mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 05:30:46 +08:00
feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
e62f4f2c74
commit
d3d7f62a02
15 changed files with 348 additions and 19 deletions
|
|
@ -4,8 +4,10 @@ import {
|
|||
HOP_VENDORS,
|
||||
defaultHopTemplate,
|
||||
isAutoHopTemplate,
|
||||
isBastionHopVendor,
|
||||
isLinuxHopVendor,
|
||||
patchHopVendorChange,
|
||||
type HopTargetAuthMode,
|
||||
type HopVendor,
|
||||
} from "../utils/hopProxy";
|
||||
|
||||
|
|
@ -18,6 +20,7 @@ export type HopProxyFieldsState = {
|
|||
hop_password: string;
|
||||
hop_command_template: string;
|
||||
hop_vrf: string;
|
||||
hop_target_auth_mode: HopTargetAuthMode;
|
||||
};
|
||||
|
||||
export const emptyHopProxyFields = (): HopProxyFieldsState => ({
|
||||
|
|
@ -29,6 +32,7 @@ export const emptyHopProxyFields = (): HopProxyFieldsState => ({
|
|||
hop_password: "",
|
||||
hop_command_template: defaultHopTemplate("zte", "ssh", ""),
|
||||
hop_vrf: "",
|
||||
hop_target_auth_mode: "bastion_managed",
|
||||
});
|
||||
|
||||
function FormLabel({ children, required }: { children: ReactNode; required?: boolean }) {
|
||||
|
|
@ -59,6 +63,7 @@ function applyHopTemplate(
|
|||
|
||||
function hopHintKey(vendor: string): string {
|
||||
const v = String(vendor || "").toLowerCase();
|
||||
if (v === "bastion") return "managedNe.hop.bastionHint";
|
||||
if (v === "linux") return "managedNe.hop.linuxHint";
|
||||
if (v === "huawei") return "managedNe.hop.huaweiHint";
|
||||
if (v === "cisco") return "managedNe.hop.ciscoHint";
|
||||
|
|
@ -67,6 +72,7 @@ function hopHintKey(vendor: string): string {
|
|||
|
||||
function templateHintKey(vendor: string): string {
|
||||
const v = String(vendor || "").toLowerCase();
|
||||
if (v === "bastion") return "managedNe.hop.templateHintBastion";
|
||||
if (v === "huawei") return "managedNe.hop.templateHintHuawei";
|
||||
if (v === "cisco") return "managedNe.hop.templateHintCisco";
|
||||
return "managedNe.hop.templateHint";
|
||||
|
|
@ -94,7 +100,9 @@ export function HopProxyFields({
|
|||
}: Props) {
|
||||
const { t } = useI18n();
|
||||
const linux = isLinuxHopVendor(value.hop_vendor);
|
||||
const bastion = isBastionHopVendor(value.hop_vendor);
|
||||
const huawei = value.hop_vendor === "huawei";
|
||||
const cliHop = !linux && !bastion;
|
||||
|
||||
const set = (patch: Partial<HopProxyFieldsState>) => onChange(patch);
|
||||
|
||||
|
|
@ -129,7 +137,20 @@ export function HopProxyFields({
|
|||
onChange={(e) => set({ hop_port: Number(e.target.value) || 22 })}
|
||||
/>
|
||||
</label>
|
||||
{!linux ? (
|
||||
{bastion ? (
|
||||
<label className="form-grid__full">
|
||||
<FormLabel>{t("managedNe.hop.targetAuthMode")}</FormLabel>
|
||||
<select
|
||||
value={value.hop_target_auth_mode}
|
||||
onChange={(e) => set({ hop_target_auth_mode: e.target.value as HopTargetAuthMode })}
|
||||
>
|
||||
<option value="bastion_managed">{t("managedNe.hop.targetAuthBastionManaged")}</option>
|
||||
<option value="manual">{t("managedNe.hop.targetAuthManual")}</option>
