05-sep: [router] automatizar tunel SSH al ASUS

This commit is contained in:
juanjo
2026-09-05 17:48:20 +02:00
parent d897e662d3
commit 5e4b6fbd31
3 changed files with 45 additions and 0 deletions

View File

@@ -84,6 +84,7 @@ Start-Process powershell -WindowStyle Hidden -ArgumentList '-Command', 'python C
| `memoria` | Protocolo completo: git pull, actualizar ficheros de memoria (MEMORIA_ABSOLUTA, ESTADO_DIARIO, AGENTS, DOCUMENTACION, README), Engram local + cloud, Obsidian sync, **trello-sync**, git push | | `memoria` | Protocolo completo: git pull, actualizar ficheros de memoria (MEMORIA_ABSOLUTA, ESTADO_DIARIO, AGENTS, DOCUMENTACION, README), Engram local + cloud, Obsidian sync, **trello-sync**, git push |
| `recordatorios` | Consultar API recordatorios en VPS: GET /todo (calendarios + recordatorios webhook) | | `recordatorios` | Consultar API recordatorios en VPS: GET /todo (calendarios + recordatorios webhook) |
| `raspberry` | Diagnosticar y mantener las Raspberry Pi del laboratorio | | `raspberry` | Diagnosticar y mantener las Raspberry Pi del laboratorio |
| `router` | Abrir el tunel SSH hacia el ASUS RT-AX88U PRO |
| `idd-procesar` o `procesar IDD` | Fetch manual de mensajes pendientes del canal IDD Telegram via Bot API, guardarlos en Google Drive y clasificarlos localmente | | `idd-procesar` o `procesar IDD` | Fetch manual de mensajes pendientes del canal IDD Telegram via Bot API, guardarlos en Google Drive y clasificarlos localmente |
| `trello-sync` | Sincronizar pendientes con Trello: local→Trello (crea/actualiza cards) + Trello→local (elimina tareas archivadas en Trello de la base de conocimiento) | | `trello-sync` | Sincronizar pendientes con Trello: local→Trello (crea/actualiza cards) + Trello→local (elimina tareas archivadas en Trello de la base de conocimiento) |
| `pelicula <nombre>` | Buscar pelicula en el videoclub y descargar a NAS | | `pelicula <nombre>` | Buscar pelicula en el videoclub y descargar a NAS |

View File

@@ -58,6 +58,17 @@ El cambio de idioma puede requerir cerrar la sesion y volver a entrar. El teclad
- El acceso remoto usa la clave privada del VPS configurada para el tunel; nunca se copia ni documenta aqui. - El acceso remoto usa la clave privada del VPS configurada para el tunel; nunca se copia ni documenta aqui.
- Si la IP cambia, consultar `hostname -I` en la Pi y actualizar el inventario. - Si la IP cambia, consultar `hostname -I` en la Pi y actualizar el inventario.
## Acceso al ASUS RT-AX88U PRO
El ASUS esta detras del router principal de Digi. Para abrir su SSH desde el PC:
```powershell
powershell -ExecutionPolicy Bypass -File scripts/router-ssh-tunnel.ps1
ssh -p 2222 usuario_del_router@127.0.0.1
```
El script mantiene el salto PC -> VPS -> Raspberry -> ASUS sin exponer el router a Internet.
## Despliegue ## Despliegue
La Pi no tiene Git operativo para este flujo. El despliegue se hace por el VPS y el tunel inverso: La Pi no tiene Git operativo para este flujo. El despliegue se hace por el VPS y el tunel inverso:

View File

@@ -0,0 +1,33 @@
$ErrorActionPreference = "Stop"
$key = "C:\Users\juanm\Documents\GitHub\contabo"
$vps = "root@185.187.169.109"
$remotePort = 18022
$localPort = 2222
if (-not (Test-Path -LiteralPath $key -PathType Leaf)) {
throw "No se encuentra la clave SSH del VPS: $key"
}
$remoteCommand = "if ss -lnt | grep -q ':$remotePort'; then echo TUNNEL_ALREADY_ACTIVE; else nohup ssh -i /root/.ssh/pi_deploy -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -p 2222 -N -L $remotePort`:192.168.50.1`:22 pi@127.0.0.1 >/tmp/router-ssh-tunnel.log 2>&1 & echo TUNNEL_STARTED; fi"
& ssh -i $key -o BatchMode=yes $vps $remoteCommand
$local = Get-NetTCPConnection -LocalPort $localPort -State Listen -ErrorAction SilentlyContinue
if (-not $local) {
$arguments = @(
"-i", $key,
"-o", "BatchMode=yes",
"-o", "ExitOnForwardFailure=yes",
"-N",
"-L", "$localPort`:127.0.0.1`:$remotePort",
$vps
)
Start-Process -FilePath "ssh.exe" -ArgumentList $arguments -WindowStyle Hidden
Start-Sleep -Seconds 2
}
if (Get-NetTCPConnection -LocalPort $localPort -State Listen -ErrorAction SilentlyContinue) {
Write-Output "Tunel activo. Conecta con: ssh -p $localPort usuario_del_router@127.0.0.1"
} else {
throw "No se pudo abrir el puerto local $localPort"
}