39 lines
97 KiB
JSON
39 lines
97 KiB
JSON
{
|
|
"schema_version": 1,
|
|
"channel": "homelab-runtime",
|
|
"command_id": "SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1",
|
|
"status": "OK",
|
|
"rc": 0,
|
|
"host": "pve01",
|
|
"mode": "read-only",
|
|
"component": "homelab-backup-moldova-control-rca",
|
|
"started_at_utc": "2026-09-22T09:05:02Z",
|
|
"finished_at_utc": "2026-09-22T09:05:02Z",
|
|
"reference_register_checked": true,
|
|
"reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66",
|
|
"error_register_checked": true,
|
|
"error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0",
|
|
"command_sha256": "0988f0ccf22795188f482b9de7d6e5bbd0042f96af78f459db72983c90a6fc99",
|
|
"duplicate_failed_command_blocked": false,
|
|
"block_reason": null,
|
|
"execution_started": true,
|
|
"change_declared": false,
|
|
"result_contract_valid": true,
|
|
"result_contract_status": null,
|
|
"result_contract_error": null,
|
|
"command_rc": 0,
|
|
"changes_made": false,
|
|
"rollback_started": false,
|
|
"rollback_restored": null,
|
|
"mutation_outcome": "NO_MUTATION",
|
|
"sanitized": true,
|
|
"secrets_included": false,
|
|
"private_addresses_included": false,
|
|
"raw_evidence_retained_locally": true,
|
|
"raw_evidence_sha256": "e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25",
|
|
"sanitized_output_sha256": "e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25",
|
|
"output_truncated_in_json": false,
|
|
"full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt",
|
|
"output": "WORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_BEGIN=1\nCOMMAND_ID=SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1\nMODE=read-only\nCOMPONENT=homelab-backup-moldova-control-rca\nMUTATION_BOUNDARY=NONE;STATIC_CONTROL_PATH_CLASSIFICATION_ONLY;NO_PROVIDER_CALL;NO_NETWORK_MUTATION;NO_TARGET_SSH;NO_BACKUP;NO_SYSTEMD_ACTION;NO_GIT_WRITE;NO_SECRET_VALUE_READOUT\nREFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66\nERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0\nRUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d\nWRAPPER_SHA256=5077444065c732451cb84898680f62361b21a24ef9eb4f191253e82ead524ea2\nAUDIT_SHA256=5777bbb204708ffcebba0753506b819833b76370ecda59b4574e1aff3b9e4593\nLEGACY_SHA256=b6e79f087b9f1d21dac4f77a7b46b743299bbb85bc716e80d2ea67c2e038bcd7\nSCHEDULER_RC=0\nSELFTEST_REPLACEMENT486=PASS\nSCHEDULER_LIVE_SELECTION={\"due_seconds\":86400,\"enabled\":true,\"logical_id\":\"xf-newfi\"}\nTARGETS_CONFIG_SHA256=aa4a75455bbfe92afaf666e8d404b35c5b41e70bc014e770c9301865ee84e221\n{\"logical_id\":\"us-netbird\",\"type\":\"vps_us\",\"scope\":\"vps\",\"user\":\"root\",\"port\":22,\"enabled\":true,\"due_seconds\":86400}\nCONTROL_PATH_CLASSIFICATION_BEGIN=1\n{\"bytes\":20163,\"executable\":true,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh\",\"sha256\":\"9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868\"}\n{\"bytes\":20006,\"executable\":true,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771s_edge_capi_netbird_20260702T170251Z.sh\",\"sha256\":\"c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5\"}\n{\"bytes\":8977,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771p_netbird_vps_peer_repair.sh\",\"sha256\":\"f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747\"}\n{\"bytes\":6970,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771ad_final_crowdsec_capi_netbird_closure.sh\",\"sha256\":\"c99d08385f5d7c0a266c1c8002b3c7b054e1bb561eb48b1f8a227f37fe430ab6\"}\n{\"bytes\":28134,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771l_crowdsec_capi_netbird_vps_egress.sh\",\"sha256\":\"401396a25d4a5cfa487f67b355b45b27140ed1ac6b49b41e342306cb618dfdb5\"}\n{\"bytes\":24918,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771l_crowdsec_capi_netbird_vps_egress_remote_20260702T151045Z.sh\",\"sha256\":\"6a6df3cc085363c2bbbb92b8c3083123fb0e583e14e242c583a321bdb5612002\"}\n{\"bytes\":31306,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771m_purge_warp_fix_netbird_egress.sh\",\"sha256\":\"0ae3b0e1e8016da55cf1756e868c51a23fe12328fae6ef4baa61c50b9e48e715\"}\n{\"bytes\":27881,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771m_purge_warp_fix_netbird_remote_20260702T151637Z.sh\",\"sha256\":\"941f683d148a01d9af9ef6ce938c8ee6874d7af1ac1ac5ee96c7d9ca7cc262a4\"}\n{\"bytes\":12586,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771n_netbird_usa_moldova_egress_only.sh\",\"sha256\":\"420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e\"}\n{\"bytes\":10125,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771n_netbird_usa_moldova_egress_remote_20260702T152139Z.sh\",\"sha256\":\"1c25cbc13f524d0f6974a71c255c5634c69380818cb1b5ad4f8f6ea9bf8c6a01\"}\n{\"bytes\":7440,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771o_netbird_management_acl_discovery.sh\",\"sha256\":\"50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322\"}\n{\"bytes\":25955,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771q_netbird_public_vps_repair_then_capi.sh\",\"sha256\":\"0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071\"}\n{\"bytes\":26359,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771r_netbird_public_vps_fixed_then_capi.sh\",\"sha256\":\"dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7\"}\n{\"bytes\":28279,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771s_vps_identity_repair_netbird_capi.sh\",\"sha256\":\"16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9\"}\n{\"bytes\":25344,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771t_temp_hostkey_netbird_identity_then_capi.sh\",\"sha256\":\"0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da\"}\n{\"bytes\":27834,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771u_find_key_fix_netbird_egress_capi.sh\",\"sha256\":\"6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb\"}\n{\"bytes\":30154,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771v_deep_key_backup_netbird_capi.sh\",\"sha256\":\"92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170\"}\n{\"bytes\":13072,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771z_after_manual_netbird_egress_capi.sh\",\"sha256\":\"f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee\"}\n{\"bytes\":9197,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/01_CURRENT_AUTHORITATIVE_STATE.md\",\"sha256\":\"844a17f9af701211699b078f5a5e8ff28bb401b377acc10fe364aa78aa3bfc9b\"}\n{\"bytes\":38895,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/index\",\"sha256\":\"93bd029aaadbac051ea3e9c7266ae0d0643ec8d0eff24a02ccb44805dc9764d2\"}\n{\"bytes\":38895,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0095/index\",\"sha256\":\"6327b174188ff5b751c03ba3e6b14d884a1d61dda42df86d8cf2e2151d74efe1\"}\n{\"bytes\":53159,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0096/index\",\"sha256\":\"0f244e69df78feba15d92d1c45c7d456e62726609ff45a6000cc5f11cc6b8e64\"}\n{\"bytes\":75082,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-1005/index\",\"sha256\":\"d7c61f503b6b7494e9aa4dde883d5a42493d81c346ba30938fe86386002dc388\"}\n{\"bytes\":31037,\"executable\":false,\"has_http\":true,\"has_netbird\":false,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md\",\"sha256\":\"f42b0e0be98c7f6d9f0e06d5565ec1cfc277e4221cbc164f21c157fe4121ad72\"}\n{\"bytes\":3587,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT.md\",\"sha256\":\"5fc43e34a1f0714ddacf7c00ed5c4bbaf788df3b8407dcfebd1333a23a623acc\"}\n{\"bytes\":1322,\"executable\":false,\"has_http\":false,\"has_netbird\":false,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/current/03_ACCESS_AND_SECRETS.md\",\"sha256\":\"e750284217dc41b5809268a0bbc54ed0948bdd14680fe2f282f307640937496c\"}\n{\"bytes\":805,