feat(managed-ne): add bastion SSH protocol proxy hop type

Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-06-05 10:47:52 +08:00
parent e62f4f2c74
commit d3d7f62a02
15 changed files with 348 additions and 19 deletions

View file

@ -4,8 +4,10 @@ import {
HOP_VENDORS,
defaultHopTemplate,
isAutoHopTemplate,
isBastionHopVendor,
isLinuxHopVendor,
patchHopVendorChange,
type HopTargetAuthMode,
type HopVendor,
} from "../utils/hopProxy";
@ -18,6 +20,7 @@ export type HopProxyFieldsState = {
hop_password: string;
hop_command_template: string;
hop_vrf: string;
hop_target_auth_mode: HopTargetAuthMode;
};
export const emptyHopProxyFields = (): HopProxyFieldsState => ({
@ -29,6 +32,7 @@ export const emptyHopProxyFields = (): HopProxyFieldsState => ({
hop_password: "",
hop_command_template: defaultHopTemplate("zte", "ssh", ""),
hop_vrf: "",
hop_target_auth_mode: "bastion_managed",
});
function FormLabel({ children, required }: { children: ReactNode; required?: boolean }) {
@ -59,6 +63,7 @@ function applyHopTemplate(
function hopHintKey(vendor: string): string {
const v = String(vendor || "").toLowerCase();
if (v === "bastion") return "managedNe.hop.bastionHint";
if (v === "linux") return "managedNe.hop.linuxHint";
if (v === "huawei") return "managedNe.hop.huaweiHint";
if (v === "cisco") return "managedNe.hop.ciscoHint";
@ -67,6 +72,7 @@ function hopHintKey(vendor: string): string {
function templateHintKey(vendor: string): string {
const v = String(vendor || "").toLowerCase();
if (v === "bastion") return "managedNe.hop.templateHintBastion";
if (v === "huawei") return "managedNe.hop.templateHintHuawei";
if (v === "cisco") return "managedNe.hop.templateHintCisco";
return "managedNe.hop.templateHint";
@ -94,7 +100,9 @@ export function HopProxyFields({
}: Props) {
const { t } = useI18n();
const linux = isLinuxHopVendor(value.hop_vendor);
const bastion = isBastionHopVendor(value.hop_vendor);
const huawei = value.hop_vendor === "huawei";
const cliHop = !linux && !bastion;
const set = (patch: Partial<HopProxyFieldsState>) => onChange(patch);
@ -129,7 +137,20 @@ export function HopProxyFields({
onChange={(e) => set({ hop_port: Number(e.target.value) || 22 })}
/>
</label>
{!linux ? (
{bastion ? (
<label className="form-grid__full">
<FormLabel>{t("managedNe.hop.targetAuthMode")}</FormLabel>
<select
value={value.hop_target_auth_mode}
onChange={(e) => set({ hop_target_auth_mode: e.target.value as HopTargetAuthMode })}
>
<option value="bastion_managed">{t("managedNe.hop.targetAuthBastionManaged")}</option>
<option value="manual">{t("managedNe.hop.targetAuthManual")}</option>
</select>
<span className="form-field-hint">{t("managedNe.hop.targetAuthHint")}</span>
</label>
) : null}
{cliHop ? (
<label>
<FormLabel>{t("managedNe.hop.protocol")}</FormLabel>
<select
@ -162,7 +183,18 @@ export function HopProxyFields({
onChange={(e) => set({ hop_password: e.target.value })}
/>
</label>
{!linux ? (
{bastion ? (
<label className="form-grid__full">
<FormLabel>{t("managedNe.hop.usernameTemplate")}</FormLabel>
<input
value={value.hop_command_template}
onChange={(e) => set({ hop_command_template: e.target.value })}
placeholder={defaultHopTemplate(value.hop_vendor, value.hop_protocol, value.hop_vrf)}
/>
<span className="form-field-hint">{t(templateHintKey(value.hop_vendor))}</span>
</label>
) : null}
{cliHop ? (
<>
<label>
<FormLabel>{t(vrfLabelKey(value.hop_vendor))}</FormLabel>

View file

@ -195,11 +195,21 @@ const en = {
huawei: "Huawei device (CLI jump)",
cisco: "Cisco device (CLI jump)",
linux: "Linux server (SSH tunnel)",
bastion: "Bastion host (SSH protocol proxy)",
},
zteHint: "Run ssh/telnet on the ZTE device to reach the target; target credentials use secondary auth.",
huaweiHint: "Run telnet / stelnet (SSH) on the Huawei hop; stelnet is SSH. Target credentials use secondary auth.",
ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.",
linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).",
bastionHint:
"SSH with composite username via bastion protocol proxy. Example: user@account@target_ip@bastion_host; password is the bastion/Vault password. JumpServer/CBH often use port 2222.",
targetAuthMode: "Target credentials",
targetAuthBastionManaged: "Bastion-managed (target password optional)",
targetAuthManual: "Manual (secondary auth after connect)",
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
usernameTemplate: "SSH username template",
templateHintBastion:
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank.",
host: "Jump host",
port: "Jump port",
protocol: "Jump protocol",
@ -221,6 +231,7 @@ const en = {
huawei: "Huawei hop",
cisco: "Cisco hop",
linux: "Linux hop",
bastion: "Bastion",
},
hostRequired: "Jump host is required",
userRequired: "Jump username is required",

