#!/bin/sh # Join this machine to a Warmbly fleet. # # curl -fsSL https:///join.sh | sh -s -- \ # --url https:// --token --role worker # # It asks the control plane to enrol the machine, writes the config the control # plane hands back, installs a systemd service for the role and a timer that # keeps it on the version the control plane wants, and starts it. # # Nothing is pushed to this machine, before or after. No inbound port is # opened, no SSH key is installed, and the only credential involved is the join # token, which is used once and never stored. # # POSIX sh: this runs under whatever /bin/sh the host has, which on Debian and # Ubuntu is dash. set -eu WARMBLY_URL="" WARMBLY_TOKEN="" WARMBLY_ROLE="" WARMBLY_REGION="" WARMBLY_NAME="" WARMBLY_IMAGE_REPO="ghcr.io/warmbly/warmbly" CONFIG_DIR="/etc/warmbly" STATE_DIR="/var/lib/warmbly" # What the container may write. Kept separate from STATE_DIR because STATE_DIR # also holds image-ref, which systemd feeds to a root `docker run`: anything # the node can rewrite there would choose the image root then executes. AGENT_DIR="/var/lib/warmbly/node" DRY_RUN="false" PRINT_UNIT="false" log() { printf '%s\n' "$*"; } warn() { printf '%s\n' "$*" >&2; } die() { printf 'error: %s\n' "$*" >&2; exit 1; } usage() { cat <<'USAGE' Join a machine to a Warmbly fleet. --url Your Warmbly instance, e.g. https://app.example.com (required) --token Fleet join token. Issue one in Fleet settings, or with `warmblyctl fleet join-token`. (required) --role worker | consumer (required) --region