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/current/04_P0_NEXT.md\",\"sha256\":\"0f6eb8b23382becc1868e8a22318d5b7629184568205bad47c3c38967a346b8f\"}\n{\"bytes\":3063,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/README_FIRST.md\",\"sha256\":\"02f7db5a75d4371a430a0034dc3e74a61ea355064fe44a1a221e8e175422a008\"}\n{\"bytes\":33401,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/SHA256SUMS\",\"sha256\":\"0939f8b9ab4de481c6e68a6abd16cb14ae5348a94e3af0d0e3f107815d0d3169\"}\n{\"bytes\":2726,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/00_START_HERE.md\",\"sha256\":\"4c4e4c85805aa00bd5f94f64fc9c2c985c44bf467058546e3cbe9d8d166d044f\"}\n{\"bytes\":3259,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/04_NETWORK_DNS_INGRESS.md\",\"sha256\":\"e3edd29ea8754ce340929f531c0ff8c1ebda4fbbf7d20a53445a665e014fbc85\"}\n{\"bytes\":3828,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/11_OPEN_ISSUES_AND_FUTURE_WORK.md\",\"sha256\":\"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647\"}\n{\"bytes\":2056,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/12_NEW_CHAT_FIRST_MESSAGE.txt\",\"sha256\":\"380315d5793449c258356145e7cff7dee7493d2c462dff3ca6f6d9eabfb673e0\"}\n{\"bytes\":1744,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/13_PROVENANCE_AND_FRESHNESS.md\",\"sha256\":\"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089\"}\n{\"bytes\":1740,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md\",\"sha256\":\"ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\"}\n{\"bytes\":3638,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/18_P0_CLOSEOUT_MASTER_PLAN_2026-08-19.md\",\"sha256\":\"0ce52a34278e57ff3dba122e2e65c57251e75484025ba13588971d0979d78ec6\"}\n{\"bytes\":1792,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md\",\"sha256\":\"12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\"}\n{\"bytes\":2265,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md\",\"sha256\":\"fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\"}\n{\"bytes\":3828,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/24_GLOBAL_BACKLOG_MASTER_2026-08-19.md\",\"sha256\":\"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647\"}\n{\"bytes\":1733,\"executable\":false,\"has_http\":false,\"has_netbird\":false,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/25_OPERATOR_CHAT_RULES_2026-08-19.md\",\"sha256\":\"69bec1f0893c32c2ea67100355f8702f20bb6671177c6c1da69e1d2407c71232\"}\n{\"bytes\":1744,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/28_PROVENANCE_AND_FRESHNESS_2026-08-19.md\",\"sha256\":\"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089\"}\n{\"bytes\":700,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/runbooks/04_NETBIRD_USA.md\",\"sha256\":\"725e2068337b379ebdf47822d5871aa5f4d5ec5956546674b2cf55b3250fb7a3\"}\n{\"bytes\":4057,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/scripts/command_guard.py\",\"sha256\":\"33c59d92a2b9c380d9208a0e2fd1353029e6edc4878053df95dbd7b9dd987d0b\"}\nCONTROL_PATH_CLASSIFICATION_END=1\nCONTROL_TOTAL_ROWS=43\nCONTROL_EXEC_ROWS=2\nCONTROL_EXTERNAL_PROVIDER_ACTION_CANDIDATES=0\nCONTROL_SSH_DEPENDENT_CANDIDATES=2\nCONTROL_NETBIRD_ONLY_CANDIDATES=0\nKNOWN_771_SAFE_STATIC_BEGIN=1\nKNOWN_SCRIPT=/root/771n_netbird_usa_moldova_egress_only.sh SHA256=420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e EXECUTABLE=false\n20:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n22:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n41: echo \"CHECK=crowdsec-capi\"\n53: DISABLE_ONLINE_API: \"true\"\n54: ARGS: \"-no-capi\"\n93: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n95:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n102:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n103:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n104:Restart=always\n105:RestartSec=5\n111: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n115:base=/etc/homelab-crowdsec-capi-netbird-egress\n123:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n124:systemctl restart privoxy 2>/dev/null || true\n126:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n128: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n131: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n132: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n134: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n146: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n149: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n160:out.append(\"# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n163:out.append(\"# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_END\")\n168: systemctl restart privoxy\n189: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new \"$user@$ip\" \"echo SSH_OK; hostname; uname -a | cut -c1-120\" 2>&1 | redact; then\n192: if ssh -n -fN -M -S \"$ctl\" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D \"[PRIVATE_IP]:${port}\" \"$user@$ip\" 2>/tmp/771n_tunnel_${profile}.err; then\n194: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771n_capi_${profile}.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n195: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n196: echo \"SOCKS_CAPI_HTTP=$code\"\n200: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n232:docker exec crowdsec cscli lapi status 2>&1 | redact || true\n233:docker exec crowdsec cscli capi status 2>&1 | redact || true\n236:netbird status 2>&1 | redact || true\n239:systemctl restart netbird 2>/dev/null || true\n241:netbird status 2>&1 | redact || true\n244:USA_IP=\"$(awk '$1 ~ /^e3qxxx\\.netbird\\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)\"\n245:MOLDOVA_IP=\"$(awk '$1 ~ /^e3qxxx-183-106\\.netbird\\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)\"\n261: write_health \"REVIEW_USA_MOLDOVA_NETBIRD_PEERS_NOT_REACHABLE\" \"WARP purged; USA/Moldova NetBird VPS peers are not reachable or do not allow SSH from edge\"\n262: echo \"NEEDED_ON_VPS=NetBird peer online, SSH reachable over NetBird, and outbound TLS to api.crowdsec.net working\"\n276:proxy_code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771n_active_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n277:echo \"ACTIVE_HTTP_PROXY_CAPI_HTTP=$proxy_code\"\n280: write_health \"REVIEW_NETBIRD_EGRESS_PROXY_FAILED\" \"NetBird VPS SSH SOCKS profile exists but HTTP proxy did not reach CrowdSec CAPI\"\n286:write_health \"OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT\" \"NetBird VPS egress profile=$profile is ready; next command can register CrowdSec CAPI through proxy http://${b}:${HTTP_PROXY_PORT}\"\n287:echo \"READY_PROXY=http://${b}:${HTTP_PROXY_PORT}\"\n288:echo \"READY_SWITCH=homelab-crowdsec-capi-egress-switch $profile\"\n290:echo \"REMOTE_STATUS=OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT\"\n306: scp -q \"$LOCAL_REMOTE_SCRIPT\" \"debian@$EDGE:$REMOTE_SCRIPT\"\n315: ssh \"debian@$EDGE\" \"sudo bash '$REMOTE_SCRIPT' '$TS'\"\nKNOWN_SCRIPT=/root/771o_netbird_management_acl_discovery.sh SHA256=50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322 EXECUTABLE=false\n25: ssh debian@$EDGE \"sudo bash -lc '\n35: netbird status --json >/tmp/771o_netbird_status.json 2>/tmp/771o_netbird_status_json.err || true\n109: ssh -o BatchMode=yes -o ConnectTimeout=8 \"$user@$host\" \"sudo bash -lc '\nKNOWN_SCRIPT=/root/771p_netbird_vps_peer_repair.sh SHA256=f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747 EXECUTABLE=false\n19: echo \"RULE=NO_WARP_FIX_NETBIRD_USA_MOLDOVA_PEERS_FOR_CROWDSEC_CAPI\"\n23: echo \"CONFIG_CHANGE=YES_RESTART_NETBIRD_ON_VPS_IF_PUBLIC_SSH_FOUND\"\n36: ssh debian@$EDGE \"sudo bash -lc '\n46: netbird status --json >/tmp/771p_edge_nb.json 2>/tmp/771p_edge_nb.err || true\n80: grep -nEi 