Files
osmedeus/public/presets/cloud-settings.example.yaml
T
j3ssie 0269cf4e26 feat: update Next.js build assets and add cloud setup E2E tests
- Update Next.js generated chunk hashes and build IDs reflecting latest dashboard build
- Update CSS stylesheet references in workflow upload page metadata
- Add comprehensive cloud setup E2E test suite (cloud_setup_test.go) with SSH password/key auth, post-command variable expansion, and Ansible integration
- Fix API priority levels to include 'medium' priority in test coverage
- Add agent-sdk test workflows (minimal, config, codex, multi-agent, session variants)
- Update E2E test utilities with runCLIInBase helper for multi-step cloud config tests
- Fix stderr/stdout capture in dependencies_target_types_test assertions
2026-04-04 13:57:34 +08:00

238 lines
9.1 KiB
YAML

# Cloud Infrastructure Configuration Example
# Save this as: ~/osmedeus-base/cloud/cloud-settings.yaml
# =============================================================================
# Cloud Provider Credentials
# =============================================================================
# Use ${ENV_VAR} syntax to reference environment variables
providers:
# AWS Configuration
aws:
access_key_id: "${AWS_ACCESS_KEY_ID}"
secret_access_key: "${AWS_SECRET_ACCESS_KEY}"
region: "us-east-1"
instance_type: "t3.medium"
# AMI ID for the worker instances.
# Leave empty to auto-select using ami_filter below.
# To find AMIs: https://cloud-images.ubuntu.com/locator/ec2/
# Or via AWS CLI: aws ec2 describe-images --owners 099720109477 \
# --filters "Name=name,Values=ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*" \
# --query 'Images | sort_by(@, &CreationDate) | [-1].ImageId' --region <your-region>
ami: ""
# AMI name filter for auto-lookup when ami is empty.
# Default: latest Ubuntu 24.04 LTS. Change to use a different OS:
# Ubuntu 22.04: "ubuntu/images/hvm-ssd/ubuntu-jammy-22.04-amd64-server-*"
# Ubuntu 24.04: "ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*"
# Debian 12: "debian-12-amd64-*"
# Amazon Linux: "al2023-ami-*-x86_64"
ami_filter: "ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*"
use_spot: false
# Google Cloud Platform Configuration
gcp:
project_id: "${GCP_PROJECT_ID}"
credentials_file: "${GCP_CREDENTIALS_FILE}"
region: "us-central1"
zone: "us-central1-a"
machine_type: "n1-standard-2"
image_family: "ubuntu-2204-lts"
use_preemptible: false
# DigitalOcean Configuration
digitalocean:
token: "${DIGITALOCEAN_TOKEN}"
region: "nyc1"
size: "s-2vcpu-4gb" # $15/month = $0.02232/hour
image: "ubuntu-22-04-x64"
snapshot_id: "" # Optional: Use custom snapshot with pre-installed tools
ssh_key_id: ""
ssh_key_fingerprint: ""
# Linode Configuration
linode:
token: "${LINODE_TOKEN}"
region: "us-east"
type: "g6-standard-2"
image: "linode/ubuntu22.04"
ssh_public_key: ""
# Azure Configuration
azure:
subscription_id: "${AZURE_SUBSCRIPTION_ID}"
tenant_id: "${AZURE_TENANT_ID}"
client_id: "${AZURE_CLIENT_ID}"
client_secret: "${AZURE_CLIENT_SECRET}"
location: "eastus"
vm_size: "Standard_B2s"
image_reference: "Canonical:UbuntuServer:22.04-LTS:latest"
# Hetzner Cloud Configuration
hetzner:
token: "${HETZNER_TOKEN}"
location: "hel1" # Helsinki, Finland (recommended for cx23)
server_type: "cx23" # 2 vCPU, 4GB RAM (current generation)
image: "ubuntu-22.04"