View file

@ -193,11 +193,21 @@ const zh = {
huawei: "华为设备(CLI 跳登)",
cisco: "思科设备(CLI 跳登)",
linux: "Linux 服务器(SSH 隧道)",
bastion: "堡垒机(SSH 协议代理)",
},
zteHint: "在 ZTE 设备上执行 ssh/telnet 命令跳转到目标,目标账号由二次认证输入。",
huaweiHint: "在华为设备上执行 telnet / stelnet(SSH)跳登;stelnet 即 SSH。目标账号由二次认证输入。",
ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。",
linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。",
bastionHint:
"SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。",
targetAuthMode: "目标凭据",
targetAuthBastionManaged: "堡垒机托管(目标密码可留空)",
targetAuthManual: "手动输入(连接后二次认证)",
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
usernameTemplate: "SSH 用户名模板",
templateHintBastion:
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27。",
host: "跳板地址",
port: "跳板端口",
protocol: "跳板协议",
@ -219,6 +229,7 @@ const zh = {
huawei: "华为跳板",
cisco: "思科跳板",
linux: "Linux跳板",
bastion: "堡垒机",
},
hostRequired: "请填写跳板地址",
userRequired: "请填写跳板用户名",

View file

@ -46,6 +46,7 @@ type FormState = {
hop_password: string;
hop_command_template: string;
hop_vrf: string;
hop_target_auth_mode: "bastion_managed" | "manual";
};
const emptyForm = (): FormState => ({
@ -68,6 +69,7 @@ const emptyForm = (): FormState => ({
hop_password: "",
hop_command_template: defaultHopTemplate("zte", "ssh", ""),
hop_vrf: "",
hop_target_auth_mode: "bastion_managed",
});
function applyHopTemplate(prev: FormState, protocol: string, vrf: string, force = false): Partial<FormState> {
@ -179,9 +181,14 @@ export function NePage() {
hop_username: form.hop_username,
hop_command_template: form.hop_command_template,
hop_vrf: form.hop_vrf,
hop_target_auth_mode: form.hop_target_auth_mode,
...(form.password ? { password: form.password } : {}),
...(form.hop_password ? { hop_password: form.hop_password } : {}),
};
const bastionManaged =
form.hop_enabled &&
form.hop_vendor === "bastion" &&
form.hop_target_auth_mode === "bastion_managed";
if (form.hop_enabled) {
if (!form.hop_host.trim()) throw new Error(t("managedNe.hop.hostRequired"));
if (!form.hop_username.trim()) throw new Error(t("managedNe.hop.userRequired"));
@ -192,8 +199,8 @@ export function NePage() {
if (!form.hop_password) delete (body as { hop_password?: string }).hop_password;
return updateManagedNe(editing.id, body);
}
if (!form.password) throw new Error(t("managedNe.form.passwordRequired"));
return createManagedNe({ ...body, password: form.password });
if (!form.password && !bastionManaged) throw new Error(t("managedNe.form.passwordRequired"));
return createManagedNe({ ...body, password: form.password || "" });
},
onSuccess: async () => {
setModalOpen(false);
@ -244,6 +251,7 @@ export function NePage() {
hop_password: batchHop.hop_password,
hop_command_template: batchHop.hop_command_template.trim(),
hop_vrf: batchHop.hop_vrf.trim(),
hop_target_auth_mode: batchHop.hop_target_auth_mode,
}),
onSuccess: async (res) => {
setBatchHopOpen(false);
@ -298,7 +306,7 @@ export function NePage() {
tags: row.tags,
remark: row.remark,
hop_enabled: row.hop_enabled,
hop_vendor: (["linux", "huawei", "cisco", "zte"].includes(row.hop_vendor)
hop_vendor: (["linux", "huawei", "cisco", "zte", "bastion"].includes(row.hop_vendor)
? row.hop_vendor
: "zte") as HopVendor,
hop_host: row.hop_host,
@ -315,6 +323,8 @@ export function NePage() {
? defaultHopTemplate(row.hop_vendor, row.hop_protocol, row.hop_vrf)
: row.hop_command_template || defaultHopTemplate(row.hop_vendor, row.hop_protocol, row.hop_vrf),
hop_vrf: row.hop_vrf,
hop_target_auth_mode:
row.hop_target_auth_mode === "manual" ? "manual" : "bastion_managed",
});
setModalOpen(true);
};
@ -489,7 +499,7 @@ export function NePage() {
title={`${row.hop_host}:${row.hop_port} (${row.hop_vendor})`}
>
{t(
`managedNe.hop.badge.${["linux", "huawei", "cisco", "zte"].includes(row.hop_vendor) ? row.hop_vendor : "zte"}`,
`managedNe.hop.badge.${["linux", "huawei", "cisco", "zte", "bastion"].includes(row.hop_vendor) ? row.hop_vendor : "zte"}`,
)}
</span>
) : null}
@ -628,15 +638,34 @@ export function NePage() {
/>
</label>
<label>
<FormLabel required={!editing}>
<FormLabel
required={
!editing &&
!(
form.hop_enabled &&
form.hop_vendor === "bastion" &&
form.hop_target_auth_mode === "bastion_managed"
)
}
>
{t("managedNe.col.password")}
{editing ? (
{editing ||
(form.hop_enabled &&
form.hop_vendor === "bastion" &&
form.hop_target_auth_mode === "bastion_managed") ? (
<span className="form-label__optional"> ({t("managedNe.form.passwordOptional")})</span>
) : null}
</FormLabel>
<input
type="password"
required={!editing}
required={
!editing &&
!(
form.hop_enabled &&
form.hop_vendor === "bastion" &&
form.hop_target_auth_mode === "bastion_managed"
)
}
value={form.password}
onChange={(e) => setForm({ ...form, password: e.target.value })}
/>
@ -684,6 +713,7 @@ export function NePage() {
hop_password: form.hop_password,
hop_command_template: form.hop_command_template,
hop_vrf: form.hop_vrf,
hop_target_auth_mode: form.hop_target_auth_mode,
}}
onChange={(patch) => setForm((prev) => ({ ...prev, ...patch }))}
hopPasswordRequired={!editing}

