diff --git a/CHANGELOG.md b/CHANGELOG.md index abb30f6..54d23b7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1550,3 +1550,8 @@ First tagged release. Establishes the `vX.Y.Z` tag convention going forward. ## [1.34.4] - 2026-08-02 ### Changed - Updated `sso-manager-node` submodule to `v1.19.6` to pull in a fix for the Vault API 403 error on the Secrets List. + +## [1.34.5] - 2026-08-02 +### Added +- Automatically build and install `theta-agent` on the host system as a systemd service during `setup.sh`. +- Added `CFG_CREATE_ALL_HTTP` option to `setup.env` to create all default proxy host entries with `forcessl=false`. diff --git a/setup.env.example b/setup.env.example index 0b2927e..5e9bf99 100644 --- a/setup.env.example +++ b/setup.env.example @@ -100,4 +100,10 @@ CFG_DOMAIN=example.com # LDAP_REPLICATION_HOSTS is a space-separated list of the other sites' LDAP URLs. # Example for Site 1: #LDAP_SERVER_ID=1 -#LDAP_REPLICATION_HOSTS="ldaps://sso.site2.com:636 ldaps://sso.site3.com:636" \ No newline at end of file +#LDAP_REPLICATION_HOSTS="ldaps://sso.site2.com:636 ldaps://sso.site3.com:636" +# ── Proxy HTTP/HTTPS Defaults ──────────────────────────────────────────────── +# If you are running the stack behind an external reverse proxy (like Cloudflare +# or another ingress) that handles TLS termination, you may want the internal +# proxy to serve everything over plain HTTP without forcing redirects to HTTPS. +# Set this to 1 to create all default proxy host entries with forcessl=false. +#CFG_CREATE_ALL_HTTP=1 diff --git a/setup.sh b/setup.sh index d382fe8..fd21ed9 100755 --- a/setup.sh +++ b/setup.sh @@ -443,6 +443,7 @@ BAOEOF CFG_ADMIN_PASS="${CFG_ADMIN_PASS:-}" CFG_SVC_PASS="${CFG_SVC_PASS:-}" CFG_PROXY_ADMIN_PASS="${CFG_PROXY_ADMIN_PASS:-}" + CFG_CREATE_ALL_HTTP="${CFG_CREATE_ALL_HTTP:-0}" # ── One-time migration from .env / proxy.env (existing deployments) ── # Preserve the operator's existing secrets so the running deployment keeps @@ -977,7 +978,7 @@ async function ensureHost(host, ip, targetPort) { host: host, ip: ip, targetPort: targetPort, - forcessl: true, + forcessl: $( [[ "$CFG_CREATE_ALL_HTTP" == "1" ]] && echo false || echo true ), targetssl: false, sso_enabled: false, created_by: 'setup.sh', @@ -1034,7 +1035,7 @@ const {Host} = require('/app/models').models; try { await Host.get($(js_str "$JUMP_HOST")); console.log('SKIP ${JUMP_HOST} (already exists)'); } catch (e) { if (e.name !== 'EntryNotFound') throw e; - await Host.create({ host: $(js_str "$JUMP_HOST"), ip: 'jump-host', targetPort: 3002, forcessl: true, targetssl: false, sso_enabled: false, created_by: 'setup.sh' }); + await Host.create({ host: $(js_str "$JUMP_HOST"), ip: 'jump-host', targetPort: 3002, forcessl: $( [[ "$CFG_CREATE_ALL_HTTP" == "1" ]] && echo false || echo true ), targetssl: false, sso_enabled: false, created_by: 'setup.sh' }); console.log('CREATED ${JUMP_HOST} -> jump-host:3002'); } process.exit(0); @@ -1044,6 +1045,52 @@ NODEEOF ) echo "$JUMP_HOSTS_OUT" | sed 's/^/[setup] /' +# ── 7c. Install theta-agent on the host ────────────────────────────────────── +info "Setting up theta-agent on the host..." +( + cd theta-agent || exit 0 + if ! command -v go >/dev/null 2>&1; then + warn "Go is not installed. Skipping theta-agent installation." + else + info " Building theta-agent..." + go build -o theta-agent main.go websocket.go config.go || warn " Failed to build theta-agent." + if [[ -x "theta-agent" ]]; then + sudo mkdir -p /etc/theta + if [[ ! -f /etc/theta/agent.yml ]]; then + sudo cp agent.yml.example /etc/theta/agent.yml + AGENT_TOKEN="$(rand_hex 16)" + sudo sed -i "s/REPLACE_WITH_AGENT_TOKEN/$AGENT_TOKEN/" /etc/theta/agent.yml + # We want to connect to either https or http depending on CFG_CREATE_ALL_HTTP + if [[ "$CFG_CREATE_ALL_HTTP" == "1" ]]; then + sudo sed -i "s|https://sso.example.com|http://${SSO_HOST}|" /etc/theta/agent.yml + else + sudo sed -i "s|https://sso.example.com|https://${SSO_HOST}|" /etc/theta/agent.yml + fi + fi + sudo cp theta-agent /usr/local/bin/theta-agent + sudo chmod +x /usr/local/bin/theta-agent + + sudo bash -c "cat <<'EOF' > /etc/systemd/system/theta-agent.service +[Unit] +Description=Theta Agent +After=network.target + +[Service] +Type=simple +ExecStart=/usr/local/bin/theta-agent +Restart=on-failure +RestartSec=5 + +[Install] +WantedBy=multi-user.target +EOF" + sudo systemctl daemon-reload + sudo systemctl enable --now theta-agent.service + info " theta-agent installed and started." + fi + fi +) + # ── 8. Summary ─────────────────────────────────────────────────────────────── echo printf '\033[1;34m[setup]\033[0m \033[1;32mDone. Your SSO + proxy stack is up.\033[0m\n'