|
||||
</select>
|
||||
<span className="form-field-hint">{t("managedNe.hop.targetAuthHint")}</span>
|
||||
</label>
|
||||
) : null}
|
||||
{cliHop ? (
|
||||
<label>
|
||||
<FormLabel>{t("managedNe.hop.protocol")}</FormLabel>
|
||||
<select
|
||||
|
|
@ -162,7 +183,18 @@ export function HopProxyFields({
|
|||
onChange={(e) => set({ hop_password: e.target.value })}
|
||||
/>
|
||||
</label>
|
||||
{!linux ? (
|
||||
{bastion ? (
|
||||
<label className="form-grid__full">
|
||||
<FormLabel>{t("managedNe.hop.usernameTemplate")}</FormLabel>
|
||||
<input
|
||||
value={value.hop_command_template}
|
||||
onChange={(e) => set({ hop_command_template: e.target.value })}
|
||||
placeholder={defaultHopTemplate(value.hop_vendor, value.hop_protocol, value.hop_vrf)}
|
||||
/>
|
||||
<span className="form-field-hint">{t(templateHintKey(value.hop_vendor))}</span>
|
||||
</label>
|
||||
) : null}
|
||||
{cliHop ? (
|
||||
<>
|
||||
<label>
|
||||
<FormLabel>{t(vrfLabelKey(value.hop_vendor))}</FormLabel>
|
||||
|
|
|
|||
|
|
@ -195,11 +195,21 @@ const en = {
|
|||
huawei: "Huawei device (CLI jump)",
|
||||
cisco: "Cisco device (CLI jump)",
|
||||
linux: "Linux server (SSH tunnel)",
|
||||
bastion: "Bastion host (SSH protocol proxy)",
|
||||
},
|
||||
zteHint: "Run ssh/telnet on the ZTE device to reach the target; target credentials use secondary auth.",
|
||||
huaweiHint: "Run telnet / stelnet (SSH) on the Huawei hop; stelnet is SSH. Target credentials use secondary auth.",
|
||||
ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.",
|
||||
linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).",
|
||||
bastionHint:
|
||||
"SSH with composite username via bastion protocol proxy. Example: user@account@target_ip@bastion_host; password is the bastion/Vault password. JumpServer/CBH often use port 2222.",
|
||||
targetAuthMode: "Target credentials",
|
||||
targetAuthBastionManaged: "Bastion-managed (target password optional)",
|
||||
targetAuthManual: "Manual (secondary auth after connect)",
|
||||
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
|
||||
usernameTemplate: "SSH username template",
|
||||
templateHintBastion:
|
||||
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank.",
|
||||
host: "Jump host",
|
||||
port: "Jump port",
|
||||
protocol: "Jump protocol",
|
||||
|
|
@ -221,6 +231,7 @@ const en = {
|
|||
huawei: "Huawei hop",
|
||||
cisco: "Cisco hop",
|
||||
linux: "Linux hop",
|
||||
bastion: "Bastion",
|
||||
},
|
||||
hostRequired: "Jump host is required",
|
||||
userRequired: "Jump username is required",
|
||||
|
|
|
|||
|
|
@ -193,11 +193,21 @@ const zh = {
|
|||
huawei: "华为设备(CLI 跳登)",
|
||||
cisco: "思科设备(CLI 跳登)",
|
||||
linux: "Linux 服务器(SSH 隧道)",
|
||||
bastion: "堡垒机(SSH 协议代理)",
|
||||
},
|
||||
zteHint: "在 ZTE 设备上执行 ssh/telnet 命令跳转到目标,目标账号由二次认证输入。",
|
||||
huaweiHint: "在华为设备上执行 telnet / stelnet(SSH)跳登;stelnet 即 SSH。目标账号由二次认证输入。",
|
||||
ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。",
|
||||
linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。",
