d552f4f326069c292b682f8930fcfb36c51ec6b3
- Added a `maybe_self_update` function in `evofw-firewall.sh` to allow agents to pull the latest version of the sync script from the server, enhancing the agent's ability to stay updated. - Updated the `/v1/agent/sync-script` endpoint to return ETag and script SHA256 headers, enabling efficient caching and conditional requests. - Modified the agent policy response to include `script_sha256`, providing visibility into the current version of the sync script. - Enhanced tests to verify the self-update functionality and ensure correct behavior of the sync script endpoint. These changes improve the maintainability and reliability of Linux agents by enabling automatic updates of critical scripts.
EvoFirewall
Централизованный firewall controller: Linux / MikroTik agents, IP lists, allow/deny политики, статистика.
Интеграции: auth-portal (SSO, app id fw), EvoBGP (источник префиксов).
Стек
- Monorepo: pnpm workspaces + turbo
apps/web— Vite + React + TanStack + shadcn/ui + ReUI Frameapps/api— Fastify 5 + Drizzle + SQLite- Packages:
@evofw/ui,@evofw/shared,@evofw/db
Быстрый старт
pnpm install
cp .env.example .env
pnpm --filter @evofw/db build
pnpm --filter @evofw/shared build
pnpm --filter @evofw/api dev # :8080
pnpm --filter @evofw/web dev # :5177
Linux agent (short link из UI /agents → Добавить агента):
curl -fsSL http://localhost:8080/agent-install/<id> | bash
# или:
curl -fsSL http://localhost:8080/<slug> | bash
Legacy one-liner:
curl -fsSL http://localhost:8080/v1/agent/install.sh | \
EVOFW_CP_URL=http://localhost:8080 \
EVOFW_SEED=dev-enroll-seed-change-me \
EVOFW_CLIENT_NAME="web-01" \
bash
Затем Approve в UI /agents.
Docs
См. docs/README.md.
Git
origin https://git.shts.su/denozord/EvoFirewall.git