Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 542e5fd33f | |||
| 848f35fc5e |
@@ -8,6 +8,19 @@ orchestration code; see each submodule's own `CHANGELOG.md`
|
|||||||
[sso-manager-node](https://github.com/theta42/sso-manager-node/blob/master/CHANGELOG.md))
|
[sso-manager-node](https://github.com/theta42/sso-manager-node/blob/master/CHANGELOG.md))
|
||||||
for what changed inside the apps it composes.
|
for what changed inside the apps it composes.
|
||||||
|
|
||||||
|
## [v1.35.0] - 2026-08-02
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **Non-interactive theta-agent configuration** — Added three `setup.env` variables
|
||||||
|
to control theta-agent installation and configuration without interactive prompts:
|
||||||
|
- `CFG_THETA_AGENT_ENABLE` (default: 1) — Enable theta-agent installation
|
||||||
|
- `CFG_THETA_AGENT_LDAP_AUTH` (default: 1) — Configure LDAP authentication via ldap-client
|
||||||
|
- `CFG_THETA_AGENT_FULL_CONTROL` (default: 1) — Enable all agent capabilities
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **`setup.sh`**: Made theta-agent setup fully non-interactive, driven by `setup.env`
|
||||||
|
variables. Defaults preserve existing behavior (all features enabled).
