Files
mac/scripts/run.sh
T
Mortdecai 2028508cb9 feat(ssh): full homelab alias set on the Mac + separate interactive key
config/ssh_homelab now carries the curated alias set from ~/bin/CLAUDE.md
(pve nodes, machines, key CTs, switch, tailscale hosts). Interactive auth
uses a NEW key, id_ed25519_homelab, because the existing id_ed25519 is
rrsync-jailed on pve173 and sshd honours the first matching authorized_keys
line per key — one key can't be both a jail and a shell there.

- setup.sh generates id_ed25519_homelab (idempotent)
- backup.sh pins the jailed key: -o IdentitiesOnly=yes -i $HOME/.ssh/id_ed25519
- scripts/authorize-mac-key.sh (run on steel141) appends the pubkey on every
  LAN host via claude's aliases; wired into run.sh
- bedroom alias: seth -> root (matches steel141; was undocumented)

Verified from the Mac: 12 aliases land as the right user@host; the backup key
is refused a shell by rrsync (checked with id — rrsync whitelists true);
backup.sh still runs. Offline at push time: bedroom thinkcentre seth-pi
pinail openclaw2 — re-run authorize-mac-key.sh when they're up.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 20:31:25 -04:00

35 lines
1.8 KiB
Bash
Executable File

#!/bin/bash
# From steel141: sync repo to the Mac, run setup there UNATTENDED, pull backups back, then tank side.
# Usage: scripts/run.sh [--no-tank]
#
# Homebrew's install needs sudo for 10+ min across child processes. We grant a TEMPORARY
# /etc/sudoers.d/mac-setup (NOPASSWD) for the run and guarantee its removal three ways:
# 1. explicit removal after setup, 2. an EXIT trap (covers failures / a dropped ssh from here),
# 3. a 40-min self-destruct on the Mac itself (covers steel141 losing the network).
# $HOMELAB_PASSWORD is used once (piped, never in argv) to install the drop-in.
set -euo pipefail
cd "$(dirname "$0")/.."
[[ -n ${HOMELAB_PASSWORD:-} ]] || { echo "HOMELAB_PASSWORD must be set"; exit 1; }
rsync -a --delete --exclude .git --exclude .backup --exclude Brewfile.lock.json ./ mac:mac/
cleanup(){ printf '%s\n' "$HOMELAB_PASSWORD" | ssh -o BatchMode=yes mac "sudo -S -p '' rm -f /etc/sudoers.d/mac-setup 2>/dev/null; sudo -K 2>/dev/null" || true; }
trap cleanup EXIT
# Install temp NOPASSWD drop-in (installer is a repo file, rsynced above; password piped to its stdin).
printf '%s\n' "$HOMELAB_PASSWORD" | ssh -o BatchMode=yes mac 'bash ~/mac/scripts/_install_sudoers.sh'
# sudo is now passwordless on the Mac; run setup unattended (Homebrew + everything).
ssh -o BatchMode=yes mac "HOSTNAME_WANT=mac ~/mac/scripts/setup.sh"
# Explicit removal + confirm; then disarm the trap so it doesn't double-run.
cleanup; trap - EXIT
ssh -o BatchMode=yes mac 'test ! -e /etc/sudoers.d/mac-setup && echo "[ok] temp sudoers removed" || echo "[WARN] temp sudoers STILL PRESENT"'
mkdir -p .backup/mac && rsync -a mac:.mac-setup-backup/ .backup/mac/
scripts/authorize-mac-key.sh
[[ ${1:-} == --no-tank ]] && exit 0
PUB=$(ssh mac cat .ssh/id_ed25519.pub)
ssh pve173 "PUB='$PUB' bash -s" < scripts/tank-side.sh
echo "tank side done; test: ssh mac ~/mac/scripts/backup.sh"