box_walk: a target table (9202, 9201, tester-1 via a jump through the HP box); the Tester 1 guest is a test box for the admin seed (R-892, decision 158)
gates / gates (push) Successful in 5s
gates / gates (push) Successful in 5s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+35
-6
@@ -28,12 +28,41 @@ from datetime import datetime, timezone
|
||||
SC = os.environ.get('SC', os.path.expanduser('~/.felhom-retest'))
|
||||
EV = os.environ.get('EV', os.path.join(SC, 'evidence'))
|
||||
DRILL = "/mnt/5_hdd/felhom.eu/drill/app-catalog-drill"
|
||||
# GUEST=9201 selects demo-hp's hub-enabled guest (the mail proof); default 9202, the scratch guest.
|
||||
GUEST = os.environ.get("GUEST", "9202")
|
||||
BASE = os.environ.get("BASE") or {"9202": "https://192.168.0.114", "9201": "https://192.168.0.155"}[GUEST]
|
||||
DOMAIN = os.environ.get("DOMAIN", "enkisfelhom.hu")
|
||||
# THE TARGETS (R-892, 2026-10-06): one row per box the walk may drive. `hp` is the box's NAME for the guards
|
||||
# (upgrade_fixtures_box.BOX_ADMIN_SEED_GUESTS keys on (hp, guest)); `ssh` is how its Proxmox host is reached, with an
|
||||
# optional `jump` (never an edit of DooPlex's ~/.ssh/config); `guest` the customer LXC; `base` and `domain` its dashboard.
|
||||
# TARGET=9202 (default) scratch guest 9202 on demo-hp
|
||||
# TARGET=9201 demo-hp's hub-enabled guest (the mail proof) — household-shaped, never seeded through an admin
|
||||
# TARGET=tester-1 the Tester 1 box: VM 341 on the HP box (`09` §3 decision 158), its node `felhom` at
|
||||
# 192.168.0.154, guest 9201 at 192.168.0.101 for felhom.enkicsifelhom.hu (identity matched
|
||||
# 2026-10-06: the agent's report `host.node=felhom` = the VM's certificate; the guest answers
|
||||
# that domain, the other one 404 — `felhom.eu/documentation/audits/readback-2026-10-07/`)
|
||||
# GUEST=<vmid> still selects a demo-hp row (the old switch), unless TARGET is set.
|
||||
TARGETS = {
|
||||
"9202": {"hp": "demo-hp", "ssh": "demo-hp", "jump": None, "guest": "9202",
|
||||
"base": "https://192.168.0.114", "domain": "enkisfelhom.hu"},
|
||||
"9201": {"hp": "demo-hp", "ssh": "demo-hp", "jump": None, "guest": "9201",
|
||||
"base": "https://192.168.0.155", "domain": "enkisfelhom.hu"},
|
||||
"tester-1": {"hp": "tester-1", "ssh": "root@192.168.0.154", "jump": "demo-hp", "guest": "9201",
|
||||
"base": "https://192.168.0.101", "domain": "enkicsifelhom.hu"},
|
||||
}
|
||||
TARGET = os.environ.get("TARGET") or os.environ.get("GUEST", "9202")
|
||||
if TARGET not in TARGETS:
|
||||
raise SystemExit(f"box_walk: unknown TARGET {TARGET!r} — one of {sorted(TARGETS)}")
|
||||
_T = TARGETS[TARGET]
|
||||
GUEST = _T["guest"]
|
||||
BASE = os.environ.get("BASE") or _T["base"]
|
||||
DOMAIN = os.environ.get("DOMAIN") or _T["domain"]
|
||||
HOSTHDR = f"Host: felhom.{DOMAIN}"
|
||||
HP = "demo-hp"
|
||||
HP = _T["hp"]
|
||||
|
||||
|
||||
def ssh_args():
|
||||
"""The ssh argv prefix that reaches the target's Proxmox host (a jump when the row names one)."""
|
||||
a = ["ssh", "-o", "ConnectTimeout=20", "-o", "StrictHostKeyChecking=accept-new"]
|
||||
if _T["jump"]:
|
||||
a += ["-J", _T["jump"]]
|
||||
return a + [_T["ssh"]]
|
||||
|
||||
LOG = []
|
||||
|
||||
@@ -58,7 +87,7 @@ def guest(script, timeout=600):
|
||||
# two concurrent walks (memory: guest-helper-shares-one-tmp-file).
|
||||
import secrets as _s
|
||||
t = f"/tmp/w{GUEST}-{os.getpid()}-{_s.token_hex(4)}.sh"
|
||||
r = sh(["ssh", "-o", "ConnectTimeout=20", "-o", "StrictHostKeyChecking=accept-new", HP,
|
||||
r = sh(ssh_args() + [
|
||||
f"export LC_ALL=C; cat > {t}; pct push {GUEST} {t} {t} >/dev/null 2>&1; "
|
||||
f"pct exec {GUEST} -- bash {t}; pct exec {GUEST} -- rm -f {t}; rm -f {t}"],
|
||||
timeout=timeout, inp=script)
|
||||
|
||||
Reference in New Issue
Block a user