mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 05:26:49 +00:00
182 lines
5.0 KiB
Bash
Executable File
182 lines
5.0 KiB
Bash
Executable File
#!/bin/bash
|
||
# setup-unpoller-credentials.sh
|
||
# Store Unifi credentials in Vault for Unpoller
|
||
#
|
||
# This script helps you store your Unifi controller credentials in Vault
|
||
# so that Unpoller can authenticate and collect metrics.
|
||
#
|
||
# USAGE:
|
||
# ======
|
||
# 1. With username/password:
|
||
# ./scripts/setup-unpoller-credentials.sh --user admin --pass yourpassword
|
||
#
|
||
# 2. With API key (same as External DNS):
|
||
# ./scripts/setup-unpoller-credentials.sh --use-api-key
|
||
#
|
||
# 3. Interactive mode (prompts for credentials):
|
||
# ./scripts/setup-unpoller-credentials.sh
|
||
#
|
||
|
||
set -euo pipefail
|
||
|
||
# Colors for output
|
||
RED='\033[0;31m'
|
||
GREEN='\033[0;32m'
|
||
YELLOW='\033[1;33m'
|
||
NC='\033[0m' # No Color
|
||
|
||
# Function to print colored output
|
||
print_info() { echo -e "${GREEN}ℹ${NC} $1"; }
|
||
print_warn() { echo -e "${YELLOW}⚠${NC} $1"; }
|
||
print_error() { echo -e "${RED}✗${NC} $1"; }
|
||
print_success() { echo -e "${GREEN}✓${NC} $1"; }
|
||
|
||
# Parse command line arguments
|
||
USE_API_KEY=false
|
||
UNIFI_USER=""
|
||
UNIFI_PASS=""
|
||
|
||
while [[ $# -gt 0 ]]; do
|
||
case $1 in
|
||
--use-api-key)
|
||
USE_API_KEY=true
|
||
shift
|
||
;;
|
||
--user)
|
||
UNIFI_USER="$2"
|
||
shift 2
|
||
;;
|
||
--pass)
|
||
UNIFI_PASS="$2"
|
||
shift 2
|
||
;;
|
||
--help|-h)
|
||
echo "Usage: $0 [OPTIONS]"
|
||
echo ""
|
||
echo "Options:"
|
||
echo " --use-api-key Use the same API key as External DNS"
|
||
echo " --user USERNAME Unifi username (local admin account)"
|
||
echo " --pass PASSWORD Unifi password"
|
||
echo " --help, -h Show this help message"
|
||
echo ""
|
||
echo "Examples:"
|
||
echo " $0 --user admin --pass mypassword"
|
||
echo " $0 --use-api-key"
|
||
echo " $0 # Interactive mode"
|
||
exit 0
|
||
;;
|
||
*)
|
||
print_error "Unknown option: $1"
|
||
echo "Use --help for usage information"
|
||
exit 1
|
||
;;
|
||
esac
|
||
done
|
||
|
||
echo "=================================================="
|
||
echo " Unpoller Credentials Setup for Vault"
|
||
echo "=================================================="
|
||
echo ""
|
||
|
||
# Check if Vault is ready
|
||
print_info "Checking if Vault is ready..."
|
||
if ! kubectl -n vault get pod vault-0 >/dev/null 2>&1; then
|
||
print_error "Vault pod not found! Please deploy infrastructure first."
|
||
exit 1
|
||
fi
|
||
|
||
if ! kubectl -n vault exec vault-0 -- vault status >/dev/null 2>&1; then
|
||
print_error "Vault is not ready! Please check Vault status."
|
||
exit 1
|
||
fi
|
||
|
||
print_success "Vault is ready"
|
||
echo ""
|
||
|
||
# Get credentials
|
||
if [ "$USE_API_KEY" = true ]; then
|
||
print_info "Using API key from External DNS configuration..."
