2023-12-28 07:24:50 +03:00
|
|
|
#!/usr/bin/bash
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-03 20:13:51 +03:00
|
|
|
cd $(dirname $0)
|
2023-12-30 18:05:58 +03:00
|
|
|
PATH=$PATH:$(dirname "$(pwd)")
|
|
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 20:13:51 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
source ../.pct-helpers
|
|
|
|
|
|
|
|
|
|
|
2023-12-29 15:29:38 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
readConfig
|
2023-12-29 15:29:38 +03:00
|
|
|
|
|
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-17 15:07:18 +03:00
|
|
|
DFL_ID=${GATE_ID:=${DFL_ID:-102}}
|
|
|
|
|
DFL_CTHOSTNAME=${GATE_HOSTNAME:-${DFL_CTHOSTNAME:-gate}}
|
2024-01-03 18:51:22 +03:00
|
|
|
|
2024-01-07 16:34:47 +03:00
|
|
|
CORES=1
|
2024-01-05 22:59:42 +03:00
|
|
|
RAM=128
|
|
|
|
|
SWAP=$RAM
|
|
|
|
|
DRIVE=0.5
|
|
|
|
|
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_WAN_IP=${DFL_WAN_IP}
|
|
|
|
|
DFL_WAN_GATE=${DFL_WAN_GATE}
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-08 06:03:08 +03:00
|
|
|
# XXX revise...
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_ADMIN_IP=${GATE_ADMIN_IP:=${DFL_ADMIN_IP:=10.0.0.2/24}}
|
2024-01-11 13:54:45 +03:00
|
|
|
ADMIN_GATE=SKIP
|
2024-01-08 06:03:08 +03:00
|
|
|
# XXX revise...
|
2024-01-04 02:25:20 +03:00
|
|
|
DFL_LAN_IP=${GATE_LAN_IP:=${DFL_LAN_IP:=10.1.1.2/24}}
|
2024-01-11 13:54:45 +03:00
|
|
|
LAN_GATE=SKIP
|
2024-01-03 18:51:22 +03:00
|
|
|
|
2023-12-29 17:01:17 +03:00
|
|
|
REBOOT=${REBOOT:=1}
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2023-12-29 16:10:14 +03:00
|
|
|
|
2024-10-18 16:30:59 +03:00
|
|
|
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
2024-10-18 16:58:25 +03:00
|
|
|
# Bootstrap cleanup...
|
2024-10-18 16:22:29 +03:00
|
|
|
|
2024-10-19 15:32:56 +03:00
|
|
|
# NOTE: this is intentionally handled before the bootstrap...
|
2024-10-18 16:49:52 +03:00
|
|
|
if ! [ -z $BOOTSTRAP_CLEAN ] ; then
|
2024-10-19 15:09:34 +03:00
|
|
|
#ID=${ID:-${DFL_ID}}
|
2024-10-18 17:32:19 +03:00
|
|
|
|
2024-10-18 16:58:25 +03:00
|
|
|
xread "ID: " ID
|
2024-10-19 16:13:36 +03:00
|
|
|
xread "Bootstrap bridge: vmbr" BOOTSTRAP_BRIDGE
|
2024-10-18 16:58:25 +03:00
|
|
|
readBridgeVars
|
2024-10-18 16:49:52 +03:00
|
|
|
|
2024-10-19 13:59:43 +03:00
|
|
|
echo "# Reverting gate's WAN bridge to: vmbr${WAN_BRIDGE}..."
