detector->detect($server); if ($reason = $os->supports('firewall')) { return ['ok' => false, 'output' => $reason]; } // long timeout: may install the firewall package first. $script = FirewallTool::for($os)->enableScript($this->sshPort($server)); $res = $this->fleet->runPrivileged($server, $script, 600); return ['ok' => $res['ok'], 'output' => $res['output']]; } /** Turn the firewall off (clean stop, never a panic/drop-all). @return array{ok: bool, output: string} */ public function disable(Server $server): array { $os = $this->detector->detect($server); $res = $this->fleet->runPrivileged($server, FirewallTool::for($os)->disableScript()); return ['ok' => $res['ok'], 'output' => $res['output']]; } /** * Detect the listening sshd Port from sshd_config (incl. drop-ins). Falls * back to 22 when nothing is set explicitly. */ private function sshPort(Server $server): int { $res = $this->fleet->runPrivileged( $server, 'grep -rhiE "^[[:space:]]*Port[[:space:]]+[0-9]+" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/ 2>/dev/null ' .'| awk \'{print $2}\' | head -1' ); $port = (int) trim($res['output']); return ($res['ok'] && $port >= 1 && $port <= 65535) ? $port : 22; } }