mirror of
https://github.com/myronblair/jarvis
synced 2026-07-28 08:43:00 -05:00
Rotate agent registration key; remove key literals from public scripts/UI
- install.sh, install-agent.sh: require JARVIS_REG_KEY env var or interactive prompt instead of baked-in key (matches install-mac.sh/install-windows.ps1 behavior) - netscan.php: reuse AGENT_REGISTRATION_KEY constant instead of a duplicate literal - agent.php + api.php: add session-authed "regkey" action so the admin install modal fetches the current key at runtime - jarvis-agents.js: fetch reg key via /api/agent/regkey instead of hardcoding it; pass JARVIS_REG_KEY in the Linux install one-liner - INFRASTRUCTURE-REFERENCE.md: scrub old key literal (rotated; real value lives only in api/config.php on VM211) Key rotated on the box + rolled out to all 11 agents (verified all re-register online). New value is in the gitignored api/config.php only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -54,7 +54,7 @@ function update_agent_seen(string $agentId, string $status = 'online', ?string $
|
|||||||
// ── Auth (all actions except register) ───────────────────────────────────────
|
// ── Auth (all actions except register) ───────────────────────────────────────
|
||||||
|
|
||||||
$agentKey = $_SERVER['HTTP_X_AGENT_KEY'] ?? '';
|
$agentKey = $_SERVER['HTTP_X_AGENT_KEY'] ?? '';
|
||||||
$browserActions = ['list', 'status', 'myip'];
|
$browserActions = ['list', 'status', 'myip', 'regkey'];
|
||||||
|
|
||||||
if ($agentAction !== 'register') {
|
if ($agentAction !== 'register') {
|
||||||
if (in_array($agentAction, $browserActions)) {
|
if (in_array($agentAction, $browserActions)) {
|
||||||
@@ -212,6 +212,10 @@ switch ($agentAction) {
|
|||||||
);
|
);
|
||||||
agent_ok();
|
agent_ok();
|
||||||
|
|
||||||
|
// ── REGKEY (browser: session-authed fetch of registration key) ───────────
|
||||||
|
case 'regkey':
|
||||||
|
agent_ok(['registration_key' => AGENT_REGISTRATION_KEY]);
|
||||||
|
|
||||||
// ── LIST (admin: get all agents status) ──────────────────────────────────
|
// ── LIST (admin: get all agents status) ──────────────────────────────────
|
||||||
case 'list':
|
case 'list':
|
||||||
// Mark agents offline if last_seen > 2 minutes ago
|
// Mark agents offline if last_seen > 2 minutes ago
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
// Network scan push endpoint — called by PVE1 cron with nmap results
|
// Network scan push endpoint — called by PVE1 cron with nmap results
|
||||||
// Authenticates via X-Registration-Key header (same key as agent installer)
|
// Authenticates via X-Registration-Key header (same key as agent installer)
|
||||||
|
|
||||||
define('NETSCAN_KEY', 'f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518');
|
define('NETSCAN_KEY', AGENT_REGISTRATION_KEY);
|
||||||
|
|
||||||
if ($method !== 'POST') {
|
if ($method !== 'POST') {
|
||||||
echo json_encode(['error' => 'POST only']); exit;
|
echo json_encode(['error' => 'POST only']); exit;
|
||||||
|
|||||||
@@ -663,7 +663,7 @@ Webhook secret: `4c8805f0285214ff0a0602b5880270b935f36a896946c7f1`
|
|||||||
|
|
||||||
### Agent System
|
### Agent System
|
||||||
Agents installed on all servers — phone home every 10s (heartbeat) / 30s (metrics).
|
Agents installed on all servers — phone home every 10s (heartbeat) / 30s (metrics).
