ops(esh-pve-2): register host, AMT phoning home to MeshCentral; note MeshCentral first-CIRA crash race

This commit is contained in:
vh
2026-10-02 22:25:37 -07:00
parent e707d87713
commit 55004090d1
4 changed files with 75 additions and 0 deletions
+13
View File
@@ -41,6 +41,19 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
MeshCentral restart re-ran its AMT manager, which logged in at once (16.1.25, power on). ⚠ MeshCentral
1.2.0 `amtmanager.js` picks TLS-vs-not over CIRA with `boundPorts.indexOf('16992')` used as a boolean
(−1 is truthy), so a TLS-only AMT can be tried without TLS. Set `tls` explicitly as above.
- **Third CIRA device: `esh-pve-2-amt`** (MS-03 at ESH, AMT 21.0.6, tunnel from ESH's public IP 128.177.138.182),
2026-10-02 2218. Same recipe. Instead of restarting MeshCentral after setting credentials, only that device's
tunnel was dropped (`sudo ss -K -tn "dst [::ffff:<public-ip>]:664"`). AMT reconnected within seconds, and the AMT
manager logged in with the new credentials. The other tunnels and the agents were untouched.
- ⚠ **A device's FIRST CIRA connection can crash MeshCentral 1.2.0** (it did once, 2026-10-02 22:18:07; the launcher
restarted it at 22:18:14 and all 14 agents came back). Read at source: in `mpsserver.js`, password-auth path for
a device not yet in the DB, `socket.tag.meshid` is set only inside the reverse-DNS callback, while
`addCiraConnection()` runs at once and its 300 ms timer reads `meshid`. `SetConnectivityState` →
`NotifyUserOfDeviceStateChange` then calls `meshid.split` on undefined, which is uncaught, so the whole server
restarts. The likely trigger is a slow PTR lookup on the source IP: ESH's resolves at zayo.com, while NH3's
has none and its two first connects did not crash. That is inferred, not measured. Reconnects of
an existing device take the other branch and are safe. **Onboard new AMTs at a quiet hour**; expect one ~7 s
MeshCentral restart.
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's