Jarrod Johnson
a8cd9a24d5
Auto-restart vtbufferd on exit
...
If vtbuffer is interrupted, then restart it.
2026-07-02 12:13:24 -04:00
Jarrod Johnson
752d04939b
Merge pull request #220 from Obihoernchen/pubkeys_addpolicy
...
Fix pubkeys.addpolicy documentation to match implementation
2026-07-02 10:31:04 -04:00
Jarrod Johnson
d24359a86c
Add comments clarifying non-voting state with respect to security expectations
2026-07-02 10:27:21 -04:00
Jarrod Johnson
a41e20b1ab
Place install_url into agama configuration
2026-07-02 10:19:26 -04:00
Markus Hilger
4c0b2e44f4
Fix pubkeys.addpolicy documentation to match implementation
...
validvalues listed 'automatic'/'manual', but that was outdated.
Commit 454e1b8267 and cc70dcfa2b
implemented unset/'tofu' (trust-on-first-use, the default), 'manual', 'ca-only',
and an implicit 'ca' (any value that isn't otherwise handled falls
through to the standard CA-verification path, keying an already
pinned match without a full CA reverify).
The validvalues fix in ecaa75d967 rejected
these new values. Add new valid values with proper documentation.
2026-07-02 15:55:50 +02:00
Jarrod Johnson
ada4cb196d
Lock down non-system users to not have open ended access
2026-07-01 21:11:27 -04:00
Jarrod Johnson
0106758ceb
Prevent overwrite of existing files when saving licenses
2026-07-01 21:06:32 -04:00
Jarrod Johnson
1934b88b0d
Use basename to ensure no path traversal in license filenames
2026-07-01 20:54:36 -04:00
Jarrod Johnson
ae290c4419
Ensure the filename cannot have path traversal in XCC2 and older
2026-07-01 20:42:22 -04:00
Jarrod Johnson
57a4c840cb
Fix web shell sessions
2026-07-01 14:47:42 -04:00
Jarrod Johnson
6bcf1b73ba
Fix stale references to wsgi style env
2026-07-01 13:49:05 -04:00
Jarrod Johnson
3a6887b4b4
Provide nicer message when requested VM does not exist
2026-07-01 09:55:15 -04:00
Jarrod Johnson
d761c7e6da
Slow down reconnect attempts to powered down Proxmox VMs and better handle closed websockets.
2026-07-01 09:30:28 -04:00
Jarrod Johnson
45b392932d
Handle unreachable proxmox host more friendly
2026-07-01 09:14:07 -04:00
Jarrod Johnson
33c67db3c4
Further mitigate potential XML misbehavior
...
Since it turns out we already incurred lxml dependency, use lxml etree instead of xml and mitigate risky xml features beyond blocking the word '!entity'
2026-07-01 08:28:25 -04:00
Jarrod Johnson
fbec09c073
Fix behavior with IPMI bad user/password
2026-06-30 15:17:45 -04:00
Jarrod Johnson
5abd080ba2
Restore some sanity to redfish error handling
2026-06-30 13:56:34 -04:00
Jarrod Johnson
9ec7100042
Merge pull request #216 from Obihoernchen/dnsmasqdhcp
...
Implement confluent2dnsmasq
2026-06-30 08:25:49 -04:00
Jarrod Johnson
0383115446
Merge pull request #217 from Obihoernchen/hwplugins
...
Add missing validvalues to attributes.py
2026-06-30 08:13:21 -04:00
Jarrod Johnson
622e8e696a
Merge pull request #218 from gosforthcross/eureka-chassis-support
...
Add MEGWARE Eureka Chassis support + Small change for how IPs/Hostnames are handled in the redfish hardwaremanagement plugin
2026-06-30 08:08:37 -04:00
gosforthcross
6505810833
Improve handling of IPs with colon notation with seperate IPv4 and IPv6 paths, as well as whitespace stripping
2026-06-30 13:05:22 +02:00
gosforthcross
fbb79de786
Include EUREKA in necessary files for loading and handling redfish and autodiscovery
2026-06-30 11:30:24 +02:00
gosforthcross
6ab7d573da
Add EUREKA discovery handler
2026-06-30 11:29:19 +02:00
gosforthcross
5435acd23e
Add redfish OEM implementation for EUREKA Chassis
2026-06-30 11:28:45 +02:00
gosforthcross
cacfce214f
Add fallback for generic redfish and add specific MEGWARE code path for EUREKA
2026-06-30 11:25:11 +02:00
gosforthcross
b4882692ea
Add port discovery via colon notation
2026-06-30 11:22:30 +02:00
Markus Hilger
aed0bf0bea
Add valid_values to hardwaremanagement.method
2026-06-30 04:26:48 +02:00
Markus Hilger
ecaa75d967
Fix validvalues typo
...
valid_values is never checked and is a typo. Use validvalues instead.