'e3qxxx|183-106|moldova|молдов|usa|america|vps|netbird|alexhost|aeza|hetzner|public ip|external ip|ssh' /etc/pve/31_HOMELAB_REFERENCE.md 2>/dev/null | sed -n '1,260p' || true\n138: echo \"TEST_PUBLIC_SSH_AND_RESTART_NETBIRD_ON_VPS_IF_FOUND\"\n158: ssh debian@$EDGE \"sudo bash -lc '\n159: systemctl restart netbird 2>/dev/null || true\n174: ssh debian@$EDGE \"sudo bash -lc '\n182: echo \"STATUS=OK_771P_VPS_PUBLIC_ACCESS_FOUND_RESTARTED_NETBIRD_REVIEW_RECHECK\"\nKNOWN_SCRIPT=/root/771q_netbird_public_vps_repair_then_capi.sh SHA256=0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI_${TS}_PROOF.txt\"\n16: echo \"STEP=771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI\"\n19: echo \"RULE=NO_WARP_REPAIR_NETBIRD_USA_MOLDOVA_THEN_CROWDSEC_CAPI\"\n23: echo \"CONFIG_CHANGE=YES_RESTART_PUBLIC_VPS_NETBIRD_AND_CAPI_IF_ROUTE_READY\"\n33: if timeout 18 ssh -n \\\n38: \"echo SSH_OK; echo HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n53: ssh debian@$EDGE \"sudo bash -lc 'command -v warp-cli >/dev/null 2>&1 && echo WARP_CLI_STILL_PRESENT || echo WARP_CLI_ABSENT=YES; dpkg -l 2>/dev/null | grep -E \\\"^ii[[:space:]]+cloudflare-warp\\\" || echo CLOUDFLARE_WARP_PACKAGE_ABSENT=YES; ss -ltnp | grep -E \\\":(40000|40001)\\\\b\\\" || echo WARP_PROXY_PORTS_ABSENT=YES'\"\n74: echo \"RESTART_NETBIRD_ON_REAL_PUBLIC_VPS_ONLY\"\n75: : >/tmp/771q_restarted.tsv\n80: echo \"RESTART_ATTEMPT profile=$profile user=$user host=$host\"\n81: out=\"/tmp/771q_restart_${profile}_${user}_$(echo \"$host\" | tr -c A-Za-z0-9 _).out\"\n82: if timeout 45 ssh -n \\\n87: \"echo BEFORE_HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; (sudo systemctl restart netbird 2>/dev/null || systemctl restart netbird 2>/dev/null || true); sleep 15; echo AFTER; command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi_after.body -w 'DIRECT_CAPI_HTTP_AFTER=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n91: printf '%s\\t%s\\t%s\\n' \"$profile\" \"$user\" \"$host\" >>/tmp/771q_restarted.tsv\n94: echo \"RESTART_FAILED profile=$profile user=$user host=$host\"\n103: echo \"PUBLIC_VPS_RESTARTED\"\n104: cat /tmp/771q_restarted.tsv || true\n106: echo \"RECHECK_EDGE_USA_MOLDOVA_AFTER_PUBLIC_RESTART\"\n107: ssh debian@$EDGE \"sudo bash -lc '\n109: systemctl restart netbird 2>/dev/null || true\n112: netbird status --json >/tmp/771q_edge_nb.json 2>/tmp/771q_edge_nb.err || true\n139: echo \"EDGE_BUILD_NETBIRD_EGRESS_AND_REGISTER_CAPI_IF_REACHABLE\"\n140: ssh debian@$EDGE \"sudo bash -s\" <<'EDGE_SCRIPT'\n146:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n148:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n167: echo \"CHECK=crowdsec-capi\"\n173:force_no_capi_stable() {\n179: DISABLE_ONLINE_API: \"true\"\n180: ARGS: \"-no-capi\"\n201:wait_lapi() {\n203: echo \"WAIT_LAPI=$label\"\n206: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771q_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n208: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n209: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}\"\n271: raise SystemExit(\"api.server block not found\")\n274: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n310: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771q_compose.yml || true\n311: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771q_compose.yml\n321: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new \"$user@$ip\" \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" 2>&1 | redact; then\n324: if ssh -n -fN -M -S \"$ctl\" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D \"[PRIVATE_IP]:${port}\" \"$user@$ip\" 2>/tmp/771q_tunnel.err; then\n326: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771q_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n327: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n328: echo \"SOCKS_CAPI_HTTP=$code\"\n332: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n360: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n362:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n369:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n370:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n371:Restart=always\n372:RestartSec=5\n378: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n382:base=/etc/homelab-crowdsec-capi-netbird-egress\n390:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n391:systemctl restart privoxy 2>/dev/null || true\n393:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n395: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n398: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n399: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n401: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n415: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n417: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n427:out.append(\"# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n430:out.append(\"# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_END\")\n435: systemctl restart privoxy\n440: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771q_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n441: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n445:register_capi() {\n447: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n448: echo \"REGISTER_CAPI proxy=$proxy_url\"\n450: force_no_capi_stable\n451: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n455: if test -f config/online_api_credentials.yaml; then\n456: mkdir -p /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-\"$TS\"\n457: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n462: wait_lapi \"REGISTER_MODE\" || return 13\n467: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n468: timeout 240 cscli capi register -y >/tmp/771q_register.out 2>&1\n470: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771q_register.out 2>&1\n483: if ! test -f config/online_api_credentials.yaml; then\n487: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\nKNOWN_SCRIPT=/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh SHA256=9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868 EXECUTABLE=true\n7:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n9:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n29: echo \"CHECK=crowdsec-capi\"\n35:force_no_capi_stable() {\n41: DISABLE_ONLINE_API: \"true\"\n42: ARGS: \"-no-capi\"\n65:wait_lapi() {\n68: echo \"WAIT_LAPI=$label\"\n71: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n73: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n74: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n75: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n149: raise SystemExit(\"api.server block not found\")\n153: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n192: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true\n193: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml\n207: timeout 12 ssh -n \\\n212: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n224: if ssh -n -fN -M -S \"$ctl\" \\\n234: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n235: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n236: echo \"SOCKS_CAPI_HTTP=$code\"\n240: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n273: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n275:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n282:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n283:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n284:Restart=always\n285:RestartSec=5\n291: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n295:base=/etc/homelab-crowdsec-capi-netbird-egress\n303:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n304:systemctl restart privoxy 2>/dev/null || true\n306:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n308: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n311: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n312: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n314: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n328: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n330: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n340:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n343:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END\")\n348: systemctl restart privoxy\n353: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n354: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n358:register_capi() {\n359: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after\n361: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n362: echo \"REGISTER_CAPI proxy=$proxy_url\"\n364: force_no_capi_stable\n365: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n369: if test -f config/online_api_credentials.yaml; then\n370: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"\n371: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n376: wait_lapi \"REGISTER_MODE\" || return 13\n381: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n382: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1\n384: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771r_register.out 2>&1\n397: if ! test -f config/online_api_credentials.yaml; then\n401: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n402: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n404: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n411: echo \"VALIDATE_CAPI\"\n415: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n416: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n418: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n419: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n420: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n421: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n422: printf '%s\\n' \"$capi_out\"\n423: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n430: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n432: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n433: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n434: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n435: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771r_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n436: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n437: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n439: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n441: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\nKNOWN_SCRIPT=/root/771r_netbird_public_vps_fixed_then_capi.sh SHA256=dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771R_NETBIRD_PUBLIC_VPS_FIXED_THEN_CAPI_${TS}_PROOF.txt\"\n10:EDGE_REMOTE=\"/tmp/771r_edge_netbird_egress_capi_${TS}.sh\"\n11:EDGE_LOCAL=\"/root/771r_edge_netbird_egress_capi_${TS}.sh\"\n26: timeout 20 ssh -n \\\n31: \"echo SSH_OK; echo USER=\\$(id -un); echo HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n51:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n53:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n73: echo \"CHECK=crowdsec-capi\"\n79:force_no_capi_stable() {\n85: DISABLE_ONLINE_API: \"true\"\n86: ARGS: \"-no-capi\"\n109:wait_lapi() {\n112: echo \"WAIT_LAPI=$label\"\n115: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n117: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n118: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n119: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n193: raise SystemExit(\"api.server block not found\")\n197: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n236: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true\n237: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml\n251: timeout 12 ssh -n \\\n256: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n268: if ssh -n -fN -M -S \"$ctl\" \\\n278: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n279: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n280: echo \"SOCKS_CAPI_HTTP=$code\"\n284: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n317: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n319:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n326:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n327:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n328:Restart=always\n329:RestartSec=5\n335: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n339:base=/etc/homelab-crowdsec-capi-netbird-egress\n347:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n348:systemctl restart privoxy 2>/dev/null || true\n350:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n352: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n355: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n356: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n358: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n372: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n374: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n384:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n387:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END\")\n392: systemctl restart privoxy\n397: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n398: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n402:register_capi() {\n403: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after\n405: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n406: echo \"REGISTER_CAPI proxy=$proxy_url\"\n408: force_no_capi_stable\n409: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n413: if test -f config/online_api_credentials.yaml; then\n414: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"\n415: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n420: wait_lapi \"REGISTER_MODE\" || return 13\n425: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n426: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1\n428: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771r_register.out 2>&1\n441: if ! test -f config/online_api_credentials.yaml; then\n445: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n446: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n448: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n455: echo \"VALIDATE_CAPI\"\n459: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n460: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n462: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n463: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n464: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n465: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n466: printf '%s\\n' \"$capi_out\"\n467: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n474: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n476: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n477: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n478: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\nKNOWN_SCRIPT=/root/771s_edge_capi_netbird_20260702T170251Z.sh SHA256=c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5 EXECUTABLE=true\n9:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n11:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n30: echo \"CHECK=crowdsec-capi\"\n36:force_no_capi_stable() {\n42: DISABLE_ONLINE_API: \"true\"\n43: ARGS: \"-no-capi\"\n65:wait_lapi() {\n67: echo \"WAIT_LAPI=$label\"\n70: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n72: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n73: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n74: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n149: raise SystemExit(\"api.server block not