSECURE=true (skips TLS verification for every request this agent +# makes — only do this on a trusted LAN) AND add -k to the outer curl +# above, since that first fetch of this very script also hits the +# self-signed endpoint before any of this script's logic can run: +# curl -fsSL -k https://homelab.example.lan/agent/linux/install.sh | \ +# sudo API_URL=https://homelab.example.lan API_TOKEN=hlm_xxx API_INSECURE=true bash +# set -euo pipefail : "${API_URL:?Set API_URL to your Homelab Manager URL, e.g. https://homelab.example.lan}" : "${API_TOKEN:?Set API_TOKEN to the per-server token generated on the Servers & Tasks page}" +API_INSECURE="${API_INSECURE:-false}" INSTALL_DIR="/usr/local/bin" CONFIG_DIR="/etc" SYSTEMD_DIR="/etc/systemd/system" INTERVAL_MINUTES="${INTERVAL_MINUTES:-15}" +CURL_INSECURE_FLAG=() +case "${API_INSECURE,,}" in + 1|true|yes) CURL_INSECURE_FLAG=(-k) ;; +esac + if [[ "$EUID" -ne 0 ]]; then echo "This installer must be run as root (it installs a systemd timer)." >&2 echo "If you're piping from curl, put sudo right after the pipe so it elevates bash, not curl:" >&2 @@ -55,13 +69,14 @@ fi echo "Installing Homelab Manager agent from $API_URL ..." -curl -fsSL "$API_URL/agent/linux/report-tasks.sh" -o "$INSTALL_DIR/homelab-manager-agent.sh" +curl -fsSL "${CURL_INSECURE_FLAG[@]}" "$API_URL/agent/linux/report-tasks.sh" -o "$INSTALL_DIR/homelab-manager-agent.sh" chmod 755 "$INSTALL_DIR/homelab-manager-agent.sh" umask 077 cat > "$CONFIG_DIR/homelab-manager-agent.env" </dev/null 2>&1; then @@ -240,7 +249,7 @@ if [[ "$DRY_RUN" == "1" ]]; then exit 0 fi -response=$(curl -sS -o /tmp/hlm-agent-response.json -w "%{http_code}" \ +response=$(curl -sS "${CURL_INSECURE_FLAG[@]}" -o /tmp/hlm-agent-response.json -w "%{http_code}" \ -X POST "$API_URL/api/agent/report" \ -H "Authorization: Bearer $API_TOKEN" \ -H "Content-Type: application/json" \ diff --git a/web/src/pages/ServersTasks.tsx b/web/src/pages/ServersTasks.tsx index d706827..100959c 100644 --- a/web/src/pages/ServersTasks.tsx +++ b/web/src/pages/ServersTasks.tsx @@ -22,12 +22,17 @@ const SCHEDULE_TYPE_OPTIONS: { value: ScheduleType; label: string }[] = [ { value: "manual", label: "Other / manual" }, ]; -function installCommand(token: string): string { - return `curl -fsSL ${window.location.origin}/agent/linux/install.sh | sudo API_URL=${window.location.origin} API_TOKEN=${token} bash`; +function installCommand(token: string, insecure: boolean): string { + const curlFlags = insecure ? "-fsSL -k" : "-fsSL"; + const envVars = insecure + ? `API_URL=${window.location.origin} API_TOKEN=${token} API_INSECURE=true` + : `API_URL=${window.location.origin} API_TOKEN=${token}`; + return `curl ${curlFlags} ${window.location.origin}/agent/linux/install.sh | sudo ${envVars} bash`; } -function uninstallCommand(): string { - return `curl -fsSL ${window.location.origin}/agent/linux/uninstall.sh | sudo bash`; +function uninstallCommand(insecure: boolean): string { + const curlFlags = insecure ? "-fsSL -k" : "-fsSL"; + return `curl ${curlFlags} ${window.location.origin}/agent/linux/uninstall.sh | sudo bash`; } const emptyTaskForm = { @@ -64,6 +69,7 @@ export default function ServersTasks({ user }: { user: CurrentUser }) { const [serverDescription, setServerDescription] = useState(""); const [newToken, setNewToken] = useState<{ server: ServerRecord; token: string } | null>(null); const [uninstallFor, setUninstallFor] = useState(null); + const [insecureAgent, setInsecureAgent] = useState(false); const loadServers = useCallback(() => { return api.servers @@ -266,12 +272,23 @@ export default function ServersTasks({ user }: { user: CurrentUser }) { {newToken.token} +

Install the agent on the server (run as root — put sudo right after the pipe, not before curl):

-
{installCommand(newToken.token)}
- +
{installCommand(newToken.token, insecureAgent)}
+
@@ -290,8 +307,8 @@ export default function ServersTasks({ user }: { user: CurrentUser }) {

Run this on the server as root to stop and remove the agent (its entry here is kept):

-
{uninstallCommand()}
- +
{uninstallCommand(insecureAgent)}
+