Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ac433b30e9 | ||
|
|
c0d17fa9ca | ||
|
|
edf3a69daa | ||
|
|
44a2212abe |
Generated
+627
-35
File diff suppressed because it is too large
Load Diff
+31
-1
@@ -12,7 +12,7 @@ members = [
|
|||||||
]
|
]
|
||||||
|
|
||||||
[workspace.package]
|
[workspace.package]
|
||||||
version = "0.5.4"
|
version = "0.5.7"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
rust-version = "1.95"
|
rust-version = "1.95"
|
||||||
license = "MIT OR Apache-2.0"
|
license = "MIT OR Apache-2.0"
|
||||||
@@ -85,6 +85,36 @@ x509-parser = "0.18"
|
|||||||
flate2 = "1.1"
|
flate2 = "1.1"
|
||||||
base64 = "0.22"
|
base64 = "0.22"
|
||||||
|
|
||||||
|
# v0.5.5: pure-Rust SSH/SFTP client for reading remote ISO libraries
|
||||||
|
# over SFTP without a kernel mount.
|
||||||
|
#
|
||||||
|
# CRITICAL #1 — crypto backend: `default-features = false` +
|
||||||
|
# `features = ["ring"]`. russh's *default* backend is `aws-lc-rs`, which
|
||||||
|
# pulls `aws-lc-sys` (C code, fiddly under musl); the `ring` feature
|
||||||
|
# instead reuses `ring 0.17` — the exact crate+version already in the
|
||||||
|
# binary via rustls + bergshamra — so SFTP adds ZERO new C/crypto deps
|
||||||
|
# and the static-musl build stays OpenSSL-free.
|
||||||
|
#
|
||||||
|
# CRITICAL #2 — pinned to EXACTLY 0.55.0, the newest russh that
|
||||||
|
# coexists with bergshamra-crypto (our SAML core). The RustCrypto
|
||||||
|
# ecosystem is mid-transition: bergshamra-crypto pins a constellation of
|
||||||
|
# release-CANDIDATE crates (`pkcs8 =0.11.0-rc.11` and its matching
|
||||||
|
# pkcs5/spki RCs) that are API-incompatible with the STABLE versions of
|
||||||
|
# the same crates in the same semver bucket. russh 0.56+ pulls those
|
||||||
|
# stable crates (`pkcs5 0.8`), which silently replaces bergshamra's RC
|
||||||
|
# copies and breaks compilation. russh ≤0.55 stays on the previous stable
|
||||||
|
# generation (`pkcs5 0.7`, `ssh-key 0.6`), which unifies with bergshamra's
|
||||||
|
# *stable* deps and leaves the RC bucket untouched — verified to compile.
|
||||||
|
# 0.55 still has the merged `russh::keys` API (keys merged at 0.50).
|
||||||
|
# IMPORTANT: do NOT bump russh past 0.55 until bergshamra-crypto adopts
|
||||||
|
# the stable RustCrypto generation; 0.56+ will not compile in this tree.
|
||||||
|
#
|
||||||
|
# SCP was deliberately rejected: the protocol is sequential-only (no
|
||||||
|
# random access → no HTTP Range, unlike SFTP/NFS) and the mature SCP
|
||||||
|
# crates wrap libssh2 (C + OpenSSL), which would break this build.
|
||||||
|
russh = { version = "=0.55.0", default-features = false, features = ["ring"] }
|
||||||
|
russh-sftp = "2.3"
|
||||||
|
|
||||||
openpxe-core = { path = "crates/core" }
|
openpxe-core = { path = "crates/core" }
|
||||||
openpxe-dhcp-proxy = { path = "crates/dhcp-proxy" }
|
openpxe-dhcp-proxy = { path = "crates/dhcp-proxy" }
|
||||||
openpxe-tftp = { path = "crates/tftp" }
|
openpxe-tftp = { path = "crates/tftp" }
|
||||||
|
|||||||
@@ -1,301 +1,270 @@
|
|||||||
# OpenPXE
|
<p align="center">
|
||||||
|
<img src="docs/openpxe-logo.svg" alt="OpenPXE" width="104" height="104" />
|
||||||
|
</p>
|
||||||
|
|
||||||
Container-native PXE boot server. A Rust reimplementation of
|
<h1 align="center">OpenPXE</h1>
|
||||||
[iVentoy (ventoy/PXE)](https://github.com/ventoy/PXE), designed from scratch
|
|
||||||
for Docker/OCI and OpenShift. Upload `.iso` files via the web UI; network
|
|
||||||
clients PXE-boot them.
|
|
||||||
|
|
||||||
> **Status:** v0.4.1 / pre-beta. Phases 1–5 complete: full PXE stack,
|
<p align="center">
|
||||||
> Queued Deployment queue, NFS-share ISO sources, live tracing log + an
|
<strong>Container-native network boot & OS deployment — built in Rust.</strong>
|
||||||
> operator terminal, per-MAC host bindings, Prometheus `/metrics`,
|
</p>
|
||||||
> light/dark theme toggle, animated OpenPXE imaging-progress widget,
|
|
||||||
> chunked ISO uploads, and per-ISO boot passwords. The test suite and
|
|
||||||
> clippy are part of the release checklist. Ready for real-hardware validation.
|
|
||||||
|
|
||||||
## Design non-negotiables
|
<p align="center">
|
||||||
|
Drag in an ISO. PXE-boot and image an entire fleet from a browser.<br/>
|
||||||
|
No iPXE scripting. No <code>dnsmasq</code> + <code>tftpd</code> + Samba glue. No glibc. No garbage collector.
|
||||||
|
</p>
|
||||||
|
|
||||||
1. **Fully offline / air-gap deployable.** Zero CDN assets. Zero external
|
<p align="center">
|
||||||
HTTP calls from the server, the browser, or the generated iPXE scripts.
|
<img alt="release" src="https://img.shields.io/badge/release-v0.5.5-2874d7" />
|
||||||
Build the container once, run forever disconnected.
|
<img alt="license" src="https://img.shields.io/badge/license-MIT%20%7C%20Apache--2.0-59824f" />
|
||||||
2. **iPXE is a backend implementation detail.** No `.ipxe` upload path, no
|
<img alt="rust" src="https://img.shields.io/badge/built%20with-Rust-fb8841?logo=rust&logoColor=white" />
|
||||||
manual script editing, no iPXE terminology in the UI. Every knob in the
|
<img alt="container" src="https://img.shields.io/badge/container--native-OCI%20%C2%B7%20OpenShift-2496ED?logo=docker&logoColor=white" />
|
||||||
web UI maps to a specific script-generation behavior inside the binary.
|
<img alt="binary" src="https://img.shields.io/badge/static-musl%20%C2%B7%20~18MB-330f1f" />
|
||||||
3. **The client trust store is off-limits.** No test-signed drivers, no
|
</p>
|
||||||
`bcdedit /set testsigning on`, no certificates injected into WinPE or
|
|
||||||
the target OS.
|
|
||||||
|
|
||||||
## What it does
|
---
|
||||||
|
|
||||||
1. **DHCP proxy** (RFC 4578). Coexists with your existing DHCP server —
|
OpenPXE turns bare-metal provisioning into a single container with a web UI. It's a
|
||||||
never assigns IPs. Listens on UDP 67 + UDP 4011.
|
ground-up Rust reimplementation of [iVentoy (ventoy/PXE)](https://github.com/ventoy/PXE),
|
||||||
2. **TFTP server** (RFC 1350 + RFC 2347/2348/2349/7440 option negotiation)
|
designed for Docker/OCI and OpenShift instead of a Windows desktop — so it drops onto
|
||||||
that serves architecture-specific iPXE binaries to firmware PXE ROMs.
|
an Unraid box, a Linux server, or a Kubernetes cluster and just runs.
|
||||||
3. **HTTP server** that serves the web UI, the generated iPXE boot scripts,
|
|
||||||
raw ISOs (with Range), and files inside ISOs without prior extraction.
|
|
||||||
4. **ISO introspection**: auto-detects the distro family and generates the
|
|
||||||
appropriate kernel+initrd or wimboot chain. No manual config.
|
|
||||||
5. **Hierarchical PXE menu** mirroring the Phase 2 spec:
|
|
||||||
```
|
|
||||||
Default > Boot from Local HDD
|
|
||||||
Installers > Linux Installers / Windows Installers
|
|
||||||
Tools > Utilities / OpenPXE Shell / Network Card Info
|
|
||||||
Queued Deployment
|
|
||||||
```
|
|
||||||
6. **Queued Deployment queue** — the coordinated launch flow. A client that
|
|
||||||
selects *Queued Deployment* gets a numbered position and waits. The
|
|
||||||
operator picks an ISO in the web UI and fires it to every waiting
|
|
||||||
client simultaneously.
|
|
||||||
7. **Web UI** (Netbox-style): sidebar nav (Dashboard / Network / Queue /
|
|
||||||
Storage / Hosts / Terminal / About), light + dark themes
|
|
||||||
(toggle top-right or press `T`), animated OpenPXE progress
|
|
||||||
widget when devices are imaging. All assets served from the binary —
|
|
||||||
no external requests.
|
|
||||||
8. **Per-MAC host bindings.** Pin a MAC to a boot target and the client
|
|
||||||
skips the menu, chains straight through.
|
|
||||||
9. **Prometheus metrics** at `/metrics` — DHCP replies by arch, TFTP
|
|
||||||
transfer counts and bytes, HTTP request counts by route, queue /
|
|
||||||
imaging gauges, uptime, build info. Plain text exposition format,
|
|
||||||
no external metrics framework dependency.
|
|
||||||
8. **Settings API** lets you change the default boot-menu timeout (default
|
|
||||||
600s), the timeout action (stay / Local HDD / Queued Deployment), and
|
|
||||||
feature toggles like Windows ISO support. The iPXE scripts regenerate
|
|
||||||
on every request using current settings.
|
|
||||||
|
|
||||||
### Architectures supported on day one
|
Upload `.iso` files (or point at a remote share), and any machine on the network boots
|
||||||
|
them — Linux installers, live tools, or stock Windows setup — with **zero iPXE knowledge
|
||||||
|
required by the operator.**
|
||||||
|
|
||||||
| DHCP option 93 | Architecture | Binary served |
|
> **Status — v0.5.5, late pre-beta.** The full PXE stack, web UI, remote ISO libraries
|
||||||
|----------------|-----------------|-------------------------|
|
> (SMB/NFS/SFTP), Windows deployment, queued fleet rollout, SAML SSO, and Prometheus
|
||||||
| `0x0000` | Legacy x86 BIOS | `undionly.kpxe` |
|
> metrics are implemented and test-covered. The release checklist gates every tag on the
|
||||||
| `0x0006` | IA32 UEFI | `snponly-i386.efi` |
|
> full test suite + `clippy`. Currently in real-hardware validation.
|
||||||
| `0x0007`/`0x0009` | x86_64 UEFI | `snponly.efi` |
|
|
||||||
| `0x000B` | ARM64 UEFI | `snponly-arm64.efi` |
|
|
||||||
|
|
||||||
UEFI firmware that sends `HTTPClient` in option 60 is handled too — we
|
## Why OpenPXE
|
||||||
skip TFTP and respond with an HTTP URL.
|
|
||||||
|
|
||||||
## Quick start — MVP container (recommended)
|
Standing up network boot the traditional way means hand-wiring `dnsmasq`, a TFTP daemon,
|
||||||
|
hand-written iPXE menu scripts, an HTTP server, and Samba — then keeping that fragile
|
||||||
|
stack alive, and discovering none of it containerizes cleanly (kernel-mount NFS, raw
|
||||||
|
sockets, `CAP_SYS_ADMIN`). iVentoy solved the UX beautifully, but it's a Windows GUI app.
|
||||||
|
|
||||||
|
OpenPXE collapses that whole stack into **one statically-linked binary in one container**:
|
||||||
|
|
||||||
|
- **A web UI does everything.** iPXE is an internal implementation detail — there is no
|
||||||
|
script upload, no `.ipxe` editing, no PXE jargon in the interface.
|
||||||
|
- **It runs anywhere a container runs.** No kernel modules, no privileged mode — proxy-mode
|
||||||
|
DHCP + `NET_BIND_SERVICE` is the entire requirement. Verified on Unraid, plain Docker,
|
||||||
|
and OpenShift's restricted SCC.
|
||||||
|
- **It's air-gap native.** Zero CDN assets, zero outbound calls from the server, browser,
|
||||||
|
or generated boot scripts. Build the image once, run it forever, disconnected.
|
||||||
|
|
||||||
|
## Highlights
|
||||||
|
|
||||||
|
#### Boot stack
|
||||||
|
- **DHCP proxy** (RFC 4578) that coexists with your existing DHCP — it never hands out IPs.
|
||||||
|
- **TFTP** (RFC 1350 + 2347/2348/2349/7440 option negotiation) serving arch-correct iPXE firmware.
|
||||||
|
- **HTTP** serving the UI, generated boot scripts, raw ISOs (with byte-range), and files
|
||||||
|
*inside* ISOs with no prior extraction.
|
||||||
|
- **Graphical iPXE boot menu** built from your uploads, with a PNG background and a clean
|
||||||
|
hierarchy — generated fresh on every request from current settings.
|
||||||
|
|
||||||
|
#### ISO management & remote libraries
|
||||||
|
- **Drag-and-drop chunked uploads** that don't 502 on multi-GB images.
