chore: rotate Beszel admin password
This commit is contained in:
parent
5de89f22d4
commit
be31212508
1 changed files with 20 additions and 17 deletions
37
compose.yaml
37
compose.yaml
|
|
@ -20,33 +20,36 @@ services:
|
||||||
start_period: 15s
|
start_period: 15s
|
||||||
retries: 3
|
retries: 3
|
||||||
|
|
||||||
beszel-verifier:
|
beszel-password-changer:
|
||||||
image: python:3.11-alpine
|
image: python:3.11-alpine
|
||||||
container_name: beszel-verifier
|
container_name: beszel-password-changer
|
||||||
restart: "no"
|
restart: "no"
|
||||||
depends_on:
|
depends_on:
|
||||||
beszel:
|
beszel:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
environment:
|
environment:
|
||||||
BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL}
|
BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL}
|
||||||
BESZEL_PASSWORD: ${BESZEL_ADMIN_PASSWORD}
|
BESZEL_OLD_PASSWORD: ${BESZEL_OLD_PASSWORD}
|
||||||
|
BESZEL_NEW_PASSWORD: ${BESZEL_NEW_PASSWORD}
|
||||||
command:
|
command:
|
||||||
- python
|
- python
|
||||||
- -c
|
- -c
|
||||||
- |
|
- |
|
||||||
import json, os, time, urllib.request
|
import json, os, urllib.request
|
||||||
base = "http://beszel:8090"
|
base = "http://beszel:8090"
|
||||||
body = json.dumps({"identity": os.environ["BESZEL_EMAIL"], "password": os.environ["BESZEL_PASSWORD"]}).encode()
|
email = os.environ["BESZEL_EMAIL"]
|
||||||
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
|
old = os.environ["BESZEL_OLD_PASSWORD"]
|
||||||
with urllib.request.urlopen(req, timeout=10) as response:
|
new = os.environ["BESZEL_NEW_PASSWORD"]
|
||||||
token = json.load(response)["token"]
|
def auth(password):
|
||||||
result = []
|
body = json.dumps({"identity": email, "password": password}).encode()
|
||||||
for _ in range(12):
|
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
|
||||||
req = urllib.request.Request(base + "/api/collections/systems/records?perPage=50", headers={"Authorization": token})
|
|
||||||
with urllib.request.urlopen(req, timeout=10) as response:
|
with urllib.request.urlopen(req, timeout=10) as response:
|
||||||
items = json.load(response)["items"]
|
return json.load(response)
|
||||||
result = [{"name": item["name"], "status": item["status"]} for item in items]
|
session = auth(old)
|
||||||
if result and all(item["status"] == "up" for item in result):
|
record_id = session["record"]["id"]
|
||||||
break
|
body = json.dumps({"password": new, "passwordConfirm": new}).encode()
|
||||||
time.sleep(5)
|
req = urllib.request.Request(base + "/api/collections/users/records/" + record_id, data=body, method="PATCH", headers={"Authorization": session["token"], "Content-Type": "application/json"})
|
||||||
print(json.dumps({"verified_systems": result}, sort_keys=True), flush=True)
|
with urllib.request.urlopen(req, timeout=10) as response:
|
||||||
|
updated = json.load(response)
|
||||||
|
verified = auth(new)
|
||||||
|
print(json.dumps({"password_changed": updated.get("id") == record_id, "new_login_ok": bool(verified.get("token"))}), flush=True)
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue