Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions GET_STARTED.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,11 @@ We provide a `quickstart.sh` script to automate the setup process. The script wi
}
```

`diode_target_override` must be an address reachable **from inside NetBox**.
If NetBox itself runs in a container, `localhost` resolves to that container
rather than to the Diode server, so use the host's IP address or FQDN
instead, for example `grpc://192.168.1.10:8080/diode`.

4. **Apply Database Migrations**
```bash
cd /opt/netbox/netbox
Expand Down
2 changes: 1 addition & 1 deletion charts/diode/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ apiVersion: v2
name: diode
description: A Helm chart for Diode
type: application
version: "1.15.3"
version: "1.15.4"
appVersion: "1.5.0"
home: https://github.com/netboxlabs/diode
sources:
Expand Down
25 changes: 25 additions & 0 deletions charts/diode/scripts/quickstart.sh
Original file line number Diff line number Diff line change
Expand Up @@ -226,8 +226,33 @@ else
fi
fi

# The NetBox Diode plugin authenticates as netbox-to-diode, a different client
# to the ingest one used by orb-agent. Surfacing it here avoids pasting the
# wrong secret and hitting "Failed to obtain access token".
NETBOX_TO_DIODE_CLIENT_ID="netbox-to-diode"

# Read it from the deployed Secret rather than the local file. When the Secret
# already existed we skipped creating it above, so a client-credentials.json
# regenerated in a fresh working directory holds values that were never applied
# to the cluster; printing those would hand out a credential that cannot
# authenticate. Fall back to the local file only when the Secret is unreadable.
NETBOX_TO_DIODE_CLIENT_SECRET=$(kubectl get secret "$DIODE_AUTH_OAUTH2_SECRET" -n "$NAMESPACE" \
-o jsonpath='{.data.client-credentials\.json}' 2>/dev/null | base64 -d 2>/dev/null \
| jq -r --arg id "$NETBOX_TO_DIODE_CLIENT_ID" \
'try (.[] | select(.client_id == $id) | .client_secret) // empty' 2>/dev/null)

if [[ -z "$NETBOX_TO_DIODE_CLIENT_SECRET" ]]; then
NETBOX_TO_DIODE_CLIENT_SECRET=$(jq -r --arg id "$NETBOX_TO_DIODE_CLIENT_ID" \
'.[] | select(.client_id == $id) | .client_secret' "$PWD/client-credentials.json")
fi

echo "----------------------------------------"
ok "Environment setup completed!"
info "Add the following to PLUGINS_CONFIG[\"netbox_diode_plugin\"] in configuration.py:"
info " \"netbox_to_diode_client_secret\": \"$NETBOX_TO_DIODE_CLIENT_SECRET\","
info "That is the $NETBOX_TO_DIODE_CLIENT_ID client secret, not the ingest one."
info "Set \"diode_target_override\" to the ingress address, reachable from NetBox."
echo
info "You can now install the diode helm chart by running:"
if [[ "$CLUSTER_DOMAIN" == "cluster.local" ]]; then
info " helm install <RELEASE_NAME> diode/diode --namespace $NAMESPACE"
Expand Down
16 changes: 15 additions & 1 deletion diode-server/docker/scripts/quickstart.sh
Original file line number Diff line number Diff line change
Expand Up @@ -192,14 +192,28 @@ fi
DIODE_NGINX_PORT=$(grep -oP 'DIODE_NGINX_PORT=\K[0-9]+' "$ENV_FILE" 2>/dev/null || echo "8080")
DIODE_TARGET="grpc://localhost:$DIODE_NGINX_PORT/diode"

# Get diode-ingest client credentials
# Get diode-ingest client credentials, used by orb-agent to ingest data
DIODE_INGEST_CLIENT_ID="diode-ingest"
DIODE_INGEST_CLIENT_SECRET=$(jq -r '.[] | select(.client_id == "'$DIODE_INGEST_CLIENT_ID'") | .client_secret' oauth2/client/client-credentials.json)

# Get netbox-to-diode client credentials, used by the NetBox Diode plugin. These
# are a different client to the ingest one above; pasting the ingest secret into
# the plugin fails with "Failed to obtain access token".
NETBOX_TO_DIODE_CLIENT_ID="netbox-to-diode"
NETBOX_TO_DIODE_CLIENT_SECRET=$(jq -r '.[] | select(.client_id == "'$NETBOX_TO_DIODE_CLIENT_ID'") | .client_secret' oauth2/client/client-credentials.json)

echo "----------------------------------------"
ok "Environment setup completed!"
info "You can now start the diode by running:"
info " $DOCKER_COMPOSE up -d"
echo
info "Configure orb-agent with diode target $DIODE_TARGET to use the following credentials:"
info " DIODE_CLIENT_ID: $DIODE_INGEST_CLIENT_ID"
info " DIODE_CLIENT_SECRET: $DIODE_INGEST_CLIENT_SECRET"
echo
info "Add the following to PLUGINS_CONFIG[\"netbox_diode_plugin\"] in configuration.py:"
info " \"netbox_to_diode_client_secret\": \"$NETBOX_TO_DIODE_CLIENT_SECRET\","
info " \"diode_target_override\": \"grpc://<diode-host>:$DIODE_NGINX_PORT/diode\","
info "That is the $NETBOX_TO_DIODE_CLIENT_ID client secret, not the ingest one above."
info "Replace <diode-host> with an address reachable from NetBox. localhost only"
info "works when NetBox runs directly on this host, outside a container."
5 changes: 5 additions & 0 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,11 @@ We provide a `quickstart.sh` script to automate the setup process. The script wi
}
```

`diode_target_override` must be an address reachable **from inside NetBox**.
If NetBox itself runs in a container, `localhost` resolves to that container
rather than to the Diode server, so use the host's IP address or FQDN
instead, for example `grpc://192.168.1.10:8080/diode`.

4. **Apply Database Migrations**
```bash
cd /opt/netbox/netbox
Expand Down
Loading