|
||||
bastionHint:
|
||||
"SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。",
|
||||
targetAuthMode: "目标凭据",
|
||||
targetAuthBastionManaged: "堡垒机托管(目标密码可留空)",
|
||||
targetAuthManual: "手动输入(连接后二次认证)",
|
||||
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
|
||||
usernameTemplate: "SSH 用户名模板",
|
||||
templateHintBastion:
|
||||
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27。",
|
||||
host: "跳板地址",
|
||||
port: "跳板端口",
|
||||
protocol: "跳板协议",
|
||||
|
|
@ -219,6 +229,7 @@ const zh = {
|
|||
huawei: "华为跳板",
|
||||
cisco: "思科跳板",
|
||||
linux: "Linux跳板",
|
||||
bastion: "堡垒机",
|
||||
},
|
||||
hostRequired: "请填写跳板地址",
|
||||
userRequired: "请填写跳板用户名",
|
||||
|
|
|
|||
|
|
@ -46,6 +46,7 @@ type FormState = {
|
|||
hop_password: string;
|
||||
hop_command_template: string;
|
||||
hop_vrf: string;
|
||||
hop_target_auth_mode: "bastion_managed" | "manual";
|
||||
};
|
||||
|
||||
const emptyForm = (): FormState => ({
|
||||
|
|
@ -68,6 +69,7 @@ const emptyForm = (): FormState => ({
|
|||
hop_password: "",
|
||||
hop_command_template: defaultHopTemplate("zte", "ssh", ""),
|
||||
hop_vrf: "",
|
||||
hop_target_auth_mode: "bastion_managed",
|
||||
});
|
||||
|
||||
function applyHopTemplate(prev: FormState, protocol: string, vrf: string, force = false): Partial<FormState> {
|
||||
|
|
@ -179,9 +181,14 @@ export function NePage() {
|
|||
hop_username: form.hop_username,
|
||||
hop_command_template: form.hop_command_template,
|
||||
hop_vrf: form.hop_vrf,
|
||||
hop_target_auth_mode: form.hop_target_auth_mode,
|
||||
...(form.password ? { password: form.password } : {}),
|
||||
...(form.hop_password ? { hop_password: form.hop_password } : {}),
|
||||
};
|
||||
const bastionManaged =
|
||||
form.hop_enabled &&
|
||||
form.hop_vendor === "bastion" &&
|
||||
form.hop_target_auth_mode === "bastion_managed";
|
||||
if (form.hop_enabled) {
|
||||
if (!form.hop_host.trim()) throw new Error(t("managedNe.hop.hostRequired"));
|
||||
if (!form.hop_username.trim()) throw new Error(t("managedNe.hop.userRequired"));
|
||||
|
|
@ -192,8 +199,8 @@ export function NePage() {
|
|||
if (!form.hop_password) delete (body as { hop_password?: string }).hop_password;
|
||||
return updateManagedNe(editing.id, body);
|
||||
}
|
||||
if (!form.password) throw new Error(t("managedNe.form.passwordRequired"));
|
||||
return createManagedNe({ ...body, password: form.password });
|
||||
if (!form.password && !bastionManaged) throw new Error(t("managedNe.form.passwordRequired"));
|
||||
return createManagedNe({ ...body, password: form.password || "" });
|
||||
},
|
||||
onSuccess: async () => {
|
||||
setModalOpen(false);
|
||||
|
|
@ -244,6 +251,7 @@ export function NePage() {
|
|||
hop_password: batchHop.hop_password,
|
||||
hop_command_template: batchHop.hop_command_template.trim(),
|
||||
hop_vrf: batchHop.hop_vrf.trim(),
|
||||
hop_target_auth_mode: batchHop.hop_target_auth_mode,
|
||||
}),
|
||||
onSuccess: async (res) => {
|
||||
setBatchHopOpen(false);
|
||||
|
|
@ -298,7 +306,7 @@ export function NePage() {
