Beszel agents are installed and verified across the fleet but the artifacts that produced them were never committed, so the deployment existed only on the hosts. Adds the per-host agent environment files (PORT, NICS, EXTRA_FILESYSTEMS and the hub's PUBLIC key), the systemd unit, the guest install script, the Synology compose, and the elway playbooks for native, guest-stage, guest-install and Synology paths. The two dated memory detail files covering the priority-1 and priority-2 waves ship alongside, per the convention that memory lands with the work it describes. No credentials here. The KEY= value in every host env is the Beszel hub's public ed25519 key, identical across all nine and public by design; the agent README says so explicitly. The nh3-nas sudo password referenced in the runbook prose lives in Vaultwarden and the helper scripts named there never contained it. ⚠ Overlapping VMIDs across hypervisors are a standing trap and are recorded in the priority-2 notes: pfi-pve 105=postgres and 100=pbs-ana, nh3-pve 105=pbs-nh3. ⚠ PBS-NH3's export was ~75.5% used at capture; resource checks are not job success monitoring and should not be read as such.
15 lines
729 B
Bash
15 lines
729 B
Bash
#!/bin/bash
|
|
set -euo pipefail
|
|
test "$(id -u)" = 0
|
|
getent passwd beszel >/dev/null || useradd --system --user-group --home-dir /var/lib/beszel-agent --shell /usr/sbin/nologin beszel
|
|
install -d -o root -g root -m 0755 /etc/beszel-agent
|
|
install -o root -g root -m 0755 /tmp/beszel-priority2-agent /usr/local/bin/beszel-agent
|
|
install -o root -g root -m 0600 /tmp/beszel-priority2.env /etc/beszel-agent/environment
|
|
install -o root -g root -m 0644 /tmp/beszel-priority2.service /etc/systemd/system/beszel-agent.service
|
|
systemd-analyze verify /etc/systemd/system/beszel-agent.service
|
|
systemctl daemon-reload
|
|
systemctl enable beszel-agent
|
|
systemctl restart beszel-agent
|
|
systemctl is-active beszel-agent
|
|
systemctl is-enabled beszel-agent
|