VM setup: apt-get only, fix root-owned ~/.gnupg, quieter installs, Remote Control confirmation - #30
Merged
Merged
Conversation
- Add NodeSource's repo directly instead of running their setup script (it used apt and ran gpg as root with the user's HOME); repair a root-owned ~/.gnupg left by earlier runs - Route apt through apt_get() so DEBIAN_FRONTEND and needrestart's opt-out actually survive sudo - Capture chatty installer output, showing it only on failure - gh auth login --web; no-op BROWSER on headless machines
claude remote-control asks 'Enable Remote Control? (y/n)' once; under systemd the empty stdin counts as no, so the service exited and restarted every minute. Run it once in the foreground right after sign-in so the user can answer, surviving the Ctrl+C that stops it, and have the health check name this fix when the service is stuck at the prompt.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes from the first live run of
claude-code-vm-setup.shon a fresh VM, where every check passed except Remote Control.Remote Control service never started
The journal showed the cause:
claude remote-controlasks a one-timeEnable Remote Control? (y/n)before it will serve. Under systemd, stdin is empty, which counts as "no", so it exited 0 and systemd restarted it every minute forever. The docs confirm the answer is stored once given, but there's no documented way to pre-set it.confirm_remote_controlstep at the end of phase 1 (right after Claude sign-in): runsclaude remote-controlonce in the foreground so the user sees Claude's own explanation and answersy, then presses Ctrl+C once the session URL shows (2-minute safety timeout). A no-opINThandler keeps Ctrl+C from aborting the script;timeout --foregroundkeeps claude able to read the terminal.trust_project_dirhelper, applied before this step as well as when writing the service.Real bugs
~/.gnupg. NodeSource's setup script was run withsudo -E, which keepsHOME, so root's gpg wrote into/home/<user>/.gnupg(gpg: WARNING: unsafe ownership on homedir). That breaks the user's own gpg later. NodeSource's repo is now added directly: the armored key goes to/etc/apt/keyrings/nodesource.asc(no gpg involved), plus anodesource.listentry and an apt pin preferring it over Ubuntu's older nodejs. The old script'snodesource.sourcesis replaced, so apt doesn't see two entries with differentSigned-By. Preflight repairs a root-owned~/.gnupgleft by earlier runs.DEBIAN_FRONTENDnever reached apt.sudoresets the environment, so the script'sexport DEBIAN_FRONTEND=noninteractivedid nothing, and a package with a debconf question could have stalled the run. All apt calls now go throughapt_get(), which setsDEBIAN_FRONTEND=noninteractive NEEDRESTART_SUSPEND=1on the sudo line itself (also passed to get.docker.com's installer).WARNING: apt does not have a stable CLI interface. This came from NodeSource's script callingapt. It's gone with the script; everything usesapt-get.Noise
needrestart's "Scanning processes / candidates / linux images" after every install: suppressed viaNEEDRESTART_SUSPEND.cargo:rerun-if-env-changed…block, get.docker.com's+ sh -ctrace,npm install -g, pip/Playwright downloads) now run throughquiet(), which captures output and shows the last 30 lines only if the command fails.Sign-in polish
gh auth login --web: skips the "How would you like to authenticate?" question.BROWSER=trueexported once in preflight when there's no display, so gh and Claude just print their URL / device code instead of "Failed opening a web browser" (and a console browser can't take over the terminal). Replaces the Claude-only version from VM setup: catch missing AVX2 up front and stop the sign-in step hanging #29.Test plan
shellcheckclean; nosudo apt-get/apt installleft outside commentsubuntu:24.04container withneedrestartinstalled, NodeSource's oldsetup_22.xalready run, and a root-owned~/.gnupg: zero occurrences of the apt CLI warning, "Scanning processes", "unsafe ownership",cargo:rerun,+ sh -cand npm "added N packages";nodesource.sourcesreplaced bynodesource.list; nodejs24.21.0-1nodesource1from NodeSource;~/.gnupgreturned to the user (700); Playwright import OKptydriver, stubclaudewith the same y/n prompt): the answer reaches claude through the terminal; Ctrl+C stops only claude and the script continues (exit 0); the timeout path also continues; project dir trusted in~/.claude.jsonclaude remote-controlconfirmation needs a signed-in VM; next live run