|
||||||
|
|
||||||
## [v1.34.0] - 2026-08-02
|
## [v1.34.0] - 2026-08-02
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
+14
-7
@@ -73,13 +73,6 @@ CFG_DOMAIN=example.com
|
|||||||
# 'sso-manager' so clients don't need a public 636 port forward. See docs.
|
# 'sso-manager' so clients don't need a public 636 port forward. See docs.
|
||||||
#CFG_LDAPS_HOST=
|
#CFG_LDAPS_HOST=
|
||||||
|
|
||||||
# Optional SMTP (outbound email from the SSO app). Leave blank to disable:
|
|
||||||
#CFG_SMTP_HOST=smtp.example.com
|
|
||||||
#CFG_SMTP_PORT=587
|
|
||||||
#CFG_SMTP_USER=noreply@example.com
|
|
||||||
#CFG_SMTP_PASS=your-smtp-password
|
|
||||||
#CFG_SMTP_FROM=SSO Manager <noreply@example.com>
|
|
||||||
|
|
||||||
# ── DO NOT put secrets here ──────────────────────────────────────────────────
|
# ── DO NOT put secrets here ──────────────────────────────────────────────────
|
||||||
# The LDAP admin password, JWT secret, admin password, LDAP service-account
|
# The LDAP admin password, JWT secret, admin password, LDAP service-account
|
||||||
# password, and the proxy's local admin password are all GENERATED (random)
|
# password, and the proxy's local admin password are all GENERATED (random)
|
||||||
@@ -90,6 +83,20 @@ CFG_DOMAIN=example.com
|
|||||||
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
||||||
# CFG_PROXY_ADMIN_PASS here.
|
# CFG_PROXY_ADMIN_PASS here.
|
||||||
|
|
||||||
|
# ── theta-agent Host Integration ─────────────────────────────────────────────
|
||||||
|
# Configure theta-agent integration with the local host. All options default to
|
||||||
|
# enabled (1). Set to 0 to disable.
|
||||||
|
#
|
||||||
|
# Enable theta-agent installation and configuration on this host.
|
||||||
|
#CFG_THETA_AGENT_ENABLE=1
|
||||||
|
#
|
||||||
|
# Configure LDAP authentication for this host via ldap-client (SSSD/PAM).
|
||||||
|
#CFG_THETA_AGENT_LDAP_AUTH=1
|
||||||
|
#
|
||||||
|
# Allow theta-agent full control of this host (arbitrary_bash, service_control,
|
||||||
|
# reboot, configure_ldap capabilities).
|
||||||
|
#CFG_THETA_AGENT_FULL_CONTROL=1
|
||||||
|
|
||||||
# ── Geo-Location Scaling (N-Way Multi-Master LDAP) ───────────────────────────
|
# ── Geo-Location Scaling (N-Way Multi-Master LDAP) ───────────────────────────
|
||||||
# If deploying this stack across multiple physical sites to provide local HA
|
# If deploying this stack across multiple physical sites to provide local HA
|
||||||
# for directory services, you can enable N-Way Multi-Master OpenLDAP replication.
|
# for directory services, you can enable N-Way Multi-Master OpenLDAP replication.
|
||||||
|
|||||||
@@ -1046,6 +1046,9 @@ NODEEOF
|
|||||||
echo "$JUMP_HOSTS_OUT" | sed 's/^/[setup] /'
|
echo "$JUMP_HOSTS_OUT" | sed 's/^/[setup] /'
|
||||||
|
|
||||||
# ── 7c. Install theta-agent on the host ──────────────────────────────────────
|
# ── 7c. Install theta-agent on the host ──────────────────────────────────────
|
||||||
|
# Controlled by CFG_THETA_AGENT_ENABLE (default: 1 = enabled)
|
||||||
|
CFG_THETA_AGENT_ENABLE="${CFG_THETA_AGENT_ENABLE:-1}"
|
||||||
|
if [[ "$CFG_THETA_AGENT_ENABLE" == "1" ]]; then
|
||||||
info "Setting up theta-agent on the host..."
|
info "Setting up theta-agent on the host..."
|
||||||
(
|
(
|
||||||
cd theta-agent || exit 0
|
cd theta-agent || exit 0
|
||||||
@@ -1090,6 +1093,52 @@ EOF"
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
)
|
)
|
||||||
|
else
|
||||||
|
info "theta-agent installation skipped (CFG_THETA_AGENT_ENABLE=0)."
|
||||||
|
fi
|
||||||
|
# ── 7d. Configure theta-agent integration with this host ─────────────────────
|
||||||
|
# Non-interactive configuration driven by setup.env variables:
|
||||||
|
# CFG_THETA_AGENT_ENABLE (default: 1) - Install/configure theta-agent
|
||||||
|
# CFG_THETA_AGENT_LDAP_AUTH (default: 1) - Configure LDAP authentication via ldap-client
|
||||||
|
# CFG_THETA_AGENT_FULL_CONTROL (default: 1) - Enable all agent capabilities
|
||||||
|
# Only runs if theta-agent was installed (section 7c) or already exists.
|
||||||
|
if [[ "$CFG_THETA_AGENT_ENABLE" == "1" ]] && [[ -x /usr/local/bin/theta-agent ]]; then
|
||||||
|
info "Configuring theta-agent integration with this host..."
|
||||||
|
|
||||||
|
# Default to enabled unless explicitly disabled
|
||||||
|
CFG_THETA_AGENT_LDAP_AUTH="${CFG_THETA_AGENT_LDAP_AUTH:-1}"
|
||||||
|
CFG_THETA_AGENT_FULL_CONTROL="${CFG_THETA_AGENT_FULL_CONTROL:-1}"
|
||||||
|
|
||||||
|
if [[ "$CFG_THETA_AGENT_LDAP_AUTH" == "1" ]]; then
|
||||||
|
info " Configuring LDAP authentication for this host..."
|
||||||
|
(
|
||||||
|
cd ldap-client || exit 0
|
||||||
|
if [[ -x "index.sh" ]]; then
|
||||||
|
bash index.sh --non-interactive 2>/dev/null || warn " ldap-client enrollment failed (continuing)..."
|
||||||
|
fi
|
||||||
|
)
|
||||||
|
else
|
||||||
|
info " LDAP authentication configuration skipped (CFG_THETA_AGENT_LDAP_AUTH=0)."
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$CFG_THETA_AGENT_FULL_CONTROL" == "1" ]]; then
|
||||||
|
info " Configuring theta-agent with full host control capabilities..."
|
||||||
|
if [[ -f /etc/theta/agent.yml ]]; then
|
||||||
|
sudo sed -i 's/arbitrary_bash: false/arbitrary_bash: true/' /etc/theta/agent.yml
|
||||||
|
sudo sed -i 's/service_control: false/service_control: true/' /etc/theta/agent.yml
|
||||||
|
sudo sed -i 's/reboot: false/reboot: true/' /etc/theta/agent.yml
|
||||||
|
sudo sed -i 's/configure_ldap: false/configure_ldap: true/' /etc/theta/agent.yml
|
||||||
|
info " theta-agent full control enabled. Restarting service..."
|
||||||
|
sudo systemctl restart theta-agent.service
|
||||||
|
else
|
||||||
|
warn " /etc/theta/agent.yml not found. Full control not configured."
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
info " theta-agent running with limited capabilities (CFG_THETA_AGENT_FULL_CONTROL=0)."
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
info " theta-agent configuration skipped (agent not installed or CFG_THETA_AGENT_ENABLE=0)."
|
||||||
|
fi
|
||||||
|
|
||||||
# ── 8. Summary ───────────────────────────────────────────────────────────────
|
# ── 8. Summary ───────────────────────────────────────────────────────────────
|
||||||
echo
|
echo
|
||||||
|
|||||||
Reference in New Issue
Block a user