fix: use docker with host pid to install tailscale via nsenter
ts-install / install-tailscale (push) Successful in 8m7s
ts-install / install-tailscale (push) Successful in 8m7s
This commit is contained in:
@@ -8,63 +8,55 @@ jobs:
|
||||
install-tailscale:
|
||||
runs-on: host
|
||||
steps:
|
||||
- name: Install Tailscale on build server host
|
||||
- name: Install tailscale on host
|
||||
run: |
|
||||
set -ex
|
||||
echo "=== Detect host OS ==="
|
||||
# Use docker with host PID to inspect host
|
||||
docker run --rm --privileged --pid=host alpine:latest sh -c '
|
||||
# Access host filesystem via /proc/1/root
|
||||
HOST_ROOT=/proc/1/root
|
||||
|
||||
# Detect OS
|
||||
if [ -f $HOST_ROOT/etc/os-release ]; then
|
||||
cat $HOST_ROOT/etc/os-release
|
||||
OS_ID=$(grep ^ID= $HOST_ROOT/etc/os-release | cut -d= -f2 | tr -d ")
|
||||
echo "Detected OS: $OS_ID"
|
||||
else
|
||||
echo "Cannot detect OS"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check if tailscale already installed
|
||||
if chroot $HOST_ROOT which tailscale 2>/dev/null; then
|
||||
echo "Tailscale already installed"
|
||||
chroot $HOST_ROOT tailscale version
|
||||
if chroot $HOST_ROOT tailscale status --json 2>/dev/null | grep -q "Running"; then
|
||||
echo "Tailscale already running"
|
||||
chroot $HOST_ROOT tailscale ip -4
|
||||
exit 0
|
||||
fi
|
||||
fi
|
||||
|
||||
# Install based on OS
|
||||
if [ "$OS_ID" = "ubuntu" ] || [ "$OS_ID" = "debian" ]; then
|
||||
echo "Installing via apt..."
|
||||
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
|
||||
elif [ "$OS_ID" = "centos" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "anolis" ]; then
|
||||
echo "Installing via yum/dnf..."
|
||||
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
|
||||
else
|
||||
echo "Attempting generic install..."
|
||||
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
|
||||
fi
|
||||
|
||||
# Enable and start tailscaled
|
||||
chroot $HOST_ROOT systemctl enable --now tailscaled 2>/dev/null || \
|
||||
chroot $HOST_ROOT service tailscaled start 2>/dev/null || \
|
||||
echo "Could not start tailscaled via init system"
|
||||
|
||||
echo "=== Install completed ==="
|
||||
'
|
||||
# Write the host-install script to a file to avoid quoting issues
|
||||
cat > /tmp/host-install.sh << 'ENDSCRIPT'
|
||||
#!/bin/sh
|
||||
set -e
|
||||
|
||||
echo "=== Getting Tailscale auth URL ==="
|
||||
# Need to run tailscale up and get the auth URL
|
||||
docker run --rm --privileged --pid=host --net=host alpine:latest sh -c '
|
||||
HOST_ROOT=/proc/1/root
|
||||
# Run tailscale up and capture the auth URL
|
||||
chroot $HOST_ROOT tailscale up --ssh --timeout 30s 2>&1 | tee /tmp/ts-auth.log || true
|
||||
echo "=== Tailscale status ==="
|
||||
chroot $HOST_ROOT tailscale status 2>&1 || true
|
||||
chroot $HOST_ROOT tailscale ip -4 2>&1 || true
|
||||
'
|
||||
# Check if we have nsenter
|
||||
if ! command -v nsenter >/dev/null 2>&1; then
|
||||
apt-get update -qq && apt-get install -y -qq util-linux curl ca-certificates
|
||||
fi
|
||||
|
||||
TARGET_PID=1
|
||||
NSENTER="nsenter -t $TARGET_PID -m -u -i -n -p"
|
||||
|
||||
echo "=== Host OS ==="
|
||||
$NSENTER cat /etc/os-release 2>&1 | head -5
|
||||
|
||||
echo ""
|
||||
echo "=== Check tailscale ==="
|
||||
if $NSENTER sh -c 'command -v tailscale' >/dev/null 2>&1; then
|
||||
echo "Tailscale already installed:"
|
||||
$NSENTER tailscale version
|
||||
else
|
||||
echo "Installing Tailscale..."
|
||||
$NSENTER sh -c 'curl -fsSL https://tailscale.com/install.sh | sh'
|
||||
echo "Starting tailscaled..."
|
||||
$NSENTER systemctl enable --now tailscaled 2>&1 || $NSENTER service tailscaled start 2>&1 || true
|
||||
sleep 3
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "=== Tailscale up (auth if needed) ==="
|
||||
$NSENTER tailscale up --ssh --timeout 60s 2>&1 || true
|
||||
|
||||
echo ""
|
||||
echo "=== Status ==="
|
||||
$NSENTER tailscale status 2>&1 || true
|
||||
echo ""
|
||||
echo "=== Tailscale IPv4 ==="
|
||||
$NSENTER tailscale ip -4 2>&1 || true
|
||||
echo ""
|
||||
echo "=== DONE ==="
|
||||
ENDSCRIPT
|
||||
|
||||
chmod +x /tmp/host-install.sh
|
||||
|
||||
# Run an alpine container with host PID and privileged access,
|
||||
# mount our script into it
|
||||
docker run --rm --privileged --pid=host \
|
||||
-v /tmp/host-install.sh:/host-install.sh:ro \
|
||||
alpine:latest sh -c 'apk add --no-cache util-linux 2>/dev/null; sh /host-install.sh'
|
||||
|
||||
Reference in New Issue
Block a user