|
||||||
Registration key: `f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518`
|
Registration key: `[rotated 2026-07-07 — stored in api/config.php on VM211, not documented here]`
|
||||||
Install command: `curl -sk http://10.48.200.211/install-agent.sh | bash -s <hostname> <linux|proxmox>`
|
Install command: `curl -sk http://10.48.200.211/install-agent.sh | bash -s <hostname> <linux|proxmox>`
|
||||||
|
|
||||||
### Self-Healing Watchdog
|
### Self-Healing Watchdog
|
||||||
@@ -918,7 +918,7 @@ sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 \
|
|||||||
| Service | Key |
|
| Service | Key |
|
||||||
|---------|-----|
|
|---------|-----|
|
||||||
| GitHub PAT | `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` (rotated 2026-07-05, scopes `repo`+`workflow`) |
|
| GitHub PAT | `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` (rotated 2026-07-05, scopes `repo`+`workflow`) |
|
||||||
| JARVIS Agent Registration | `f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518` |
|
| JARVIS Agent Registration | `[rotated 2026-07-07 — stored in api/config.php on VM211, not documented here]` |
|
||||||
| Proxmox API Token | `root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b` |
|
| Proxmox API Token | `root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b` |
|
||||||
| HA Long-lived Token | `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiIzNmI0N2I1Njk5ZGQ0MTQ2ODMwZWFmYjZiYTQ1MjJkMSIsImlhdCI6MTc4MDIwMzU5NCwiZXhwIjoyMDk1NTYzNTk0fQ.sYRok-jRDlA4lFgWxLQELcEjkJNGQdprk6ZziLwLtXE` |
|
| HA Long-lived Token | `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiIzNmI0N2I1Njk5ZGQ0MTQ2ODMwZWFmYjZiYTQ1MjJkMSIsImlhdCI6MTc4MDIwMzU5NCwiZXhwIjoyMDk1NTYzNTk0fQ.sYRok-jRDlA4lFgWxLQELcEjkJNGQdprk6ZziLwLtXE` |
|
||||||
| Sonarr API | `b43e04350a594846b4ee95261c29e9e0` |
|
| Sonarr API | `b43e04350a594846b4ee95261c29e9e0` |
|
||||||
|
|||||||
@@ -21,7 +21,14 @@ JARVIS_HOST=""
|
|||||||
INSTALL_DIR="/opt/jarvis-agent"
|
INSTALL_DIR="/opt/jarvis-agent"
|
||||||
CONFIG_DIR="/etc/jarvis-agent"
|
CONFIG_DIR="/etc/jarvis-agent"
|
||||||
STATE_DIR="/var/lib/jarvis-agent"
|
STATE_DIR="/var/lib/jarvis-agent"
|
||||||
REG_KEY="f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518"
|
REG_KEY="${JARVIS_REG_KEY:-}"
|
||||||
|
if [ -z "$REG_KEY" ] && [ -r /dev/tty ]; then
|
||||||
|
read -rp "Enter JARVIS registration key: " REG_KEY </dev/tty
|
||||||
|
fi
|
||||||
|
if [ -z "$REG_KEY" ]; then
|
||||||
|
echo "ERROR: registration key required (set JARVIS_REG_KEY env var or enter at prompt)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
|
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
|
||||||
|
|
||||||
echo "=== JARVIS Agent Installer v3.0 ==="
|
echo "=== JARVIS Agent Installer v3.0 ==="
|
||||||
|
|||||||
+1
-1
@@ -19,7 +19,7 @@ $_e1 = $_earlyParts[1] ?? '';
|
|||||||
$_skipSession = match(true) {
|
$_skipSession = match(true) {
|
||||||
$_e0 === 'ping' => true,
|
$_e0 === 'ping' => true,
|
||||||
$_e0 === 'netscan' => true,
|
$_e0 === 'netscan' => true,
|
||||||
$_e0 === 'agent' && !in_array($_e1, ['list','status','myip'], true) => true,
|
$_e0 === 'agent' && !in_array($_e1, ['list','status','myip','regkey'], true) => true,
|
||||||
default => false,
|
default => false,
|
||||||
};
|
};
|
||||||
if (!$_skipSession) {
|
if (!$_skipSession) {
|
||||||
|
|||||||
