Installing the agent against a Homelab Manager instance with a self-signed cert failed: curl verifies TLS by default on the install download, the report-tasks.sh fetch inside install.sh, and every periodic check-in — not just the outer one-liner, so passing -k to only that first curl wasn't enough. Mirrors the existing Proxmox/Synology "insecure" toggle pattern already in this app. - install.sh and report-tasks.sh accept API_INSECURE=true, adding -k to their own curl calls; install.sh persists it into the agent's env file so the periodic systemd timer picks it up too. - The Servers & Tasks page has a new checkbox next to the generated install/uninstall commands that adds -k and API_INSECURE=true for you, so the outer one-liner (which install.sh's own logic can't touch) also skips verification. Off by default — only for a trusted LAN. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
118 lines
3.9 KiB
Bash
118 lines
3.9 KiB
Bash
#!/usr/bin/env bash
|
|
# Installs the Homelab Manager task-reporting agent as a systemd timer.
|
|
#
|
|
# Usage (must run as root — if not already root, put sudo right after the
|
|
# pipe so it applies to bash, not to curl):
|
|
# curl -fsSL https://homelab.example.lan/agent/linux/install.sh | \
|
|
# sudo API_URL=https://homelab.example.lan API_TOKEN=hlm_xxx bash
|
|
#
|
|
# If Homelab Manager is served with a self-signed certificate, also pass
|
|
# API_INSECURE=true (skips TLS verification for every request this agent
|
|
# makes — only do this on a trusted LAN) AND add -k to the outer curl
|
|
# above, since that first fetch of this very script also hits the
|
|
# self-signed endpoint before any of this script's logic can run:
|
|
# curl -fsSL -k https://homelab.example.lan/agent/linux/install.sh | \
|
|
# sudo API_URL=https://homelab.example.lan API_TOKEN=hlm_xxx API_INSECURE=true bash
|
|
#
|
|
set -euo pipefail
|
|
|
|
: "${API_URL:?Set API_URL to your Homelab Manager URL, e.g. https://homelab.example.lan}"
|
|
: "${API_TOKEN:?Set API_TOKEN to the per-server token generated on the Servers & Tasks page}"
|
|
API_INSECURE="${API_INSECURE:-false}"
|
|
|
|
INSTALL_DIR="/usr/local/bin"
|
|
CONFIG_DIR="/etc"
|
|
SYSTEMD_DIR="/etc/systemd/system"
|
|
INTERVAL_MINUTES="${INTERVAL_MINUTES:-15}"
|
|
|
|
CURL_INSECURE_FLAG=()
|
|
case "${API_INSECURE,,}" in
|
|
1|true|yes) CURL_INSECURE_FLAG=(-k) ;;
|
|
esac
|
|
|
|
if [[ "$EUID" -ne 0 ]]; then
|
|
echo "This installer must be run as root (it installs a systemd timer)." >&2
|
|
echo "If you're piping from curl, put sudo right after the pipe so it elevates bash, not curl:" >&2
|
|
echo " curl -fsSL ... | sudo API_URL=... API_TOKEN=... bash" >&2
|
|
exit 1
|
|
fi
|
|
|
|
suggest_package_install() {
|
|
local pkg="$1"
|
|
if command -v apt-get >/dev/null 2>&1; then
|
|
echo " sudo apt-get update && sudo apt-get install -y $pkg"
|
|
elif command -v dnf >/dev/null 2>&1; then
|
|
echo " sudo dnf install -y $pkg"
|
|
elif command -v yum >/dev/null 2>&1; then
|
|
echo " sudo yum install -y $pkg"
|
|
elif command -v apk >/dev/null 2>&1; then
|
|
echo " sudo apk add $pkg"
|
|
elif command -v pacman >/dev/null 2>&1; then
|
|
echo " sudo pacman -S $pkg"
|
|
elif command -v zypper >/dev/null 2>&1; then
|
|
echo " sudo zypper install -y $pkg"
|
|
fi
|
|
}
|
|
|
|
for bin in curl jq; do
|
|
if ! command -v "$bin" >/dev/null 2>&1; then
|
|
echo "Required dependency '$bin' is not installed. Try:" >&2
|
|
suggest_package_install "$bin" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
if ! command -v systemctl >/dev/null 2>&1; then
|
|
echo "systemctl was not found — this installer requires a systemd-based Linux distribution." >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Installing Homelab Manager agent from $API_URL ..."
|
|
|
|
curl -fsSL "${CURL_INSECURE_FLAG[@]}" "$API_URL/agent/linux/report-tasks.sh" -o "$INSTALL_DIR/homelab-manager-agent.sh"
|
|
chmod 755 "$INSTALL_DIR/homelab-manager-agent.sh"
|
|
|
|
umask 077
|
|
cat > "$CONFIG_DIR/homelab-manager-agent.env" <<EOF
|
|
API_URL=$API_URL
|
|
API_TOKEN=$API_TOKEN
|
|
API_INSECURE=$API_INSECURE
|
|
EOF
|
|
chmod 600 "$CONFIG_DIR/homelab-manager-agent.env"
|
|
|
|
cat > "$SYSTEMD_DIR/homelab-manager-agent.service" <<EOF
|
|
[Unit]
|
|
Description=Report scheduled tasks to Homelab Manager
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
EnvironmentFile=$CONFIG_DIR/homelab-manager-agent.env
|
|
ExecStart=$INSTALL_DIR/homelab-manager-agent.sh
|
|
EOF
|
|
|
|
cat > "$SYSTEMD_DIR/homelab-manager-agent.timer" <<EOF
|
|
[Unit]
|
|
Description=Periodically report scheduled tasks to Homelab Manager
|
|
|
|
[Timer]
|
|
OnBootSec=2min
|
|
OnUnitActiveSec=${INTERVAL_MINUTES}min
|
|
Persistent=true
|
|
|
|
[Install]
|
|
WantedBy=timers.target
|
|
EOF
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now homelab-manager-agent.timer
|
|
|
|
echo "Installed. Running an initial report now..."
|
|
"$INSTALL_DIR/homelab-manager-agent.sh"
|
|
|
|
echo "Done. The agent reports every ${INTERVAL_MINUTES} minute(s) via the 'homelab-manager-agent.timer' systemd timer."
|
|
if [[ ${#CURL_INSECURE_FLAG[@]} -gt 0 ]]; then
|
|
echo "To remove it later: curl -fsSL -k $API_URL/agent/linux/uninstall.sh | sudo bash"
|
|
else
|
|
echo "To remove it later: curl -fsSL $API_URL/agent/linux/uninstall.sh | sudo bash"
|
|
fi
|