ssh_key_name: "" # Name of SSH key registered in Hetzner
#
# Available locations:
# hel1 (Helsinki) fsn1 (Falkenstein) nbg1 (Nuremberg)
# ash (Ashburn) hil (Hillsboro) sin (Singapore)
# Note: not all server types are available in every location.
#
# Server types (current generation):
# Cost-optimized (shared x86): cx23, cx33, cx43, cx53
# Cost-optimized (shared ARM): cax11, cax21, cax31, cax41
# Shared AMD: cpx11, cpx21, cpx31, cpx41, cpx51
# Dedicated CPU: ccx13, ccx23, ccx33, ccx43, ccx53, ccx63
#
# List available types via API:
# curl -s -H "Authorization: Bearer $HETZNER_TOKEN" \
# https://api.hetzner.cloud/v1/server_types | jq '.server_types[].name'
# =============================================================================
# Default Settings
# =============================================================================
defaults:
# Default cloud provider to use
provider: "digitalocean"
# Execution mode: "vm" or "serverless" (serverless not yet implemented)
mode: "vm"
# Default number of instances to create
max_instances: 10
# Use spot/preemptible instances (cheaper but can be terminated)
use_spot: false
# Maximum time to wait for infrastructure creation
timeout: "30m"
# Automatically destroy infrastructure if creation fails
cleanup_on_failure: true
# =============================================================================
# Cost Limits
# =============================================================================
# Prevent accidental overspending
limits:
# Maximum hourly cost (USD) - blocks provisioning if exceeded
max_hourly_spend: 10.0
# Maximum total cost (USD) - terminates infrastructure if exceeded
max_total_spend: 100.0
# Maximum number of instances across all providers
max_instances: 20
# =============================================================================
# State Storage
# =============================================================================
state:
# Backend type (only "local" supported currently)
backend: "local"
# Path to store Pulumi state and infrastructure metadata
path: "{{base_folder}}/cloud-state"
# =============================================================================
# SSH Configuration
# =============================================================================
# For accessing workers to collect results
ssh:
# Path to private key file
private_key_path: "~/.ssh/id_rsa"
# Or provide key content directly (base64 encoded)
private_key_content: ""
# Path to public key file (for worker access)
public_key_path: "~/.ssh/id_rsa.pub"
# Or provide public key content directly
public_key_content: ""
# SSH username (default: root for most cloud VMs)
user: "root"
# SSH password — STRONGLY ADVISED NOT TO USE.
# Key-based authentication is far more secure. Only use this for ad-hoc
# machines that don't have key-based auth configured.
# Uses sshpass under the hood (must be installed: brew install sshpass / apt install sshpass)
password: ""
# SSH port (default: 22)
port: ""
# =============================================================================
# Worker Setup Commands
# =============================================================================
# Commands to run on each worker via SSH before starting scans.
# You have full control — add whatever install/config steps you need.
setup:
commands:
- "# Example: install osmedeus and tools"
- "# sudo apt-get update && sudo apt-get install -y curl git tmux unzip jq"
- "# curl -fsSL https://www.osmedeus.org/install.sh | bash"
- "# export PATH=$HOME/.local/bin:$PATH && osmedeus install base --preset"
- "# export PATH=$HOME/.local/bin:$PATH && osmedeus install binary --all"
# Post-setup commands run after setup.commands complete.
# Template variables are expanded per-worker:
# {{public_ip}} - Worker's public IP address
# {{private_ip}} - Worker's private IP address
# {{worker_name}} - Resource name (e.g., osmw-1775159841-0)
# {{worker_id}} - Cloud resource ID (e.g., i-0437adf5...)
# {{infra_id}} - Infrastructure ID (e.g., cloud-aws-1775159841)
# {{provider}} - Provider name (e.g., aws, digitalocean)
# {{ssh_user}} - SSH username (e.g., ubuntu, root)
# {{index}} - Worker index (0, 1, 2, ...)
post_commands:
- "# Example: register as a distributed worker"
- "# osmedeus worker join --redis-url redis://master:6379 --alias {{worker_name}}"
- "# Example: notify a remote server"
- "# curl -s https://my-server.com/api/register?ip={{public_ip}}&name={{worker_name}}&infra={{infra_id}}"
# ---------------------------------------------------------------------------
# Ansible Setup (alternative to raw SSH commands)
# ---------------------------------------------------------------------------
# When enabled, runs an ansible playbook against all workers instead of
# setup.commands. Falls back to SSH commands if ansible fails.
# The inventory file is auto-generated with all worker IPs.
ansible:
enabled: false
# Path to the ansible playbook. A default example is provided at this path.
# Edit it to customize: ~/osmedeus-base/cloud-infra/setup-playbook.yaml
playbook_path: "{{base_folder}}/cloud-infra/setup-playbook.yaml"
# Path where the dynamic inventory is written (auto-generated per run)
inventory_path: "{{base_folder}}/cloud-infra/inventory.ini"
# Extra variables passed to ansible-playbook as --extra-vars
extra_vars: {}
# osmedeus_version: "v5.0.2"
# redis_url: "redis://master:6379"
# Additional ansible-playbook flags (e.g., "-vvv" for debug, "--tags setup")
extra_args: ""
# =============================================================================
# Usage Examples
# =============================================================================
# Set a config value:
# osmedeus cloud config set defaults.provider digitalocean
# osmedeus cloud config set providers.digitalocean.token ${DIGITALOCEAN_TOKEN}
# osmedeus cloud config set limits.max_hourly_spend 5.0
#
# Show current config:
# osmedeus cloud config show
#
# Create infrastructure:
# osmedeus cloud create --instances 5
#
# List active infrastructure:
# osmedeus cloud list
#
# Run workflow on cloud workers:
# osmedeus cloud run -f general -t example.com --instances 3
#
# Destroy infrastructure:
# osmedeus cloud destroy