Follow the sibling project's rename to dev-updater
It is no longer "local" -- it serves over WireGuard rather than the LAN -- and it is specifically for developing new apps. Renaming the references here at the same time keeps one name to search for across both repos. Also drops the last references to gen-dev-cert.sh, which the in-process certificate generation replaced: the build script and the Gradle task now say to start the server once, and test-wg-tunnel.sh reads the certificates from the XDG directory rather than the repo. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017xn8nHw1tw1R6PtiY1eEtw
This commit is contained in:
1 parent
65743b899d
commit
56491f84b0
12 files changed
+42
-41
No files matched your search
+6
-6
@@ -14,8 +14,8 @@
|
||||
# The veth pair stands in for "the internet" carrying WireGuard's UDP; the
|
||||
# wg interfaces are real, with a real handshake and real keys. 10.66.0.1 is
|
||||
# deliberately the same address the leaf certificate carries a SAN for
|
||||
# (gen-dev-cert.sh), so a client inside the tunnel completes the same
|
||||
# pinned-TLS handshake a phone will.
|
||||
# (certs.rs covers every local address), so a client inside the tunnel
|
||||
# completes the same pinned-TLS handshake a phone will.
|
||||
#
|
||||
# ./test-wg-tunnel.sh up create the tunnel (needs sudo)
|
||||
# ./test-wg-tunnel.sh test run the server on wg0 and reach it from "phone"
|
||||
@@ -80,8 +80,9 @@ up() {
|
||||
}
|
||||
|
||||
test_tunnel() {
|
||||
if [ ! -f "$REPO/certs/leaf.pem" ]; then
|
||||
echo "No certs/ -- run ./gen-dev-cert.sh first." >&2
|
||||
CERTS="${XDG_CONFIG_HOME:-$HOME/.config}/ai-app/certs"
|
||||
if [ ! -f "$CERTS/leaf.pem" ]; then
|
||||
echo "No certificates in $CERTS -- start ai-server once; it makes them." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ ! -x "$REPO/server/target/debug/ai-server" ]; then
|
||||
@@ -98,13 +99,12 @@ test_tunnel() {
|
||||
ss -tlnp 2>/dev/null | grep 8443 | sed 's/^/ /' || echo " (nothing on 8443)"
|
||||
|
||||
echo "==> From inside the tunnel: GET /sessions through wg1 -> wg0"
|
||||
TOKEN=$(sudo cat "$REPO/config.json" 2>/dev/null | sed -n 's/.*"sha256": "\(.*\)".*/\1/p' | head -1)
|
||||
if [ -z "${AI_TOKEN:-}" ]; then
|
||||
echo " (set AI_TOKEN=<the enrollment token> to test an authorized call;"
|
||||
echo " without it this only proves reachability + TLS, via a 401)"
|
||||
fi
|
||||
sudo ip netns exec "$NS" curl -s -o /dev/null -w " HTTP %{http_code} (TLS ok, pinned CA)\n" \
|
||||
--cacert "$REPO/certs/ca.pem" \
|
||||
--cacert "$CERTS/ca.pem" \
|
||||
${AI_TOKEN:+-H "Authorization: Bearer $AI_TOKEN"} \
|
||||
"https://$SERVER_WG_IP:8443/sessions" || echo " UNREACHABLE"
|
||||
|
||||
|
||||
Reference in new issue
Block a user