Add isolated Debian installer with credential setup and guarded updates
This commit is contained in:
@@ -15,6 +15,7 @@ SSH = ['ssh', '-i', str(Path.home()/'.ssh/athena_key'), '-o', 'BatchMode=yes', '
|
||||
|
||||
class NetworkClient:
|
||||
def __init__(self):
|
||||
self.disabled = os.environ.get('DECK_NETWORK_MODE') == 'disabled'
|
||||
self.local = os.environ.get('DECK_NETWORK_SOCKET') == '1'
|
||||
self.job = None
|
||||
self.lock = threading.Lock()
|
||||
@@ -22,6 +23,8 @@ class NetworkClient:
|
||||
self.cached_at = 0
|
||||
|
||||
def call(self, action, values=None, ingress='management'):
|
||||
if self.disabled:
|
||||
raise ValueError('WireGuard ist in dieser eigenständigen Installation nicht angebunden.')
|
||||
data = dict(values or {}, action=action)
|
||||
if self.local:
|
||||
from network.rpc import request
|
||||
@@ -38,6 +41,8 @@ class NetworkClient:
|
||||
return value
|
||||
|
||||
def status(self, ingress='management'):
|
||||
if self.disabled:
|
||||
return dict(installed=False, install_supported=False, state='disabled-module', ingress=ingress, error='Eigenständige Installation ohne WireGuard-Modul. Zugriff ist per SSH-Tunnel möglich. Vorhandene Gateways werden nicht verändert.')
|
||||
with self.lock:
|
||||
if self.job and self.job['state'] == 'running':
|
||||
return dict(installed=False, state='installing', job=self.job.copy(), ingress=ingress)
|
||||
@@ -53,6 +58,8 @@ class NetworkClient:
|
||||
return dict(result, ingress=ingress, job=self.job)
|
||||
|
||||
def install(self, password, api_token=None):
|
||||
if self.disabled:
|
||||
raise ValueError('WireGuard-Installation ist für diese eigenständige Instanz deaktiviert.')
|
||||
if self.local:
|
||||
raise ValueError('Die Server-Instanz ist bereits installiert.')
|
||||
if not isinstance(password, str) or not 16 <= len(password) <= 256:
|
||||
|
||||
Reference in New Issue
Block a user