chore: rotate Beszel admin password

This commit is contained in:
sascha 2026-09-09 09:56:18 +02:00
parent 5de89f22d4
commit be31212508

View file

@ -20,33 +20,36 @@ services:
start_period: 15s start_period: 15s
retries: 3 retries: 3
beszel-verifier: beszel-password-changer:
image: python:3.11-alpine image: python:3.11-alpine
container_name: beszel-verifier container_name: beszel-password-changer
restart: "no" restart: "no"
depends_on: depends_on:
beszel: beszel:
condition: service_healthy condition: service_healthy
environment: environment:
BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL} BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL}
BESZEL_PASSWORD: ${BESZEL_ADMIN_PASSWORD} BESZEL_OLD_PASSWORD: ${BESZEL_OLD_PASSWORD}
BESZEL_NEW_PASSWORD: ${BESZEL_NEW_PASSWORD}
command: command:
- python - python
- -c - -c
- | - |
import json, os, time, urllib.request import json, os, urllib.request
base = "http://beszel:8090" base = "http://beszel:8090"
body = json.dumps({"identity": os.environ["BESZEL_EMAIL"], "password": os.environ["BESZEL_PASSWORD"]}).encode() email = os.environ["BESZEL_EMAIL"]
old = os.environ["BESZEL_OLD_PASSWORD"]
new = os.environ["BESZEL_NEW_PASSWORD"]
def auth(password):
body = json.dumps({"identity": email, "password": password}).encode()
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"}) req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
with urllib.request.urlopen(req, timeout=10) as response: with urllib.request.urlopen(req, timeout=10) as response:
token = json.load(response)["token"] return json.load(response)
result = [] session = auth(old)
for _ in range(12): record_id = session["record"]["id"]
req = urllib.request.Request(base + "/api/collections/systems/records?perPage=50", headers={"Authorization": token}) body = json.dumps({"password": new, "passwordConfirm": new}).encode()
req = urllib.request.Request(base + "/api/collections/users/records/" + record_id, data=body, method="PATCH", headers={"Authorization": session["token"], "Content-Type": "application/json"})
with urllib.request.urlopen(req, timeout=10) as response: with urllib.request.urlopen(req, timeout=10) as response:
items = json.load(response)["items"] updated = json.load(response)
result = [{"name": item["name"], "status": item["status"]} for item in items] verified = auth(new)
if result and all(item["status"] == "up" for item in result): print(json.dumps({"password_changed": updated.get("id") == record_id, "new_login_ok": bool(verified.get("token"))}), flush=True)
break
time.sleep(5)
print(json.dumps({"verified_systems": result}, sort_keys=True), flush=True)