ops(esh-pve-2): register host, AMT phoning home to MeshCentral; note MeshCentral first-CIRA crash race
This commit is contained in:
@@ -41,6 +41,19 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
|
||||
MeshCentral restart re-ran its AMT manager, which logged in at once (16.1.25, power on). ⚠ MeshCentral
|
||||
1.2.0 `amtmanager.js` picks TLS-vs-not over CIRA with `boundPorts.indexOf('16992')` used as a boolean
|
||||
(−1 is truthy), so a TLS-only AMT can be tried without TLS. Set `tls` explicitly as above.
|
||||
- **Third CIRA device: `esh-pve-2-amt`** (MS-03 at ESH, AMT 21.0.6, tunnel from ESH's public IP 128.177.138.182),
|
||||
2026-10-02 2218. Same recipe. Instead of restarting MeshCentral after setting credentials, only that device's
|
||||
tunnel was dropped (`sudo ss -K -tn "dst [::ffff:<public-ip>]:664"`). AMT reconnected within seconds, and the AMT
|
||||
manager logged in with the new credentials. The other tunnels and the agents were untouched.
|
||||
- ⚠ **A device's FIRST CIRA connection can crash MeshCentral 1.2.0** (it did once, 2026-10-02 22:18:07; the launcher
|
||||
restarted it at 22:18:14 and all 14 agents came back). Read at source: in `mpsserver.js`, password-auth path for
|
||||
a device not yet in the DB, `socket.tag.meshid` is set only inside the reverse-DNS callback, while
|
||||
`addCiraConnection()` runs at once and its 300 ms timer reads `meshid`. `SetConnectivityState` →
|
||||
`NotifyUserOfDeviceStateChange` then calls `meshid.split` on undefined, which is uncaught, so the whole server
|
||||
restarts. The likely trigger is a slow PTR lookup on the source IP: ESH's resolves at zayo.com, while NH3's
|
||||
has none and its two first connects did not crash. That is inferred, not measured. Reconnects of
|
||||
an existing device take the other branch and are safe. **Onboard new AMTs at a quiet hour**; expect one ~7 s
|
||||
MeshCentral restart.
|
||||
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
|
||||
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
|
||||
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's
|
||||
|
||||
Reference in New Issue
Block a user