View file

@ -143,6 +143,7 @@ export const batchApplyHopManagedNe = (
hop_command_template: string;
hop_vrf: string;
hop_vendor?: string;
hop_target_auth_mode?: string;
},
) => apiPost<{ ok: boolean; updated: number }>("/v1/managed-ne/batch-hop", { ids, hop });

View file

@ -144,6 +144,7 @@ export type ManagedNeItem = {
hop_username: string;
hop_command_template: string;
hop_vrf: string;
hop_target_auth_mode: string;
created_at: string;
updated_at: string;
};

View file

@ -2,9 +2,19 @@
import { ciscoHopTemplate, huaweiHopTemplate, isAutoHopTemplate, zteHopTemplate } from "./zteHop";
export type HopVendor = "zte" | "huawei" | "cisco" | "linux";
export type HopVendor = "zte" | "huawei" | "cisco" | "linux" | "bastion";
export const HOP_VENDORS: HopVendor[] = ["zte", "huawei", "cisco", "linux"];
export type HopTargetAuthMode = "bastion_managed" | "manual";
export const HOP_VENDORS: HopVendor[] = ["zte", "huawei", "cisco", "linux", "bastion"];
export function bastionHopTemplate(): string {
return "{hop_user}@{target_user}@{target_ip}@{hop_host}";
}
export function isBastionHopVendor(vendor: string): boolean {
return String(vendor || "").toLowerCase() === "bastion";
}
export function isLinuxHopVendor(vendor: string): boolean {
return String(vendor || "").toLowerCase() === "linux";
@ -20,16 +30,34 @@ export function defaultHopTemplate(vendor: string, protocol: string, vrf: string
if (v === "huawei") return huaweiHopTemplate(protocol, vrf);
if (v === "cisco") return ciscoHopTemplate(protocol, vrf);
if (v === "linux") return "";
if (v === "bastion") return bastionHopTemplate();
return zteHopTemplate(protocol, vrf);
}
export function patchHopVendorChange(
vendor: HopVendor,
prev: { hop_protocol: string; hop_vrf: string; hop_command_template: string; hop_vendor?: string },
): { hop_vendor: HopVendor; hop_protocol: string; hop_vrf: string; hop_command_template: string } {
): {
hop_vendor: HopVendor;
hop_protocol: string;
hop_vrf: string;
hop_command_template: string;
hop_port?: number;
hop_target_auth_mode?: HopTargetAuthMode;
} {
if (vendor === "linux") {
return { hop_vendor: "linux", hop_protocol: "ssh", hop_vrf: "", hop_command_template: "" };
}
if (vendor === "bastion") {
return {
hop_vendor: "bastion",
hop_protocol: "ssh",
hop_port: 22,
hop_vrf: "",
hop_command_template: bastionHopTemplate(),
hop_target_auth_mode: "bastion_managed" as HopTargetAuthMode,
};
}
const protocol = prev.hop_protocol || "ssh";
const vrf = prev.hop_vrf || "";
return {

View file

@ -42,5 +42,6 @@ export function isAutoHopTemplate(
if (v === "huawei") return t === huaweiHopTemplate(protocol, vrf);
if (v === "cisco") return t === ciscoHopTemplate(protocol, vrf);
if (v === "linux") return t === "";
if (v === "bastion") return t === "{hop_user}@{target_user}@{target_ip}@{hop_host}";
return t === zteHopTemplate(protocol, vrf);
}