wan-watchdog: log actions to journal + kick dyndns on WAN IP change
Shrinks external-access blip after ISP re-IP (was waiting up to 5min for the dyndns timer). Adds journal logging so WAN events are auditable. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
932dae38d5
commit
a1a25a8b75
1 changed files with 14 additions and 3 deletions
|
|
@ -47,15 +47,24 @@ let
|
||||||
if [ -n "$cur_ip" ] && [ "$cur_ip" != "$old_ip" ]; then
|
if [ -n "$cur_ip" ] && [ "$cur_ip" != "$old_ip" ]; then
|
||||||
$conntrack -F >/dev/null 2>&1 || true
|
$conntrack -F >/dev/null 2>&1 || true
|
||||||
${pkgs.coreutils}/bin/printf '%s' "$cur_ip" > "$ipfile"
|
${pkgs.coreutils}/bin/printf '%s' "$cur_ip" > "$ipfile"
|
||||||
# Only page on a real change, not the first-ever run.
|
# Push the new IP to Cloudflare now instead of waiting up to 5min for
|
||||||
[ -n "$old_ip" ] && notify "WAN IP changed $old_ip -> $cur_ip; flushed NAT conntrack."
|
# the dyndns timer — shrinks the window external clients (public DNS)
|
||||||
|
# can't reach our self-hosted services after an ISP re-IP.
|
||||||
|
$systemctl start --no-block cloudflare-dyndns.service >/dev/null 2>&1 || true
|
||||||
|
if [ -n "$old_ip" ]; then # skip the first-ever run
|
||||||
|
echo "wan-watchdog: WAN IP $old_ip -> $cur_ip; flushed conntrack, kicked dyndns"
|
||||||
|
notify "WAN IP changed $old_ip -> $cur_ip; flushed NAT conntrack + refreshed DNS."
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# --- 2. Connectivity check via the WAN ---
|
# --- 2. Connectivity check via the WAN ---
|
||||||
if $ping -c1 -W3 -I "$wan" 1.1.1.1 >/dev/null 2>&1 \
|
if $ping -c1 -W3 -I "$wan" 1.1.1.1 >/dev/null 2>&1 \
|
||||||
|| $ping -c1 -W3 -I "$wan" 8.8.8.8 >/dev/null 2>&1; then
|
|| $ping -c1 -W3 -I "$wan" 8.8.8.8 >/dev/null 2>&1; then
|
||||||
prev=$(${pkgs.coreutils}/bin/cat "$failfile" 2>/dev/null || echo 0)
|
prev=$(${pkgs.coreutils}/bin/cat "$failfile" 2>/dev/null || echo 0)
|
||||||
[ "$prev" -ge 3 ] && notify "WAN back up (was down ~$(( prev * 30 ))s)."
|
if [ "$prev" -ge 3 ]; then
|
||||||
|
echo "wan-watchdog: WAN recovered after ~$(( prev * 30 ))s"
|
||||||
|
notify "WAN back up (was down ~$(( prev * 30 ))s)."
|
||||||
|
fi
|
||||||
echo 0 > "$failfile"
|
echo 0 > "$failfile"
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
@ -65,10 +74,12 @@ let
|
||||||
echo "$fails" > "$failfile"
|
echo "$fails" > "$failfile"
|
||||||
case "$fails" in
|
case "$fails" in
|
||||||
3) # ~90s down: renew the lease
|
3) # ~90s down: renew the lease
|
||||||
|
echo "wan-watchdog: WAN unreachable ~90s, renewing $wan lease + flushing conntrack"
|
||||||
$networkctl renew "$wan" >/dev/null 2>&1 || true
|
$networkctl renew "$wan" >/dev/null 2>&1 || true
|
||||||
$conntrack -F >/dev/null 2>&1 || true
|
$conntrack -F >/dev/null 2>&1 || true
|
||||||
notify "WAN unreachable ~90s: renewed $wan DHCP lease + flushed conntrack." ;;
|
notify "WAN unreachable ~90s: renewed $wan DHCP lease + flushed conntrack." ;;
|
||||||
8) # ~4min down: full network stack restart
|
8) # ~4min down: full network stack restart
|
||||||
|
echo "wan-watchdog: WAN still down ~4min, restarting systemd-networkd"
|
||||||
$systemctl restart systemd-networkd >/dev/null 2>&1 || true
|
$systemctl restart systemd-networkd >/dev/null 2>&1 || true
|
||||||
$conntrack -F >/dev/null 2>&1 || true
|
$conntrack -F >/dev/null 2>&1 || true
|
||||||
notify "WAN still down ~4min: restarted systemd-networkd." ;;
|
notify "WAN still down ~4min: restarted systemd-networkd." ;;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue