#!/bin/sh set -e -f ${DRY_RUN:+-n} -u tool=${0%/*} . "$tool"/lib/functions.sh . "$tool"/etc/vm.sh rule_help () { cat >&2 <<-EOF DESCRIPTION: ce script regroupe des fonctions utilitaires pour gérer la VM _depuis_ une machine distante ; il sert à la fois d'outil et de documentation. Voir \`$tool/vm_host' pour les utilitaires côté machine hôte. Voir \`$tool/vm_hosted' pour les utilitaires côté VM hébergée. SYNTAX: $0 \$RULE \${RULE}_SYNTAX RULES: $(sed -ne 's/^rule_\([^_][^ ]*\) () {\( *#.*\|\)/\t\1\2/p' "$tool"/vm.sh "$0") ENVIRONMENT: TRACE # affiche les commandes avant leur exécution $(sed -ne 's/^readonly \([^ ][^ =]*\).*}\( *#.*\|\)$/\t$\1\2/p' "$tool"/vm.sh "$0") EOF } rule_git_config () { ( cd "$tool" git config remote.host.url >/dev/null || git remote add host $vm_host:tool/vm git config --replace remote.host HEAD:refs/heads/origin git config remote.$vm.url >/dev/null || git remote add vm root@$vm_fqdn:tool/vm git config --replace remote.$vm HEAD:refs/heads/origin ) } rule_git_push () { # SYNTAX: {host|vm} $git_commit_options local remote=${1#remote=}; shift git add . && git commit -a -C HEAD "$@" && GIT_SSH=./vm_ssh git push -v -f "$remote" } rule_ssh () { "$tool"/vm_ssh $vm_fqdn "$@" } rule__ssh_known_hosts_update () { "$tool"/vm_ssh $vm_fqdn "$@" \ -o StrictHostKeyChecking=no \ -o CheckHostIP=no \ -o HashKnownHosts=no \ whoami } rule_disk_key_send () { gpg --decrypt var/lib/luks/$vm_fqdn.key.gpg | "$tool"/vm_ssh root@$vm_fqdn "$@" \ -o CheckHostIP=no \ -o HostKeyAlias=init.$vm_fqdn \ tee /lib/cryptsetup/passfifo \>/dev/null } rule_disk_key_backup () { for part in root var home do mkdir -p var/lib/luks rule_ssh -l root ' \ tmp=$(mktemp) cryptsetup luksHeaderBackup \ /dev/$vm_lvm_vg/${vm_lvm_lv}_${part} \ --header-backup-file "$tmp" \ cat "$tmp" shred --remove "$tmp" ' | gpg --encrypt --recipient $USER@ \ -o var/lib/luks/${vm_lvm_lv}_${part}.luks.gpg done } rule=${1:-help} ${1+shift} case $rule in (help);; (*) test ! "$(hostname --fqdn)" = "$vm_fqdn" test ! "$(hostname --fqdn)" = "$vm_host" set -x ;; esac rule_$rule "$@"