# readme


Once you open the tar package, you will see this README file and along with other files. To run the script, just run
./start.sh . The log file will be created in same directory as car.log

The scripts checks the integrity of certificates and does the validations. It provides the option to user to recover
found issues, if any.

The start.sh script installs all dependencies, creates the virtual environment, install the CARR package and starts
the script. Next invocation of start.sh script will skip installation and will directly run CARR script.

CARR script is installed at ~/.virtualenvs/carr_script directory. User can delete this dir to remove the CARR package.
Next invocation of the start.sh will install the CARR package in the same directory again.

> rm -rf ~/.virtualenvs/carr_script

If PIP or virtualenv was installed during the script execution, user can uninstall these using below commands
> python3 -m pip uninstall virtualenv
> python3 -m pip uninstall pip

## Usage

### IMPORTANT: Two-Step Workflow
CARR enforces a two-step workflow for safety:
1. **Step 1 - Dry Run**: Always run in dry run mode first to generate the recovery config
2. **Step 2 - Apply Fix**: Run without `-d` flag to apply fixes using the auto-discovered recovery config

The recovery config (`validation_config_recovery_mode.yaml`) is automatically used in fix mode.
To customize which certificates to rotate, edit the recovery config and set `validate: false` for certificates to skip.

### Common Flags (Available in Both Modes)
- `-d` : Dry run only (no fixes applied). Generates validation_config_recovery_mode.yaml. Default lead time is 825 days.
- `-o` : Download dependencies from internet if connectivity is available
- `-t <days>` : Lead time in days (31-825) to check for certificate expiry. Default is 825 days.
- `-h` : Print usage information

### Interactive Mode (Default)
Run with prompts for user input:
```
# Step 1: Dry run to generate recovery config
./start.sh -d

# Step 2: Apply fixes (uses validation_config_recovery_mode.yaml automatically)
./start.sh
```

### Automation Mode
Run the script in automation mode using --auto-mode CLI arg (no interactive prompts):
```
./start.sh --auto-mode --admin-pwd <password> [OPTIONS]
```

**Required:**
- `--auto-mode` : Enable automation mode
- `--admin-pwd <password>` : Admin user password

**Optional:**
- `--root-pwd <password>` : Root user password (defaults to admin password)
- `--ip-address <ip>` : Node IP address (required when running outside NSX manager)
- `--admin-user <username>` : Admin username (defaults to 'admin')

**Behavior:**
- No interactive prompts - credentials must be provided via command line
- Automatically applies fixes (no confirmation prompts)
- Exits with error if validation fails
- All sites must have the same passwords
- Supports all common flags (`-d`, `-t`, `-o`)

**Examples:**
```
# Step 1: Dry run inside NSX manager
./start.sh --auto-mode --admin-pwd "MyPassword123" -d

# Step 2: Apply fixes inside NSX manager
./start.sh --auto-mode --admin-pwd "MyPassword123"

# Step 1: Dry run outside NSX manager
./start.sh --auto-mode --admin-pwd "MyPassword123" --ip-address "192.168.1.10" -d

# Step 2: Apply fixes outside NSX manager
./start.sh --auto-mode --admin-pwd "MyPassword123" --ip-address "192.168.1.10"

# With separate root password
./start.sh --auto-mode --admin-pwd "AdminPass123" --root-pwd "RootPass456" --ip-address "192.168.1.10"

# Dry-run with custom lead time
./start.sh --auto-mode --admin-pwd "MyPassword123" -d -t 90
```
