Add an opt-in insecure-TLS mode for the agent, for self-signed certs

Installing the agent against a Homelab Manager instance with a
self-signed cert failed: curl verifies TLS by default on the install
download, the report-tasks.sh fetch inside install.sh, and every
periodic check-in — not just the outer one-liner, so passing -k to only
that first curl wasn't enough. Mirrors the existing Proxmox/Synology
"insecure" toggle pattern already in this app.

- install.sh and report-tasks.sh accept API_INSECURE=true, adding -k to
  their own curl calls; install.sh persists it into the agent's env
  file so the periodic systemd timer picks it up too.
- The Servers & Tasks page has a new checkbox next to the generated
  install/uninstall commands that adds -k and API_INSECURE=true for
  you, so the outer one-liner (which install.sh's own logic can't
  touch) also skips verification.

Off by default — only for a trusted LAN.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
bobbanandClaude Sonnet 5 committed 2026-09-15 18:26:19 +02:00
1 parent f5d3c25c89
commit 130212baec
3 files changed
+56 -11

No files matched your search

+10 -1
View File
@@ -5,6 +5,9 @@
#
# API_URL=https://homelab.example.lan API_TOKEN=hlm_xxx ./report-tasks.sh --dry-run
#
# Set API_INSECURE=true (also written to the env file by install.sh when
# passed there) if Homelab Manager uses a self-signed certificate.
#
set -euo pipefail
ENV_FILE="${ENV_FILE:-/etc/homelab-manager-agent.env}"
@@ -15,6 +18,7 @@ fi
API_URL="${API_URL:-}"
API_TOKEN="${API_TOKEN:-}"
API_INSECURE="${API_INSECURE:-false}"
DRY_RUN=0
[[ "${1:-}" == "--dry-run" ]] && DRY_RUN=1
@@ -23,6 +27,11 @@ if [[ -z "$API_URL" || -z "$API_TOKEN" ]]; then
exit 1
fi
CURL_INSECURE_FLAG=()
case "${API_INSECURE,,}" in
1|true|yes) CURL_INSECURE_FLAG=(-k) ;;
esac
suggest_package_install() {
local pkg="$1"
if command -v apt-get >/dev/null 2>&1; then
@@ -240,7 +249,7 @@ if [[ "$DRY_RUN" == "1" ]]; then
exit 0
fi
response=$(curl -sS -o /tmp/hlm-agent-response.json -w "%{http_code}" \
response=$(curl -sS "${CURL_INSECURE_FLAG[@]}" -o /tmp/hlm-agent-response.json -w "%{http_code}" \
-X POST "$API_URL/api/agent/report" \
-H "Authorization: Bearer $API_TOKEN" \
-H "Content-Type: application/json" \