found\")\n153: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n191: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true\n192: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml\n204: timeout 12 ssh -n \\\n209: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n221: if ssh -n -fN -M -S \"$ctl\" \\\n231: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n232: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n233: echo \"SOCKS_CAPI_HTTP=$code\"\n237: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n269: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n271:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n278:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n279:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n280:Restart=always\n281:RestartSec=5\n287: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n291:base=/etc/homelab-crowdsec-capi-netbird-egress\n299:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n300:systemctl restart privoxy 2>/dev/null || true\n302:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n304: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n307: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n308: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n310: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n325: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n328: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n339:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n342:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END\")\n347: systemctl restart privoxy\n352: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n353: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n357:register_capi() {\n359: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n360: echo \"REGISTER_CAPI proxy=$proxy_url\"\n362: force_no_capi_stable\n363: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n367: if test -f config/online_api_credentials.yaml; then\n368: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"\n369: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n374: wait_lapi \"REGISTER_MODE\" || return 13\n379: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n380: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1\n382: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771s_register.out 2>&1\n395: if ! test -f config/online_api_credentials.yaml; then\n399: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n400: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n402: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n409: echo \"VALIDATE_CAPI\"\n413: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n414: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n416: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n417: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n418: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n419: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n420: printf '%s\\n' \"$capi_out\"\n421: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n428: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n430: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n431: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n432: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n433: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n434: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n435: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n437: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n439: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n443:echo \"STEP=771S_EDGE_NETBIRD_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771s_vps_identity_repair_netbird_capi.sh SHA256=16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771S_VPS_IDENTITY_REPAIR_NETBIRD_CAPI_${TS}_PROOF.txt\"\n13:EDGE_REMOTE=\"/tmp/771s_edge_capi_netbird_${TS}.sh\"\n14:EDGE_LOCAL=\"/root/771s_edge_capi_netbird_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n171: raise SystemExit(\"api.server block not found\")\n175: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n213: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true\n214: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml\n226: timeout 12 ssh -n \\\n231: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n243: if ssh -n -fN -M -S \"$ctl\" \\\n253: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n254: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n255: echo \"SOCKS_CAPI_HTTP=$code\"\n259: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n291: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n293:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n300:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n301:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n302:Restart=always\n303:RestartSec=5\n309: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n313:base=/etc/homelab-crowdsec-capi-netbird-egress\n321:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n322:systemctl restart privoxy 2>/dev/null || true\n324:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n326: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n329: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n330: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n332: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n347: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n350: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n361:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n364:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END\")\n369: systemctl restart privoxy\n374: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n375: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n379:register_capi() {\n381: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n382: echo \"REGISTER_CAPI proxy=$proxy_url\"\n384: force_no_capi_stable\n385: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n389: if test -f config/online_api_credentials.yaml; then\n390: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"\n391: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n396: wait_lapi \"REGISTER_MODE\" || return 13\n401: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n402: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1\n404: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771s_register.out 2>&1\n417: if ! test -f config/online_api_credentials.yaml; then\n421: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n422: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n424: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n431: echo \"VALIDATE_CAPI\"\n435: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n436: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n438: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n439: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n440: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n441: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n442: printf '%s\\n' \"$capi_out\"\n443: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n450: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n452: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n453: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n454: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n455: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n456: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n457: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\nKNOWN_SCRIPT=/root/771t_temp_hostkey_netbird_identity_then_capi.sh SHA256=0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da EXECUTABLE=false\n8:PROOF=\"/root/evidence/771T_TEMP_HOSTKEY_NETBIRD_IDENTITY_THEN_CAPI_${TS}_PROOF.txt\"\n11:EDGE_SCRIPT_LOCAL=\"/root/771t_edge_capi_${TS}.sh\"\n12:EDGE_SCRIPT_REMOTE=\"/tmp/771t_edge_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n50: