X-Git-Url: https://git.cyclocoop.org/?p=lhc%2Fateliers.git;a=blobdiff_plain;f=vm_remote;h=f951f3c6e0d9ee631a277e5794b122250644383a;hp=65536b357cdb3232180442f3269b241149c2c365;hb=5b3f6649997abf4786ec2b1292abf712d4358567;hpb=fdea46138aab165fff4ba27888c354c87190de9a diff --git a/vm_remote b/vm_remote index 65536b3..f951f3c 100755 --- a/vm_remote +++ b/vm_remote @@ -1,74 +1,85 @@ #!/bin/sh set -e -f ${DRY_RUN:+-n} -u tool=${0%/*} -. "$tool"/lib/functions.sh +. "$tool"/lib/rule.sh . "$tool"/etc/vm.sh -rule_help () { +rule_help () { # SYNTAX: [--hidden] + local hidden; [ ${1:+set} ] || hidden=set cat >&2 <<-EOF - DESCRIPTION: ce script regroupe des fonctions utilitaires - pour gérer la VM _depuis_ une machine distante ; - il sert à la fois d'outil et de documentation. - Voir \`$tool/vm_host' pour les utilitaires côté machine hôte. - Voir \`$tool/vm_hosted' pour les utilitaires côté VM hébergée. + DESCRIPTION: + ce script regroupe des règles pour administrer la VM ($vm_fqdn) + _depuis_ une machine distante ; + il sert à la fois d'outil (aisément bidouillable) + et de documentation (préçise). + Voir \`$tool/vm_host' pour les règles côté machine hôte ($vm_host). + Voir \`$tool/vm_hosted' pour les règles côté VM hébergée ($vm_fqdn). SYNTAX: $0 \$RULE \${RULE}_SYNTAX RULES: - $(sed -ne 's/^rule_\([^_][^ ]*\) () {\( *#.*\|\)/\t\1\2/p' "$tool"/vm.sh "$0") + $(sed -ne "s/^rule_\(${hidden:+[^_]}[^ ]*\) () {\( *#.*\|\)/ \1\2/p" "$tool"/etc/vm.sh "$0") ENVIRONMENT: TRACE # affiche les commandes avant leur exécution - $(sed -ne 's/^readonly \([^ ][^ =]*\).*}\( *#.*\|\)$/\t$\1\2/p' "$tool"/vm.sh "$0") + $(sed -ne 's/^readonly \([^ ][^ =]*\).*}\( *#.*\|\)$/\t$\1\2/p' "$tool"/etc/vm.sh "$0") EOF } -rule_git_config () { +rule_git_configure () { # DESCRIPTION: configure ./.git correctement ( cd "$tool" - git config remote.host.url >/dev/null || + git remote rm host || true git remote add host $vm_host:tool/vm - git config --replace remote.host HEAD:refs/heads/origin - git config remote.$vm.url >/dev/null || - git remote add vm root@$vm_fqdn:tool/vm - git config --replace remote.$vm HEAD:refs/heads/origin + git config --replace remote.host.push HEAD:refs/remotes/master + git remote rm hosted || true + git remote add hosted root@$vm_fqdn:tool/vm + git config --replace remote.hosted.push HEAD:refs/remotes/master + git submodule update --init ) } -rule_git_push () { # SYNTAX: $remote $options +rule_git_push () { # SYNTAX: {host|hosted} $git_push_options + ( + cd "$tool" local remote=${1#remote=}; shift - git add . && - git commit -a -C HEAD "$@" && - GIT_SSH=./vm_ssh git push -v -f "$remote" + GIT_SSH=./lib/ssh git push -v "$remote" "$@" + info "penser à faire : vm_hosted git_reset" + ) } rule_ssh () { - "$tool"/vm_ssh $vm_fqdn "$@" + "$tool"/lib/ssh $vm_fqdn "$@" + } +rule_mosh () { + mosh --ssh="$tool/lib/ssh $*" $vm_fqdn } rule__ssh_known_hosts_update () { - "$tool"/vm_ssh $vm_fqdn "$@" \ + rule ssh \ -o StrictHostKeyChecking=no \ -o CheckHostIP=no \ -o HashKnownHosts=no \ whoami } -rule_disk_key_send () { - gpg --decrypt var/lib/luks/$vm_fqdn.key.gpg | - "$tool"/vm_ssh root@$vm_fqdn "$@" \ +rule_luks_key_send () { # NOTE: envoie la clef de déchiffrement des partitions au démarrage de la VM. + gpg --decrypt var/sec/luks/$vm_fqdn.key.gpg | + "$tool"/lib/ssh root@$vm_fqdn "$@" \ -o CheckHostIP=no \ -o HostKeyAlias=init.$vm_fqdn \ tee /lib/cryptsetup/passfifo \>/dev/null } -rule_disk_key_backup () { - for part in root swap var home +rule_luks_key_backup () { # NOTE: sauvegarde localement les entêtes des partitions chiffrées. ENVIRONMENT: $gpg_recipient + for part in root var home do - mkdir -p var/lib/luks - rule_ssh -l root ' \ - tmp=$(mktemp) - cryptsetup luksHeaderBackup \ - /dev/$vm_lvm_vg/${vm_lvm_lv}_${part} \ - --header-backup-file "$tmp" \ - cat "$tmp" - shred --remove "$tmp" + mkdir -p var/sec/luks + rule ssh -l root ' \ + set -e -f -u; + exec 2>/dev/null; + tmp=$(mktemp -t "luks.'"$part"'.XXXXXXXX.tmp" --dry-run); + cryptsetup luksHeaderBackup >/dev/null \ + /dev/'"$vm_lvm_vg"'/'"$vm_lvm_lv"'_'"$part"' \ + --header-backup-file "$tmp"; \ + cat "$tmp"; + shred >/dev/null --remove "$tmp"; \ ' | - gpg --encrypt --recipient $USER@ \ - -o var/lib/luks/${vm_lvm_lv}_${part}.luks.gpg + gpg --encrypt --recipient "${gpg_recipient:-$USER@}" \ + -o var/sec/luks/${vm_lvm_lv}_${part}.luks.gpg done } @@ -77,9 +88,8 @@ ${1+shift} case $rule in (help);; (*) - test ! "$(hostname --fqdn)" = "$vm_fqdn" - test ! "$(hostname --fqdn)" = "$vm_host" - set "${TRACE:+-x}" + assert 'test ! "$(hostname --fqdn)" = "$vm_fqdn"' vm_fqdn + assert 'test ! "$(hostname --fqdn)" = "$vm_host"' vm_host ;; esac -rule_$rule "$@" +rule $rule "$@"