deploy/runner-egress-check.sh

v1.40.0
gitbay/deploy/runner-egress-check.sh history · blame · raw

41 lines · 1664 bytes · executable

 1#!/bin/sh
 2# Check the CI runner's host egress rule (#260) as the runner's user:
 3# the forge over loopback on 22 must answer (the runner polls there),
 4# and the admin sshd on 2222 must not, on loopback or the public
 5# address. `make deploy-runner` runs this after loading the rule and
 6# before restarting the runner, and stops on a failure.
 7#
 8#   ssh -p 2222 root@bay1 'sh -s' < deploy/runner-egress-check.sh
 9set -eu
10
11RUNNER_USER="${RUNNER_USER:-ci-runner}"
12# hostname -I lists the host's addresses, IPv4 first on bay1; the first
13# is the public one there.
14public=$(hostname -I | awk '{print $1}')
15
16probe() {
17    su -s /bin/bash "$RUNNER_USER" -c "timeout 5 bash -c 'exec 3<>/dev/tcp/$1/$2'" </dev/null 2>/dev/null
18}
19
20nft list table inet gitbay_runner >/dev/null
21
22# The runner polls 127.0.0.1:22. If the rule blocks that, the running
23# runner is already cut off, so remove the table: CI keeps polling as it
24# did before the deploy, and the exit still stops make before the restart.
25if ! probe 127.0.0.1 22; then
26    nft destroy table inet gitbay_runner
27    echo "$RUNNER_USER cannot reach 127.0.0.1:22 with the egress rule loaded;" >&2
28    echo "removed table inet gitbay_runner so the runner keeps polling. Fix the rule and deploy again." >&2
29    exit 1
30fi
31if ! probe "$public" 22; then
32    echo "$RUNNER_USER cannot reach $public:22: builds would not reach the forge" >&2
33    exit 1
34fi
35for dest in 127.0.0.1:2222 "$public:2222"; do
36    if probe "${dest%:*}" "${dest##*:}"; then
37        echo "$RUNNER_USER reaches $dest: the egress rule is not in force" >&2
38        exit 1
39    fi
40done
41echo "egress for $RUNNER_USER: 127.0.0.1:22 and $public:22 open, 2222 refused"