|
|||
tags: row.tags,
|
||||
remark: row.remark,
|
||||
hop_enabled: row.hop_enabled,
|
||||
hop_vendor: (["linux", "huawei", "cisco", "zte"].includes(row.hop_vendor)
|
||||
hop_vendor: (["linux", "huawei", "cisco", "zte", "bastion"].includes(row.hop_vendor)
|
||||
? row.hop_vendor
|
||||
: "zte") as HopVendor,
|
||||
hop_host: row.hop_host,
|
||||
|
|
@ -315,6 +323,8 @@ export function NePage() {
|
|||
? defaultHopTemplate(row.hop_vendor, row.hop_protocol, row.hop_vrf)
|
||||
: row.hop_command_template || defaultHopTemplate(row.hop_vendor, row.hop_protocol, row.hop_vrf),
|
||||
hop_vrf: row.hop_vrf,
|
||||
hop_target_auth_mode:
|
||||
row.hop_target_auth_mode === "manual" ? "manual" : "bastion_managed",
|
||||
});
|
||||
setModalOpen(true);
|
||||
};
|
||||
|
|
@ -489,7 +499,7 @@ export function NePage() {
|
|||
title={`${row.hop_host}:${row.hop_port} (${row.hop_vendor})`}
|
||||
>
|
||||
{t(
|
||||
`managedNe.hop.badge.${["linux", "huawei", "cisco", "zte"].includes(row.hop_vendor) ? row.hop_vendor : "zte"}`,
|
||||
`managedNe.hop.badge.${["linux", "huawei", "cisco", "zte", "bastion"].includes(row.hop_vendor) ? row.hop_vendor : "zte"}`,
|
||||
)}
|
||||
</span>
|
||||
) : null}
|
||||
|
|
@ -628,15 +638,34 @@ export function NePage() {
|
|||
/>
|
||||
</label>
|
||||
<label>
|
||||
<FormLabel required={!editing}>
|
||||
<FormLabel
|
||||
required={
|
||||
!editing &&
|
||||
!(
|
||||
form.hop_enabled &&
|
||||
form.hop_vendor === "bastion" &&
|
||||
form.hop_target_auth_mode === "bastion_managed"
|
||||
)
|
||||
}
|
||||
>
|
||||
{t("managedNe.col.password")}
|
||||
{editing ? (
|
||||
{editing ||
|
||||
(form.hop_enabled &&
|
||||
form.hop_vendor === "bastion" &&
|
||||
form.hop_target_auth_mode === "bastion_managed") ? (
|
||||
<span className="form-label__optional"> ({t("managedNe.form.passwordOptional")})</span>
|
||||
) : null}
|
||||
</FormLabel>
|
||||
<input
|
||||
type="password"
|
||||
required={!editing}
|
||||
required={
|
||||
!editing &&
|
||||
!(
|
||||
form.hop_enabled &&
|
||||
form.hop_vendor === "bastion" &&
|
||||
form.hop_target_auth_mode === "bastion_managed"
|
||||
)
|
||||
}
|
||||
value={form.password}
|
||||
onChange={(e) => setForm({ ...form, password: e.target.value })}
|
||||
/>
|
||||
|
|
@ -684,6 +713,7 @@ export function NePage() {
|
|||
hop_password: form.hop_password,
|
||||
hop_command_template: form.hop_command_template,
|
||||
hop_vrf: form.hop_vrf,
|
||||
hop_target_auth_mode: form.hop_target_auth_mode,
|
||||
}}
|
||||
onChange={(patch) => setForm((prev) => ({ ...prev, ...patch }))}
|
||||
hopPasswordRequired={!editing}
|
||||
|
|
|
|||
|
|
@ -143,6 +143,7 @@ export const batchApplyHopManagedNe = (
|
|||
hop_command_template: string;
|
||||
hop_vrf: string;
|
||||
hop_vendor?: string;
|
||||
hop_target_auth_mode?: string;
|
||||
},
|
||||
) => apiPost<{ ok: boolean; updated: number }>("/v1/managed-ne/batch-hop", { ids, hop });
|
||||
|
||||
|
|
|
|||
|
|
@ -144,6 +144,7 @@ export type ManagedNeItem = {
|
|||
hop_username: string;
|
||||