|
||||||
|
- **Automatic introspection** — detects the distro family and generates the right
|
||||||
|
kernel+initrd or Windows `wimboot` chain. No manual config.
|
||||||
|
- **Remote ISO libraries, streamed on demand** (no local cache) over **SMB, NFS, or SFTP** —
|
||||||
|
see the table below.
|
||||||
|
|
||||||
|
#### Fleet deployment
|
||||||
|
- **Queued Deployment** — clients join a queue and wait; the operator fires one image at
|
||||||
|
every waiting machine simultaneously.
|
||||||
|
- **Per-MAC host bindings** — pin a MAC straight to a target (with optional auto hostname,
|
||||||
|
auto IP, and an unattended answer file); it skips the menu and chains through.
|
||||||
|
- **Unattended installs** — upload Kickstart / Preseed / Autoinstall / Windows answer files;
|
||||||
|
they're templated per-host (hostname / IP / MAC) and served only to booting clients.
|
||||||
|
- **Windows deployment** from a stock Microsoft ISO — **every binary the client runs stays
|
||||||
|
Microsoft-signed** (details below).
|
||||||
|
|
||||||
|
#### Operations & access
|
||||||
|
- **SAML 2.0 single sign-on** (pure-Rust SP, no OpenSSL/xmlsec) alongside local accounts.
|
||||||
|
- **Custom branding** — light / dark / PXE-client logos and favicon.
|
||||||
|
- **Notifications** — Slack / Teams / Discord webhooks and SMTP email on boot events.
|
||||||
|
- **Prometheus `/metrics`**, a built-in operator **terminal**, live tracing log, and
|
||||||
|
`/healthz` · `/readyz` probes.
|
||||||
|
- **Layered config** — defaults → TOML file → `OPENPXE_*` env, in that order.
|
||||||
|
|
||||||
|
## Built in Rust
|
||||||
|
|
||||||
|
Rust isn't a checkbox here — it's why OpenPXE deploys the way it does:
|
||||||
|
|
||||||
|
- **One static binary, ~18 MB.** Compiled to `x86_64-unknown-linux-musl` — no glibc, no
|
||||||
|
interpreter, no sidecar runtime. The runtime image is "binary + a few CLI tools."
|
||||||
|
- **No garbage collector, async throughout.** A Tokio runtime drives DHCP, TFTP, HTTP, and
|
||||||
|
many concurrent multi-GB ISO streams on a tiny, predictable memory footprint — it idles
|
||||||
|
near-zero and never GC-pauses mid-transfer.
|
||||||
|
- **Memory-safe by construction.** `unsafe` is **denied workspace-wide**; the only
|
||||||
|
exceptions are two small, individually-audited FFI calls (`statvfs` for disk usage and a
|
||||||
|
Samba `SIGHUP`).
|
||||||
|
- **OpenSSL-free, pure-Rust crypto.** TLS via `rustls`/`ring`; the SAML Service Provider
|
||||||
|
does XML-DSig verification with RustCrypto — no `xmlsec`, no `libxml2`, no C crypto to
|
||||||
|
CVE-patch. Even the SMB/NFS/SFTP clients avoid C libraries.
|
||||||
|
- **Sub-minute, reproducible container builds.** Cross-compiled with `cargo-zigbuild`
|
||||||
|
(zig as the linker) — a full image builds in well under a minute on a warm cache, with
|
||||||
|
no QEMU emulation.
|
||||||
|
|
||||||
|
## Quick start
|
||||||
|
|
||||||
|
### Run the container
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# 1. Pull bundled iPXE binaries (~2 MB, one-time).
|
# Build the self-contained image (iPXE binaries are fetched + built inside the Dockerfile).
|
||||||
./scripts/fetch-ipxe.sh
|
docker build -f deploy/docker/Dockerfile -t openpxe:0.5.5 .
|
||||||
|
|
||||||
# 2. Build the container image (~3 min first time).
|
# Run it on the box plugged into your PXE network. Host networking is required in
|
||||||
docker buildx build -f deploy/docker/Dockerfile -t openpxe:0.4.1 --load .
|
# proxy mode so the container sees DHCPDISCOVER broadcasts; set PUBLIC_IP to this
|
||||||
|
# host's LAN address so advertised boot URLs are reachable.
|
||||||
# 3. Run it on the box plugged into your PXE network. Set PUBLIC_IP to
|
docker run -d --name openpxe --network host \
|
||||||
# this host's LAN address so advertised iPXE URLs are reachable.
|
|
||||||
docker run -d --name openpxe \
|
|
||||||
--network host \
|
|
||||||
-e OPENPXE_PUBLIC_IP=10.0.0.5 \
|
-e OPENPXE_PUBLIC_IP=10.0.0.5 \
|
||||||
-e OPENPXE_DHCP_MODE=proxy \
|
-e OPENPXE_DHCP_MODE=proxy \
|
||||||
-v $PWD/data/isos:/var/lib/openpxe/isos \
|
-v $PWD/data/isos:/var/lib/openpxe/isos \
|
||||||
-v $PWD/data/work:/var/lib/openpxe/work \
|
-v $PWD/data/work:/var/lib/openpxe/work \
|
||||||
openpxe:0.4.1
|
openpxe:0.5.5
|
||||||
|
|
||||||
# 4. Open the UI and drop an ISO in.
|
# Open the UI and drop an ISO in.
|
||||||
open http://10.0.0.5
|
open http://10.0.0.5
|
||||||
```
|
```
|
||||||
|
|
||||||
Host networking is required in proxy mode so the container sees DHCPDISCOVER
|
> On macOS/Windows, Docker runs inside a Linux VM, so "host network" means the VM — use
|
||||||
broadcasts from the PXE VLAN. On macOS/Windows hosts Docker runs in a Linux
|
> the `openpxe-dev` service in `docker-compose.yml` for API-only testing on a laptop:
|
||||||
VM, so "host" means the VM — use `openpxe-dev` in `docker-compose.yml` for
|
> `OPENPXE_PUBLIC_IP=127.0.0.1 docker compose up openpxe-dev`.
|
||||||
API-only testing on a laptop.
|
|
||||||
|
|
||||||
### Quick start — docker compose
|
### Build from source
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# MVP / API testing on a laptop (no DHCP, high ports):
|
./scripts/fetch-ipxe.sh # populate assets/ipxe/ (embedded at compile time)
|
||||||
OPENPXE_PUBLIC_IP=127.0.0.1 docker compose up openpxe-dev
|
cargo run --release # needs root or CAP_NET_BIND_SERVICE for :80/:69
|
||||||
# Real PXE deployment on a Linux host (host network, DHCP proxy on):
|
|
||||||
OPENPXE_PUBLIC_IP=10.0.0.5 docker compose up openpxe
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Multi-arch build + push
|
### Pre-seed ISOs from a directory
|
||||||
|
|
||||||
For deploying to x86_64 servers, build both arches in one manifest:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# One-time: bootstrap a multi-arch builder.
|
|
||||||
docker buildx create --name openpxe-multi --driver docker-container --use
|
|
||||||
|
|
||||||
# Build + push both linux/amd64 and linux/arm64 under one tag.
|
|
||||||
docker buildx build --builder openpxe-multi \
|
|
||||||
--platform linux/amd64,linux/arm64 \
|
|
||||||
-t ghcr.io/YOUR-ORG/openpxe:0.4.1 \
|
|
||||||
--push \
|
|
||||||
-f deploy/docker/Dockerfile .
|
|
||||||
```
|
|
||||||
|
|
||||||
On an Apple Silicon host, the amd64 stage runs under QEMU emulation (~10-15 min for a cold cache). On a Linux x86_64 host, both arches build natively at normal speed. CI runners on GitHub Actions with `docker/build-push-action@v5` handle this cleanly.
|
|
||||||
|
|
||||||
### Build from source (no container)
|
|
||||||
|
|
||||||
```bash
|
|
||||||
./scripts/fetch-ipxe.sh
|
|
||||||
cargo run --release # needs NET_BIND_SERVICE or root for :80/:69
|
|
||||||
```
|
|
||||||
|
|
||||||
### Container health probes
|
|
||||||
|
|
||||||
| Endpoint | Purpose |
|
|
||||||
|-------------|---------------------------------------------------------------|
|
|
||||||
| `/healthz` | Liveness — HTTP stack alive. Always 200. |
|
|
||||||
| `/readyz` | Readiness — 200 only if iPXE binaries bundled + ISO dir OK. |
|
|
||||||
| `/api/status` | Full JSON status: versions, assets, counts, live settings, SMB state. |
|
|
||||||
|
|
||||||
### Pre-seeding ISOs from a directory
|
|
||||||
|
|
||||||
For CI, pre-baked homelab deployments, or a fresh PVC, the binary has a
|
|
||||||
`seed` subcommand that imports every `*.iso` from a host path through the
|
|
||||||
same pipeline the web UI uses (introspection + boot-entry generation):
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-v /my/iso-library:/seed:ro \
|
-v /my/iso-library:/seed:ro \
|
||||||
-v openpxe-data:/var/lib/openpxe/isos \
|
-v openpxe-data:/var/lib/openpxe/isos \
|
||||||
-e OPENPXE_PUBLIC_IP=10.0.0.5 \
|
-e OPENPXE_PUBLIC_IP=10.0.0.5 \
|
||||||
openpxe:0.4.1 seed --from /seed
|
openpxe:0.5.5 seed --from /seed # add --dry-run to preview
|
||||||
|
|
||||||
# Dry run first to see what would be imported:
|
|
||||||
docker run --rm -v /my/iso-library:/seed:ro openpxe:0.4.1 seed --from /seed --dry-run
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Environment overrides
|
## Remote ISO libraries
|
||||||
|
|
||||||
| Var | Default | Meaning |
|
Point OpenPXE at a NAS and boot ISOs straight off it — **read on demand, no local copy**,
|
||||||
|------------------------|-----------------------------|----------------------------------------|
|
so a 50-ISO library costs zero disk on the OpenPXE host. All three clients are userspace
|
||||||
| `OPENPXE_HTTP_PORT` | `80` | Web UI + boot script HTTP port |
|
(no kernel mounts, no `CAP_SYS_ADMIN`); pick whichever your storage speaks.
|
||||||
| `OPENPXE_TFTP_PORT` | `69` | TFTP port |
|
|
||||||
| `OPENPXE_DHCP_PORT` | `67` | DHCP server-side port |
|
|
||||||
| `OPENPXE_DHCP_MODE` | `proxy` | `proxy` or `disabled` |
|
|
||||||
| `OPENPXE_PUBLIC_IP` | auto-detect | Advertised IP for clients. Startup **fails** if unset and auto-detect returns loopback. |
|
|
||||||
| `OPENPXE_ISO_DIR` | `/var/lib/openpxe/isos` | Where uploaded ISOs live |
|
|
||||||
| `OPENPXE_WORK_DIR` | `/var/lib/openpxe/work` | Scratch + runtime settings |
|
|
||||||
| `OPENPXE_LOG` | `info,openpxe=debug` | `tracing` filter |
|
|
||||||
|
|
||||||
## What the boot menu looks like on a real client
|
| Protocol | Implementation | Auth | HTTP Range¹ |
|
||||||
|
|----------|----------------|------|-------------|
|
||||||
|
| **NFS** (v3) | Pure-Rust in-process client | Client-IP (server export list) | ✅ |
|
||||||
|
| **SFTP** (SSH) | Pure-Rust in-process client (`russh`) | Password **or** SSH key · host-key TOFU | ✅ |
|
||||||
|
| **SMB** / CIFS | Userspace `smbclient` | Guest or username/password | — |
|
||||||
|
|
||||||
|
¹ Range support lets clients seek into a multi-GB ISO without downloading what comes
|
||||||
|
before it — needed for kernel/initrd extraction and `httpdisk`-style boots. NFS and SFTP
|
||||||
|
expose explicit offsets; the SMB CLI streams sequentially, so SMB-sourced ISOs serve whole-file.
|
||||||
|
|
||||||
|
## Supported client architectures
|
||||||
|
|
||||||
|
| DHCP option 93 | Architecture | Firmware served |
|
||||||
|
|----------------|--------------|-----------------|
|
||||||
|
| `0x0000` | Legacy x86 BIOS | `undionly.kpxe` |
|
||||||
|
| `0x0006` | IA32 UEFI | `snponly-i386.efi` |
|
||||||
|
| `0x0007` / `0x0009` | x86_64 UEFI | `snponly.efi` |
|
||||||
|
| `0x000B` | ARM64 UEFI | `snponly-arm64.efi` |
|
||||||
|
|
||||||
|
UEFI firmware that advertises `HTTPClient` (option 60) skips TFTP entirely and is handed an HTTP URL.
