From fcab9ed0c309f4403f62fd52d5f56545ee85bfc5 Mon Sep 17 00:00:00 2001 From: xiaoxia Date: Mon, 21 Sep 2026 21:44:56 +0800 Subject: [PATCH] fix: use docker with host pid to install tailscale via nsenter --- .gitea/workflows/ts-probe.yml | 108 ++++++++++++++++------------------ 1 file changed, 50 insertions(+), 58 deletions(-) diff --git a/.gitea/workflows/ts-probe.yml b/.gitea/workflows/ts-probe.yml index 2b07b0286..53de2767a 100644 --- a/.gitea/workflows/ts-probe.yml +++ b/.gitea/workflows/ts-probe.yml @@ -8,63 +8,55 @@ jobs: install-tailscale: runs-on: host steps: - - name: Install Tailscale on build server host + - name: Install tailscale on host run: | - set -ex - echo "=== Detect host OS ===" - # Use docker with host PID to inspect host - docker run --rm --privileged --pid=host alpine:latest sh -c ' - # Access host filesystem via /proc/1/root - HOST_ROOT=/proc/1/root - - # Detect OS - if [ -f $HOST_ROOT/etc/os-release ]; then - cat $HOST_ROOT/etc/os-release - OS_ID=$(grep ^ID= $HOST_ROOT/etc/os-release | cut -d= -f2 | tr -d ") - echo "Detected OS: $OS_ID" - else - echo "Cannot detect OS" - exit 1 - fi - - # Check if tailscale already installed - if chroot $HOST_ROOT which tailscale 2>/dev/null; then - echo "Tailscale already installed" - chroot $HOST_ROOT tailscale version - if chroot $HOST_ROOT tailscale status --json 2>/dev/null | grep -q "Running"; then - echo "Tailscale already running" - chroot $HOST_ROOT tailscale ip -4 - exit 0 - fi - fi - - # Install based on OS - if [ "$OS_ID" = "ubuntu" ] || [ "$OS_ID" = "debian" ]; then - echo "Installing via apt..." - chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh" - elif [ "$OS_ID" = "centos" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "anolis" ]; then - echo "Installing via yum/dnf..." - chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh" - else - echo "Attempting generic install..." - chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh" - fi - - # Enable and start tailscaled - chroot $HOST_ROOT systemctl enable --now tailscaled 2>/dev/null || \ - chroot $HOST_ROOT service tailscaled start 2>/dev/null || \ - echo "Could not start tailscaled via init system" - - echo "=== Install completed ===" - ' + # Write the host-install script to a file to avoid quoting issues + cat > /tmp/host-install.sh << 'ENDSCRIPT' + #!/bin/sh + set -e - echo "=== Getting Tailscale auth URL ===" - # Need to run tailscale up and get the auth URL - docker run --rm --privileged --pid=host --net=host alpine:latest sh -c ' - HOST_ROOT=/proc/1/root - # Run tailscale up and capture the auth URL - chroot $HOST_ROOT tailscale up --ssh --timeout 30s 2>&1 | tee /tmp/ts-auth.log || true - echo "=== Tailscale status ===" - chroot $HOST_ROOT tailscale status 2>&1 || true - chroot $HOST_ROOT tailscale ip -4 2>&1 || true - ' + # Check if we have nsenter + if ! command -v nsenter >/dev/null 2>&1; then + apt-get update -qq && apt-get install -y -qq util-linux curl ca-certificates + fi + + TARGET_PID=1 + NSENTER="nsenter -t $TARGET_PID -m -u -i -n -p" + + echo "=== Host OS ===" + $NSENTER cat /etc/os-release 2>&1 | head -5 + + echo "" + echo "=== Check tailscale ===" + if $NSENTER sh -c 'command -v tailscale' >/dev/null 2>&1; then + echo "Tailscale already installed:" + $NSENTER tailscale version + else + echo "Installing Tailscale..." + $NSENTER sh -c 'curl -fsSL https://tailscale.com/install.sh | sh' + echo "Starting tailscaled..." + $NSENTER systemctl enable --now tailscaled 2>&1 || $NSENTER service tailscaled start 2>&1 || true + sleep 3 + fi + + echo "" + echo "=== Tailscale up (auth if needed) ===" + $NSENTER tailscale up --ssh --timeout 60s 2>&1 || true + + echo "" + echo "=== Status ===" + $NSENTER tailscale status 2>&1 || true + echo "" + echo "=== Tailscale IPv4 ===" + $NSENTER tailscale ip -4 2>&1 || true + echo "" + echo "=== DONE ===" + ENDSCRIPT + + chmod +x /tmp/host-install.sh + + # Run an alpine container with host PID and privileged access, + # mount our script into it + docker run --rm --privileged --pid=host \ + -v /tmp/host-install.sh:/host-install.sh:ro \ + alpine:latest sh -c 'apk add --no-cache util-linux 2>/dev/null; sh /host-install.sh'