## Problem - Using the new `inst.listen_on` boot option to disable remote access to the server looks inconsistent (for disabling the SSH access you can use the `systemd.mask=sshd.service` boot option) - Simplify the implementation, limiting access to some interface or IP address was not requested - Related to https://github.com/agama-project/agama/pull/3269 ## Solution - Use systemd services to implement disabling the remote access - ~~Implement new `agama-web-server-local` and `agama-web-server-remote` services~~ - ~~By default the remote service is enabled, but the user can disable it and enable the local service instead using the `systemd.mask=agama-web-server-remote.service systemd.wants=agama-web-server-local.service` boot parameters.~~ - Support new `inst.remote=0` boot option ## Testing - Tested manually ## Notes I tried several approaches but either they did not work or were a bit hacky: 1. First a wanted to be the both local and remote services enabled by default. Because of conflicts only one of them should be running at a time. I used `Before` and `After` so the remote service starts first and the conflict should block the local service from running. Disabling the remote service allows running the local service automatically. The problem was that there is probably some race condition and sometimes the local service was actually running instead of the remote by default. I tried several changes but nothing helped. 2. Then I added code to the local service to explicitly check whether the remote service is disabled or not (using `ExecCondition` attribute). But that feels a bit hacky and it is a hidden magic. 3. Then I realized that the same way how you can disable a service at boot using `systemd.mask` option you can also enable a disabled service using the `systemd.wants` parameter. So instead of enabling both services enable only the default remote one. The users then can explicitly disable the remote service and enable the local one using the `systemd.mask=agama-web-server-remote.service systemd.wants=agama-web-server-local.service` boot options. But that turned out to be quite complicated. 4. So let's implement simple `inst.remote=0` boot option which disables the remotes access to the Agama installer. The SSH service can be disabled using the standard `systemd.mask=sshd.service` option.
19 lines
822 B
Desktop File
19 lines
822 B
Desktop File
[Unit]
|
|
Description=Agama Web Server
|
|
# agama-hostname might change the host name which is used when creating
|
|
# a self signed certificate, run it before the web server
|
|
After=network-online.target agama.service agama-hostname.service
|
|
BindsTo=agama.service
|
|
|
|
[Service]
|
|
EnvironmentFile=-/run/agama/environment.conf
|
|
Environment="AGAMA_LOG=debug,zbus=info"
|
|
Type=notify
|
|
# listen only on the loopback interface if the inst.remote=0 boot option is set
|
|
ExecStart=/usr/bin/bash -c "grep -q '\\binst.remote=0\\b' /run/agama/cmdline.d/agama.conf && exec /usr/bin/agama-web-server serve --address ::1:80,127.0.0.1:80 --address ::1:443,127.0.0.1:443 || exec /usr/bin/agama-web-server serve --address :::80,0.0.0.0:80 --address :::443,0.0.0.0:443"
|
|
PIDFile=/run/agama/web.pid
|
|
User=root
|
|
TimeoutStopSec=5
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|