Expand description
isb server add: make a fresh Linux box an isb agent over SSH.
The SSH key is used for this and nothing after: it installs incus (from
Zabbly’s stable channel, as isb machine does in its VM), the isb binary
(checksum checked on both ends), runs isb host setup, writes the
agent’s TLS material and a systemd unit for isb serve --agent, and
optionally closes the box’s firewall to everything but SSH and the agent
port from the control plane. From then on the control plane speaks only
mTLS to the agent.
Structs§
- AddOptions
- What
isb server addwas given. - Ssh
- Runs commands on the box over SSH with exactly the given key: no agent, no user ssh config, a known_hosts file of its own.
Constants§
- AGENT_
HOME - AGENT_
TLS_ DIR - AGENT_
UNIT - AGENT_
USER - Where things go on the box.
- DEFAULT_
AGENT_ PORT
Functions§
- check_
address - What the control plane dials: a host name or an address.
- check_
cidr - A CIDR or address for
ufw allow from. - elf_
arch x86_64oraarch64from an ELF header, if it is a Linux executable.- own_
binary - This process’s own executable, when it is a Linux build for
arch. - render_
script - The root script: everything idempotent, so a second
server add(or a rerun after a failure) converges.ssh_portstays open in the firewall; a dedicated VM, bootstrapped through incus, has none. - render_
unit - The agent’s unit.
- run
- Run the bootstrap, reporting each step to
p. - sha256_
hex - ssh_
host - The host part of
user@host. - validate_
name - Server names:
[a-z0-9-], a letter first, at most 40 (sovm-and the longest org name fit).