@@ -432,12 +432,16 @@ function renderAgentsTab(agents, metrics) {
|
|||||||
}).join('');
|
}).join('');
|
||||||
}
|
}
|
||||||
|
|
||||||
function openAgentModal() {
|
async function openAgentModal() {
|
||||||
const os = detectOS();
|
const os = detectOS();
|
||||||
const title = document.getElementById('agentModalTitle');
|
const title = document.getElementById('agentModalTitle');
|
||||||
const content = document.getElementById('agentModalContent');
|
const content = document.getElementById('agentModalContent');
|
||||||
const modal = document.getElementById('agentModal');
|
const modal = document.getElementById('agentModal');
|
||||||
const regKey = 'f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518';
|
let regKey = '<YOUR-REGISTRATION-KEY>';
|
||||||
|
try {
|
||||||
|
const rkResp = await fetch('/api/agent/regkey');
|
||||||
|
if (rkResp.ok) { const rk = await rkResp.json(); if (rk.registration_key) regKey = rk.registration_key; }
|
||||||
|
} catch (e) { /* not logged in — placeholder stays */ }
|
||||||
const jUrl = window.location.origin;
|
const jUrl = window.location.origin;
|
||||||
// Fixed 2026-07-07: this used to be hardcoded to https://jarvis.orbishosting.com/agent,
|
// Fixed 2026-07-07: this used to be hardcoded to https://jarvis.orbishosting.com/agent,
|
||||||
// which isn't reachable from outside the LAN at all (no FortiGate VIP forwards the
|
// which isn't reachable from outside the LAN at all (no FortiGate VIP forwards the
|
||||||
@@ -480,10 +484,9 @@ function openAgentModal() {
|
|||||||
},
|
},
|
||||||
linux: {
|
linux: {
|
||||||
label:'Linux',
|
label:'Linux',
|
||||||
// install.sh takes positional args (hostname, agent_type) and reads the
|
// install.sh takes positional args (hostname, agent_type); JARVIS URL and
|
||||||
// JARVIS URL from an env var — the registration key is already baked in,
|
// registration key come from env vars (key is no longer baked into the script).
|
||||||
// no --key flag exists.
|
cmd:'curl -sSL '+baseUrl+'/install.sh | JARVIS_URL='+jUrl+' JARVIS_REG_KEY=\''+regKey+'\' bash -s -- $(hostname) linux',
|
||||||
cmd:'curl -sSL '+baseUrl+'/install.sh | JARVIS_URL='+jUrl+' bash -s -- $(hostname) linux',
|
|
||||||
dl: baseUrl+'/install.sh',
|
dl: baseUrl+'/install.sh',
|
||||||
note:'Run in terminal (sudo). Installs as a systemd service.'
|
note:'Run in terminal (sudo). Installs as a systemd service.'
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -21,7 +21,14 @@ JARVIS_HOST=""
|
|||||||
INSTALL_DIR="/opt/jarvis-agent"
|
INSTALL_DIR="/opt/jarvis-agent"
|
||||||
CONFIG_DIR="/etc/jarvis-agent"
|
CONFIG_DIR="/etc/jarvis-agent"
|
||||||
STATE_DIR="/var/lib/jarvis-agent"
|
STATE_DIR="/var/lib/jarvis-agent"
|
||||||
REG_KEY="f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518"
|
REG_KEY="${JARVIS_REG_KEY:-}"
|
||||||
|
if [ -z "$REG_KEY" ] && [ -r /dev/tty ]; then
|
||||||
|
read -rp "Enter JARVIS registration key: " REG_KEY </dev/tty
|
||||||
|
fi
|
||||||
|
if [ -z "$REG_KEY" ]; then
|
||||||
|
echo "ERROR: registration key required (set JARVIS_REG_KEY env var or enter at prompt)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
|
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
|
||||||
|
|
||||||
echo "=== JARVIS Agent Installer v3.0 ==="
|
echo "=== JARVIS Agent Installer v3.0 ==="
|
||||||
|
|||||||
Reference in New Issue
Block a user