ci: add with-vpn script to repo and test mounted execution
Some checks failed
Deploy Canina / deploy (push) Failing after 2s
Some checks failed
Deploy Canina / deploy (push) Failing after 2s
This commit is contained in:
parent
cbe83356ce
commit
454197d4ed
81
.gitea/scripts/with-vpn.sh
Normal file
81
.gitea/scripts/with-vpn.sh
Normal file
@ -0,0 +1,81 @@
|
||||
#!/bin/bash
|
||||
# with-vpn.sh - Run a command with VPN active, while preserving SSH & Server IP routing
|
||||
set -e
|
||||
|
||||
VPN_CONFIG="/opt/services/vpn/fmr.kaarma.top.ovpn"
|
||||
VPN_AUTH="/opt/services/vpn/auth.txt"
|
||||
VPN_LOG="/tmp/vpn-cicd.log"
|
||||
VPN_PID_FILE="/var/run/openvpn-cicd.pid"
|
||||
CMD="$*"
|
||||
|
||||
DEFAULT_GW="87.248.133.137"
|
||||
DEFAULT_IFACE="ens18"
|
||||
|
||||
log() { echo "[$(date '+%H:%M:%S')] [with-vpn] $*"; }
|
||||
|
||||
vpn_is_up() {
|
||||
ip link show tun0 &>/dev/null 2>&1
|
||||
}
|
||||
|
||||
start_vpn() {
|
||||
if vpn_is_up; then
|
||||
log "VPN already up (tun0 exists)"
|
||||
return 0
|
||||
fi
|
||||
|
||||
log "Starting OpenVPN safely with --route-nopull..."
|
||||
openvpn \
|
||||
--config "$VPN_CONFIG" \
|
||||
--auth-user-pass "$VPN_AUTH" \
|
||||
--data-ciphers AES-128-CBC \
|
||||
--route-nopull \
|
||||
--daemon \
|
||||
--log "$VPN_LOG" \
|
||||
--writepid "$VPN_PID_FILE" \
|
||||
--script-security 2
|
||||
|
||||
log "Waiting for VPN tun0..."
|
||||
for i in $(seq 1 30); do
|
||||
if vpn_is_up; then
|
||||
log "tun0 is UP after ${i}x2s"
|
||||
return 0
|
||||
fi
|
||||
sleep 2
|
||||
done
|
||||
|
||||
log "ERROR: VPN failed to connect after 60 seconds"
|
||||
tail -20 "$VPN_LOG" 2>/dev/null || true
|
||||
return 1
|
||||
}
|
||||
|
||||
stop_vpn() {
|
||||
log "Stopping VPN..."
|
||||
if [ -f "$VPN_PID_FILE" ]; then
|
||||
VPN_PID=$(cat "$VPN_PID_FILE")
|
||||
if [ -n "$VPN_PID" ]; then
|
||||
kill "$VPN_PID" 2>/dev/null || true
|
||||
sleep 2
|
||||
fi
|
||||
rm -f "$VPN_PID_FILE"
|
||||
fi
|
||||
pkill -f "openvpn.*fmr.kaarma" 2>/dev/null || true
|
||||
log "VPN stopped safely"
|
||||
}
|
||||
|
||||
cleanup() {
|
||||
local EXIT_CODE=$?
|
||||
log "Cleanup (exit code: $EXIT_CODE)..."
|
||||
stop_vpn
|
||||
exit $EXIT_CODE
|
||||
}
|
||||
|
||||
trap cleanup EXIT INT TERM
|
||||
|
||||
start_vpn
|
||||
|
||||
log "Running command: $CMD"
|
||||
eval "$CMD"
|
||||
EXIT_CODE=$?
|
||||
|
||||
log "Command finished with exit code: $EXIT_CODE"
|
||||
exit $EXIT_CODE
|
||||
Loading…
Reference in New Issue
Block a user