|
||||||
|
|
||||||
|
## The boot menu, on a real client
|
||||||
|
|
||||||
```
|
```
|
||||||
OpenPXE - network boot menu
|
OpenPXE — network boot menu
|
||||||
|
|
||||||
------------------------- Default -------------------------
|
------------------------- Default -------------------------
|
||||||
Boot from Local HDD
|
Boot from Local HDD
|
||||||
----------------------- Installers -----------------------
|
----------------------- Installers ------------------------
|
||||||
Linux Installers >
|
Linux Installers >
|
||||||
Windows Installers > (only if enabled in Settings)
|
Windows Installers > (only if enabled in Settings)
|
||||||
-------------------------- Tools --------------------------
|
-------------------------- Tools --------------------------
|
||||||
Tools > Utilities / Shell /
|
Tools > Utilities / OpenPXE Shell / NIC Info / Reboot
|
||||||
NIC Info / Reboot /
|
|
||||||
Exit and continue BIOS
|
|
||||||
---------------------- Queued Deployment ------------------
|
---------------------- Queued Deployment ------------------
|
||||||
Queued Deployment (join queue)
|
Queued Deployment (join queue)
|
||||||
```
|
```
|
||||||
|
|
||||||
Linux/Windows submenus show file sizes iVentoy-style:
|
Linux/Windows submenus list images iVentoy-style with sizes:
|
||||||
|
|
||||||
```
|
```
|
||||||
OpenPXE - Linux Installers
|
OpenPXE — Linux Installers
|
||||||
|
|
||||||
[ 4376 MB] CentOS-7-x86_64-DVD-1810
|
|
||||||
[ 2002 MB] Fedora-Workstation-Live-x86_64-38-1.6
|
|
||||||
[ 4699 MB] ubuntu-22.04.2-desktop-amd64
|
[ 4699 MB] ubuntu-22.04.2-desktop-amd64
|
||||||
|
[ 2002 MB] Fedora-Workstation-Live-x86_64-38-1.6
|
||||||
< Back to main menu
|
< Back to main menu
|
||||||
```
|
```
|
||||||
|
|
||||||
iPXE never appears in the UI — the whole hierarchy above is generated from
|
The entire hierarchy is generated from what you upload and toggle — iPXE never surfaces.
|
||||||
ISOs you upload via drag-and-drop in the web UI plus toggles in Settings.
|
|
||||||
|
## Windows deployment
|
||||||
|
|
||||||
|
Enable **Windows ISO support** in Settings, then upload a **stock, unmodified** Microsoft ISO:
|
||||||
|
|
||||||
|
1. On upload, OpenPXE uses `wimlib-imagex` to inject exactly two plain-text files into the
|
||||||
|
WinPE image (`winpeshl.ini` + `startnet.cmd`) — no drivers, no certificates.
|
||||||
|
2. The container's Samba `smbd` serves the extracted install tree on `:445`.
|
||||||
|
3. The client chainloads `wimboot` → patched WinPE → Windows Setup running off the share.
|
||||||
|
|
||||||
|
**Every executable the client runs is stock Microsoft-signed.** OpenPXE never ships
|
||||||
|
drivers, never installs certificates into the client trust store, and never recommends
|
||||||
|
`bcdedit /set testsigning on`. The SMB approach is adapted (re-implemented, not copied)
|
||||||
|
from [Bootimus](https://github.com/garybowers/bootimus) (Apache-2.0). Port `445` must be
|
||||||
|
directly reachable from clients; Windows 10/11 client SKUs are the tested target.
|
||||||
|
|
||||||
|
## Configuration
|
||||||
|
|
||||||
|
All settings have defaults and layer **defaults → TOML (`--config` / `OPENPXE_CONFIG`) →
|
||||||
|
`OPENPXE_*` env**. The common knobs:
|
||||||
|
|
||||||
|
| Var | Default | Meaning |
|
||||||
|
|-----|---------|---------|
|
||||||
|
| `OPENPXE_PUBLIC_IP` | auto-detect | IP advertised to clients. **Startup fails** if unset and auto-detect yields loopback. |
|
||||||
|
| `OPENPXE_DHCP_MODE` | `proxy` | `proxy` or `disabled` |
|
||||||
|
| `OPENPXE_HTTP_PORT` | `80` | Web UI + boot-script HTTP port |
|
||||||
|
| `OPENPXE_TFTP_PORT` | `69` | TFTP port |
|
||||||
|
| `OPENPXE_DHCP_PORT` | `67` | DHCP server-side port |
|
||||||
|
| `OPENPXE_ISO_DIR` | `/var/lib/openpxe/isos` | Uploaded ISOs |
|
||||||
|
| `OPENPXE_WORK_DIR` | `/var/lib/openpxe/work` | Scratch, settings, share + branding state |
|
||||||
|
| `OPENPXE_LOG` | `info,openpxe=info` | `tracing` filter |
|
||||||
|
|
||||||
## OpenShift
|
## OpenShift
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
oc apply -f deploy/openshift/
|
oc apply -f deploy/openshift/
|
||||||
oc -n openpxe get all
|
|
||||||
oc -n openpxe get route openpxe -o jsonpath='{.spec.host}'
|
oc -n openpxe get route openpxe -o jsonpath='{.spec.host}'
|
||||||
```
|
```
|
||||||
|
|
||||||
### Why a custom SCC?
|
The bundled `openpxe-scc` grants exactly `hostNetwork` (CNI overlays don't deliver L2
|
||||||
|
broadcast into pod netns) and `NET_BIND_SERVICE` (to bind ports <1024) — nothing else.
|
||||||
|
No raw sockets, no privileged mode. The Route covers `80/TCP`; PXE clients reach UDP
|
||||||
|
67/69/4011 on the node's host IP directly.
|
||||||
|
|
||||||
The default `restricted-v2` blocks `hostNetwork` and all capabilities. PXE
|
## Health & observability
|
||||||
cannot work without host network (CNI overlays don't deliver L2 broadcast
|
|
||||||
into pod netns), and we need `NET_BIND_SERVICE` to bind <1024. The custom
|
|
||||||
`openpxe-scc` grants exactly those two and nothing else. No raw sockets,
|
|
||||||
no privileged mode — proxy-mode DHCP sidesteps the usual requirements.
|
|
||||||
|
|
||||||
### What's on host ports
|
| Endpoint | Purpose |
|
||||||
|
|----------|---------|
|
||||||
| Port | Proto | Purpose |
|
| `/healthz` | Liveness — always 200 if the HTTP stack is up. |
|
||||||
|----------|-------|---------------------------------|
|
| `/readyz` | Readiness — 200 only once iPXE firmware is bundled and the ISO dir is reachable. |
|
||||||
| 67 | UDP | DHCP server (proxy replies) |
|
| `/api/status` | Full JSON: version, assets, counts, live settings, share + SMB state. |
|
||||||
| 69 | UDP | TFTP |
|
| `/metrics` | Prometheus text format — DHCP replies by arch, TFTP/HTTP counts, queue gauges, uptime. |
|
||||||
| 4011 | UDP | PXE Boot Server discovery |
|
|
||||||
| 80 | TCP | Web UI + HTTP boot assets |
|
|
||||||
|
|
||||||
The OpenShift Route only covers 80/TCP. Clients on the PXE network talk to
|
|
||||||
the node's host IP directly for UDP.
|
|
||||||
|
|
||||||
## Windows support
|
|
||||||
|
|
||||||
Enabled by toggling **Windows ISO support** under Settings. The flow:
|
|
||||||
|
|
||||||
1. Upload a stock Microsoft Windows install ISO (vanilla, no pre-processing).
|
|
||||||
2. On upload, OpenPXE extracts the ISO and uses `wimlib-imagex` to rewrite
|
|
||||||
image index 2 (WinPE) of `sources/boot.wim`. It injects exactly two
|
|
||||||
plain-text files:
|
|
||||||
- `Windows/System32/winpeshl.ini` — tells WinPE to run `startnet.cmd`.
|
|
||||||
- `Windows/System32/startnet.cmd` — runs `wpeinit`, waits for the SMB
|
|
||||||
host to be reachable, `net use Z: \\<server>\<share> /user:guest`,
|
|
||||||
then `Z:\setup.exe`.
|
|
||||||
3. The container's Samba `smbd` serves the extracted install tree on :445.
|
|
||||||
4. The client gets chainloaded into wimboot → patched WinPE → Windows Setup
|
|
||||||
running off the SMB share. **Every binary the client executes is stock
|
|
||||||
Microsoft-signed.**
|
|
||||||
|
|
||||||
### What we never do
|
|
||||||
|
|
||||||
- Ship drivers — signed, test-signed, or otherwise — that load on the client.
|
|
||||||
- Install certificates into the target's trust store or WinPE boot policy.
|
|
||||||
- Recommend `bcdedit /set testsigning on` or any equivalent signing-policy
|
|
||||||
weakening.
|
|
||||||
|
|
||||||
### Credit & limitations
|
|
||||||
|
|
||||||
The SMB-based approach is adapted from [Bootimus](https://github.com/garybowers/bootimus)
|
|
||||||
(Apache-2.0). Re-implemented in Rust; no code was copied verbatim. Known
|
|
||||||
operational constraints inherited from the design:
|
|
||||||
|
|
||||||
- **Port 445 must be directly reachable from PXE clients.** `net use`
|
|
||||||
ignores alternate ports. In OpenShift this means `hostPort: 445` on the
|
|
||||||
deployment; on a host that already runs SMB it will collide.
|
|
||||||
- Windows 10/11 client SKUs are the tested target. Server SKUs untested.
|
|
||||||
- Hardware with NICs/storage controllers missing from WinPE's bundled
|
|
||||||
drivers will need a driver-pack injection step (not yet implemented).
|
|
||||||
|
|
||||||
## Queued Deployment
|
|
||||||
|
|
||||||
The coordinated launch flow, end to end:
|
|
||||||
|
|
||||||
1. A client boots and picks **Queued Deployment** in the PXE menu (or falls
|
|
||||||
through on timeout with the default `timeout_action`).
|
|
||||||
2. The client joins the queue, gets a numbered queue position, and enters a
|
|
||||||
long-poll loop (25s per request, auto-renewed).
|
|
||||||
3. In the web UI's **Queued Deployment** tab, the operator sees each waiting
|
|
||||||
client with its MAC, IP, arch, and position.
|
|
||||||
4. The operator selects an image and clicks **Launch for all waiting**.
|
|
||||||
The server broadcasts the assignment to every queued client via a
|
|
||||||
`tokio::sync::Notify`; each client's next poll returns the boot script
|
|
||||||
for the chosen image.
|
|
||||||
5. Every client chains the same image at effectively the same moment. The
|
|
||||||
queue stays visible until the operator releases entries, which keeps a
|
|
||||||
useful audit trail during hardware testing.
|
|
||||||
|
|
||||||
No user-facing iPXE anywhere in this flow. The client only ever runs
|
|
||||||
scripts we generate; the operator only interacts with the web UI.
|
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
See [`docs/architecture.md`](docs/architecture.md) for the protocol stack,
|
Workspace of focused crates — `core`, `dhcp-proxy`, `tftp`, `http-api`, `iso-store`,
|
||||||
crate layout, and the full decision log.
|
`ipxe-assets`, `webui`, and the `openpxe` binary. See
|
||||||
|
[`docs/architecture.md`](docs/architecture.md) for the protocol stack, crate layout, and
|
||||||
|
the full decision log.
|
||||||
|
|
||||||
## Licence
|
## License
|
||||||
|
|
||||||
MIT OR Apache-2.0.
|
Dual-licensed under **MIT OR Apache-2.0** — use whichever fits your project.
|
||||||
|
|||||||
+136
-4
@@ -37,8 +37,8 @@ use openpxe_core::{
|
|||||||
};
|
};
|
||||||
use openpxe_ipxe_assets::asset_bytes;
|
use openpxe_ipxe_assets::asset_bytes;
|
||||||
use openpxe_iso_store::{
|
use openpxe_iso_store::{
|
||||||
render_template, IsoCategory, IsoMeta, IsoSource, NfsAddRequest, SmbAddRequest, SmbState,
|
render_template, IsoCategory, IsoMeta, IsoSource, NfsAddRequest, SftpAddRequest, SmbAddRequest,
|
||||||
UnattendedKind, UnattendedMeta,
|
SmbState, UnattendedKind, UnattendedMeta,
|
||||||
};
|
};
|
||||||
use serde::{Deserialize, Serialize};
|
use serde::{Deserialize, Serialize};
|
||||||
use serde_json::json;
|
use serde_json::json;
|
||||||
@@ -188,6 +188,15 @@ pub fn build_router(state: AppState) -> Router {
|
|||||||
)
|
)
|
||||||
.route("/api/nfs-shares/:id", delete(api_nfs_shares_remove))
|
.route("/api/nfs-shares/:id", delete(api_nfs_shares_remove))
|
||||||
.route("/api/nfs-shares/:id/scan", post(api_nfs_shares_scan))
|
.route("/api/nfs-shares/:id/scan", post(api_nfs_shares_scan))
|
||||||
|
// v0.5.5: SFTP-over-SSH share manager (pure-Rust russh client).
|
||||||
|
// Parallel to SMB/NFS so the UI reuses the same form/error/hint
|
||||||
|
// rendering. Like NFS, SFTP-sourced ISOs support Range requests.
|
||||||
|
.route(
|
||||||
|
"/api/sftp-shares",
|
||||||
|
get(api_sftp_shares_list).post(api_sftp_shares_add),
|
||||||
|
)
|
||||||
|
.route("/api/sftp-shares/:id", delete(api_sftp_shares_remove))
|
||||||
|
.route("/api/sftp-shares/:id/scan", post(api_sftp_shares_scan))
|
||||||
// Phase 4: Network info (read-only) + DNS edit.
|
// Phase 4: Network info (read-only) + DNS edit.
|
||||||
.route("/api/network", get(api_network).put(api_network_put))
|
.route("/api/network", get(api_network).put(api_network_put))
|
||||||
// Phase 4: live-log stream + recent buffer for the Terminal tab.
|
// Phase 4: live-log stream + recent buffer for the Terminal tab.
