secubox-deb/scripts/sync-all-routes.sh
CyberMind-FR d5df48c5d8 fix(infra): mitmproxy route sync stability — restore metablogizer sites
Root cause: log() in sync-mitmproxy-routes.sh wrote to stdout, polluting
$(fix_dead_container_routes ...) capture → corrupted JSON → jq parse
errors → set -e abort → bad routes pushed to mitmproxy container →
mitmproxy restart-loop → HAProxy backend DOWN → HTTP 503 on every
*.gk2.secubox.in metablog vhost (arm, zkp, 3d, ~160 sites).

Fixes:
- log() now writes to stderr (>&2) — preserves stdout for command-sub
- fix_dead_container_routes returns 0 (was returning $fixed count, set -e
  killed the caller's assignment)
- sync-all-routes.sh routes metablog domains to port 8900 (was 9080,
  which is webui.conf default_server → "Wrong Domain")
- defensive 2>/dev/null || true on jq reads
- fallback to old routes_json on jq write failure (preserves last valid
  state instead of crashing)
- flock guard prevents concurrent runs on /run/sync-mitmproxy-routes.lock

Verified: systemctl start sync-mitmproxy-routes.service exits 0/SUCCESS,
244 routes valid in mitmproxy container, all four spot-checked domains
(admin.gk2, arm.gk2, zkp.gk2, 3d.gk2) return HTTP 200 with correct titles.

Note: also disabled duplicate timer secubox-route-sync.timer on the
board (executed the same script, racing on same file). systemd-level
change is on board only, not in repo.

See .claude/HISTORY.md Session 153 for full symptom chain and verification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 09:54:52 +02:00

92 lines
2.7 KiB
Bash
Executable File

#!/bin/bash
# SecuBox Routes Auto-Sync - All Services
# Syncs routes from streamlit, metablogizer, and other services to mitmproxy
set -euo pipefail
ROUTES_FILE="/srv/mitmproxy/haproxy-routes.json"
LOG_TAG="routes-sync"
log() { logger -t "$LOG_TAG" "$1"; echo "[$(date +%H:%M:%S)] $1"; }
log "Starting full routes sync..."
# Ensure mitmproxy container is running
if ! lxc-info -n mitmproxy 2>/dev/null | grep -q "RUNNING"; then
log "Starting mitmproxy container..."
lxc-start -n mitmproxy 2>/dev/null || true
sleep 3
fi
# Get container IPs
STREAMLIT_IP=$(lxc-attach -n streamlit -- ip -4 addr show eth0 2>/dev/null | grep -oP "inet \K[\d.]+" || echo "10.100.0.50")
GITEA_IP=$(lxc-attach -n gitea -- ip -4 addr show eth0 2>/dev/null | grep -oP "inet \K[\d.]+" || echo "10.100.0.40")
python3 << PYEOF
import json
import subprocess
from pathlib import Path
routes_file = "$ROUTES_FILE"
streamlit_ip = "$STREAMLIT_IP"
gitea_ip = "$GITEA_IP"
host_ip = "192.168.1.200"
# Load existing routes
routes = {}
if Path(routes_file).exists():
routes = json.loads(Path(routes_file).read_text())
updated = 0
# 1. Streamlit instances
try:
import tomllib
with open("/etc/secubox/streamlit.toml", "rb") as f:
cfg = tomllib.load(f)
for name, inst in cfg.get("instances", {}).items():
domain = inst.get("domain", f"{name}.gk2.secubox.in")
port = inst.get("port")
if port:
routes[domain] = [streamlit_ip, int(port)]
updated += 1
print(f"Streamlit: {updated} routes")
except Exception as e:
print(f"Streamlit error: {e}")
# 2. Metablogizer sites (static sites served by nginx on 9080)
try:
result = subprocess.run(
["curl", "-s", "--unix-socket", "/run/secubox/metablogizer.sock", "http://localhost/access"],
capture_output=True, text=True, timeout=5
)
data = json.loads(result.stdout)
mb_count = 0
for site in data.get("sites", []):
domain = site.get("domain")
if domain and site.get("published"):
routes[domain] = [host_ip, 8900]
mb_count += 1
print(f"Metablogizer: {mb_count} routes")
updated += mb_count
except Exception as e:
print(f"Metablogizer error: {e}")
# 3. Fixed routes
routes["admin.gk2.secubox.in"] = [host_ip, 9080]
routes["git.gk2.secubox.in"] = [gitea_ip, 3000]
# Save routes
Path(routes_file).write_text(json.dumps(routes, indent=2, sort_keys=True))
print(f"Total: {len(routes)} routes saved")
PYEOF
# Copy routes to mitmproxy container
log "Syncing to mitmproxy container..."
cat "$ROUTES_FILE" | lxc-attach -n mitmproxy -- tee /srv/mitmproxy/haproxy-routes.json > /dev/null
# Reload mitmproxy
lxc-attach -n mitmproxy -- pkill -HUP mitmdump 2>/dev/null || true
log "Routes sync complete"