From 5e4b6fbd3136a426c90fbc0b9c5ef2b1d3f742b0 Mon Sep 17 00:00:00 2001 From: juanjo Date: Sat, 5 Sep 2026 17:48:20 +0200 Subject: [PATCH] 05-sep: [router] automatizar tunel SSH al ASUS --- AGENTS.md | 1 + docs/raspberry_pi.md | 11 +++++++++++ scripts/router-ssh-tunnel.ps1 | 33 +++++++++++++++++++++++++++++++++ 3 files changed, 45 insertions(+) create mode 100644 scripts/router-ssh-tunnel.ps1 diff --git a/AGENTS.md b/AGENTS.md index 7d7def3..6dca54d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -84,6 +84,7 @@ Start-Process powershell -WindowStyle Hidden -ArgumentList '-Command', 'python C | `memoria` | Protocolo completo: git pull, actualizar ficheros de memoria (MEMORIA_ABSOLUTA, ESTADO_DIARIO, AGENTS, DOCUMENTACION, README), Engram local + cloud, Obsidian sync, **trello-sync**, git push | | `recordatorios` | Consultar API recordatorios en VPS: GET /todo (calendarios + recordatorios webhook) | | `raspberry` | Diagnosticar y mantener las Raspberry Pi del laboratorio | +| `router` | Abrir el tunel SSH hacia el ASUS RT-AX88U PRO | | `idd-procesar` o `procesar IDD` | Fetch manual de mensajes pendientes del canal IDD Telegram via Bot API, guardarlos en Google Drive y clasificarlos localmente | | `trello-sync` | Sincronizar pendientes con Trello: local→Trello (crea/actualiza cards) + Trello→local (elimina tareas archivadas en Trello de la base de conocimiento) | | `pelicula ` | Buscar pelicula en el videoclub y descargar a NAS | diff --git a/docs/raspberry_pi.md b/docs/raspberry_pi.md index 665aec0..8b459c8 100644 --- a/docs/raspberry_pi.md +++ b/docs/raspberry_pi.md @@ -58,6 +58,17 @@ El cambio de idioma puede requerir cerrar la sesion y volver a entrar. El teclad - El acceso remoto usa la clave privada del VPS configurada para el tunel; nunca se copia ni documenta aqui. - Si la IP cambia, consultar `hostname -I` en la Pi y actualizar el inventario. +## Acceso al ASUS RT-AX88U PRO + +El ASUS esta detras del router principal de Digi. Para abrir su SSH desde el PC: + +```powershell +powershell -ExecutionPolicy Bypass -File scripts/router-ssh-tunnel.ps1 +ssh -p 2222 usuario_del_router@127.0.0.1 +``` + +El script mantiene el salto PC -> VPS -> Raspberry -> ASUS sin exponer el router a Internet. + ## Despliegue La Pi no tiene Git operativo para este flujo. El despliegue se hace por el VPS y el tunel inverso: diff --git a/scripts/router-ssh-tunnel.ps1 b/scripts/router-ssh-tunnel.ps1 new file mode 100644 index 0000000..542cd9e --- /dev/null +++ b/scripts/router-ssh-tunnel.ps1 @@ -0,0 +1,33 @@ +$ErrorActionPreference = "Stop" + +$key = "C:\Users\juanm\Documents\GitHub\contabo" +$vps = "root@185.187.169.109" +$remotePort = 18022 +$localPort = 2222 + +if (-not (Test-Path -LiteralPath $key -PathType Leaf)) { + throw "No se encuentra la clave SSH del VPS: $key" +} + +$remoteCommand = "if ss -lnt | grep -q ':$remotePort'; then echo TUNNEL_ALREADY_ACTIVE; else nohup ssh -i /root/.ssh/pi_deploy -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -p 2222 -N -L $remotePort`:192.168.50.1`:22 pi@127.0.0.1 >/tmp/router-ssh-tunnel.log 2>&1 & echo TUNNEL_STARTED; fi" +& ssh -i $key -o BatchMode=yes $vps $remoteCommand + +$local = Get-NetTCPConnection -LocalPort $localPort -State Listen -ErrorAction SilentlyContinue +if (-not $local) { + $arguments = @( + "-i", $key, + "-o", "BatchMode=yes", + "-o", "ExitOnForwardFailure=yes", + "-N", + "-L", "$localPort`:127.0.0.1`:$remotePort", + $vps + ) + Start-Process -FilePath "ssh.exe" -ArgumentList $arguments -WindowStyle Hidden + Start-Sleep -Seconds 2 +} + +if (Get-NetTCPConnection -LocalPort $localPort -State Listen -ErrorAction SilentlyContinue) { + Write-Output "Tunel activo. Conecta con: ssh -p $localPort usuario_del_router@127.0.0.1" +} else { + throw "No se pudo abrir el puerto local $localPort" +}