Rotate agent registration key; remove key literals from public scripts/UI

- install.sh, install-agent.sh: require JARVIS_REG_KEY env var or interactive prompt instead of baked-in key (matches install-mac.sh/install-windows.ps1 behavior)

- netscan.php: reuse AGENT_REGISTRATION_KEY constant instead of a duplicate literal

- agent.php + api.php: add session-authed "regkey" action so the admin install modal fetches the current key at runtime

- jarvis-agents.js: fetch reg key via /api/agent/regkey instead of hardcoding it; pass JARVIS_REG_KEY in the Linux install one-liner

- INFRASTRUCTURE-REFERENCE.md: scrub old key literal (rotated; real value lives only in api/config.php on VM211)

Key rotated on the box + rolled out to all 11 agents (verified all re-register online). New value is in the gitignored api/config.php only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Claude
2026-07-07 20:22:00 -05:00
parent 18783dc137
commit f7309a15fc
7 changed files with 881 additions and 860 deletions
+5 -1
View File
@@ -54,7 +54,7 @@ function update_agent_seen(string $agentId, string $status = 'online', ?string $
// ── Auth (all actions except register) ───────────────────────────────────────
$agentKey = $_SERVER['HTTP_X_AGENT_KEY'] ?? '';
$browserActions = ['list', 'status', 'myip'];
$browserActions = ['list', 'status', 'myip', 'regkey'];
if ($agentAction !== 'register') {
if (in_array($agentAction, $browserActions)) {
@@ -212,6 +212,10 @@ switch ($agentAction) {
);
agent_ok();
// ── REGKEY (browser: session-authed fetch of registration key) ───────────
case 'regkey':
agent_ok(['registration_key' => AGENT_REGISTRATION_KEY]);
// ── LIST (admin: get all agents status) ──────────────────────────────────
case 'list':
// Mark agents offline if last_seen > 2 minutes ago
+1 -1
View File
@@ -2,7 +2,7 @@
// Network scan push endpoint — called by PVE1 cron with nmap results
// Authenticates via X-Registration-Key header (same key as agent installer)
define('NETSCAN_KEY', 'f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518');
define('NETSCAN_KEY', AGENT_REGISTRATION_KEY);
if ($method !== 'POST') {
echo json_encode(['error' => 'POST only']); exit;
@@ -663,7 +663,7 @@ Webhook secret: `4c8805f0285214ff0a0602b5880270b935f36a896946c7f1`
### Agent System
Agents installed on all servers — phone home every 10s (heartbeat) / 30s (metrics).
Registration key: `f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518`
Registration key: `[rotated 2026-07-07 — stored in api/config.php on VM211, not documented here]`
Install command: `curl -sk http://10.48.200.211/install-agent.sh | bash -s <hostname> <linux|proxmox>`
### Self-Healing Watchdog
@@ -918,7 +918,7 @@ sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 \
| Service | Key |
|---------|-----|
| GitHub PAT | `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` (rotated 2026-07-05, scopes `repo`+`workflow`) |
| JARVIS Agent Registration | `f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518` |
| JARVIS Agent Registration | `[rotated 2026-07-07 — stored in api/config.php on VM211, not documented here]` |
| Proxmox API Token | `root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b` |
| HA Long-lived Token | `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiIzNmI0N2I1Njk5ZGQ0MTQ2ODMwZWFmYjZiYTQ1MjJkMSIsImlhdCI6MTc4MDIwMzU5NCwiZXhwIjoyMDk1NTYzNTk0fQ.sYRok-jRDlA4lFgWxLQELcEjkJNGQdprk6ZziLwLtXE` |
| Sonarr API | `b43e04350a594846b4ee95261c29e9e0` |
+8 -1
View File
@@ -21,7 +21,14 @@ JARVIS_HOST=""
INSTALL_DIR="/opt/jarvis-agent"
CONFIG_DIR="/etc/jarvis-agent"
STATE_DIR="/var/lib/jarvis-agent"
REG_KEY="f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518"
REG_KEY="${JARVIS_REG_KEY:-}"
if [ -z "$REG_KEY" ] && [ -r /dev/tty ]; then
read -rp "Enter JARVIS registration key: " REG_KEY </dev/tty
fi
if [ -z "$REG_KEY" ]; then
echo "ERROR: registration key required (set JARVIS_REG_KEY env var or enter at prompt)" >&2
exit 1
fi
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
echo "=== JARVIS Agent Installer v3.0 ==="
+1 -1
View File
@@ -19,7 +19,7 @@ $_e1 = $_earlyParts[1] ?? '';
$_skipSession = match(true) {
$_e0 === 'ping' => true,
$_e0 === 'netscan' => true,
$_e0 === 'agent' && !in_array($_e1, ['list','status','myip'], true) => true,
$_e0 === 'agent' && !in_array($_e1, ['list','status','myip','regkey'], true) => true,
default => false,
};
if (!$_skipSession) {
@@ -432,12 +432,16 @@ function renderAgentsTab(agents, metrics) {
}).join('');
}
function openAgentModal() {
async function openAgentModal() {
const os = detectOS();
const title = document.getElementById('agentModalTitle');
const content = document.getElementById('agentModalContent');
const modal = document.getElementById('agentModal');
const regKey = 'f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518';
let regKey = '<YOUR-REGISTRATION-KEY>';
try {
const rkResp = await fetch('/api/agent/regkey');
if (rkResp.ok) { const rk = await rkResp.json(); if (rk.registration_key) regKey = rk.registration_key; }
} catch (e) { /* not logged in — placeholder stays */ }
const jUrl = window.location.origin;
// Fixed 2026-07-07: this used to be hardcoded to https://jarvis.orbishosting.com/agent,
// which isn't reachable from outside the LAN at all (no FortiGate VIP forwards the
@@ -480,10 +484,9 @@ function openAgentModal() {
},
linux: {
label:'Linux',
// install.sh takes positional args (hostname, agent_type) and reads the
// JARVIS URL from an env var — the registration key is already baked in,
// no --key flag exists.
cmd:'curl -sSL '+baseUrl+'/install.sh | JARVIS_URL='+jUrl+' bash -s -- $(hostname) linux',
// install.sh takes positional args (hostname, agent_type); JARVIS URL and
// registration key come from env vars (key is no longer baked into the script).
cmd:'curl -sSL '+baseUrl+'/install.sh | JARVIS_URL='+jUrl+' JARVIS_REG_KEY=\''+regKey+'\' bash -s -- $(hostname) linux',
dl: baseUrl+'/install.sh',
note:'Run in terminal (sudo). Installs as a systemd service.'
},
+8 -1
View File
@@ -21,7 +21,14 @@ JARVIS_HOST=""
INSTALL_DIR="/opt/jarvis-agent"
CONFIG_DIR="/etc/jarvis-agent"
STATE_DIR="/var/lib/jarvis-agent"
REG_KEY="f846a9aaf7ce9a61742c63c87c4186052a71d2a580c65518"
REG_KEY="${JARVIS_REG_KEY:-}"
if [ -z "$REG_KEY" ] && [ -r /dev/tty ]; then
read -rp "Enter JARVIS registration key: " REG_KEY </dev/tty
fi
if [ -z "$REG_KEY" ]; then
echo "ERROR: registration key required (set JARVIS_REG_KEY env var or enter at prompt)" >&2
exit 1
fi
SERVICE_FILE="/etc/systemd/system/jarvis-agent.service"
echo "=== JARVIS Agent Installer v3.0 ==="