diff --git a/GET_STARTED.md b/GET_STARTED.md index 7e6036cc..e9e43c2d 100644 --- a/GET_STARTED.md +++ b/GET_STARTED.md @@ -90,6 +90,11 @@ We provide a `quickstart.sh` script to automate the setup process. The script wi } ``` + `diode_target_override` must be an address reachable **from inside NetBox**. + If NetBox itself runs in a container, `localhost` resolves to that container + rather than to the Diode server, so use the host's IP address or FQDN + instead, for example `grpc://192.168.1.10:8080/diode`. + 4. **Apply Database Migrations** ```bash cd /opt/netbox/netbox diff --git a/charts/diode/Chart.yaml b/charts/diode/Chart.yaml index 3dd114ee..4cf761da 100644 --- a/charts/diode/Chart.yaml +++ b/charts/diode/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: diode description: A Helm chart for Diode type: application -version: "1.15.3" +version: "1.15.4" appVersion: "1.5.0" home: https://github.com/netboxlabs/diode sources: diff --git a/charts/diode/scripts/quickstart.sh b/charts/diode/scripts/quickstart.sh index 77840530..973b5b82 100755 --- a/charts/diode/scripts/quickstart.sh +++ b/charts/diode/scripts/quickstart.sh @@ -226,8 +226,33 @@ else fi fi +# The NetBox Diode plugin authenticates as netbox-to-diode, a different client +# to the ingest one used by orb-agent. Surfacing it here avoids pasting the +# wrong secret and hitting "Failed to obtain access token". +NETBOX_TO_DIODE_CLIENT_ID="netbox-to-diode" + +# Read it from the deployed Secret rather than the local file. When the Secret +# already existed we skipped creating it above, so a client-credentials.json +# regenerated in a fresh working directory holds values that were never applied +# to the cluster; printing those would hand out a credential that cannot +# authenticate. Fall back to the local file only when the Secret is unreadable. +NETBOX_TO_DIODE_CLIENT_SECRET=$(kubectl get secret "$DIODE_AUTH_OAUTH2_SECRET" -n "$NAMESPACE" \ + -o jsonpath='{.data.client-credentials\.json}' 2>/dev/null | base64 -d 2>/dev/null \ + | jq -r --arg id "$NETBOX_TO_DIODE_CLIENT_ID" \ + 'try (.[] | select(.client_id == $id) | .client_secret) // empty' 2>/dev/null) + +if [[ -z "$NETBOX_TO_DIODE_CLIENT_SECRET" ]]; then + NETBOX_TO_DIODE_CLIENT_SECRET=$(jq -r --arg id "$NETBOX_TO_DIODE_CLIENT_ID" \ + '.[] | select(.client_id == $id) | .client_secret' "$PWD/client-credentials.json") +fi + echo "----------------------------------------" ok "Environment setup completed!" +info "Add the following to PLUGINS_CONFIG[\"netbox_diode_plugin\"] in configuration.py:" +info " \"netbox_to_diode_client_secret\": \"$NETBOX_TO_DIODE_CLIENT_SECRET\"," +info "That is the $NETBOX_TO_DIODE_CLIENT_ID client secret, not the ingest one." +info "Set \"diode_target_override\" to the ingress address, reachable from NetBox." +echo info "You can now install the diode helm chart by running:" if [[ "$CLUSTER_DOMAIN" == "cluster.local" ]]; then info " helm install diode/diode --namespace $NAMESPACE" diff --git a/diode-server/docker/scripts/quickstart.sh b/diode-server/docker/scripts/quickstart.sh index 5c7fa5bd..f168c81f 100755 --- a/diode-server/docker/scripts/quickstart.sh +++ b/diode-server/docker/scripts/quickstart.sh @@ -192,14 +192,28 @@ fi DIODE_NGINX_PORT=$(grep -oP 'DIODE_NGINX_PORT=\K[0-9]+' "$ENV_FILE" 2>/dev/null || echo "8080") DIODE_TARGET="grpc://localhost:$DIODE_NGINX_PORT/diode" -# Get diode-ingest client credentials +# Get diode-ingest client credentials, used by orb-agent to ingest data DIODE_INGEST_CLIENT_ID="diode-ingest" DIODE_INGEST_CLIENT_SECRET=$(jq -r '.[] | select(.client_id == "'$DIODE_INGEST_CLIENT_ID'") | .client_secret' oauth2/client/client-credentials.json) +# Get netbox-to-diode client credentials, used by the NetBox Diode plugin. These +# are a different client to the ingest one above; pasting the ingest secret into +# the plugin fails with "Failed to obtain access token". +NETBOX_TO_DIODE_CLIENT_ID="netbox-to-diode" +NETBOX_TO_DIODE_CLIENT_SECRET=$(jq -r '.[] | select(.client_id == "'$NETBOX_TO_DIODE_CLIENT_ID'") | .client_secret' oauth2/client/client-credentials.json) + echo "----------------------------------------" ok "Environment setup completed!" info "You can now start the diode by running:" info " $DOCKER_COMPOSE up -d" +echo info "Configure orb-agent with diode target $DIODE_TARGET to use the following credentials:" info " DIODE_CLIENT_ID: $DIODE_INGEST_CLIENT_ID" info " DIODE_CLIENT_SECRET: $DIODE_INGEST_CLIENT_SECRET" +echo +info "Add the following to PLUGINS_CONFIG[\"netbox_diode_plugin\"] in configuration.py:" +info " \"netbox_to_diode_client_secret\": \"$NETBOX_TO_DIODE_CLIENT_SECRET\"," +info " \"diode_target_override\": \"grpc://:$DIODE_NGINX_PORT/diode\"," +info "That is the $NETBOX_TO_DIODE_CLIENT_ID client secret, not the ingest one above." +info "Replace with an address reachable from NetBox. localhost only" +info "works when NetBox runs directly on this host, outside a container." diff --git a/docs/getting-started.md b/docs/getting-started.md index 3e240180..34de09f1 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -90,6 +90,11 @@ We provide a `quickstart.sh` script to automate the setup process. The script wi } ``` + `diode_target_override` must be an address reachable **from inside NetBox**. + If NetBox itself runs in a container, `localhost` resolves to that container + rather than to the Diode server, so use the host's IP address or FQDN + instead, for example `grpc://192.168.1.10:8080/diode`. + 4. **Apply Database Migrations** ```bash cd /opt/netbox/netbox