graphene-os-server-infrastr.../ovh-mitigation.py
Daniel Micay c5a724ea7e drop code for toggling OVH permanent mitigation
This functionality was deprecated in July and is being removed in
September.
2025-08-09 17:41:33 -04:00

54 lines
1.5 KiB
Python

#!/usr/bin/env python3
import json
import ovh
import sys
def err(*args, **kwargs):
print(*args, file=sys.stderr, **kwargs)
sys.exit(1)
if len(sys.argv) != 4:
err("expected 3 arguments")
with open("ovh-mitigation.json") as config:
config = json.load(config)
system = sys.argv[1]
action = sys.argv[2]
ip = sys.argv[3]
client = ovh.Client(
endpoint=config["endpoint"],
application_key=config["application_key"],
application_secret=config["application_secret"],
consumer_key=config["consumer_key"],
)
if system == "mitigation":
if action == "status":
result = client.get(f"/ip/{ip}/mitigation")
if len(result) == 0:
print("mitigation disabled")
elif len(result) == 1:
result = client.get(f"/ip/{ip}/mitigation/{result[0]}")
print("automatic: " + str(result["auto"]))
print("permanent: " + str(result["permanent"]))
print("state: " + result["state"])
else:
err("expected single result")
else:
err("unknown action: " + action)
elif system == "firewall":
if action == "status":
result = client.get(f"/ip/{ip}/firewall/{ip}")
print("enabled: " + str(result["enabled"]))
print("state: " + result["state"])
elif action == "enable":
client.put(f'/ip/{ip}/firewall/{ip}', enabled=True)
elif action == "disable":
client.put(f"/ip/{ip}/firewall/{ip}", enabled=False)
else:
err("unknown action: " + action)
else:
err("unknown system: " + system)