Merge pull request #33 from outis1one/claude/kind-knuth-j1AO6
Claude/kind knuth j1 ao6
This commit is contained in:
@@ -2195,20 +2195,42 @@ if [ "$INSTALL_NETBIRD" = "y" ] || [ "$INSTALL_NETBIRD" = "Y" ]; then
|
||||
|
||||
if [ "$DRY_RUN" = true ]; then
|
||||
echo "[DRY-RUN] Would download and run NetBird install script"
|
||||
echo "[DRY-RUN] Would ensure openssh-server is installed (required for NetBird SSH)"
|
||||
echo "[DRY-RUN] Would configure netbird systemd service with --allow-server-ssh"
|
||||
else
|
||||
# NetBird v0.60.0+ requires openssh-server for SSH access.
|
||||
# It injects /etc/ssh/sshd_config.d/99-netbird.conf and listens on port 22022.
|
||||
echo "Ensuring openssh-server is installed (required for NetBird SSH)..."
|
||||
apt install -y openssh-server 2>/dev/null || echo "Warning: openssh-server install failed, continuing..."
|
||||
systemctl enable ssh 2>/dev/null || true
|
||||
systemctl start ssh 2>/dev/null || true
|
||||
|
||||
curl -fsSL https://pkgs.netbird.io/install.sh | sh || echo "Warning: NetBird installation failed, continuing..."
|
||||
|
||||
# Persist --allow-server-ssh so this machine accepts NetBird SSH connections
|
||||
# without requiring interactive re-authentication on every connection.
|
||||
echo "Configuring NetBird to allow SSH server (persistent across reboots)..."
|
||||
mkdir -p /etc/systemd/system/netbird.service.d
|
||||
cat > /etc/systemd/system/netbird.service.d/ssh-server.conf << 'NETBIRD_OVERRIDE'
|
||||
[Service]
|
||||
ExecStart=
|
||||
ExecStart=/usr/bin/netbird service run --allow-server-ssh
|
||||
NETBIRD_OVERRIDE
|
||||
systemctl daemon-reload 2>/dev/null || true
|
||||
echo " ✓ NetBird will start with --allow-server-ssh on every boot"
|
||||
|
||||
echo ""
|
||||
echo "NetBird installed. Setup instructions:"
|
||||
echo " 1. Create account at https://app.netbird.io (or self-host)"
|
||||
echo " 2. Run 'netbird up' and authenticate via browser"
|
||||
echo ""
|
||||
echo "For NetBird SSH functionality:"
|
||||
echo " • Enable SSH in NetBird dashboard settings"
|
||||
echo " • Use 'netbird ssh <peer-name>' to connect to peers"
|
||||
echo " • NetBird manages SSH keys automatically when using 'netbird ssh'"
|
||||
echo " • Traditional SSH also works using peer IPs from 'netbird status'"
|
||||
echo " • Configure ACL rules in dashboard for SSH access (port 22)"
|
||||
echo "For NetBird SSH functionality (v0.60.0+ method):"
|
||||
echo " • openssh-server is installed and --allow-server-ssh is persisted"
|
||||
echo " • Enable SSH per-peer in the NetBird dashboard (Peers > [peer] > SSH)"
|
||||
echo " • NetBird injects /etc/ssh/sshd_config.d/99-netbird.conf automatically"
|
||||
echo " • Connect from another NetBird peer: ssh user@<netbird-ip>"
|
||||
echo " • Get peer IPs with: netbird status"
|
||||
echo " • SSH will work without re-authenticating each connection"
|
||||
echo ""
|
||||
fi
|
||||
else
|
||||
@@ -7554,11 +7576,13 @@ else
|
||||
echo " - Password login: ENABLED"
|
||||
fi
|
||||
echo ""
|
||||
echo " NetBird SSH Access (independent of traditional SSH):"
|
||||
echo " - NetBird manages its own keys automatically"
|
||||
echo " - Works even with password auth disabled"
|
||||
echo " - Connect with: netbird ssh <peer-name>"
|
||||
echo " - Enable in NetBird dashboard first"
|
||||
echo " NetBird SSH Access (v0.60.0+ method):"
|
||||
echo " - Requires openssh-server running (installed by this script)"
|
||||
echo " - Enable per-peer in NetBird dashboard: Peers > [peer] > SSH"
|
||||
echo " - NetBird injects /etc/ssh/sshd_config.d/99-netbird.conf"
|
||||
echo " - Connect from another peer: ssh user@<netbird-ip>"
|
||||
echo " - Get peer IPs with: netbird status"
|
||||
echo " - Note: old 'netbird ssh <peer-name>' command no longer works"
|
||||
echo ""
|
||||
echo " You can use ANY combination:"
|
||||
echo " ✓ GitHub + Launchpad + NetBird SSH"
|
||||
@@ -7626,6 +7650,11 @@ if [ "$INSTALL_NETBIRD" = "y" ] || [ "$INSTALL_NETBIRD" = "Y" ]; then
|
||||
echo " 1. Run 'netbird up' (opens browser for authentication)"
|
||||
echo " 2. View connected peers: netbird status"
|
||||
echo " 3. Configure ACLs in dashboard: https://app.netbird.io"
|
||||
echo " 4. Enable SSH per-peer: Peers > [peer] > SSH (in dashboard)"
|
||||
echo " 5. Connect via SSH: ssh user@<netbird-ip>"
|
||||
echo " Note: --allow-server-ssh is pre-configured in systemd override"
|
||||
echo " (/etc/systemd/system/netbird.service.d/ssh-server.conf)"
|
||||
echo " so SSH works without re-authenticating on every connection"
|
||||
echo ""
|
||||
fi
|
||||
if [ "$INSTALL_RUSTDESK" = "y" ] || [ "$INSTALL_RUSTDESK" = "Y" ]; then
|
||||
|
||||
Reference in New Issue
Block a user