2.6 KiB
PXmon RepoTunneling
RepoTunneling gives an ipfabric node temporary package repository access
through a disposable gateway VM.
The node does not receive full internet access. PXmon only adds an ip rule
for the gateway VM address and configures the node package manager to use the
gateway as an HTTP proxy.
Topology
ipfabric node
-> ip rule to gateway public IP using the node-specific routing table
-> gateway VM with squid
-> internet repositories
The routing table is not hard-coded. Always pass the correct table for that
node with --table.
1. Prepare The Gateway VM
The gateway VM must have normal internet access and must be reachable from the ipfabric node after adding the destination-specific route rule.
If the gateway VM is already managed by PXmon:
pxmon cluster repo-tunnel gateway-setup repo-vm \
--allow 198.51.100.20/32 \
--port 3128
If it is not managed by PXmon, print the setup script and run it manually on the gateway VM:
pxmon cluster repo-tunnel gateway-script \
--allow 198.51.100.20/32 \
--port 3128
Use one --allow per node source IP/CIDR. Do not leave squid open to the
internet.
2. Enable RepoTunneling On The ipfabric Node
pxmon cluster repo-tunnel enable edge-node-1 \
--gateway 203.0.113.10:3128 \
--gateway-ip 203.0.113.10 \
--table 1010 \
--manager dnf
--gateway-ip is optional when the node can resolve the gateway hostname or
when --gateway is already an IP. It is useful before DNS works through the
proxy path.
PXmon writes managed package-manager config:
- apt:
/etc/apt/apt.conf.d/99-pxmon-repo-tunnel - dnf: managed block in
/etc/dnf/dnf.conf - yum: managed block in
/etc/yum.conf
3. Install Packages
For a one-shot package operation:
pxmon cluster repo-tunnel install edge-node-1 \
--gateway 203.0.113.10:3128 \
--gateway-ip 203.0.113.10 \
--table 1010 \
--manager dnf \
-- dnf install -y curl jq smartmontools
By default install removes the proxy config and matching ip rule after the
command. Add --keep-enabled if you want to leave it active.
4. Inspect Or Disable
pxmon cluster repo-tunnel status edge-node-1
pxmon cluster repo-tunnel disable edge-node-1 \
--gateway 203.0.113.10:3128 \
--gateway-ip 203.0.113.10 \
--table 1010
Notes
--tableis required because ipfabric route table IDs differ between servers.- Use
--no-ruleonly if you already created the needed route rule manually and only want PXmon to manage package proxy config. - For AlmaLinux 8,
--manager dnfis the expected mode. - The gateway should be disposable and firewall-restricted.