5013148ffe
User-reported install fixes: - Branding: every user-facing 'SSO Manager' string now says 'Theta Directory' (agent logs, CLI usage, agent.yml.example, installer wizard). - Wizard page: the URL/join-key text boxes were never shown. The layout used Surface.Width (0 at wizard init) instead of SurfaceWidth and combined WordWrap with AutoSize (mutually exclusive in VCL). Rewritten with the canonical Inno pattern (SurfaceWidth + ScaleY + explicit label height). - No console window after install: the tray and helper now build as GUI-subsystem binaries (-H=windowsgui) in build_all.sh and scripts/setup-build-env.ps1. The agent stays a console app for foreground debugging (as a service it never shows a console). - The daemon never came up after install: install-service now starts the service immediately, so the tray IPC socket exists right away and the tray connects instead of logging 'actively refused' until a reboot. Verified: go build/vet/test green; tray+helper PE subsystem = GUI (2), agent = console (3); installer compiles; tray runs silently.
99 lines
4.1 KiB
Plaintext
99 lines
4.1 KiB
Plaintext
# theta-agent configuration file
|
|
# Default location: /etc/theta42/agent.yml (Linux) or %ProgramData%\Theta42\agent.yml (Windows)
|
|
|
|
server_url: "https://sso.example.com"
|
|
|
|
# This agent's own token. Leave EMPTY when installing with a join key -- the
|
|
# agent fills it in itself once the SSO enrolls it. The server records only a
|
|
# hash and rejects any token it did not issue, so a locally invented value will
|
|
# never connect.
|
|
auth_token: ""
|
|
|
|
# The one credential you need to add a host. Used only while auth_token is
|
|
# empty: the SSO exchanges it for this agent's own token + public key on first
|
|
# connect, and the agent then blanks this line. Get one from the SSO
|
|
# (Directory -> Install Agent, or POST /api/agent/join-keys).
|
|
join_key: ""
|
|
|
|
# Base64 of the SSO's RAW 32-byte Ed25519 public key (NOT a PEM body). Filled in
|
|
# automatically when enrolling with a join key; set it by hand only if you
|
|
# pre-registered this host.
|
|
#
|
|
# Required for any high-risk command. Without it the agent still reports
|
|
# telemetry, but REFUSES reboot / service_restart / configure_ldap /
|
|
# arbitrary_bash / update_binary, because it has no way to verify them.
|
|
public_key: ""
|
|
|
|
location: "default" # Location identifier (e.g., site, datacenter) for naming
|
|
|
|
# Local LDAP byte-pump socket (DESIGN.md ??4). The agent forwards raw LDAP bytes
|
|
# from this socket to the SSO, which relays them into its OpenLDAP. The agent
|
|
# never parses LDAP. Point SSSD at it with:
|
|
# ldap_uri = ldapi://%2frun%2ftheta%2fldap.sock
|
|
# (Windows relies on the TCP loopback listener 127.0.0.1:389 instead.)
|
|
ldap_socket: "/run/theta/ldap.sock"
|
|
|
|
# Auto-connect the WireGuard tunnel when this host is away from home and the
|
|
# directory WebSocket is up. The tray checkbox persists here too.
|
|
auto_vpn: false
|
|
|
|
# Windows-specific (DESIGN-WINDOWS.md ??11). Ignored on Linux.
|
|
service_name: "theta-agent" # Windows service name
|
|
desktop_helper: "" # theta-agent-helper.exe path (session-0 ops)
|
|
public_ip_detect: true # false = air-gap: never call external IP services
|
|
|
|
# WireGuard mesh client (DESIGN-WINDOWS.md ??5). The signed wireguard_apply
|
|
# command pushes the peer config down the WSS channel; these are local paths.
|
|
wireguard:
|
|
tunnel_name: "theta-mesh"
|
|
conf: "" # "" = platform default (/etc/wireguard/... or %ProgramData%\Theta42\wg\...)
|
|
executable: "" # wireguard.exe path (Windows; "" = PATH/default install)
|
|
|
|
capabilities:
|
|
# ---------------------------------------------------------
|
|
# Basic Capabilities (Safe, read-only or infrastructure management)
|
|
# ---------------------------------------------------------
|
|
|
|
# Push CPU, RAM, GPU, and ZFS metrics to Theta Directory
|
|
telemetry: true
|
|
|
|
# Allow Theta Directory to push down SSSD and SSH keys configuration
|
|
configure_ldap: true
|
|
|
|
# Serve the local LDAP byte-pump socket for SSSD/PAM (DESIGN.md ??4)
|
|
ldap_tunnel: true
|
|
|
|
# Render OpenBao secrets to local files from /etc/theta/templates (DESIGN.md ??5)
|
|
secrets: true
|
|
|
|
# Apply node IAM (sudo rules, SSH keys, access control, revocation) (DESIGN.md ??6)
|
|
iam: true
|
|
|
|
# Accept signed wireguard_apply/wireguard_remove commands (DESIGN-WINDOWS.md ??5)
|
|
wireguard: false
|
|
|
|
# Secret templates to render (DESIGN.md ??5). Each maps a local template to a
|
|
# target file and an optional post-render reload. The template embeds secrets as
|
|
# {{ bao "secret/data/nodes/<node-id>/<name>#<key>" }}.
|
|
# secrets:
|
|
# - template: /etc/theta/templates/db.env.tpl
|
|
# target: /etc/theta/db.env
|
|
# reload: systemctl reload app
|
|
|
|
# ---------------------------------------------------------
|
|
# Advanced Capabilities (High risk, remote operations)
|
|
# ---------------------------------------------------------
|
|
|
|
# Allow remote system reboots via Theta Directory
|
|
reboot: false
|
|
|
|
# Allow restarting, starting, or stopping specific systemd services.
|
|
# Must be an explicit list of allowed service names.
|
|
# Example: ["gitea", "nginx", "docker"]
|
|
# Setting to true or [] denies all.
|
|
service_control: []
|
|
|
|
# CRITICAL: Allow the execution of raw bash scripts sent from Theta Directory.
|
|
# Useful for GitOps deployments, but allows remote code execution.
|
|
arbitrary_bash: false
|