Files
pxmon/docs/REPOTUNNELING.md
2026-06-16 21:52:10 +04:00

2.6 KiB

PXmon RepoTunneling

RepoTunneling gives an ipfabric node temporary package repository access through a disposable gateway VM.

The node does not receive full internet access. PXmon only adds an ip rule for the gateway VM address and configures the node package manager to use the gateway as an HTTP proxy.

Topology

ipfabric node
  -> ip rule to gateway public IP using the node-specific routing table
  -> gateway VM with squid
  -> internet repositories

The routing table is not hard-coded. Always pass the correct table for that node with --table.

1. Prepare The Gateway VM

The gateway VM must have normal internet access and must be reachable from the ipfabric node after adding the destination-specific route rule.

If the gateway VM is already managed by PXmon:

pxmon cluster repo-tunnel gateway-setup repo-vm \
  --allow 198.51.100.20/32 \
  --port 3128

If it is not managed by PXmon, print the setup script and run it manually on the gateway VM:

pxmon cluster repo-tunnel gateway-script \
  --allow 198.51.100.20/32 \
  --port 3128

Use one --allow per node source IP/CIDR. Do not leave squid open to the internet.

2. Enable RepoTunneling On The ipfabric Node

pxmon cluster repo-tunnel enable edge-node-1 \
  --gateway 203.0.113.10:3128 \
  --gateway-ip 203.0.113.10 \
  --table 1010 \
  --manager dnf

--gateway-ip is optional when the node can resolve the gateway hostname or when --gateway is already an IP. It is useful before DNS works through the proxy path.

PXmon writes managed package-manager config:

  • apt: /etc/apt/apt.conf.d/99-pxmon-repo-tunnel
  • dnf: managed block in /etc/dnf/dnf.conf
  • yum: managed block in /etc/yum.conf

3. Install Packages

For a one-shot package operation:

pxmon cluster repo-tunnel install edge-node-1 \
  --gateway 203.0.113.10:3128 \
  --gateway-ip 203.0.113.10 \
  --table 1010 \
  --manager dnf \
  -- dnf install -y curl jq smartmontools

By default install removes the proxy config and matching ip rule after the command. Add --keep-enabled if you want to leave it active.

4. Inspect Or Disable

pxmon cluster repo-tunnel status edge-node-1
pxmon cluster repo-tunnel disable edge-node-1 \
  --gateway 203.0.113.10:3128 \
  --gateway-ip 203.0.113.10 \
  --table 1010

Notes

  • --table is required because ipfabric route table IDs differ between servers.
  • Use --no-rule only if you already created the needed route rule manually and only want PXmon to manage package proxy config.
  • For AlmaLinux 8, --manager dnf is the expected mode.
  • The gateway should be disposable and firewall-restricted.