2023-12-28 07:24:50 +03:00
|
|
|
#!/usr/bin/bash
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-03 20:13:51 +03:00
|
|
|
cd $(dirname $0)
|
2023-12-30 18:05:58 +03:00
|
|
|
PATH=$PATH:$(dirname "$(pwd)")
|
|
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 20:13:51 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
source ../.pct-helpers
|
|
|
|
|
|
|
|
|
|
|
2023-12-29 15:29:38 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
readConfig
|
2023-12-29 15:29:38 +03:00
|
|
|
|
|
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-17 15:07:18 +03:00
|
|
|
DFL_ID=${GATE_ID:=${DFL_ID:-102}}
|
|
|
|
|
DFL_CTHOSTNAME=${GATE_HOSTNAME:-${DFL_CTHOSTNAME:-gate}}
|
2024-01-03 18:51:22 +03:00
|
|
|
|
2024-01-07 16:34:47 +03:00
|
|
|
CORES=1
|
2024-01-05 22:59:42 +03:00
|
|
|
RAM=128
|
|
|
|
|
SWAP=$RAM
|
|
|
|
|
DRIVE=0.5
|
|
|
|
|
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_WAN_IP=${DFL_WAN_IP}
|
|
|
|
|
DFL_WAN_GATE=${DFL_WAN_GATE}
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-08 06:03:08 +03:00
|
|
|
# XXX revise...
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_ADMIN_IP=${GATE_ADMIN_IP:=${DFL_ADMIN_IP:=10.0.0.2/24}}
|
2024-01-11 13:54:45 +03:00
|
|
|
ADMIN_GATE=SKIP
|
2024-01-08 06:03:08 +03:00
|
|
|
# XXX revise...
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_LAN_IP=${GATE_LAN_IP:=${DFL_LAN_IP:=10.1.1.2/24}}
|
2024-01-11 13:54:45 +03:00
|
|
|
LAN_GATE=SKIP
|
2024-01-03 18:51:22 +03:00
|
|
|
|
2023-12-29 17:01:17 +03:00
|
|
|
REBOOT=${REBOOT:=1}
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 18:51:22 +03:00
|
|
|
readVars
|
2023-12-29 16:10:14 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_1="\
|
|
|
|
|
--hostname $CTHOSTNAME \
|
2024-01-07 16:34:47 +03:00
|
|
|
--cores $CORES \
|
2024-01-05 22:59:42 +03:00
|
|
|
--memory $RAM \
|
|
|
|
|
--swap $SWAP \
|
2023-12-31 05:20:11 +03:00
|
|
|
--net0 name=wan,bridge=vmbr${WAN_BRIDGE},firewall=1${WAN_GATE:+,gw=${WAN_GATE}}${WAN_IP:+,ip=${WAN_IP}},type=veth \
|
2024-01-03 18:51:22 +03:00
|
|
|
--net1 name=admin,bridge=vmbr${ADMIN_BRIDGE},firewall=1${ADMIN_IP:+,ip=${ADMIN_IP}},type=veth \
|
|
|
|
|
--net2 name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1${LAN_IP:+,ip=${LAN_IP}},type=veth \
|
2023-12-29 16:10:14 +03:00
|
|
|
--storage local-lvm \
|
2024-01-05 22:59:42 +03:00
|
|
|
--rootfs local-lvm:$DRIVE \
|
2023-12-29 16:10:14 +03:00
|
|
|
--unprivileged 1 \
|
2024-01-08 04:15:19 +03:00
|
|
|
--features nesting=1 \
|
2023-12-29 16:10:14 +03:00
|
|
|
${PCT_EXTRA} \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_2="\
|
2023-12-29 17:01:17 +03:00
|
|
|
--startup order=80 \
|
|
|
|
|
--onboot 1 \
|
2023-12-29 16:10:14 +03:00
|
|
|
"
|
2023-12-28 07:24:50 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Building config..."
|
2024-01-10 03:57:49 +03:00
|
|
|
buildAssets
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Creating CT..."
|
2024-01-03 18:51:22 +03:00
|
|
|
pctCreateAlpine $ID "${OPTS_STAGE_1}" "$PASS"
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Installing dependencies..."
|
2024-01-13 00:12:59 +03:00
|
|
|
@ lxc-attach $ID apk add bash bridge iptables traefik logrotate
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Copying assets..."
|
2023-12-28 07:24:50 +03:00
|
|
|
@ pct-push-r $ID ./assets /
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Setup: traefik..."
|
2023-12-28 07:24:50 +03:00
|
|
|
@ lxc-attach $ID rc-update add traefik
|
|
|
|
|
@ lxc-attach $ID rc-service traefik start
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Setup: iptables..."
|
2023-12-28 07:24:50 +03:00
|
|
|
@ lxc-attach $ID rc-update add iptables
|
|
|
|
|
@ lxc-attach $ID bash /root/routing.sh
|
|
|
|
|
@ lxc-attach $ID rc-service iptables save
|
|
|
|
|
@ lxc-attach $ID rc-service iptables start
|
|
|
|
|
|
2024-01-03 19:59:49 +03:00
|
|
|
echo "# Setup: iptables update script..."
|
|
|
|
|
@ lxc-attach $ID rc-update add local
|
2024-01-10 02:14:36 +03:00
|
|
|
@ lxc-attach $ID -- ln -s /root/routing.sh /etc/local.d/iptables-update.start
|
2024-01-03 19:59:49 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Post config..."
|
2024-01-03 18:51:22 +03:00
|
|
|
pctSet $ID "${OPTS_STAGE_2}" $REBOOT
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-10 17:56:40 +03:00
|
|
|
saveLastRunConfig
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Done."
|
2023-12-28 07:24:50 +03:00
|
|
|
|
|
|
|
|
|
2023-12-29 17:01:17 +03:00
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# vim:set ts=4 sw=4 :
|