echo \"CHECK=crowdsec-capi\"\n56:force_no_capi_stable() {\n62: DISABLE_ONLINE_API: \"true\"\n63: ARGS: \"-no-capi\"\n85:wait_lapi() {\n87: echo \"WAIT_LAPI=$label\"\n90: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n92: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n93: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n94: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n166: raise SystemExit(\"api.server block not found\")\n169: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771t_compose.yml || true\n208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771t_compose.yml\n217: timeout 15 ssh -n -o BatchMode=yes -o ConnectTimeout=8 -o StrictHostKeyChecking=accept-new \"$TARGET_USER@$TARGET_NB\" \\\n218: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771t_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n236: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n238:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n245:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n246:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n247:Restart=always\n248:RestartSec=5\n254: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n258:base=/etc/homelab-crowdsec-capi-netbird-egress\n266:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n267:systemctl restart privoxy 2>/dev/null || true\n269:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n271: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n274: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n275: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n277: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n293: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n296: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n307:out.append(\"# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n310:out.append(\"# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_END\")\n315: systemctl restart privoxy\n320: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771t_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n321: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n322: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n329:register_capi() {\n331: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n332: echo \"REGISTER_CAPI proxy=$proxy_url\"\n334: force_no_capi_stable\n335: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n339: if test -f config/online_api_credentials.yaml; then\n340: mkdir -p /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-\"$TS\"\n341: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n346: wait_lapi \"REGISTER_MODE\" || return 13\n351: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n352: timeout 240 cscli capi register -y >/tmp/771t_register.out 2>&1\n354: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771t_register.out 2>&1\n367: if ! test -f config/online_api_credentials.yaml; then\n371: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n372: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n374: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n381: echo \"VALIDATE_CAPI\"\n385: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n386: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n388: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n389: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n390: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n391: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n392: printf '%s\\n' \"$capi_out\"\n393: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n400: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n402: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n403: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n404: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n405: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771t_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n406: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n407: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n409: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n411: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n415:echo \"STEP=771T_EDGE_CAPI_VIA_VERIFIED_NETBIRD_PEER\"\n418:systemctl restart netbird 2>/dev/null || true\nKNOWN_SCRIPT=/root/771u_find_key_fix_netbird_egress_capi.sh SHA256=6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb EXECUTABLE=false\n8:PROOF=\"/root/evidence/771U_FIND_KEY_FIX_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt\"\n11:EDGE_REMOTE=\"/tmp/771u_edge_register_capi_${TS}.sh\"\n12:EDGE_LOCAL=\"/root/771u_edge_register_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n167: raise SystemExit(\"api.server block not found\")\n170: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771u_compose.yml || true\n208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771u_compose.yml\n213: ssh-keygen -q -t ed25519 -N \"\" -C \"homelab-crowdsec-capi-netbird-egress-edge\" -f \"$SSH_KEY\"\n227: timeout 15 ssh -n \\\n234: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771u_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n253: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n255:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n262:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n263:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i \"${SSH_KEY}\" -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n264:Restart=always\n265:RestartSec=5\n271: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n275:base=/etc/homelab-crowdsec-capi-netbird-egress\n283:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n284:systemctl restart privoxy 2>/dev/null || true\n286:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n288: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n291: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n292: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n294: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n310: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n313: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n324:out.append(\"# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n327:out.append(\"# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_END\")\n332: systemctl restart privoxy\n337: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771u_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n338: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n339: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n346:register_capi() {\n348: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n349: echo \"REGISTER_CAPI proxy=$proxy_url\"\n351: force_no_capi_stable\n352: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n356: if test -f config/online_api_credentials.yaml; then\n357: mkdir -p /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-\"$TS\"\n358: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n363: wait_lapi \"REGISTER_MODE\" || return 13\n368: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n369: timeout 240 cscli capi register -y >/tmp/771u_register.out 2>&1\n371: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771u_register.out 2>&1\n384: if ! test -f config/online_api_credentials.yaml; then\n388: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n389: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n391: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n398: echo \"VALIDATE_CAPI\"\n402: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n403: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n405: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n406: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n407: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n408: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n409: printf '%s\\n' \"$capi_out\"\n410: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n417: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n419: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n420: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n421: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n422: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771u_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n423: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n424: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n426: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n428: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n432:echo \"STEP=771U_EDGE_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771v_deep_key_backup_netbird_capi.sh SHA256=92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771V_DEEP_KEY_BACKUP_NETBIRD_CAPI_${TS}_PROOF.txt\"\n11:EDGE_LOCAL=\"/root/771v_edge_netbird_capi_${TS}.sh\"\n12:EDGE_REMOTE=\"/tmp/771v_edge_netbird_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n168: raise SystemExit(\"api.server block not found\")\n172: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n210: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771v_compose.yml || true\n211: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771v_compose.yml\n216: ssh-keygen -q -t ed25519 -N \"\" -C \"homelab-crowdsec-capi-netbird-egress-edge\" -f \"$SSH_KEY\"\n230: timeout 15 ssh -n \\\n237: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771v_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n256: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n258:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n265:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n266:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i \"${SSH_KEY}\" -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n267:Restart=always\n268:RestartSec=5\n274: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n278:base=/etc/homelab-crowdsec-capi-netbird-egress\n286:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n287:systemctl restart privoxy 2>/dev/null || true\n289:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n291: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n294: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n295: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n297: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n313: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n316: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n327:out.append(\"# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n330:out.append(\"# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_END\")\n335: systemctl restart privoxy\n340: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771v_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n341: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n342: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n349:register_capi() {\n351: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n352: echo \"REGISTER_CAPI proxy=$proxy_url\"\n354: force_no_capi_stable\n355: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n359: if test -f config/online_api_credentials.yaml; then\n360: mkdir -p /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-\"$TS\"\n361: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n366: wait_lapi \"REGISTER_MODE\" || return 13\n371: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n372: timeout 240 cscli capi register -y >/tmp/771v_register.out 2>&1\n374: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771v_register.out 2>&1\n387: if ! test -f config/online_api_credentials.yaml; then\n391: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n392: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n394: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n401: echo \"VALIDATE_CAPI\"\n405: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n406: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n408: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n409: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n410: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n411: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n412: printf '%s\\n' \"$capi_out\"\n413: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n420: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n422: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n423: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n424: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n425: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771v_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n426: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n427: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n429: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n431: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n435:echo \"STEP=771V_EDGE_NETBIRD_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771z_after_manual_netbird_egress_capi.sh SHA256=f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee EXECUTABLE=false\n8:PROOF=\"/root/evidence/771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt\"\n14: echo \"STEP=771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI\"\n17: echo \"RULE=VERIFY_RELAY_MAIL_EGRESS_AND_REGISTER_CROWDSEC_CAPI\"\n21: ssh debian@$EDGE \"sudo bash -s\" <<'EDGE'\n27:HEALTH=/var/lib/homelab-health/crowdsec-capi.txt\n38: echo \"CHECK=crowdsec-capi\"\n44:wait_lapi() {\n46: echo \"WAIT_LAPI=$label\"\n49: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n51: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n52: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}\"\n59:force_no_capi() {\n65: DISABLE_ONLINE_API: \"true\"\n66: ARGS: \"-no-capi\"\n87:enable_capi_compose() {\n112: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|socket-proxy|published:|target:' /tmp/771z_compose.yml || true\n113: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771z_compose.yml\n180: raise SystemExit(\"api.server block not found\")\n183: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n194:echo \"NETBIRD_RESTART\"\n195:systemctl restart netbird 2>/dev/null || true\n199:netbird status 2>&1 | redact || true\n202:netbird status --json >/tmp/771z_nb.json 2>/tmp/771z_nb.err || true\n229:echo \"CAPI_DIRECT_TEST_AFTER_MANUAL_NETBIRD\"\n230:capi_code=\"$(curl -4 -sk --http1.1 --connect-timeout 12 --max-time 45 -o /tmp/771z_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n231:trace=\"$(curl -4 -sk --connect-timeout 12 --max-time 30 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n232:echo \"CAPI_DIRECT_HTTP=$capi_code\"\n237:if test \"$capi_code\" = \"000\"; then\n238: force_no_capi\n239: wait_lapi \"CAPI_ROUTE_NOT_READY_SAFE\" || true\n240: write_health \"REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY\" \"After manual NetBird setup, edge still cannot reach api.crowdsec.net; CrowdSec remains LAPI-only no-capi\"\n241: echo \"EDGE_STATUS=REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY_CAPI_NOT_DONE\"\n246:echo \"CAPI_ROUTE_READY_REGISTER_NOW\"\n248:mkdir -p \"manual-backups/771z-$TS\"\n249:test -f config/config.yaml && cp -a config/config.yaml \"manual-backups/771z-$TS/config.yaml.before\" || true\n250:test -f config/user.yaml && cp -a config/user.yaml \"manual-backups/771z-$TS/user.yaml.before\" || true\n251:test -f config/online_api_credentials.yaml && mv config/online_api_credentials.yaml \"manual-backups/771z-$TS/online_api_credentials.yaml.before\" || true\n254:enable_capi_compose || {\n255: force_no_capi\n256: wait_lapi \"COMPOSE_FAIL_SAFE\" || true\n257: write_health \"REVIEW_CAPI_COMPOSE_ENABLE_FAILED\" \"Direct CAPI route works, but compose CAPI enable failed\"\n262:wait_lapi \"REGISTER_MODE\" || exit 73\n266: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n267: timeout 240 cscli capi register -y >/tmp/771z_register.out 2>&1\n269: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771z_register.out 2>&1\n281:if test \"${reg_rc:-NA}\" != \"0\" || ! test -f config/online_api_credentials.yaml; then\n282: force_no_capi\n283: wait_lapi \"REGISTER_FAIL_SAFE\" || true\n284: write_health \"REVIEW_CAPI_ROUTE_READY_BUT_REGISTER_FAILED\" \"Direct CAPI route works, but cscli capi register failed; restored no-capi\"\n285: echo \"EDGE_STATUS=REVIEW_CAPI_REGISTER_FAILED_NOT_DONE\"\n290:stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n291:awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n294:enable_capi_compose || exit 75\n300: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n301: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771z_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n303: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n304: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml' || true)\"\n305: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n306: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n307: printf '%s\\n' \"$capi_out\"\n308: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n315: write_health \"OK_CAPI_REGISTERED_ENABLED_STABLE_MANUAL_NETBIRD_EGRESS\" \"CrowdSec CAPI registered and stable after manual NetBird egress via relay/mail\"\n316: echo \"EDGE_STATUS=OK_CROWDSEC_CAPI_100_PERCENT_REGISTERED_ENABLED_STABLE\"\n321:force_no_capi\n322:wait_lapi \"VALIDATION_FAIL_SAFE\" || true\n323:write_health \"REVIEW_CAPI_REGISTERED_BUT_NOT_STABLE_RESTORED_NO_CAPI\" \"CAPI registration happened but stability validation failed; restored no-capi\"\n324:echo \"EDGE_STATUS=REVIEW_CAPI_NOT_STABLE_RESTORED_NO_CAPI\"\n331: code=$(curl -sk --connect-timeout 8 --max-time 20 --resolve \"$h:443:$EDGE\" -o \"/tmp/771z_$h.html\" -w \"%{http_code}\" \"https://$h/\" || true)\n337: echo STATUS=OK_771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_DONE\nKNOWN_771_SAFE_STATIC_END=1\nPOLICY_DOCS_BEGIN=1\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\n1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD\n9:NetBird:\n14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures.\n16:Current:\n17:`/usr/local/sbin/pvepro-relay-healthcheck`\n27:- new NetBird TCP 80/443\n37:`PASS_RELAY_HEALTHCHECK_OK`\n40:enabled/active.\n48:Old USA observer had been converted to Gotify-only before retirement.\n50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon.\n78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf`\n86:- timer active\n89:Rollback backup:\n92:Old USA observer then:\n93:- backup created\n95:- service inactive\n96:- 80-second freeze proved no further health-file updates\n98:- old NetBird server still stopped\n99:- old host NetBird client still connected\n100:- Moldova peer reachable\n102:Old observer backup:\n103:`/root/retired-homelab-dr-observer-20260818T221046Z`\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\n1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD\n5:Old USA mail/NetBird VPS:\n7:- secondary NetBird IPv4 `[PRIVATE_IP]`\n10:Old NetBird server stack stopped after successful migration.\n11:Host-level NetBird client left running for rollback/peer observation.\n33:NetBird:\n36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`.\n56:- Moldova synthetic check passes\n59:Important health discovery:\n60:- `/api/health` 404 on exact deployed version\n61:- `:9000/health` 503 in combined relay/server mode\n62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy\n65:Backups on new server include migration/cutover snapshots such as:\n66:`/root/netbird-cutover-20260818T145807Z`\n69:- upgrade NetBird\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\n1:# CRITICAL KEEP / RETIRE DECISIONS\n3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof.\n11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore |\n12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect |\n16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup |\n18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first |\n19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties |\n20:| Moldova relay | KEEP | independent relay/external health |\n21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII |\n24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement |\n27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active |\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\n1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD\n9:NetBird:\n14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures.\n16:Current:\n17:`/usr/local/sbin/pvepro-relay-healthcheck`\n27:- new NetBird TCP 80/443\n37:`PASS_RELAY_HEALTHCHECK_OK`\n40:enabled/active.\n48:Old USA observer had been converted to Gotify-only before retirement.\n50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon.\n78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf`\n86:- timer active\n89:Rollback backup:\n92:Old USA observer then:\n93:- backup created\n95:- service inactive\n96:- 80-second freeze proved no further health-file updates\n98:- old NetBird server still stopped\n99:- old host NetBird client still connected\n100:- Moldova peer reachable\n102:Old observer backup:\n103:`/root/retired-homelab-dr-observer-20260818T221046Z`\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\n1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD\n5:Old USA mail/NetBird VPS:\n7:- secondary NetBird IPv4 `[PRIVATE_IP]`\n10:Old NetBird server stack stopped after successful migration.\n11:Host-level NetBird client left running for rollback/peer observation.\n33:NetBird:\n36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`.\n56:- Moldova synthetic check passes\n59:Important health discovery:\n60:- `/api/health` 404 on exact deployed version\n61:- `:9000/health` 503 in combined relay/server mode\n62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy\n65:Backups on new server include migration/cutover snapshots such as:\n66:`/root/netbird-cutover-20260818T145807Z`\n69:- upgrade NetBird\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\n1:# CRITICAL KEEP / RETIRE DECISIONS\n3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof.\n11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore |\n12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect |\n16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup |\n18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first |\n19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties |\n20:| Moldova relay | KEEP | independent relay/external health |\n21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII |\n24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement |\n27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active |\nPOLICY_DOCS_END=1\nCONTROL_UNIT_REFERENCES_BEGIN=1\nCONTROL_UNIT_REFERENCES_END=1\nDECISION=PASS_BACKUP_1123_NO_EXTERNAL_PROVIDER_CONTROL_PATH_PROVEN\nNEXT_GATE=RETIRE_US_NETBIRD_TARGET_FROM_ACTIVE_BACKUPV2_POLICY_THEN_COMBINED_REPAIR\nTASK_RESULT=PASS_HOMELAB_BACKUP_MOLDOVA_CONTROL_RCA\nCHANGES_MADE_BY_1123=false\nPRODUCT_MUTATION_BY_1123=false\nVM_MUTATION_BY_1123=false\nCLOUD_MUTATION_BY_1123=false\nHOMELAB_RESULT_CONTRACT={\"version\":1,\"command_id\":\"SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1\",\"status\":\"OK\",\"changes_made\":false,\"rollback_started\":false,\"rollback_restored\":null}\nWORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_END=1\n"
|
|
}
|