hop_command_template: string;
|
||||
hop_vrf: string;
|
||||
hop_target_auth_mode: string;
|
||||
created_at: string;
|
||||
updated_at: string;
|
||||
};
|
||||
|
|
|
|||
|
|
@ -2,9 +2,19 @@
|
|||
|
||||
import { ciscoHopTemplate, huaweiHopTemplate, isAutoHopTemplate, zteHopTemplate } from "./zteHop";
|
||||
|
||||
export type HopVendor = "zte" | "huawei" | "cisco" | "linux";
|
||||
export type HopVendor = "zte" | "huawei" | "cisco" | "linux" | "bastion";
|
||||
|
||||
export const HOP_VENDORS: HopVendor[] = ["zte", "huawei", "cisco", "linux"];
|
||||
export type HopTargetAuthMode = "bastion_managed" | "manual";
|
||||
|
||||
export const HOP_VENDORS: HopVendor[] = ["zte", "huawei", "cisco", "linux", "bastion"];
|
||||
|
||||
export function bastionHopTemplate(): string {
|
||||
return "{hop_user}@{target_user}@{target_ip}@{hop_host}";
|
||||
}
|
||||
|
||||
export function isBastionHopVendor(vendor: string): boolean {
|
||||
return String(vendor || "").toLowerCase() === "bastion";
|
||||
}
|
||||
|
||||
export function isLinuxHopVendor(vendor: string): boolean {
|
||||
return String(vendor || "").toLowerCase() === "linux";
|
||||
|
|
@ -20,16 +30,34 @@ export function defaultHopTemplate(vendor: string, protocol: string, vrf: string
|
|||
if (v === "huawei") return huaweiHopTemplate(protocol, vrf);
|
||||
if (v === "cisco") return ciscoHopTemplate(protocol, vrf);
|
||||
if (v === "linux") return "";
|
||||
if (v === "bastion") return bastionHopTemplate();
|
||||
return zteHopTemplate(protocol, vrf);
|
||||
}
|
||||
|
||||
export function patchHopVendorChange(
|
||||
vendor: HopVendor,
|
||||
prev: { hop_protocol: string; hop_vrf: string; hop_command_template: string; hop_vendor?: string },
|
||||
): { hop_vendor: HopVendor; hop_protocol: string; hop_vrf: string; hop_command_template: string } {
|
||||
): {
|
||||
hop_vendor: HopVendor;
|
||||
hop_protocol: string;
|
||||
hop_vrf: string;
|
||||
hop_command_template: string;
|
||||
hop_port?: number;
|
||||
hop_target_auth_mode?: HopTargetAuthMode;
|
||||
} {
|
||||
if (vendor === "linux") {
|
||||
return { hop_vendor: "linux", hop_protocol: "ssh", hop_vrf: "", hop_command_template: "" };
|
||||
}
|
||||
if (vendor === "bastion") {
|
||||
return {
|
||||
hop_vendor: "bastion",
|
||||
hop_protocol: "ssh",
|
||||
hop_port: 22,
|
||||
hop_vrf: "",
|
||||
hop_command_template: bastionHopTemplate(),
|
||||
hop_target_auth_mode: "bastion_managed" as HopTargetAuthMode,
|
||||
};
|
||||
}
|
||||
const protocol = prev.hop_protocol || "ssh";
|
||||
const vrf = prev.hop_vrf || "";
|
||||
return {
|
||||
|
|
|
|||
|
|
@ -42,5 +42,6 @@ export function isAutoHopTemplate(
|
|||
if (v === "huawei") return t === huaweiHopTemplate(protocol, vrf);
|
||||
if (v === "cisco") return t === ciscoHopTemplate(protocol, vrf);
|
||||
if (v === "linux") return t === "";
|
||||
if (v === "bastion") return t === "{hop_user}@{target_user}@{target_ip}@{hop_host}";
|
||||
return t === zteHopTemplate(protocol, vrf);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue