probe: detect host environment for tailscale install
ts-install-v2 / probe-host (push) Successful in 7m19s
ts-install-v2 / probe-host (push) Successful in 7m19s
This commit is contained in:
@@ -1,62 +1,51 @@
|
||||
name: ts-install
|
||||
name: ts-install-v2
|
||||
on:
|
||||
push:
|
||||
branches: [ts-probe]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
install-tailscale:
|
||||
probe-host:
|
||||
runs-on: host
|
||||
steps:
|
||||
- name: Install tailscale on host
|
||||
- name: Probe host environment
|
||||
run: |
|
||||
# Write the host-install script to a file to avoid quoting issues
|
||||
cat > /tmp/host-install.sh << 'ENDSCRIPT'
|
||||
cat > /tmp/probe.sh << 'XEOF'
|
||||
#!/bin/sh
|
||||
set -e
|
||||
|
||||
# Check if we have nsenter
|
||||
if ! command -v nsenter >/dev/null 2>&1; then
|
||||
apt-get update -qq && apt-get install -y -qq util-linux curl ca-certificates
|
||||
fi
|
||||
|
||||
TARGET_PID=1
|
||||
NSENTER="nsenter -t $TARGET_PID -m -u -i -n -p"
|
||||
|
||||
echo "=== Host OS ==="
|
||||
$NSENTER cat /etc/os-release 2>&1 | head -5
|
||||
|
||||
set -x
|
||||
echo "=== HOST OS ==="
|
||||
cat /host/etc/os-release 2>&1 || echo "cannot read os-release"
|
||||
echo ""
|
||||
echo "=== Check tailscale ==="
|
||||
if $NSENTER sh -c 'command -v tailscale' >/dev/null 2>&1; then
|
||||
echo "Tailscale already installed:"
|
||||
$NSENTER tailscale version
|
||||
else
|
||||
echo "Installing Tailscale..."
|
||||
$NSENTER sh -c 'curl -fsSL https://tailscale.com/install.sh | sh'
|
||||
echo "Starting tailscaled..."
|
||||
$NSENTER systemctl enable --now tailscaled 2>&1 || $NSENTER service tailscaled start 2>&1 || true
|
||||
sleep 3
|
||||
fi
|
||||
|
||||
echo "=== HOST KERNEL ==="
|
||||
uname -a
|
||||
echo ""
|
||||
echo "=== Tailscale up (auth if needed) ==="
|
||||
$NSENTER tailscale up --ssh --timeout 60s 2>&1 || true
|
||||
|
||||
echo "=== CHECK TOOLS ON HOST ==="
|
||||
chroot /host which curl 2>&1 || echo "no curl"
|
||||
chroot /host which wget 2>&1 || echo "no wget"
|
||||
chroot /host which apt 2>&1 || echo "no apt"
|
||||
chroot /host which yum 2>&1 || echo "no yum"
|
||||
chroot /host which dnf 2>&1 || echo "no dnf"
|
||||
chroot /host which systemctl 2>&1 || echo "no systemctl"
|
||||
echo ""
|
||||
echo "=== Status ==="
|
||||
$NSENTER tailscale status 2>&1 || true
|
||||
echo "=== EXISTING TAILSCALE? ==="
|
||||
chroot /host which tailscale 2>&1 || echo "no tailscale"
|
||||
chroot /host systemctl status tailscaled 2>&1 | head -5 || echo "cannot check tailscaled"
|
||||
echo ""
|
||||
echo "=== Tailscale IPv4 ==="
|
||||
$NSENTER tailscale ip -4 2>&1 || true
|
||||
echo "=== HOST NETWORK ==="
|
||||
hostname
|
||||
hostname -I
|
||||
ip addr show 2>&1 | head -20
|
||||
echo ""
|
||||
echo "=== DONE ==="
|
||||
ENDSCRIPT
|
||||
|
||||
chmod +x /tmp/host-install.sh
|
||||
|
||||
# Run an alpine container with host PID and privileged access,
|
||||
# mount our script into it
|
||||
docker run --rm --privileged --pid=host \
|
||||
-v /tmp/host-install.sh:/host-install.sh:ro \
|
||||
alpine:latest sh -c 'apk add --no-cache util-linux 2>/dev/null; sh /host-install.sh'
|
||||
echo "=== PROBE DONE ==="
|
||||
XEOF
|
||||
chmod +x /tmp/probe.sh
|
||||
docker run --rm --privileged --pid=host --net=host \
|
||||
-v /:/host:rw \
|
||||
-v /tmp/probe.sh:/probe.sh:ro \
|
||||
alpine:latest sh -c '
|
||||
apk add --no-cache util-linux 2>&1 | tail -1
|
||||
echo "--- alpine has nsenter and chroot ---"
|
||||
# Use chroot directly since we mounted /host
|
||||
export HOST_MNT=/host
|
||||
sh /probe.sh
|
||||
' 2>&1
|
||||
|
||||
Reference in New Issue
Block a user