Skip to main content

Module bootstrap

Module bootstrap 

Source
Expand description

isb server add: make a fresh Linux box an isb agent over SSH.

The SSH key is used for this and nothing after: it installs incus (from Zabbly’s stable channel, as isb machine does in its VM), the isb binary (checksum checked on both ends), runs isb host setup, writes the agent’s TLS material and a systemd unit for isb serve --agent, and optionally closes the box’s firewall to everything but SSH and the agent port from the control plane. From then on the control plane speaks only mTLS to the agent.

Structs§

AddOptions
What isb server add was given.
Ssh
Runs commands on the box over SSH with exactly the given key: no agent, no user ssh config, a known_hosts file of its own.

Constants§

AGENT_HOME
AGENT_TLS_DIR
AGENT_UNIT
AGENT_USER
Where things go on the box.
DEFAULT_AGENT_PORT

Functions§

check_address
What the control plane dials: a host name or an address.
check_cidr
A CIDR or address for ufw allow from.
elf_arch
x86_64 or aarch64 from an ELF header, if it is a Linux executable.
own_binary
This process’s own executable, when it is a Linux build for arch.
render_script
The root script: everything idempotent, so a second server add (or a rerun after a failure) converges. ssh_port stays open in the firewall; a dedicated VM, bootstrapped through incus, has none.
render_unit
The agent’s unit.
run
Run the bootstrap, reporting each step to p.
sha256_hex
ssh_host
The host part of user@host.
validate_name
Server names: [a-z0-9-], a letter first, at most 40 (so vm- and the longest org name fit).