Note: This can break existing scripts if invalid values are used.
2026-06-30 04:21:16 +02:00
Markus Hilger
1129089307
Rename confluent2dnsmasqdhcp -> confluent2dnsmasq
2026-06-30 02:59:12 +02:00
Markus Hilger
6a12b6c977
Use ip route for listen-address and detect missing /prefixlen
2026-06-30 02:55:52 +02:00
Markus Hilger
007b374c73
Implement confluent2dnsmasqdhcp
...
confleunt2dnsmasqdhcp creates static DHCP entries for dnsmasq
for nodes with defined net.*.hwaddr.
2026-06-30 02:55:23 +02:00
Jarrod Johnson
99405aa6c4
Merge pull request #215 from qisback/add-missing-man-pages
...
doc/man: add man pages for previously undocumented client commands
2026-06-29 12:33:21 -04:00
Jarrod Johnson
a2d4285ee9
Merge remote-tracking branch 'xcat/master'
2026-06-29 11:33:23 -04:00
Jarrod Johnson
3ce0988f5a
Fix -s on certutil
2026-06-29 11:30:49 -04:00
Markus Hilger
8a655be794
Update download link in README
2026-06-29 01:57:34 +02:00
Markus Hilger
6308703a10
Use new documentation url in README
2026-06-29 01:56:16 +02:00
Laurence
00a772785d
doc/man: add man pages for previously undocumented client commands
...
These commands ship in confluent_client/bin but had no .ronn man page, so
they did not appear in the generated documentation. Add man pages matching
the existing style, with synopsis and options taken from each command's
argument parser:
- confluent2ansible: export node inventory to an Ansible hosts file
- confluent2lxca: export nodes to a Lenovo XClarity Administrator bulk import CSV
- confluent2xcat: export nodes to an xCAT stanza definition (and optional macs.csv)
- dir2img: build a FAT image from a directory for nodemedia upload
- nodecertutil: manage BMC CA certificates and sign BMC certificates
- nodegrouprename: rename a node group
- noderename: rename nodes
2026-06-28 19:22:34 +01:00
Jarrod Johnson
2c669358b3
Restore ability for certutil to run as standalone script
...
Also make days an argument
2026-06-26 12:12:25 -04:00
Jarrod Johnson
97e0f4d253
Rework autoconsole logic
...
Match autocons
Skip unless EFI x86_64.
If SPCR, trust it and use that unconditionally.
Otherwise, if only one can respond to TIOCMGET, then use that one.
If multiple can respond, but exactly one shows carrier, use that.
2026-06-25 16:41:14 -04:00
Jarrod Johnson
9462de42ac
Fix setboot when network not in bootorder
2026-06-25 15:56:11 -04:00
Jarrod Johnson
e748a97eae
Only count copernicus replies that have OK status
2026-06-25 15:08:23 -04:00
Jarrod Johnson
c1eea55610
When possible, check confluent user access to file
...
If a confluent user is a system user, do not allow them to
upload paths that their user would not have access to otherwise.
For non-system users, continue with the path based banned behavior.
2026-06-25 12:14:54 -04:00
Jarrod Johnson
d59652e0fd
Prevent staging of files from indicating path traversal
2026-06-25 10:09:28 -04:00
Jarrod Johnson
46fbc11a93
Other than skipauth type users (unix domain socket root/confluent), no longer allow confluent user addition/manipulation.
2026-06-25 09:55:09 -04:00
Jarrod Johnson
78ffd509c9
Have messages force normalizing the incoming filenames
...
This avoids downstream code that may expect specific locations from being confused.
2026-06-25 09:48:11 -04:00
Jarrod Johnson
7845376eaf
Fix debian deployment on slow network link up
...
When network link was slow to establish, it would fall right through
the network initilalization code.
Now keep working it until a result is acheived.
2026-06-25 08:36:37 -04:00
Jarrod Johnson
8fdf3a9abe
Do not set 0.0.0.0 gateway
2026-06-24 15:58:45 -04:00
Jarrod Johnson
1449eee4f4
Fix to more reliably default to 47
2026-06-23 09:55:29 -04:00
Jarrod Johnson
cf7f2f434d
Add function for nodes to request a TLS certificate from confluent
...
Also, make certificate lifetime default configurable as attribute, with 47 as explicit default.
2026-06-23 09:39:16 -04:00
Jarrod Johnson
1068be423a
Remove some python2 considerations
2026-06-23 08:30:21 -04:00