|
||||||
@@ -856,6 +865,57 @@ async fn iso_raw(
|
|||||||
Err(e) => (StatusCode::BAD_GATEWAY, format!("nfs stream: {e}")).into_response(),
|
Err(e) => (StatusCode::BAD_GATEWAY, format!("nfs stream: {e}")).into_response(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
IsoSource::Sftp {
|
||||||
|
share_id,
|
||||||
|
relative_path,
|
||||||
|
} => {
|
||||||
|
// v0.5.5: SFTP sources support Range requests because SFTP
|
||||||
|
// opens a seekable file handle (seek to offset, then bounded
|
||||||
|
// reads). Identical handling to the NFS arm above.
|
||||||
|
let total = meta.size_bytes;
|
||||||
|
let range = match parse_range(headers.get(header::RANGE), total) {
|
||||||
|
Some(triple) => triple,
|
||||||
|
None if headers.get(header::RANGE).is_some() => {
|
||||||
|
return Response::builder()
|
||||||
|
.status(StatusCode::RANGE_NOT_SATISFIABLE)
|
||||||
|
.header(header::CONTENT_RANGE, format!("bytes */{total}"))
|
||||||
|
.body(Body::empty())
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
// No Range header — serve the whole file.
|
||||||
|
None => (0, total.saturating_sub(1), false),
|
||||||
|
};
|
||||||
|
let (start, end, partial) = range;
|
||||||
|
let len = if total == 0 { 0 } else { end - start + 1 };
|
||||||
|
let max_len = if total == 0 { None } else { Some(len) };
|
||||||
|
match state
|
||||||
|
.sftp_shares
|
||||||
|
.stream_iso(share_id, relative_path, start, max_len)
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(stream) => {
|
||||||
|
let body = Body::from_stream(stream);
|
||||||
|
let status = if partial {
|
||||||
|
StatusCode::PARTIAL_CONTENT
|
||||||
|
} else {
|
||||||
|
StatusCode::OK
|
||||||
|
};
|
||||||
|
let mut builder = Response::builder()
|
||||||
|
.status(status)
|
||||||
|
.header(header::CONTENT_TYPE, "application/octet-stream")
|
||||||
|
.header(header::ACCEPT_RANGES, "bytes")
|
||||||
|
.header(header::CONTENT_LENGTH, len);
|
||||||
|
if partial {
|
||||||
|
builder = builder.header(
|
||||||
|
header::CONTENT_RANGE,
|
||||||
|
format!("bytes {start}-{end}/{total}"),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
builder.body(body).unwrap()
|
||||||
|
}
|
||||||
|
Err(e) => (StatusCode::BAD_GATEWAY, format!("sftp stream: {e}")).into_response(),
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1490,6 +1550,19 @@ async fn api_docs() -> Json<serde_json::Value> {
|
|||||||
"summary": "Re-list a share for new ISOs."},
|
"summary": "Re-list a share for new ISOs."},
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"name": "SFTP shares",
|
||||||
|
"endpoints": [
|
||||||
|
{"method": "GET", "path": "/api/sftp-shares",
|
||||||
|
"summary": "List configured SFTP-over-SSH shares with connection state and iso counts."},
|
||||||
|
{"method": "POST", "path": "/api/sftp-shares",
|
||||||
|
"summary": "Register an SFTP share. Body: { server, export, username, port?, password? | private_key? + passphrase? }. The server's SSH host key is pinned trust-on-first-use."},
|
||||||
|
{"method": "DELETE", "path": "/api/sftp-shares/:id",
|
||||||
|
"summary": "Forget a share, drop its entries from the ISO store, and scrub its credentials file."},
|
||||||
|
{"method": "POST", "path": "/api/sftp-shares/:id/scan",
|
||||||
|
"summary": "Re-list a share for new ISOs."},
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"name": "Network",
|
"name": "Network",
|
||||||
"endpoints": [
|
"endpoints": [
|
||||||
@@ -1963,6 +2036,8 @@ struct StatusResponse {
|
|||||||
smb_share_reachable: usize,
|
smb_share_reachable: usize,
|
||||||
nfs_share_count: usize,
|
nfs_share_count: usize,
|
||||||
nfs_share_reachable: usize,
|
nfs_share_reachable: usize,
|
||||||
|
sftp_share_count: usize,
|
||||||
|
sftp_share_reachable: usize,
|
||||||
host_bindings: usize,
|
host_bindings: usize,
|
||||||
custom_logo: bool,
|
custom_logo: bool,
|
||||||
branding: BrandingStatus,
|
branding: BrandingStatus,
|
||||||
@@ -1983,6 +2058,9 @@ async fn api_status(State(state): State<AppState>) -> Json<StatusResponse> {
|
|||||||
let smb_reachable = smb_shares.iter().filter(|m| m.reachable).count();
|
let smb_reachable = smb_shares.iter().filter(|m| m.reachable).count();
|
||||||
let nfs_shares = state.nfs_shares.list();
|
let nfs_shares = state.nfs_shares.list();
|
||||||
let nfs_reachable = nfs_shares.iter().filter(|m| m.reachable).count();
|
let nfs_reachable = nfs_shares.iter().filter(|m| m.reachable).count();
|
||||||
|
// v0.5.5: SFTP shares fold into the same "reachable shares" tile.
|
||||||
|
let sftp_shares = state.sftp_shares.list();
|
||||||
|
let sftp_reachable = sftp_shares.iter().filter(|m| m.reachable).count();
|
||||||
let isos = state.iso_store.list();
|
let isos = state.iso_store.list();
|
||||||
let clients = state.clients.list();
|
let clients = state.clients.list();
|
||||||
let queue_entries = state.queue.list();
|
let queue_entries = state.queue.list();
|
||||||
@@ -2003,7 +2081,7 @@ async fn api_status(State(state): State<AppState>) -> Json<StatusResponse> {
|
|||||||
.set_queue_counts(queue_entries.len() as u64, imaging as u64);
|
.set_queue_counts(queue_entries.len() as u64, imaging as u64);
|
||||||
state
|
state
|
||||||
.metrics
|
.metrics
|
||||||
.set_nfs_active((smb_reachable + nfs_reachable) as u64);
|
.set_nfs_active((smb_reachable + nfs_reachable + sftp_reachable) as u64);
|
||||||
state.metrics.record_http(openpxe_core::HttpRoute::Api);
|
state.metrics.record_http(openpxe_core::HttpRoute::Api);
|
||||||
let now = time::OffsetDateTime::now_utc();
|
let now = time::OffsetDateTime::now_utc();
|
||||||
let uptime_secs = (now - state.started_at).whole_seconds().max(0);
|
let uptime_secs = (now - state.started_at).whole_seconds().max(0);
|
||||||
@@ -2025,6 +2103,9 @@ async fn api_status(State(state): State<AppState>) -> Json<StatusResponse> {
|
|||||||
// metric works regardless of protocol mix.
|
// metric works regardless of protocol mix.
|
||||||
nfs_share_count: nfs_shares.len(),
|
nfs_share_count: nfs_shares.len(),
|
||||||
nfs_share_reachable: nfs_reachable,
|
nfs_share_reachable: nfs_reachable,
|
||||||
|
// v0.5.5: SFTP share counts, summed into the same dashboard tile.
|
||||||
|
sftp_share_count: sftp_shares.len(),
|
||||||
|
sftp_share_reachable: sftp_reachable,
|
||||||
host_bindings: state.hosts.len(),
|
host_bindings: state.hosts.len(),
|
||||||
custom_logo: state.branding.has_any_web_logo(),
|
custom_logo: state.branding.has_any_web_logo(),
|
||||||
branding: BrandingStatus {
|
branding: BrandingStatus {
|
||||||
@@ -2348,6 +2429,48 @@ async fn api_nfs_shares_scan(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ─── SFTP share API (v0.5.5) ───────────────────────────────────────────────
|
||||||
|
//
|
||||||
|
// Parallel to the NFS shares API. The pure-Rust `russh` + `russh-sftp`
|
||||||
|
// client gives us in-process listing and streaming, no subprocess. Like
|
||||||
|
// NFS (and unlike SMB), SFTP-sourced ISOs support HTTP Range requests —
|
||||||
|
// SFTP opens a seekable file handle. Auth is password OR SSH private
|
||||||
|
// key; the server's host key is pinned trust-on-first-use.
|
||||||
|
|
||||||
|
async fn api_sftp_shares_list(State(state): State<AppState>) -> Json<serde_json::Value> {
|
||||||
|
Json(json!({ "shares": state.sftp_shares.list() }))
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn api_sftp_shares_add(
|
||||||
|
State(state): State<AppState>,
|
||||||
|
Json(req): Json<SftpAddRequest>,
|
||||||
|
) -> Response {
|
||||||
|
match state.sftp_shares.add(req).await {
|
||||||
|
Ok(s) => (StatusCode::CREATED, Json(s)).into_response(),
|
||||||
|
Err(err) => (StatusCode::BAD_REQUEST, Json(err)).into_response(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn api_sftp_shares_remove(
|
||||||
|
State(state): State<AppState>,
|
||||||
|
AxumPath(id): AxumPath<String>,
|
||||||
|
) -> Response {
|
||||||
|
match state.sftp_shares.remove(&id).await {
|
||||||
|
Ok(()) => StatusCode::NO_CONTENT.into_response(),
|
||||||
|
Err(e) => (StatusCode::INTERNAL_SERVER_ERROR, format!("{e}")).into_response(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn api_sftp_shares_scan(
|
||||||
|
State(state): State<AppState>,
|
||||||
|
AxumPath(id): AxumPath<String>,
|
||||||
|
) -> Response {
|
||||||
|
match state.sftp_shares.rescan(&id).await {
|
||||||
|
Ok(n) => Json(json!({ "ok": true, "iso_count": n })).into_response(),
|
||||||
|
Err(e) => (StatusCode::BAD_REQUEST, format!("{e}")).into_response(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// ─── Network info API ──────────────────────────────────────────────────────
|
// ─── Network info API ──────────────────────────────────────────────────────
|
||||||
|
|
||||||
async fn api_network(State(state): State<AppState>) -> Json<serde_json::Value> {
|
async fn api_network(State(state): State<AppState>) -> Json<serde_json::Value> {
|
||||||
@@ -2715,7 +2838,16 @@ async fn api_metrics(State(state): State<AppState>) -> Response {
|
|||||||
.iter()
|
.iter()
|
||||||
.filter(|m| m.reachable)
|
.filter(|m| m.reachable)
|
||||||
.count();
|
.count();
|
||||||
state.metrics.set_nfs_active((smb_ok + nfs_ok) as u64);
|
// v0.5.5: SFTP shares fold into the same reachable-shares gauge.
|
||||||
|
let sftp_ok = state
|
||||||
|
.sftp_shares
|
||||||
|
.list()
|
||||||
|
.iter()
|
||||||
|
.filter(|m| m.reachable)
|
||||||
|
.count();
|
||||||
|
state
|
||||||
|
.metrics
|
||||||
|
.set_nfs_active((smb_ok + nfs_ok + sftp_ok) as u64);
|
||||||
|
|
||||||
let now = time::OffsetDateTime::now_utc();
|
let now = time::OffsetDateTime::now_utc();
|
||||||
let uptime = (now - state.started_at).whole_seconds().max(0) as u64;
|
let uptime = (now - state.started_at).whole_seconds().max(0) as u64;
|
||||||
|
|||||||
@@ -61,16 +61,24 @@ pub fn render_menu(isos: &[IsoMeta], settings: &Settings, base_url: &str) -> Str
|
|||||||
// returns a full-screen 1024×768 PNG now — the operator's logo on a
|
// returns a full-screen 1024×768 PNG now — the operator's logo on a
|
||||||
// dark field, or a default OpenPXE mark when none is uploaded. The
|
// dark field, or a default OpenPXE mark when none is uploaded. The
|
||||||
// `--top 290` reserves the top band (where the logo paints) so the
|
// `--top 290` reserves the top band (where the logo paints) so the
|
||||||
// menu text lands below it. On an iPXE build *with* `IMAGE_PNG` +
|
// menu text lands below it.
|
||||||
// `CONSOLE_FRAMEBUFFER` (our x86_64 UEFI binaries, built from source
|
//
|
||||||
// — see deploy/docker/Dockerfile) this paints the background and
|
// v0.5.7: gate the whole command behind `iseq ${platform} efi`.
|
||||||
// overlays the menu. On a build *without* PNG support (the fetched
|
// `console --picture` needs IMAGE_PNG + CONSOLE_FRAMEBUFFER, which
|
||||||
// BIOS/i386/arm64 binaries) the whole `console --picture …` command
|
// only our from-source UEFI binaries carry (x86_64/arm64 UEFI — see
|
||||||
// fails and the `|| console` resets to a clean full-screen text
|
// deploy/docker/Dockerfile). The fetched BIOS `undionly.kpxe` has
|
||||||
// menu. Either way there's no ASCII placeholder anymore.
|
// neither, and on legacy BIOS the `--picture` attempt misbehaves
|
||||||
|
// *before* the trailing `|| console` fallback can recover (it tries
|
||||||
|
// to set a framebuffer mode the BIOS console can't honour). Guarding
|
||||||
|
// on platform means BIOS clients never issue the command at all —
|
||||||
|
// they drop straight to the plain text menu — while UEFI clients
|
||||||
|
// still get the graphical background. A PNG-less UEFI build (e.g. the
|
||||||
|
// upstream i386-efi baseline) still falls back gracefully through the
|
||||||
|
// same `|| console`. No operator toggle needed; mixed BIOS+UEFI
|
||||||
|
// fleets each get the right treatment automatically.
