feat(cira-tunnel-watchdog): auto-drop stale AMT CIRA tunnels on MeshCentral's MPS
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# Install the CIRA tunnel watchdog on pfi-tacticalrmm (MeshCentral's host). Idempotent.
|
||||
# scripts/elway infra-ops@10.250.50.57 --playbook playbooks/cira-tunnel-watchdog.yaml
|
||||
# Source + rationale: services/cira-tunnel-watchdog/.
|
||||
steps:
|
||||
- name: script
|
||||
sudo: true
|
||||
upload:
|
||||
src: services/cira-tunnel-watchdog/cira-tunnel-watchdog
|
||||
dest: /usr/local/sbin/cira-tunnel-watchdog
|
||||
mode: "0755"
|
||||
- name: service unit
|
||||
sudo: true
|
||||
upload:
|
||||
src: services/cira-tunnel-watchdog/cira-tunnel-watchdog.service
|
||||
dest: /etc/systemd/system/cira-tunnel-watchdog.service
|
||||
mode: "0644"
|
||||
- name: timer unit
|
||||
sudo: true
|
||||
upload:
|
||||
src: services/cira-tunnel-watchdog/cira-tunnel-watchdog.timer
|
||||
dest: /etc/systemd/system/cira-tunnel-watchdog.timer
|
||||
mode: "0644"
|
||||
- name: reload and enable the timer
|
||||
sudo: true
|
||||
shell: systemctl daemon-reload && systemctl enable --now cira-tunnel-watchdog.timer
|
||||
changed_when: "false"
|
||||
|
||||
verify:
|
||||
- name: timer is active and scheduled
|
||||
sudo: true
|
||||
shell: systemctl is-active --quiet cira-tunnel-watchdog.timer && systemctl list-timers cira-tunnel-watchdog.timer --no-pager | grep -q cira-tunnel-watchdog
|
||||
changed_when: "false"
|
||||
- name: the live MPS capture parses (dry run exits 0)
|
||||
sudo: true
|
||||
shell: /usr/local/sbin/cira-tunnel-watchdog --dry-run
|
||||
changed_when: "false"
|
||||
Reference in New Issue
Block a user