Add unattended host recovery safeguards
This commit is contained in:
+35
-1
@@ -64,7 +64,40 @@ install_base_packages() {
|
||||
apt-get update
|
||||
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
||||
ca-certificates curl git gnupg jq openssl wireguard-tools iptables \
|
||||
iproute2 pciutils rsync unattended-upgrades
|
||||
iproute2 pciutils rsync unattended-upgrades ethtool
|
||||
}
|
||||
|
||||
setup_remote_recovery() {
|
||||
log "Remote-Recovery (Hardware-Watchdog und Wake-on-LAN) konfigurieren"
|
||||
|
||||
if [[ ${ENABLE_HARDWARE_WATCHDOG:-true} == true ]]; then
|
||||
[[ -e /dev/watchdog0 || -e /dev/watchdog ]] || \
|
||||
die "Hardware-Watchdog angefordert, aber kein Watchdog-Gerät vorhanden."
|
||||
install -d -m 0755 /etc/systemd/system.conf.d
|
||||
cat >/etc/systemd/system.conf.d/90-mike-ai-watchdog.conf <<'EOF'
|
||||
[Manager]
|
||||
# PID 1 feeds the hardware watchdog. If the kernel or userspace freezes long
|
||||
# enough that it cannot be fed, the firmware resets the machine.
|
||||
RuntimeWatchdogSec=60s
|
||||
RebootWatchdogSec=10min
|
||||
KExecWatchdogSec=10min
|
||||
EOF
|
||||
systemctl daemon-reexec
|
||||
fi
|
||||
|
||||
if [[ -n ${WAKE_ON_LAN_INTERFACE:-} ]]; then
|
||||
ip link show "$WAKE_ON_LAN_INTERFACE" >/dev/null 2>&1 || \
|
||||
die "Wake-on-LAN-Interface existiert nicht: $WAKE_ON_LAN_INTERFACE"
|
||||
ethtool "$WAKE_ON_LAN_INTERFACE" | grep -q 'Supports Wake-on:.*g' || \
|
||||
die "Das Interface unterstützt kein Wake-on-LAN per Magic Packet."
|
||||
cat >/etc/network/if-up.d/mike-ai-wol <<EOF
|
||||
#!/bin/sh
|
||||
[ "\${IFACE:-}" = "$WAKE_ON_LAN_INTERFACE" ] || exit 0
|
||||
/usr/sbin/ethtool -s "$WAKE_ON_LAN_INTERFACE" wol g
|
||||
EOF
|
||||
chmod 0755 /etc/network/if-up.d/mike-ai-wol
|
||||
ethtool -s "$WAKE_ON_LAN_INTERFACE" wol g
|
||||
fi
|
||||
}
|
||||
|
||||
install_docker() {
|
||||
@@ -393,6 +426,7 @@ PY
|
||||
|
||||
hostnamectl set-hostname "$AI_HOSTNAME"
|
||||
install_base_packages
|
||||
setup_remote_recovery
|
||||
install_docker
|
||||
install_nvidia
|
||||
setup_wireguard
|
||||
|
||||
Reference in New Issue
Block a user