|
||||||
let _ = writeln!(
|
let _ = writeln!(
|
||||||
s,
|
s,
|
||||||
"console --picture {base}/branding/pxe-logo --top 290 || console"
|
"iseq ${{platform}} efi && console --picture {base}/branding/pxe-logo --top 290 || console"
|
||||||
);
|
);
|
||||||
// Map iPXE's ${{buildarch}} + ${{platform}} into the human form the
|
// Map iPXE's ${{buildarch}} + ${{platform}} into the human form the
|
||||||
// user asked for (e.g. "x86 BIOS", "x86_64 UEFI", "arm64 UEFI").
|
// user asked for (e.g. "x86 BIOS", "x86_64 UEFI", "arm64 UEFI").
|
||||||
|
|||||||
+1
-1
@@ -7,7 +7,7 @@ expression: rendered
|
|||||||
set base-url http://10.0.0.5
|
set base-url http://10.0.0.5
|
||||||
set esc:hex 1b
|
set esc:hex 1b
|
||||||
set cls ${esc:string}[2J
|
set cls ${esc:string}[2J
|
||||||
console --picture http://10.0.0.5/branding/pxe-logo --top 290 || console
|
iseq ${platform} efi && console --picture http://10.0.0.5/branding/pxe-logo --top 290 || console
|
||||||
set arch-label ${buildarch} ${platform}
|
set arch-label ${buildarch} ${platform}
|
||||||
iseq ${buildarch} i386 && iseq ${platform} pcbios && set arch-label x86 BIOS || iseq ${buildarch} x86_64 && iseq ${platform} efi && set arch-label x86_64 UEFI || iseq ${buildarch} arm64 && iseq ${platform} efi && set arch-label arm64 UEFI || true
|
iseq ${buildarch} i386 && iseq ${platform} pcbios && set arch-label x86 BIOS || iseq ${buildarch} x86_64 && iseq ${platform} efi && set arch-label x86_64 UEFI || iseq ${buildarch} arm64 && iseq ${platform} efi && set arch-label arm64 UEFI || true
|
||||||
:menu
|
:menu
|
||||||
|
|||||||
@@ -5,7 +5,9 @@ use openpxe_core::{
|
|||||||
AdminStore, BootLog, BrandingStore, ClientRegistry, DeploymentQueue, HostBindings, LogBus,
|
AdminStore, BootLog, BrandingStore, ClientRegistry, DeploymentQueue, HostBindings, LogBus,
|
||||||
Metrics, NotifyStore, SettingsStore, SsoStore,
|
Metrics, NotifyStore, SettingsStore, SsoStore,
|
||||||
};
|
};
|
||||||
use openpxe_iso_store::{IsoStore, NfsShareManager, SmbManager, SmbShareManager, UnattendedStore};
|
use openpxe_iso_store::{
|
||||||
|
IsoStore, NfsShareManager, SftpShareManager, SmbManager, SmbShareManager, UnattendedStore,
|
||||||
|
};
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
use time::OffsetDateTime;
|
use time::OffsetDateTime;
|
||||||
|
|
||||||
@@ -67,6 +69,13 @@ pub struct AppState {
|
|||||||
/// In-process (no subprocess); supports HTTP Range requests on
|
/// In-process (no subprocess); supports HTTP Range requests on
|
||||||
/// NFS-sourced ISOs because NFSv3 READ3 takes an explicit offset.
|
/// NFS-sourced ISOs because NFSv3 READ3 takes an explicit offset.
|
||||||
pub nfs_shares: NfsShareManager,
|
pub nfs_shares: NfsShareManager,
|
||||||
|
/// v0.5.5: SFTP-over-SSH share manager — pure-Rust userspace
|
||||||
|
/// consumer via `russh` + `russh-sftp` (ring backend, no OpenSSL).
|
||||||
|
/// Ships alongside SMB/NFS as the third remote-library protocol.
|
||||||
|
/// In-process (no subprocess, no kernel mount); supports HTTP Range
|
||||||
|
/// requests because SFTP opens a seekable file handle. Authenticates
|
||||||
|
/// the server's SSH host key on a trust-on-first-use basis.
|
||||||
|
pub sftp_shares: SftpShareManager,
|
||||||
/// v0.5.2: uploaded unattended-install answer files (Kickstart /
|
/// v0.5.2: uploaded unattended-install answer files (Kickstart /
|
||||||
/// Preseed / Autoinstall / Windows answer files). Served on demand to
|
/// Preseed / Autoinstall / Windows answer files). Served on demand to
|
||||||
/// booting clients with per-host hostname/IP/MAC templating; lives in
|
/// booting clients with per-host hostname/IP/MAC templating; lives in
|
||||||
|
|||||||
+123
-12
@@ -96,6 +96,8 @@ async fn dispatch(state: &AppState, argv: &[String]) -> Result<String, String> {
|
|||||||
"share" | "smb-share" => smb_share_command(state, tail).await,
|
"share" | "smb-share" => smb_share_command(state, tail).await,
|
||||||
"smb" => smb_command(state, tail).await,
|
"smb" => smb_command(state, tail).await,
|
||||||
"nfs" => nfs_share_command(state, tail).await,
|
"nfs" => nfs_share_command(state, tail).await,
|
||||||
|
// v0.5.5: SFTP-over-SSH remote shares (in-process russh client).
|
||||||
|
"sftp" => sftp_share_command(state, tail).await,
|
||||||
"log" => log_command(state, tail),
|
"log" => log_command(state, tail),
|
||||||
"whoami" => Ok("operator".to_string()),
|
"whoami" => Ok("operator".to_string()),
|
||||||
"echo" => Ok(tail.join(" ")),
|
"echo" => Ok(tail.join(" ")),
|
||||||
@@ -118,17 +120,21 @@ fn status_text(s: &AppState) -> String {
|
|||||||
// v0.4.67: NFSv3 sources too.
|
// v0.4.67: NFSv3 sources too.
|
||||||
let nfs_shares = s.nfs_shares.list();
|
let nfs_shares = s.nfs_shares.list();
|
||||||
let nfs_reachable = nfs_shares.iter().filter(|m| m.reachable).count();
|
let nfs_reachable = nfs_shares.iter().filter(|m| m.reachable).count();
|
||||||
|
// v0.5.5: SFTP-over-SSH sources too.
|
||||||
|
let sftp_shares = s.sftp_shares.list();
|
||||||
|
let sftp_reachable = sftp_shares.iter().filter(|m| m.reachable).count();
|
||||||
format!(
|
format!(
|
||||||
"OpenPXE {ver}\n\
|
"OpenPXE {ver}\n\
|
||||||
base url: {base}\n\
|
base url: {base}\n\
|
||||||
interface: {nic}\n\
|
interface: {nic}\n\
|
||||||
uptime: {up}\n\
|
uptime: {up}\n\
|
||||||
isos: {n_isos} (local: {n_local}, smb: {n_smb}, nfs: {n_nfs})\n\
|
isos: {n_isos} (local: {n_local}, smb: {n_smb}, nfs: {n_nfs}, sftp: {n_sftp})\n\
|
||||||
clients: {n_clients}\n\
|
clients: {n_clients}\n\
|
||||||
queue: {n_entries}\n\
|
queue: {n_entries}\n\
|
||||||
smb server: {smb}\n\
|
smb server: {smb}\n\
|
||||||
smb shares: {n_smb_total} configured ({n_smb_active} reachable)\n\
|
smb shares: {n_smb_total} configured ({n_smb_active} reachable)\n\
|
||||||
nfs shares: {n_nfs_total} configured ({n_nfs_active} reachable)\n",
|
nfs shares: {n_nfs_total} configured ({n_nfs_active} reachable)\n\
|
||||||
|
sftp shares: {n_sftp_total} configured ({n_sftp_active} reachable)\n",
|
||||||
ver = env!("CARGO_PKG_VERSION"),
|
ver = env!("CARGO_PKG_VERSION"),
|
||||||
base = s.public_base_url,
|
base = s.public_base_url,
|
||||||
nic = if s.nic_name.is_empty() {
|
nic = if s.nic_name.is_empty() {
|
||||||
@@ -150,6 +156,10 @@ fn status_text(s: &AppState) -> String {
|
|||||||
.iter()
|
.iter()
|
||||||
.filter(|i| matches!(i.source, openpxe_iso_store::IsoSource::Nfs { .. }))
|
.filter(|i| matches!(i.source, openpxe_iso_store::IsoSource::Nfs { .. }))
|
||||||
.count(),
|
.count(),
|
||||||
|
n_sftp = isos
|
||||||
|
.iter()
|
||||||
|
.filter(|i| matches!(i.source, openpxe_iso_store::IsoSource::Sftp { .. }))
|
||||||
|
.count(),
|
||||||
n_clients = clients.len(),
|
n_clients = clients.len(),
|
||||||
n_entries = queue_entries.len(),
|
n_entries = queue_entries.len(),
|
||||||
smb = smb.map_or_else(|| "(disabled)".into(), |s| format!("{s:?}")),
|
smb = smb.map_or_else(|| "(disabled)".into(), |s| format!("{s:?}")),
|
||||||
@@ -157,6 +167,8 @@ fn status_text(s: &AppState) -> String {
|
|||||||
n_smb_active = smb_reachable,
|
n_smb_active = smb_reachable,
|
||||||
n_nfs_total = nfs_shares.len(),
|
n_nfs_total = nfs_shares.len(),
|
||||||
n_nfs_active = nfs_reachable,
|
n_nfs_active = nfs_reachable,
|
||||||
|
n_sftp_total = sftp_shares.len(),
|
||||||
|
n_sftp_active = sftp_reachable,
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -177,6 +189,8 @@ fn isos_text(s: &AppState) -> String {
|
|||||||
openpxe_iso_store::IsoSource::Smb { share_id, .. } => format!("smb:{share_id}"),
|
openpxe_iso_store::IsoSource::Smb { share_id, .. } => format!("smb:{share_id}"),
|
||||||
// v0.4.67: NFSv3 via in-process nfs3_client.
|
// v0.4.67: NFSv3 via in-process nfs3_client.
|
||||||
openpxe_iso_store::IsoSource::Nfs { share_id, .. } => format!("nfs:{share_id}"),
|
openpxe_iso_store::IsoSource::Nfs { share_id, .. } => format!("nfs:{share_id}"),
|
||||||
|
// v0.5.5: SFTP-over-SSH via in-process russh.
|
||||||
|
openpxe_iso_store::IsoSource::Sftp { share_id, .. } => format!("sftp:{share_id}"),
|
||||||
};
|
};
|
||||||
let _ = writeln!(
|
let _ = writeln!(
|
||||||
out,
|
out,
|
||||||
@@ -321,11 +335,9 @@ async fn smb_share_command(s: &AppState, args: &[String]) -> Result<String, Stri
|
|||||||
}
|
}
|
||||||
Some("add") => {
|
Some("add") => {
|
||||||
// share add //server/share [guest|user:password]
|
// share add //server/share [guest|user:password]
|
||||||
let target = args
|
let target = args.get(1).ok_or_else(|| {
|
||||||
.get(1)
|
"usage: share add //server/share [guest|user:password]".to_string()
|
||||||
.ok_or_else(|| {
|
})?;
|
||||||
"usage: share add //server/share [guest|user:password]".to_string()
|
|
||||||
})?;
|
|
||||||
// Accept either `//server/share` (UNC-style) or
|
// Accept either `//server/share` (UNC-style) or
|
||||||
// `server:share` (shorter to type).
|
// `server:share` (shorter to type).
|
||||||
let stripped = target.trim_start_matches('/').trim_start_matches('\\');
|
let stripped = target.trim_start_matches('/').trim_start_matches('\\');
|
||||||
@@ -401,11 +413,7 @@ async fn nfs_share_command(s: &AppState, args: &[String]) -> Result<String, Stri
|
|||||||
return Ok("(no NFS shares configured)".into());
|
return Ok("(no NFS shares configured)".into());
|
||||||
}
|
}
|
||||||
let mut out = String::new();
|
let mut out = String::new();
|
||||||
let _ = writeln!(
|
let _ = writeln!(out, "{:<24} {:<7} {:<6} TARGET", "ID", "STATUS", "ISOS");
|
||||||
out,
|
|
||||||
"{:<24} {:<7} {:<6} TARGET",
|
|
||||||
"ID", "STATUS", "ISOS"
|
|
||||||
);
|
|
||||||
for m in shares {
|
for m in shares {
|
||||||
let status = if m.reachable { "ok" } else { "down" };
|
let status = if m.reachable { "ok" } else { "down" };
|
||||||
let _ = writeln!(
|
let _ = writeln!(
|
||||||
@@ -476,6 +484,104 @@ async fn nfs_share_command(s: &AppState, args: &[String]) -> Result<String, Stri
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── sftp (v0.5.5) ────────────────────────────────────────────────────────
|
||||||
|
//
|
||||||
|
// Parallel to nfs_share_command. The terminal `add` only supports
|
||||||
|
// password auth — pasting a multiline PEM private key through the
|
||||||
|
// terminal is impractical, so key-based shares are added via the WebUI.