|
||
API_KEY=$(kubectl -n external-dns get secret external-dns-unifi-secret -o jsonpath='{.data.api-key}' | base64 -d)
|
||
UNIFI_USER="$API_KEY"
|
||
UNIFI_PASS="$API_KEY"
|
||
print_success "API key retrieved: ${API_KEY:0:10}..."
|
||
elif [ -z "$UNIFI_USER" ] || [ -z "$UNIFI_PASS" ]; then
|
||
# Interactive mode
|
||
print_info "No credentials provided, entering interactive mode..."
|
||
echo ""
|
||
echo "Choose authentication method:"
|
||
echo " 1) Use API key (same as External DNS)"
|
||
echo " 2) Use Unifi local admin username/password"
|
||
echo ""
|
||
read -rp "Enter choice [1-2]: " choice
|
||
|
||
case $choice in
|
||
1)
|
||
print_info "Retrieving API key from External DNS..."
|
||
API_KEY=$(kubectl -n external-dns get secret external-dns-unifi-secret -o jsonpath='{.data.api-key}' | base64 -d)
|
||
UNIFI_USER="$API_KEY"
|
||
UNIFI_PASS="$API_KEY"
|
||
print_success "API key retrieved: ${API_KEY:0:10}..."
|
||
;;
|
||
2)
|
||
read -rp "Enter Unifi username: " UNIFI_USER
|
||
read -rsp "Enter Unifi password: " UNIFI_PASS
|
||
echo ""
|
||
;;
|
||
*)
|
||
print_error "Invalid choice"
|
||
exit 1
|
||
;;
|
||
esac
|
||
fi
|
||
|
||
# Validate credentials are not empty
|
||
if [ -z "$UNIFI_USER" ] || [ -z "$UNIFI_PASS" ]; then
|
||
print_error "Credentials cannot be empty!"
|
||
exit 1
|
||
fi
|
||
|
||
echo ""
|
||
print_info "Storing credentials in Vault..."
|
||
|
||
# Store credentials in Vault
|
||
if kubectl -n vault exec vault-0 -- vault kv put secret/unpoller \
|
||
unifi-user="$UNIFI_USER" \
|
||
unifi-pass="$UNIFI_PASS" >/dev/null 2>&1; then
|
||
print_success "Credentials stored in Vault at: secret/unpoller"
|
||
else
|
||
print_error "Failed to store credentials in Vault"
|
||
exit 1
|
||
fi
|
||
|
||
echo ""
|
||
print_info "Verifying credentials were stored correctly..."
|
||
|
||
# Verify the secret exists
|
||
if kubectl -n vault exec vault-0 -- vault kv get secret/unpoller >/dev/null 2>&1; then
|
||
print_success "Credentials verified in Vault"
|
||
else
|
||
print_error "Failed to verify credentials in Vault"
|
||
exit 1
|
||
fi
|
||
|
||
echo ""
|
||
print_success "Setup complete!"
|
||
echo ""
|
||
echo "Next steps:"
|
||
echo " 1. Deploy or update Unpoller: helmfile apply"
|
||
echo " 2. Wait for Unpoller to sync credentials from Vault (via ExternalSecret)"
|
||
echo " 3. Check Unpoller logs: kubectl -n unpoller logs -l app.kubernetes.io/name=unpoller"
|
||
echo " 4. Verify metrics in Prometheus: http://prometheus.kube.huskypup.net"
|
||
echo " 5. View dashboards in Grafana: http://grafana.kube.huskypup.net"
|
||
echo ""
|
||
echo "Grafana will have 7 new Unifi dashboards:"
|
||
echo " - Unifi Access Points"
|
||
echo " - Unifi Clients"
|
||
echo " - Unifi DPI (Deep Packet Inspection)"
|
||
echo " - Unifi Gateway"
|
||
echo " - Unifi Sites"
|
||
echo " - Unifi Switches"
|
||
echo " - Unifi PDU"
|
||
echo ""
|