- Add `felis setup` TUI for initial Owner provisioning and optional Cloudflare edge - Refactor breakGlass to share console TUI model (runConsoleTUI) with setup mode - Session auth respects configured [auth].admin_hostname; fallback to op.console.<root> - Protect linked Yggdrasil admins from Mojang-priority reclaim (spec §B3) - cfsetup: idempotent Access app/policy creation, better 401/403 errors, GET + lookup - Bootstrap: auto-install cloudflared, symlink /etc/felis/felis.toml - Add sequence diagrams for ping-to-join, claim, and link flows
116 lines
3.7 KiB
Go
116 lines
3.7 KiB
Go
package main
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"flag"
|
|
"fmt"
|
|
"io"
|
|
"os"
|
|
"strings"
|
|
|
|
"felis.lolicon.best/internal/api"
|
|
"felis.lolicon.best/internal/config"
|
|
"felis.lolicon.best/internal/store"
|
|
)
|
|
|
|
// cmdSetup is the normal first-run operator console. It is intentionally separate
|
|
// from breakGlass: setup creates the initial Owner and optional web edge; breakGlass
|
|
// is reserved for emergency local recovery/reset.
|
|
func cmdSetup(args []string, stdout, stderr io.Writer) int {
|
|
fs := flag.NewFlagSet("setup", flag.ContinueOnError)
|
|
fs.SetOutput(stderr)
|
|
cfgPath := fs.String("config", "/etc/felis/felis.toml", "path to felis.toml")
|
|
if err := fs.Parse(args); err != nil {
|
|
if errors.Is(err, flag.ErrHelp) {
|
|
return 0
|
|
}
|
|
return 2
|
|
}
|
|
|
|
if os.Geteuid() != 0 {
|
|
fmt.Fprintln(stderr, "felis setup: refused — the setup console must run as root (try: sudo felis setup)")
|
|
return 1
|
|
}
|
|
|
|
cfg, err := config.Load(*cfgPath)
|
|
if err != nil {
|
|
fmt.Fprintf(stderr, "felis setup: %v\n", err)
|
|
return 1
|
|
}
|
|
|
|
ctx := context.Background()
|
|
drv, err := store.Open(ctx, cfg.Database.URL)
|
|
if err != nil {
|
|
fmt.Fprintf(stderr, "felis setup: open database: %v\n", err)
|
|
return 1
|
|
}
|
|
defer drv.Close()
|
|
|
|
repo := api.NewPGRepo(drv.DB())
|
|
adminExists, err := repo.AdminExists(ctx)
|
|
if err != nil {
|
|
fmt.Fprintf(stderr, "felis setup: detect existing admin: %v\n", err)
|
|
return 1
|
|
}
|
|
|
|
res, err := runSetupTUI(ctx, repo, cfg.Server.RootDomain, cfg.Auth.AdminHostname, cfg.Auth.PanelHostname, accountableOSUser(), adminExists)
|
|
if err != nil {
|
|
fmt.Fprintf(stderr, "felis setup: %v\n", err)
|
|
return 1
|
|
}
|
|
|
|
if !res.provisioned && !res.edgeConfigured {
|
|
fmt.Fprintln(stdout, "felis setup: cancelled — no changes made.")
|
|
return 0
|
|
}
|
|
|
|
if res.provisioned {
|
|
fmt.Fprintf(stdout, "\nfelis setup: Owner account %q provisioned; local-password login is ENABLED.\n", res.username)
|
|
fmt.Fprintf(stdout, "Recorded as %q (mode: %s, os user: %s).\n", res.accountable, res.mode, res.osUser)
|
|
if res.displayPassword != "" {
|
|
fmt.Fprintf(stdout, "One-time password (you MUST change it on first login):\n\n %s\n\n", res.displayPassword)
|
|
} else {
|
|
fmt.Fprintln(stdout, "Log in with the password you just entered (you MUST change it on first login).")
|
|
}
|
|
if res.auditWarning != "" {
|
|
fmt.Fprintf(stdout, "WARNING: the accountability audit row was NOT written: %s\n", res.auditWarning)
|
|
}
|
|
if url := adminLoginURL(res.rootDomain, res.adminHostname); url != "" {
|
|
fmt.Fprintf(stdout, "Log in at %s with that username and password.\n", url)
|
|
}
|
|
}
|
|
|
|
if res.edgeConfigured {
|
|
fmt.Fprintf(stdout, "\nfelis setup: Cloudflare Tunnel + Access edge configured.\n")
|
|
if len(res.edgeRoutedHosts) > 0 {
|
|
fmt.Fprintf(stdout, "Routed web hostnames: %s\n", strings.Join(res.edgeRoutedHosts, ", "))
|
|
}
|
|
if res.edgeConfigPath != "" {
|
|
fmt.Fprintf(stdout, "Wrote tunnel config: %s\n", res.edgeConfigPath)
|
|
}
|
|
fmt.Fprintf(stdout, "\nACTION REQUIRED — make felis-api trust the edge:\n")
|
|
fmt.Fprintf(stdout, " in %s under [auth], set:\n", *cfgPath)
|
|
if res.edgePanelHostname != "" {
|
|
fmt.Fprintf(stdout, " panel_hostname = %q\n", res.edgePanelHostname)
|
|
}
|
|
if res.edgeAdminHostname != "" {
|
|
fmt.Fprintf(stdout, " admin_hostname = %q\n", res.edgeAdminHostname)
|
|
}
|
|
fmt.Fprintf(stdout, " access_jwt_aud = %q\n", res.edgeAud)
|
|
fmt.Fprintln(stdout, "Then start the tunnel: cloudflared tunnel run")
|
|
fmt.Fprintln(stdout, "Verify the Access app actually guards the admin face before relying on it.")
|
|
}
|
|
return 0
|
|
}
|
|
|
|
func adminLoginURL(rootDomain, adminHostname string) string {
|
|
if h := strings.TrimSpace(adminHostname); h != "" {
|
|
return "https://" + h
|
|
}
|
|
if rootDomain != "" {
|
|
return "https://op.console." + rootDomain
|
|
}
|
|
return ""
|
|
}
|