## Problem - https://jira.suse.com/browse/AGM-153 - For security reasons it should be possible to disable remote access to the Agama web server. A server which is not reachable cannot be hacked. 😃 ## Solution - Add a new `inst.listen_on` boot option, the possible values: - `inst.listen_on=all` - listen on all network interfaces (allow local and remote access). This is the default behavior used even without the `inst.listen_on` option, added just for completeness. - `inst.listen_on=localhost` - listen only on loop back (localhost) device. This disables remote access, Agama can be accessed only locally. - `inst.listen_on=<ip>` - listen on the specified IP address. Both IPv4 and IPv6 addresses are supported. It is possible to use multiple IP addresses separated by comma. Addresses not found in the system are ignored. - `inst.listen_on=<interface>` - listen on the specified network interface. Multiple interfaces can be separated by comma. Not found interfaces are ignored. Agama always listens on the local loop back interface even when specifying a specific network interface or IP address for listening. The reason is to avoid reporting connection errors by the Firefox started in the Live ISO. ## Details - The `--address2` CLI option has been removed, instead it is possible to specify `--address` option multiple times. - The PR includes the @mvidner's patch https://github.com/agama-project/agama/pull/3111 - fallback to an IPv4 address when listening to IPv6 address fails (when IPv6 is disabled with the `ipv6.disable=1` boot option) - Added the `agama-web-server.sh` wrapper script started from the systemd service. It evaluates the boot parameters and builds the address parameters for the Agama server. ## Notes - The other network services like SSH can be disabled using the standard `systemd.mask` boot option. For example to disable the SSH service use this boot option: `systemd.mask=sshd.service`. (I'll document this as well...) ## Testing - Tested manually in all scenarios: with disabled remote access, listening on the specified IPv6 (including link local address) or IPv4 address, listening on specified interface, listening on multiple interfaces - Tested Martin's patch with the `ipv6.disable=1` boot option, Agama properly listens on the IPv4 addresses in that case. --------- Co-authored-by: Martin Vidner <mvidner@suse.com>
76 lines
3.1 KiB
Bash
Executable file
76 lines
3.1 KiB
Bash
Executable file
#!/bin/bash
|
|
set -eu
|
|
# After building this part of Agama, install it so that it is ready for run time
|
|
# This is used by agama.spec and testing-in-container.sh
|
|
|
|
# The caller (RPM .spec) is expected to set these environment variables:
|
|
# NAME=%{name}
|
|
# SRCDIR=.
|
|
# DESTDIR=%{buildroot}
|
|
# bindir=%{_bindir}
|
|
# datadir=%{_datadir}
|
|
# pamvendordir=%{_pam_vendordir}
|
|
# unitdir=%{_unitdir}
|
|
# libexecdir=%{_libexecdir}
|
|
# mandir=%{_mandir}
|
|
# pamvendordir=%{_pam_vendordir}
|
|
: ${RUST_TARGET:=release}
|
|
|
|
if [ "${1-}" = --system ]; then
|
|
SRCDIR=.
|
|
DESTDIR=""
|
|
NAME=agama
|
|
RUST_TARGET=debug
|
|
bindir=/usr/bin
|
|
datadir=/usr/share
|
|
mandir=/usr/share/man
|
|
libexecdir=/usr/lib
|
|
unitdir=/usr/lib/systemd/system
|
|
pamvendordir=/etc/pam.d
|
|
fi
|
|
|
|
# install regular file, with mode 644 (not an executable with mode 755)
|
|
install6() {
|
|
install -m 0644 "$@"
|
|
}
|
|
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-autoinstall"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-proxy-setup"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-web-server"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-web-server.sh"
|
|
|
|
install6 -D -p "${SRCDIR}"/share/agama.pam "${DESTDIR}${pamvendordir}"/agama
|
|
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/dasd.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/iscsi.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/profile.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/software.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/zfcp.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.model.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/jsonnet "${SRCDIR}"/share/agama.libsonnet
|
|
|
|
install -D -t "${DESTDIR}${libexecdir}" "${SRCDIR}"/share/agama-scripts.sh
|
|
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-autoinstall.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-proxy-setup.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-scripts.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-web-server.service
|
|
|
|
# create the licenses directory
|
|
install -d -m 0755 "${DESTDIR}${datadir}"/agama/eula
|
|
|
|
# install manpages
|
|
install6 -D -t "${DESTDIR}${mandir}"/man1 "${SRCDIR}"/out/man/*
|
|
|
|
# install shell completion scripts
|
|
install6 -D "${SRCDIR}"/out/shell/"${NAME}".bash "${DESTDIR}${datadir}/bash-completion/completions/${NAME}"
|
|
install6 -D -t "${DESTDIR}${datadir}"/zsh/site-functions "${SRCDIR}"/out/shell/_"${NAME}"
|
|
install6 -D -t "${DESTDIR}${datadir}"/fish/vendor_completions.d "${SRCDIR}"/out/shell/"${NAME}".fish
|
|
|
|
# install OpenAPI specification
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/openapi "${SRCDIR}"/out/openapi/*
|
|
|
|
# install translations
|
|
make -C "${SRCDIR}/po" install DESTDIR="${DESTDIR}" datadir="${datadir}"
|