|
||||||
|
|
||||||
|
async fn sftp_share_command(s: &AppState, args: &[String]) -> Result<String, String> {
|
||||||
|
match args.first().map(String::as_str) {
|
||||||
|
None | Some("list") => {
|
||||||
|
let shares = s.sftp_shares.list();
|
||||||
|
if shares.is_empty() {
|
||||||
|
return Ok("(no SFTP shares configured)".into());
|
||||||
|
}
|
||||||
|
let mut out = String::new();
|
||||||
|
let _ = writeln!(out, "{:<24} {:<7} {:<6} TARGET", "ID", "STATUS", "ISOS");
|
||||||
|
for m in shares {
|
||||||
|
let status = if m.reachable { "ok" } else { "down" };
|
||||||
|
let _ = writeln!(
|
||||||
|
out,
|
||||||
|
"{:<24} {:<7} {:<6} {}@{}:{}",
|
||||||
|
truncate(&m.id, 24),
|
||||||
|
status,
|
||||||
|
m.iso_count,
|
||||||
|
m.username,
|
||||||
|
m.server,
|
||||||
|
m.export,
|
||||||
|
);
|
||||||
|
if let Some(e) = m.last_error {
|
||||||
|
let _ = writeln!(out, " error: {e}");
|
||||||
|
}
|
||||||
|
if let Some(h) = m.last_hint {
|
||||||
|
let _ = writeln!(out, " hint: {h}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(out)
|
||||||
|
}
|
||||||
|
Some("add") => {
|
||||||
|
// sftp add <user>@<server>:<export> <password> [port]
|
||||||
|
let target = args.get(1).ok_or_else(|| {
|
||||||
|
"usage: sftp add <user>@<server>:<export> <password> [port] \
|
||||||
|
(key auth: use the WebUI)"
|
||||||
|
.to_string()
|
||||||
|
})?;
|
||||||
|
let password = args
|
||||||
|
.get(2)
|
||||||
|
.ok_or_else(|| "a password is required (key auth: use the WebUI)".to_string())?;
|
||||||
|
let (user, rest) = target
|
||||||
|
.split_once('@')
|
||||||
|
.ok_or_else(|| "target must be 'user@server:/export'".to_string())?;
|
||||||
|
let (server, export) = rest
|
||||||
|
.split_once(':')
|
||||||
|
.ok_or_else(|| "target must be 'user@server:/export'".to_string())?;
|
||||||
|
let port = args.get(3).and_then(|s| s.parse::<u16>().ok());
|
||||||
|
let req = openpxe_iso_store::SftpAddRequest {
|
||||||
|
server: server.to_string(),
|
||||||
|
export: export.to_string(),
|
||||||
|
username: Some(user.to_string()),
|
||||||
|
port,
|
||||||
|
password: Some(password.clone()),
|
||||||
|
private_key: None,
|
||||||
|
passphrase: None,
|
||||||
|
};
|
||||||
|
match s.sftp_shares.add(req).await {
|
||||||
|
Ok(m) => Ok(format!("added {} ({} isos)", m.id, m.iso_count)),
|
||||||
|
Err(e) => {
|
||||||
|
let mut out = format!("add failed: {}", e.error);
|
||||||
|
if let Some(h) = e.hint {
|
||||||
|
out.push_str("\nhint: ");
|
||||||
|
out.push_str(&h);
|
||||||
|
}
|
||||||
|
Err(out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Some("remove") => {
|
||||||
|
let id = args
|
||||||
|
.get(1)
|
||||||
|
.ok_or_else(|| "usage: sftp remove <id>".to_string())?;
|
||||||
|
match s.sftp_shares.remove(id).await {
|
||||||
|
Ok(()) => Ok(format!("removed {id}")),
|
||||||
|
Err(e) => Err(format!("remove failed: {e}")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Some("scan") => {
|
||||||
|
let id = args
|
||||||
|
.get(1)
|
||||||
|
.ok_or_else(|| "usage: sftp scan <id>".to_string())?;
|
||||||
|
match s.sftp_shares.rescan(id).await {
|
||||||
|
Ok(n) => Ok(format!("re-scanned {id}: {n} isos")),
|
||||||
|
Err(e) => Err(format!("scan failed: {e}")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Some(other) => Err(format!(
|
||||||
|
"unknown sftp subcommand: {other}\ntry: sftp [list|add|remove|scan]"
|
||||||
|
)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// ── smb ────────────────────────────────────────────────────────────────
|
// ── smb ────────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[allow(clippy::unused_async)]
|
#[allow(clippy::unused_async)]
|
||||||
@@ -622,6 +728,11 @@ OpenPXE terminal — available commands:
|
|||||||
nfs remove <id> forget an NFS share
|
nfs remove <id> forget an NFS share
|
||||||
nfs scan <id> re-list an NFS share for new ISOs
|
nfs scan <id> re-list an NFS share for new ISOs
|
||||||
|
|
||||||
|
sftp list list configured SFTP-over-SSH shares
|
||||||
|
sftp add <user>@<srv>:<export> <pass> [port] add an SFTP share (key auth: WebUI)
|
||||||
|
sftp remove <id> forget an SFTP share
|
||||||
|
sftp scan <id> re-list an SFTP share for new ISOs
|
||||||
|
|
||||||
smb status outbound Samba state (Windows install media)
|
smb status outbound Samba state (Windows install media)
|
||||||
smb start | stop | reload control the outbound smbd
|
smb start | stop | reload control the outbound smbd
|
||||||
|
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ use axum::body::Body;
|
|||||||
use axum::http::{header, Request, StatusCode};
|
use axum::http::{header, Request, StatusCode};
|
||||||
use openpxe_core::{ClientRegistry, DeploymentQueue, HostBindings, LogBus, Metrics, SettingsStore};
|
use openpxe_core::{ClientRegistry, DeploymentQueue, HostBindings, LogBus, Metrics, SettingsStore};
|
||||||
use openpxe_http_api::{build_router, AppState};
|
use openpxe_http_api::{build_router, AppState};
|
||||||
use openpxe_iso_store::{IsoStore, NfsShareManager, SmbShareManager};
|
use openpxe_iso_store::{IsoStore, NfsShareManager, SftpShareManager, SmbShareManager};
|
||||||
use tempfile::tempdir;
|
use tempfile::tempdir;
|
||||||
use tower::ServiceExt;
|
use tower::ServiceExt;
|
||||||
|
|
||||||
@@ -96,6 +96,7 @@ async fn build_state() -> (AppState, tempfile::TempDir) {
|
|||||||
let settings = SettingsStore::load_or_default(dir.path());
|
let settings = SettingsStore::load_or_default(dir.path());
|
||||||
let smb_shares = SmbShareManager::new(dir.path(), iso_store.clone());
|
let smb_shares = SmbShareManager::new(dir.path(), iso_store.clone());
|
||||||
let nfs_shares = NfsShareManager::new(dir.path(), iso_store.clone());
|
let nfs_shares = NfsShareManager::new(dir.path(), iso_store.clone());
|
||||||
|
let sftp_shares = SftpShareManager::new(dir.path(), iso_store.clone());
|
||||||
let unattended = openpxe_iso_store::UnattendedStore::new(dir.path().join("unattended"));
|
let unattended = openpxe_iso_store::UnattendedStore::new(dir.path().join("unattended"));
|
||||||
unattended.ensure_dir().await.unwrap();
|
unattended.ensure_dir().await.unwrap();
|
||||||
let log_bus = LogBus::new(64);
|
let log_bus = LogBus::new(64);
|
||||||
@@ -124,6 +125,7 @@ async fn build_state() -> (AppState, tempfile::TempDir) {
|
|||||||
smb: None,
|
smb: None,
|
||||||
smb_shares,
|
smb_shares,
|
||||||
nfs_shares,
|
nfs_shares,
|
||||||
|
sftp_shares,
|
||||||
unattended,
|
unattended,
|
||||||
uploads: openpxe_http_api::uploads::UploadSessions::default(),
|
uploads: openpxe_http_api::uploads::UploadSessions::default(),
|
||||||
log_bus,
|
log_bus,
|
||||||
|
|||||||
@@ -39,6 +39,10 @@ image = { version = "0.25", default-features = false, features = ["png", "jpeg",
|
|||||||
# kernel mount. See crates/iso-store/src/nfs_share.rs for usage.
|
# kernel mount. See crates/iso-store/src/nfs_share.rs for usage.
|
||||||
nfs3_client = { workspace = true }
|
nfs3_client = { workspace = true }
|
||||||
nfs3_types = { workspace = true }
|
nfs3_types = { workspace = true }
|
||||||
|
# v0.5.5: pure-Rust SSH/SFTP client (ring backend) for the SFTP remote
|
||||||
|
# share path. See crates/iso-store/src/sftp_share.rs for usage.
|
||||||
|
russh = { workspace = true }
|
||||||
|
russh-sftp = { workspace = true }
|
||||||
# Needed for the Stream trait that wraps the mpsc receiver feeding
|
# Needed for the Stream trait that wraps the mpsc receiver feeding
|
||||||
# NFS read-loop bytes into axum's Body::from_stream.
|
# NFS read-loop bytes into axum's Body::from_stream.
|
||||||
futures = { workspace = true }
|
futures = { workspace = true }
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ pub mod entry;
|
|||||||
pub mod introspect;
|
pub mod introspect;
|
||||||
pub mod nfs_share;
|
pub mod nfs_share;
|
||||||
pub mod pxe_logo;
|
pub mod pxe_logo;
|
||||||
|
pub mod sftp_share;
|
||||||
pub mod smb;
|
pub mod smb;
|
||||||
pub mod smb_share;
|
pub mod smb_share;
|
||||||
pub mod store;
|
pub mod store;
|
||||||
@@ -40,6 +41,13 @@ pub use smb_share::{SmbAddRequest, SmbShare, SmbShareError, SmbShareManager, Smb
|
|||||||
// "works in any container" property as SMB, plus support for HTTP
|
// "works in any container" property as SMB, plus support for HTTP
|
||||||
// Range requests because NFSv3 READ3 takes an explicit offset.
|
// Range requests because NFSv3 READ3 takes an explicit offset.
|
||||||
pub use nfs_share::{NfsAddRequest, NfsShare, NfsShareError, NfsShareManager, NfsStream};
|
pub use nfs_share::{NfsAddRequest, NfsShare, NfsShareError, NfsShareManager, NfsStream};
|
||||||
|
// v0.5.5: SFTP-over-SSH remote shares via the pure-Rust `russh` +
|
||||||
|
// `russh-sftp` crates (ring backend — no OpenSSL, no new C deps). Like
|
||||||
|
// NFS, supports HTTP Range requests because SFTP opens a seekable file
|
||||||
|
// handle. See crates/iso-store/src/sftp_share.rs.
|
||||||
|
pub use sftp_share::{
|
||||||
|
SftpAddRequest, SftpAuthKind, SftpShare, SftpShareError, SftpShareManager, SftpStream,
|
||||||
|
};
|
||||||
pub use store::{
|
pub use store::{
|
||||||
generate_boot_entries_for, slugify_str, IsoCategory, IsoMeta, IsoSource, IsoStore, UploadHandle,
|
generate_boot_entries_for, slugify_str, IsoCategory, IsoMeta, IsoSource, IsoStore, UploadHandle,
|
||||||
};
|
};
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -24,6 +24,10 @@ use tokio::io::AsyncWriteExt;
|
|||||||
/// `nfs3_client` crate (in-process, no subprocess). Same "works in
|
/// `nfs3_client` crate (in-process, no subprocess). Same "works in
|
||||||
/// any container" property as SMB, plus Range requests work because
|
/// any container" property as SMB, plus Range requests work because
|
||||||
/// NFSv3 READ3 takes an explicit offset.
|
/// NFSv3 READ3 takes an explicit offset.
|
||||||
|
/// `Sftp` (v0.5.5) — remote SFTP-over-SSH share, streamed via the
|
||||||
|
/// pure-Rust `russh` + `russh-sftp` crates (in-process). Like NFS it
|
||||||
|
/// supports HTTP Range requests because SFTP opens a seekable file
|
||||||
|
/// handle (`SSH_FXP_READ` at offset).
|
||||||
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
|
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
|
||||||
#[serde(tag = "kind", rename_all = "snake_case")]
|
#[serde(tag = "kind", rename_all = "snake_case")]
|
||||||
pub enum IsoSource {
|
pub enum IsoSource {
|
||||||
@@ -42,6 +46,13 @@ pub enum IsoSource {
|
|||||||
/// Filename at the export root.
|
/// Filename at the export root.
|
||||||
relative_path: String,
|
relative_path: String,
|
||||||
},
|
},
|
||||||
|
/// v0.5.5: SFTP-over-SSH via the in-process `russh` + `russh-sftp`
|
||||||
|
/// crates.
|
||||||
|
Sftp {
|
||||||
|
share_id: String,
|
||||||
|
/// Filename at the export root.
|
||||||
|
relative_path: String,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Where the ISO lands in the PXE menu hierarchy.
|
/// Where the ISO lands in the PXE menu hierarchy.
|
||||||
@@ -299,11 +310,11 @@ impl IsoStore {
|
|||||||
None
|
None
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// SMB and NFS sources have no local path — they're
|
// SMB, NFS, and SFTP sources have no local path — they're
|
||||||
// streamed in-process. Callers must inspect the source
|
// streamed in-process. Callers must inspect the source
|
||||||
// kind first and dispatch to the appropriate share
|
// kind first and dispatch to the appropriate share
|
||||||
// manager.
|
// manager.
