aboutsummaryrefslogtreecommitdiff
path: root/scripts/testing/tests/test_hardening.py
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-06-25 23:12:51 -0400
committerCraig Jennings <c@cjennings.net>2026-06-25 23:12:51 -0400
commit5f63b11936fb3eff942082641883a620125ee3e6 (patch)
tree40b927b34bcda57d0d9516f6d0eb5821a3d82c38 /scripts/testing/tests/test_hardening.py
parentc3edd86dc31ccf3db6ad6060de5a949b41a7b809 (diff)
downloadarchsetup-5f63b11936fb3eff942082641883a620125ee3e6.tar.gz
archsetup-5f63b11936fb3eff942082641883a620125ee3e6.zip
test(archsetup): migrate bare-metal runner to key auth + Testinfra
run-test-baremetal.sh SSHed to the target as root by password throughout, which archsetup's sshd hardening (PermitRootLogin prohibit-password) kills mid-install, the same break the VM runner already fixed. It also still called the validation.sh shell sweep (run_all_validations, validate_all_services, validate_zfs_services), the last caller keeping those functions alive. It now mirrors the VM runner. After the first SSH, and after any genesis rollback so the key survives it, inject_root_key authorizes a throwaway root key, and every later ssh_cmd plus the raw scp transfers and log-copies thread SSH_KEY_OPT to survive the hardening. The shell sweep is replaced with run_testinfra_validation, now the authoritative validator on both runners. A --port option, threaded through every SSH and scp, lets the runner target a test VM on 2222 instead of only real hardware on 22. inject_root_key now authorizes root@$VM_IP instead of root@localhost, so one helper serves both runners (the VM runner sets VM_IP=localhost). Validated against the ZFS VM (--validate-only, localhost:2222): connectivity, the ZFS check, key authorization, and the Testinfra sweep all connect and run over the key-based ssh-config. A green bare-metal install still needs real ZFS hardware.
Diffstat (limited to 'scripts/testing/tests/test_hardening.py')
0 files changed, 0 insertions, 0 deletions