|
2024-10-18 16:58:25 +03:00
|
|
|
@ sed -i \
|
2024-10-19 16:40:43 +03:00
|
|
|
-e 's/^\(net0.*vmbr\)'${BOOTSTRAP_BRIDGE}'/\1'${WAN_BRIDGE}'/' \
|
2024-10-18 16:58:25 +03:00
|
|
|
/etc/pve/lxc/${ID}.conf
|
|
|
|
|
exit
|
2024-10-18 16:22:29 +03:00
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
2024-10-18 16:30:59 +03:00
|
|
|
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
2024-10-18 16:58:25 +03:00
|
|
|
# Bootstrap...
|
2024-10-18 16:30:59 +03:00
|
|
|
|
2024-10-18 16:58:25 +03:00
|
|
|
if ! [ -z $BOOTSTRAP ] ; then
|
2024-10-19 16:13:36 +03:00
|
|
|
xread "Bootstrap bridge: vmbr" BOOTSTRAP_BRIDGE
|
2024-10-18 17:32:19 +03:00
|
|
|
# this will allow the bootstrapped CTs to access the network...
|
2024-10-19 16:13:36 +03:00
|
|
|
WAN_BRIDGE=${BOOTSTRAP_BRIDGE}
|
2024-10-18 16:58:25 +03:00
|
|
|
fi
|
2024-10-18 16:30:59 +03:00
|
|
|
|
|
|
|
|
|
2024-10-18 16:49:52 +03:00
|
|
|
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
|
|
|
|
|
2024-10-18 16:58:25 +03:00
|
|
|
readVars
|
2024-10-18 16:49:52 +03:00
|
|
|
|
|
|
|
|
|
2024-10-18 16:22:29 +03:00
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2023-12-29 16:10:14 +03:00
|
|
|
|
2024-09-21 22:57:42 +03:00
|
|
|
# XXX add interface bootstrap...
|
2024-01-20 22:22:32 +03:00
|
|
|
INTERFACES=(
|
|
|
|
|
"name=wan,bridge=vmbr${WAN_BRIDGE},firewall=1${WAN_GATE:+,gw=${WAN_GATE}}${WAN_IP:+,ip=${WAN_IP}},type=veth"
|
|
|
|
|
"name=admin,bridge=vmbr${ADMIN_BRIDGE},firewall=1${ADMIN_IP:+,ip=${ADMIN_IP}},type=veth"
|
|
|
|
|
"name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1${LAN_IP:+,ip=${LAN_IP}},type=veth"
|
|
|
|
|
)
|
2023-12-29 16:10:14 +03:00
|
|
|
|
|
|
|
|
OPTS_STAGE_2="\
|
2023-12-29 17:01:17 +03:00
|
|
|
--startup order=80 \
|
|
|
|
|
--onboot 1 \
|
2023-12-29 16:10:14 +03:00
|
|
|
"
|
2023-12-28 07:24:50 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Building config..."
|
2024-01-10 03:57:49 +03:00
|
|
|
buildAssets
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Creating CT..."
|
2024-01-20 22:22:32 +03:00
|
|
|
pctCreateAlpine $ID "$PASS"
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-09-21 22:57:42 +03:00
|
|
|
# XXX this requires a bootsrapped interface...
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Installing dependencies..."
|
2024-01-13 00:12:59 +03:00
|
|
|
@ lxc-attach $ID apk add bash bridge iptables traefik logrotate
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Copying assets..."
|
2024-01-20 17:58:46 +03:00
|
|
|
pctPushAssets $ID
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Setup: traefik..."
|
2023-12-28 07:24:50 +03:00
|
|
|
@ lxc-attach $ID rc-update add traefik
|
|
|
|
|
@ lxc-attach $ID rc-service traefik start
|
|
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Setup: iptables..."
|
2023-12-28 07:24:50 +03:00
|
|
|
@ lxc-attach $ID rc-update add iptables
|
|
|
|
|
@ lxc-attach $ID bash /root/routing.sh
|
|
|
|
|
@ lxc-attach $ID rc-service iptables save
|
|
|
|
|
@ lxc-attach $ID rc-service iptables start
|
|
|
|
|
|
2024-01-03 19:59:49 +03:00
|
|
|
echo "# Setup: iptables update script..."
|
|
|
|
|
@ lxc-attach $ID rc-update add local
|
2024-01-10 02:14:36 +03:00
|
|
|
@ lxc-attach $ID -- ln -s /root/routing.sh /etc/local.d/iptables-update.start
|
2024-01-03 19:59:49 +03:00
|
|
|
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Post config..."
|
2024-01-03 18:51:22 +03:00
|
|
|
pctSet $ID "${OPTS_STAGE_2}" $REBOOT
|
2024-01-18 03:44:49 +03:00
|
|
|
pctSetNotes $ID
|
2023-12-28 07:24:50 +03:00
|
|
|
|
2024-01-10 17:56:40 +03:00
|
|
|
saveLastRunConfig
|
|
|
|
|
|
2024-01-26 03:06:55 +03:00
|
|
|
showNotes
|
2024-01-03 19:27:52 +03:00
|
|
|
echo "# Done."
|
2023-12-28 07:24:50 +03:00
|
|
|
|
|
|
|
|
|
2023-12-29 17:01:17 +03:00
|
|
|
|
2023-12-28 07:24:50 +03:00
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# vim:set ts=4 sw=4 :
|