|
||||||
IsoSource::Smb { .. } | IsoSource::Nfs { .. } => None,
|
IsoSource::Smb { .. } | IsoSource::Nfs { .. } | IsoSource::Sftp { .. } => None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -363,9 +374,9 @@ impl IsoStore {
|
|||||||
pub fn drop_external_source(&self, share_id: &str) {
|
pub fn drop_external_source(&self, share_id: &str) {
|
||||||
let mut g = self.inner.write();
|
let mut g = self.inner.write();
|
||||||
g.isos.retain(|_, m| match &m.source {
|
g.isos.retain(|_, m| match &m.source {
|
||||||
IsoSource::Smb { share_id: sid, .. } | IsoSource::Nfs { share_id: sid, .. } => {
|
IsoSource::Smb { share_id: sid, .. }
|
||||||
sid != share_id
|
| IsoSource::Nfs { share_id: sid, .. }
|
||||||
}
|
| IsoSource::Sftp { share_id: sid, .. } => sid != share_id,
|
||||||
IsoSource::Local => true,
|
IsoSource::Local => true,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -659,7 +670,10 @@ mod tests {
|
|||||||
// good.
|
// good.
|
||||||
let s = linux_cmdline(DistroFamily::DebianUbuntu, "ubuntu-24-04");
|
let s = linux_cmdline(DistroFamily::DebianUbuntu, "ubuntu-24-04");
|
||||||
assert!(s.contains("boot=casper"), "{s}");
|
assert!(s.contains("boot=casper"), "{s}");
|
||||||
assert!(s.contains("iso-url=${base-url}/iso/ubuntu-24-04.iso"), "{s}");
|
assert!(
|
||||||
|
s.contains("iso-url=${base-url}/iso/ubuntu-24-04.iso"),
|
||||||
|
"{s}"
|
||||||
|
);
|
||||||
assert!(s.contains("ds=nocloud"), "{s}");
|
assert!(s.contains("ds=nocloud"), "{s}");
|
||||||
assert!(s.contains("ip=dhcp"), "{s}");
|
assert!(s.contains("ip=dhcp"), "{s}");
|
||||||
assert!(!s.contains("netboot=url"), "legacy option leaked: {s}");
|
assert!(!s.contains("netboot=url"), "legacy option leaked: {s}");
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ use openpxe_core::{
|
|||||||
};
|
};
|
||||||
use openpxe_dhcp_proxy::DhcpProxyServer;
|
use openpxe_dhcp_proxy::DhcpProxyServer;
|
||||||
use openpxe_http_api::{build_router, AppState};
|
use openpxe_http_api::{build_router, AppState};
|
||||||
use openpxe_iso_store::{IsoStore, NfsShareManager, SmbManager, SmbShareManager};
|
use openpxe_iso_store::{IsoStore, NfsShareManager, SftpShareManager, SmbManager, SmbShareManager};
|
||||||
use openpxe_tftp::TftpServer;
|
use openpxe_tftp::TftpServer;
|
||||||
use std::net::{Ipv4Addr, SocketAddr};
|
use std::net::{Ipv4Addr, SocketAddr};
|
||||||
use std::path::PathBuf;
|
use std::path::PathBuf;
|
||||||
@@ -94,14 +94,19 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
let public_base_url = format!("http://{our_ip}");
|
// v0.5.6: the advertised base URL must carry the HTTP port. Every
|
||||||
|
// client-facing URL (the DHCP-proxy iPXE filename, UEFI HTTP boot,
|
||||||
|
// and the menu's kernel/initrd/ISO links) is derived from this one
|
||||||
|
// string, so omitting the port silently pointed PXE clients at :80 —
|
||||||
|
// breaking every non-80 deployment (e.g. the Unraid template's 4200,
|
||||||
|
// chosen to dodge the webGUI). See `build_public_base_url`.
|
||||||
|
let public_base_url = build_public_base_url(our_ip, config.server.http_port);
|
||||||
|
|
||||||
let iso_store = IsoStore::new(config.paths.iso_dir.clone());
|
let iso_store = IsoStore::new(config.paths.iso_dir.clone());
|
||||||
iso_store.load_from_disk().await?;
|
iso_store.load_from_disk().await?;
|
||||||
// v0.5.2: unattended answer-file store (Kickstart/Preseed/Autoinstall/
|
// v0.5.2: unattended answer-file store (Kickstart/Preseed/Autoinstall/
|
||||||
// Windows answer files). Separate directory from the ISO store.
|
// Windows answer files). Separate directory from the ISO store.
|
||||||
let unattended =
|
let unattended = openpxe_iso_store::UnattendedStore::new(config.paths.unattended_dir.clone());
|
||||||
openpxe_iso_store::UnattendedStore::new(config.paths.unattended_dir.clone());
|
|
||||||
if let Err(e) = unattended.load_from_disk().await {
|
if let Err(e) = unattended.load_from_disk().await {
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
target: "openpxe::unattended",
|
target: "openpxe::unattended",
|
||||||
@@ -155,6 +160,19 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// v0.5.5: SFTP-over-SSH share manager — pure-Rust in-process
|
||||||
|
// consumer via `russh` + `russh-sftp` (ring backend, no OpenSSL).
|
||||||
|
// The third remote-library protocol alongside SMB/NFS; like NFS it
|
||||||
|
// works in any container (no subprocess, no kernel mount) and
|
||||||
|
// supports HTTP Range requests because SFTP file handles seek.
|
||||||
|
let sftp_shares = SftpShareManager::new(&config.paths.work_dir, iso_store.clone());
|
||||||
|
if let Err(e) = sftp_shares.load_and_rescan().await {
|
||||||
|
tracing::warn!(
|
||||||
|
target: "openpxe::sftp",
|
||||||
|
"could not reload SFTP shares on startup: {e}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Sniff network details for the Network tab. None of these are
|
// Sniff network details for the Network tab. None of these are
|
||||||
// required for PXE to work — they're informational, surfaced in the
|
// required for PXE to work — they're informational, surfaced in the
|
||||||
// UI so an operator doesn't have to drop to a shell to find their
|
// UI so an operator doesn't have to drop to a shell to find their
|
||||||
@@ -183,6 +201,7 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
smb: Some(smb.clone()),
|
smb: Some(smb.clone()),
|
||||||
smb_shares: smb_shares.clone(),
|
smb_shares: smb_shares.clone(),
|
||||||
nfs_shares: nfs_shares.clone(),
|
nfs_shares: nfs_shares.clone(),
|
||||||
|
sftp_shares: sftp_shares.clone(),
|
||||||
unattended: unattended.clone(),
|
unattended: unattended.clone(),
|
||||||
uploads: openpxe_http_api::uploads::UploadSessions::default(),
|
uploads: openpxe_http_api::uploads::UploadSessions::default(),
|
||||||
log_bus: log_bus.clone(),
|
log_bus: log_bus.clone(),
|
||||||
@@ -332,6 +351,20 @@ async fn seed_from_dir(
|
|||||||
/// a loopback address (which would give every PXE client an unreachable
|
/// a loopback address (which would give every PXE client an unreachable
|
||||||
/// `http://127.0.0.1/...`). Users in multi-homed setups should set
|
/// `http://127.0.0.1/...`). Users in multi-homed setups should set
|
||||||
/// `OPENPXE_PUBLIC_IP` explicitly.
|
/// `OPENPXE_PUBLIC_IP` explicitly.
|
||||||
|
/// Build the base URL advertised to PXE clients. The port is included
|
||||||
|
/// unless it's the HTTP default (80), keeping the common case clean
|
||||||
|
/// (`http://10.0.0.5`) while a remapped port (`http://10.0.0.5:4200`)
|
||||||
|
/// stays reachable. This is the single source of truth for every
|
||||||
|
/// client-facing URL — the DHCP-proxy iPXE filename, UEFI HTTP boot, and
|
||||||
|
/// the boot menu's kernel/initrd/ISO links all derive from it.
|
||||||
|
fn build_public_base_url(ip: Ipv4Addr, http_port: u16) -> String {
|
||||||
|
if http_port == 80 {
|
||||||
|
format!("http://{ip}")
|
||||||
|
} else {
|
||||||
|
format!("http://{ip}:{http_port}")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
fn detect_primary_ipv4() -> Option<Ipv4Addr> {
|
fn detect_primary_ipv4() -> Option<Ipv4Addr> {
|
||||||
// First try: route to the public internet. `UdpSocket::connect` to a
|
// First try: route to the public internet. `UdpSocket::connect` to a
|
||||||
// well-known external address causes the OS to populate `local_addr`
|
// well-known external address causes the OS to populate `local_addr`
|
||||||
@@ -465,3 +498,26 @@ fn prefix_to_dotted(prefix: u8) -> String {
|
|||||||
mask & 0xff
|
mask & 0xff
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn public_base_url_includes_non_default_port() {
|
||||||
|
// The v0.5.6 regression guard: a remapped HTTP port (e.g. the
|
||||||
|
// Unraid template's 4200) MUST appear in the advertised URL, or
|
||||||
|
// PXE clients fetch :80 — the wrong service — and boot fails.
|
||||||
|
let ip: Ipv4Addr = "192.168.1.49".parse().unwrap();
|
||||||
|
assert_eq!(build_public_base_url(ip, 4200), "http://192.168.1.49:4200");
|
||||||
|
assert_eq!(build_public_base_url(ip, 8080), "http://192.168.1.49:8080");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn public_base_url_omits_default_port() {
|
||||||
|
// Port 80 stays clean (no `:80`) so the common case reads nicely
|
||||||
|
// and matches what every browser/iPXE assumes by default.
|
||||||
|
let ip: Ipv4Addr = "10.0.0.5".parse().unwrap();
|
||||||
|
assert_eq!(build_public_base_url(ip, 80), "http://10.0.0.5");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+124
-13
@@ -291,11 +291,11 @@
|
|||||||
el('div', {class: 'trend'},
|
el('div', {class: 'trend'},
|
||||||
isos.filter(i => i.introspection.family === 'windows_pe').length + ' Windows · ' +
|
isos.filter(i => i.introspection.family === 'windows_pe').length + ' Windows · ' +
|
||||||
isos.filter(i => i.introspection.family !== 'windows_pe').length + ' Linux · ' +
|
isos.filter(i => i.introspection.family !== 'windows_pe').length + ' Linux · ' +
|
||||||
// v0.4.67: count both protocols. Label generically since
|
// v0.4.67+v0.5.5: count all remote-share protocols. Label
|
||||||
// operators may be using one, the other, or both.
|
// generically since operators may use any mix of SMB/NFS/SFTP.
|
||||||
((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0)) +
|
((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0) + (status.sftp_share_reachable || 0)) +
|
||||||
' remote share' +
|
' remote share' +
|
||||||
(((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0)) === 1 ? '' : 's')),
|
(((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0) + (status.sftp_share_reachable || 0)) === 1 ? '' : 's')),
|
||||||
])),
|
])),
|
||||||
el('div', {class: 'card'}, el('div', {class: 'stat'}, [
|
el('div', {class: 'card'}, el('div', {class: 'stat'}, [
|
||||||
el('div', {class: 'label'}, 'Uptime'),
|
el('div', {class: 'label'}, 'Uptime'),
|
||||||
@@ -508,10 +508,11 @@
|
|||||||
// v0.4.67: NFSv3 added back as an in-process Rust client
|
// v0.4.67: NFSv3 added back as an in-process Rust client
|
||||||
// (nfs3_client crate). Both protocols available side-by-side;
|
// (nfs3_client crate). Both protocols available side-by-side;
|
||||||
// operators pick whichever their NAS prefers.
|
// operators pick whichever their NAS prefers.
|
||||||
const [isos, settings, smbRes, nfsRes, disk, unattRes] = await Promise.all([
|
const [isos, settings, smbRes, nfsRes, sftpRes, disk, unattRes] = await Promise.all([
|
||||||
getJSON('/api/isos'), getJSON('/api/settings'),
|
getJSON('/api/isos'), getJSON('/api/settings'),
|
||||||
getJSON('/api/smb-shares'),
|
getJSON('/api/smb-shares'),
|
||||||
getJSON('/api/nfs-shares'),
|
getJSON('/api/nfs-shares'),
|
||||||
|
getJSON('/api/sftp-shares'),
|
||||||
getJSON('/api/storage/disk').catch(() => ({
|
getJSON('/api/storage/disk').catch(() => ({
|
||||||
total_bytes: 0, available_bytes: 0, used_bytes: 0, path: '?',
|
total_bytes: 0, available_bytes: 0, used_bytes: 0, path: '?',
|
||||||
})),
|
})),
|
||||||
@@ -519,6 +520,7 @@
|
|||||||
]);
|
]);
|
||||||
const shares = smbRes.shares || [];
|
const shares = smbRes.shares || [];
|
||||||
const nfsShares = nfsRes.shares || [];
|
const nfsShares = nfsRes.shares || [];
|
||||||
|
const sftpShares = sftpRes.shares || [];
|
||||||
const unattendedFiles = unattRes.files || [];
|
const unattendedFiles = unattRes.files || [];
|
||||||
|
|
||||||
// ── Upload card ──
|
// ── Upload card ──
|
||||||
@@ -829,6 +831,7 @@
|
|||||||
const protoSelect = el('select', {}, [
|
const protoSelect = el('select', {}, [
|
||||||
el('option', {value:'nfs'}, 'NFS (NFSv3)'),
|
el('option', {value:'nfs'}, 'NFS (NFSv3)'),
|
||||||
el('option', {value:'smb'}, 'SMB / CIFS'),
|
el('option', {value:'smb'}, 'SMB / CIFS'),
|
||||||
|
el('option', {value:'sftp'}, 'SFTP (SSH)'),
|
||||||
]);
|
]);
|
||||||
|
|
||||||
// SMB inputs.
