feat(beszel): commit the fleet agent rollout — configs, playbooks and runbooks

Beszel agents are installed and verified across the fleet but the artifacts that
produced them were never committed, so the deployment existed only on the hosts.

Adds the per-host agent environment files (PORT, NICS, EXTRA_FILESYSTEMS and the
hub's PUBLIC key), the systemd unit, the guest install script, the Synology
compose, and the elway playbooks for native, guest-stage, guest-install and
Synology paths. The two dated memory detail files covering the priority-1 and
priority-2 waves ship alongside, per the convention that memory lands with the
work it describes.

No credentials here. The KEY= value in every host env is the Beszel hub's public
ed25519 key, identical across all nine and public by design; the agent README
says so explicitly. The nh3-nas sudo password referenced in the runbook prose
lives in Vaultwarden and the helper scripts named there never contained it.

⚠ Overlapping VMIDs across hypervisors are a standing trap and are recorded in
the priority-2 notes: pfi-pve 105=postgres and 100=pbs-ana, nh3-pve 105=pbs-nh3.
⚠ PBS-NH3's export was ~75.5% used at capture; resource checks are not job
success monitoring and should not be read as such.
This commit is contained in:
vh
2026-09-11 22:09:18 -07:00
parent 88e171bea6
commit ddfa1a6e5b
21 changed files with 340 additions and 0 deletions
+6
View File
@@ -0,0 +1,6 @@
steps:
- name: Install only Beszel through existing Proxmox guest agent
sudo: true
shell: |
set -euo pipefail
qm guest exec {{ vmid }} -- /bin/bash /tmp/beszel-priority2-install.sh | python3 -c 'import json,sys; r=json.load(sys.stdin); print(r.get("out-data","")); print(r.get("err-data","")); sys.exit(0 if r.get("exited") and r.get("exitcode")==0 else 1)'
+21
View File
@@ -0,0 +1,21 @@
steps:
- name: Stage verified binary as existing SSH user
upload:
src: /tmp/beszel-priority1/beszel-agent
dest: /tmp/beszel-priority2-agent
mode: '0755'
- name: Stage service unit
upload:
src: configs/beszel-agent/beszel-agent.service
dest: /tmp/beszel-priority2.service
mode: '0644'
- name: Stage host mount configuration
upload:
src: '{{ env_file }}'
dest: /tmp/beszel-priority2.env
mode: '0644'
- name: Stage bounded agent installer
upload:
src: configs/beszel-agent/guest-install.sh
dest: /tmp/beszel-priority2-install.sh
mode: '0700'
+37
View File
@@ -0,0 +1,37 @@
vars:
env_file: configs/beszel-agent/hosts/ana-nas.env
binary_file: /tmp/beszel-priority1/beszel-agent
steps:
- name: Create unprivileged agent account and config directory
sudo: true
shell: |
set -eu
getent passwd beszel >/dev/null || useradd --system --user-group --home-dir /var/lib/beszel-agent --shell /usr/sbin/nologin beszel
install -d -o root -g root -m 0755 /etc/beszel-agent
- name: Install verified version-matched binary
sudo: true
upload:
src: '{{ binary_file }}'
dest: /usr/local/bin/beszel-agent
mode: '0755'
- name: Install host-specific public key and mount configuration
sudo: true
upload:
src: '{{ env_file }}'
dest: /etc/beszel-agent/environment
mode: '0600'
- name: Install unprivileged service
sudo: true
upload:
src: configs/beszel-agent/beszel-agent.service
dest: /etc/systemd/system/beszel-agent.service
mode: '0644'
- name: Enable monitoring agent
sudo: true
shell: |
set -eu
systemd-analyze verify /etc/systemd/system/beszel-agent.service
systemctl daemon-reload
systemctl enable beszel-agent
systemctl restart beszel-agent
systemctl is-active beszel-agent
+27
View File
@@ -0,0 +1,27 @@
steps:
- name: Verify DSM paths and prepare agent-only directory
sudo: true
shell: |
set -eu
test -d /usr/share/zoneinfo
test -S /var/run/docker.sock
test ! -e /volume1/compose/beszel/compose.yaml
mkdir -p /volume1/compose/beszel/agent-data
- name: Upload version-matched Synology agent configuration
sudo: true
upload:
src: stacks/beszel/synology/compose.yaml
dest: /volume1/compose/beszel/compose.yaml
mode: '0644'
- name: Start only the monitoring agent
sudo: true
shell: |
set -eu
cd /volume1/compose/beszel
/usr/local/bin/docker compose config --quiet
/usr/local/bin/docker compose pull beszel-agent
/usr/local/bin/docker compose up -d beszel-agent
verify:
- name: Check agent and existing backup service
sudo: true
shell: /usr/local/bin/docker ps --format '{{.Names}} {{.Status}}' && /usr/local/bin/docker logs --tail 15 beszel-agent