|
// SMB inputs.
|
||||||
@@ -893,11 +896,58 @@
|
|||||||
]),
|
]),
|
||||||
]);
|
]);
|
||||||
|
|
||||||
|
// SFTP inputs (v0.5.5). Pure-Rust russh client, in-process, so
|
||||||
|
// SFTP-sourced ISOs support HTTP Range like NFS. Auth is password
|
||||||
|
// OR an SSH private key (PEM, optional passphrase); the server's
|
||||||
|
// host key is pinned trust-on-first-use on the first connect.
|
||||||
|
const sftpServerIn = el('input', {type:'text', placeholder:'10.0.0.5'});
|
||||||
|
const sftpExportIn = el('input', {type:'text', placeholder:'/srv/isos'});
|
||||||
|
const sftpUserIn = el('input', {type:'text', placeholder:'root'});
|
||||||
|
const sftpPortIn = el('input', {type:'number', placeholder:'22', min:'1', max:'65535'});
|
||||||
|
const sftpAuthMode = el('select', {}, [
|
||||||
|
el('option', {value:'password'}, 'Password'),
|
||||||
|
el('option', {value:'key'}, 'SSH private key'),
|
||||||
|
]);
|
||||||
|
const sftpPassIn = el('input', {type:'password', placeholder:'••••••••'});
|
||||||
|
const sftpKeyIn = el('textarea', {rows:'4',
|
||||||
|
placeholder:'-----BEGIN OPENSSH PRIVATE KEY-----',
|
||||||
|
style:'width:100%;font-family:ui-monospace,monospace;font-size:12px;resize:vertical'});
|
||||||
|
const sftpPassphraseIn = el('input', {type:'password',
|
||||||
|
placeholder:'(only if the private key is encrypted)'});
|
||||||
|
const sftpPassBlock = el('label', {class:'field'},
|
||||||
|
[el('span', {class:'name'}, 'Password'), sftpPassIn]);
|
||||||
|
const sftpKeyBlock = el('div', {}, [
|
||||||
|
el('label', {class:'field'},
|
||||||
|
[el('span', {class:'name'}, 'SSH private key (PEM)'), sftpKeyIn]),
|
||||||
|
el('label', {class:'field', style:'margin-top:10px'},
|
||||||
|
[el('span', {class:'name'}, 'Key passphrase (optional)'), sftpPassphraseIn]),
|
||||||
|
]);
|
||||||
|
const syncSftpAuth = () => {
|
||||||
|
const key = sftpAuthMode.value === 'key';
|
||||||
|
sftpPassBlock.style.display = key ? 'none' : '';
|
||||||
|
sftpKeyBlock.style.display = key ? '' : 'none';
|
||||||
|
};
|
||||||
|
sftpAuthMode.addEventListener('change', syncSftpAuth);
|
||||||
|
syncSftpAuth();
|
||||||
|
const sftpFields = el('div', {}, [
|
||||||
|
el('div', {class:'form-row cols-2'}, [
|
||||||
|
el('label', {class:'field'}, [el('span', {class:'name'}, 'SSH server'), sftpServerIn]),
|
||||||
|
el('label', {class:'field'}, [el('span', {class:'name'}, 'Export path'), sftpExportIn]),
|
||||||
|
]),
|
||||||
|
el('div', {class:'form-row cols-3', style:'margin-top:14px'}, [
|
||||||
|
el('label', {class:'field'}, [el('span', {class:'name'}, 'Username'), sftpUserIn]),
|
||||||
|
el('label', {class:'field'}, [el('span', {class:'name'}, 'Port'), sftpPortIn]),
|
||||||
|
el('label', {class:'field'}, [el('span', {class:'name'}, 'Auth'), sftpAuthMode]),
|
||||||
|
]),
|
||||||
|
el('div', {style:'margin-top:14px'}, [sftpPassBlock, sftpKeyBlock]),
|
||||||
|
]);
|
||||||
|
|
||||||
// Swap the visible field block + clear any stale message.
|
// Swap the visible field block + clear any stale message.
|
||||||
const syncProto = () => {
|
const syncProto = () => {
|
||||||
const nfs = protoSelect.value === 'nfs';
|
const p = protoSelect.value;
|
||||||
smbFields.style.display = nfs ? 'none' : '';
|
smbFields.style.display = p === 'smb' ? '' : 'none';
|
||||||
nfsFields.style.display = nfs ? '' : 'none';
|
nfsFields.style.display = p === 'nfs' ? '' : 'none';
|
||||||
|
sftpFields.style.display = p === 'sftp' ? '' : 'none';
|
||||||
shareMsg.replaceChildren();
|
shareMsg.replaceChildren();
|
||||||
shareMsg.className = 'msg';
|
shareMsg.className = 'msg';
|
||||||
};
|
};
|
||||||
@@ -924,6 +974,40 @@
|
|||||||
shareMsg.className = 'msg ok';
|
shareMsg.className = 'msg ok';
|
||||||
render('storage');
|
render('storage');
|
||||||
} else { await showShareError(r); }
|
} else { await showShareError(r); }
|
||||||
|
} else if (protoSelect.value === 'sftp') {
|
||||||
|
if (!sftpServerIn.value || !sftpExportIn.value || !sftpUserIn.value) {
|
||||||
|
shareMsg.replaceChildren(document.createTextNode('Server, export, and username are required.'));
|
||||||
|
shareMsg.className = 'msg err'; return;
|
||||||
|
}
|
||||||
|
const useKey = sftpAuthMode.value === 'key';
|
||||||
|
if (useKey && !sftpKeyIn.value.trim()) {
|
||||||
|
shareMsg.replaceChildren(document.createTextNode('Paste the SSH private key, or switch Auth to Password.'));
|
||||||
|
shareMsg.className = 'msg err'; return;
|
||||||
|
}
|
||||||
|
if (!useKey && !sftpPassIn.value) {
|
||||||
|
shareMsg.replaceChildren(document.createTextNode('Password is required, or switch Auth to SSH private key.'));
|
||||||
|
shareMsg.className = 'msg err'; return;
|
||||||
|
}
|
||||||
|
shareMsg.replaceChildren(document.createTextNode('Connecting…'));
|
||||||
|
shareMsg.className = 'msg';
|
||||||
|
const body = {
|
||||||
|
server: sftpServerIn.value,
|
||||||
|
export: sftpExportIn.value,
|
||||||
|
username: sftpUserIn.value,
|
||||||
|
};
|
||||||
|
if (sftpPortIn.value) { body.port = parseInt(sftpPortIn.value, 10); }
|
||||||
|
if (useKey) {
|
||||||
|
body.private_key = sftpKeyIn.value;
|
||||||
|
if (sftpPassphraseIn.value) { body.passphrase = sftpPassphraseIn.value; }
|
||||||
|
} else {
|
||||||
|
body.password = sftpPassIn.value;
|
||||||
|
}
|
||||||
|
const r = await postJSON('/api/sftp-shares', body);
|
||||||
|
if (r.ok) {
|
||||||
|
shareMsg.replaceChildren(document.createTextNode('Connected.'));
|
||||||
|
shareMsg.className = 'msg ok';
|
||||||
|
render('storage');
|
||||||
|
} else { await showShareError(r); }
|
||||||
} else {
|
} else {
|
||||||
if (!nfsServerIn.value || !nfsExportIn.value) {
|
if (!nfsServerIn.value || !nfsExportIn.value) {
|
||||||
shareMsg.replaceChildren(document.createTextNode('Server and export are required.'));
|
shareMsg.replaceChildren(document.createTextNode('Server and export are required.'));
|
||||||
@@ -962,9 +1046,36 @@
|
|||||||
el('span'),
|
el('span'),
|
||||||
]));
|
]));
|
||||||
|
|
||||||
const totalShares = shares.length + nfsShares.length;
|
const sftpRowEls = sftpShares.map(m => el('div', {class: 'nfs-row' + (m.reachable ? '' : ' down')}, [
|
||||||
|
el('span', {class: 'dot ' + (m.reachable ? 'ok' : 'err')}),
|
||||||
|
el('div', {}, [
|
||||||
|
el('div', {class:'id'}, [el('span', {class:'proto-badge'}, 'SFTP'),
|
||||||
|
document.createTextNode(m.username + '@' + m.server + ':' + m.export)]),
|
||||||
|
el('div', {class:'meta'},
|
||||||
|
'SSH · ' + (m.auth === 'key' ? 'key' : 'password') + ' · ' +
|
||||||
|
(m.reachable ? m.iso_count + ' isos' : 'not reachable')),
|
||||||
|
m.host_key_fingerprint
|
||||||
|
? el('div', {style:'margin-top:4px;opacity:.65;font-size:11px;font-family:ui-monospace,monospace;word-break:break-all'},
|
||||||
|
'host key ' + m.host_key_fingerprint)
|
||||||
|
: null,
|
||||||
|
m.last_error ? el('div', {class:'err'}, '⚠ ' + m.last_error) : null,
|
||||||
|
m.last_hint ? el('div', {style:'margin-top:4px;opacity:.78;font-size:12px'}, m.last_hint) : null,
|
||||||
|
]),
|
||||||
|
el('button', {class:'ghost', onclick: async () => {
|
||||||
|
const r = await postJSON('/api/sftp-shares/' + encodeURIComponent(m.id) + '/scan', {});
|
||||||
|
if (r.ok) render('storage');
|
||||||
|
}}, 'Re-scan'),
|
||||||
|
el('button', {class:'danger', onclick: async () => {
|
||||||
|
if (!confirm('Forget ' + m.server + ':' + m.export + '?')) return;
|
||||||
|
await fetch('/api/sftp-shares/' + encodeURIComponent(m.id), {method:'DELETE'});
|
||||||
|
render('storage');
|
||||||
|
}}, 'Remove'),
|
||||||
|
el('span'),
|
||||||
|
]));
|
||||||
|
|
||||||
|
const totalShares = shares.length + nfsShares.length + sftpShares.length;
|
||||||
const remoteRows = totalShares
|
const remoteRows = totalShares
|
||||||
? [...smbRowEls, ...nfsRowEls]
|
? [...smbRowEls, ...nfsRowEls, ...sftpRowEls]
|
||||||
: [el('div', {class:'empty'}, 'No remote shares configured.')];
|
: [el('div', {class:'empty'}, 'No remote shares configured.')];
|
||||||
syncProto();
|
syncProto();
|
||||||
|
|
||||||
@@ -1071,13 +1182,13 @@
|
|||||||
]),
|
]),
|
||||||
el('span'),
|
el('span'),
|
||||||
]),
|
]),
|
||||||
el('div', {style:'margin-top:14px'}, [smbFields, nfsFields]),
|
el('div', {style:'margin-top:14px'}, [smbFields, nfsFields, sftpFields]),
|
||||||
addShare, shareMsg,
|
addShare, shareMsg,
|
||||||
el('div', {style:'margin-top:18px;display:grid;gap:8px'}, remoteRows),
|
el('div', {style:'margin-top:18px;display:grid;gap:8px'}, remoteRows),
|
||||||
el('p', {class:'msg', style:'margin-top:14px'},
|
el('p', {class:'msg', style:'margin-top:14px'},
|
||||||
'Remote .iso libraries are read on demand — no local cache to ' +
|
'Remote .iso libraries are read on demand — no local cache to ' +
|
||||||
'preserve disk usage. Support for NFS 3.0 and SMB. Ensure that ' +
|
'preserve disk usage. Support for NFS 3.0, SMB, and SFTP (SSH). ' +
|
||||||
'the hosts IP address is provisioned.'),
|
'Ensure that the hosts IP address is provisioned.'),
|
||||||
]),
|
]),
|
||||||
]),
|
]),
|
||||||
el('div', {class:'card'}, [
|
el('div', {class:'card'}, [
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<svg viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg" role="img" aria-label="OpenPXE">
|
||||||
|
<title>OpenPXE</title>
|
||||||
|
<!-- Static README mark: the "rainbow-horizon" medallion from the web UI,
|
||||||
|
with the SMIL animation removed so it renders reliably as an <img>
|
||||||
|
on Gitea/GitHub. -->
|
||||||
|
<defs>
|
||||||
|
<linearGradient id="opxRainbow" x1="0" y1="0" x2="1" y2="0">
|
||||||
|
<stop offset="0%" stop-color="#330f1f"/>
|
||||||
|
<stop offset="12.56%" stop-color="#c83228"/>
|
||||||
|
<stop offset="25.06%" stop-color="#fb8841"/>
|
||||||
|
<stop offset="37.56%" stop-color="#d3dd92"/>
|
||||||
|
<stop offset="50.06%" stop-color="#59824f"/>
|
||||||
|
<stop offset="62.06%" stop-color="#002414"/>
|
||||||
|
<stop offset="74.06%" stop-color="#00143d"/>
|
||||||
|
<stop offset="86.06%" stop-color="#2874d7"/>
|
||||||
|
<stop offset="100%" stop-color="#99c2ff"/>
|
||||||
|
</linearGradient>
|
||||||
|
</defs>
|
||||||
|
<circle cx="12" cy="12" r="10.5" fill="url(#opxRainbow)"
|
||||||
|
stroke="rgba(0,0,0,0.18)" stroke-width="0.6"/>
|
||||||
|
</svg>
|
||||||
|
After Width: | Height: | Size: 984 B |
Reference in New Issue
Block a user