2024-01-07 16:18:27 +03:00
|
|
|
#!/usr/bin/bash
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
cd $(dirname $0)
|
|
|
|
|
PATH=$PATH:$(dirname "$(pwd)")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
source ../.pct-helpers
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
readConfig
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-13 09:55:32 +03:00
|
|
|
webAppConfig Nextcloud
|
|
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
DFL_ID=${DFL_ID:=300}
|
|
|
|
|
DFL_CTHOSTNAME=${DFL_CTHOSTNAME:=nextcloud}
|
|
|
|
|
|
2024-01-07 16:34:47 +03:00
|
|
|
DFL_CORES=${DFL_CORES:=2}
|
2024-01-07 16:18:27 +03:00
|
|
|
DFL_RAM=${DFL_RAM:=2048}
|
2024-01-08 06:03:08 +03:00
|
|
|
DFL_SWAP=${DFL_SWAP:=${DFL_RAM}}
|
2024-01-07 16:18:27 +03:00
|
|
|
DFL_DRIVE=${DFL_DRIVE:=40}
|
|
|
|
|
|
2024-01-18 03:29:51 +03:00
|
|
|
# XXX do we request these???
|
|
|
|
|
GATE_LAN_IP=${GATE_LAN_IP:-${DFL_GATE_LAN_IP}}
|
|
|
|
|
GATE_HOSTNAME=${GATE_HOSTNAME:-${DFL_GATE_HOSTNAME}}
|
|
|
|
|
WAN_IP=${WAN_IP:-${DFL_WAN_IP}}
|
2024-01-08 06:28:42 +03:00
|
|
|
|
2024-01-18 03:29:51 +03:00
|
|
|
#WAN_IP=SKIP
|
2024-01-11 13:54:45 +03:00
|
|
|
WAN_GATE=SKIP
|
|
|
|
|
ADMIN_IP=SKIP
|
|
|
|
|
ADMIN_GATE=SKIP
|
|
|
|
|
LAN_IP=SKIP
|
|
|
|
|
LAN_GATE=SKIP
|
2024-01-07 16:18:27 +03:00
|
|
|
|
|
|
|
|
REBOOT=${REBOOT:=1}
|
|
|
|
|
|
|
|
|
|
readVars
|
|
|
|
|
|
2024-01-13 09:55:32 +03:00
|
|
|
# Nextcloud-specific configuration...
|
|
|
|
|
APP_DOMAIN=$DOMAIN
|
2024-01-18 03:29:51 +03:00
|
|
|
#DB_PASS=
|
|
|
|
|
#APP_PASS=
|
|
|
|
|
#SEC_ALERTS=SKIP
|
2024-01-13 09:55:32 +03:00
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-08 02:40:38 +03:00
|
|
|
# NOTE: TKL gui will not function correctly without nesting enabled...
|
2024-01-07 16:18:27 +03:00
|
|
|
OPTS_STAGE_1="\
|
|
|
|
|
--hostname $CTHOSTNAME \
|
2024-01-07 16:34:47 +03:00
|
|
|
--cores $CORES \
|
2024-01-07 16:18:27 +03:00
|
|
|
--memory $RAM \
|
|
|
|
|
--swap $SWAP \
|
|
|
|
|
--net0 name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1,ip=dhcp,type=veth \
|
|
|
|
|
--storage local-lvm \
|
|
|
|
|
--rootfs local-lvm:$DRIVE \
|
|
|
|
|
--unprivileged 1 \
|
2024-01-08 04:15:19 +03:00
|
|
|
--features nesting=1 \
|
2024-01-07 16:18:27 +03:00
|
|
|
${PCT_EXTRA} \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_2="\
|
|
|
|
|
--onboot 1 \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
echo "# Building config..."
|
2024-01-10 03:57:49 +03:00
|
|
|
buildAssets
|
2024-01-07 16:18:27 +03:00
|
|
|
|
|
|
|
|
echo "# Creating CT..."
|
2024-01-10 18:12:24 +03:00
|
|
|
pctCreateTurnkey 'nextcloud' $ID "$OPTS_STAGE_1" "$PASS"
|
2024-01-07 16:18:27 +03:00
|
|
|
|
2024-01-08 05:43:58 +03:00
|
|
|
echo "# Starting TKL UI..."
|
2024-01-08 06:11:42 +03:00
|
|
|
# XXX might be a good idea to reaaad stuff from config...
|
|
|
|
|
@ lxc-attach $ID -- bash -c "\
|
|
|
|
|
HUB_APIKEY=SKIP \
|
|
|
|
|
SEC_UPDATES=SKIP \
|
|
|
|
|
${APP_DOMAIN:+APP_DOMAIN=${APP_DOMAIN}} \
|
|
|
|
|
${DB_PASS:+DB_PASS=${DB_PASS}} \
|
|
|
|
|
${APP_PASS:+APP_PASS=${APP_PASS}} \
|
|
|
|
|
${SEC_ALERTS:+SEC_ALERTS=${SEC_ALERTS}} \
|
|
|
|
|
/usr/sbin/turnkey-init"
|
2024-01-08 05:02:29 +03:00
|
|
|
|
2024-01-08 03:11:55 +03:00
|
|
|
echo "# Updating config..."
|
2024-01-08 04:01:44 +03:00
|
|
|
# add gate IP to trusted_proxies...
|
2024-01-08 04:15:19 +03:00
|
|
|
@ lxc-attach $ID -- bash -c "\
|
|
|
|
|
sed -i \
|
2024-01-18 03:29:51 +03:00
|
|
|
-e \"/trusted_domains/i\\ 'trusted_proxies' =>\\n array (\\n 0 => '${GATE_LAN_IP/\/*}\\/32',\\n ),\" \
|
2024-01-08 04:15:19 +03:00
|
|
|
/var/www/nextcloud/config/config.php"
|
2024-01-15 16:47:30 +03:00
|
|
|
|
2024-01-08 04:01:44 +03:00
|
|
|
# add self IP to trusted_domains -- enable setup from local network...
|
2024-01-18 00:45:54 +03:00
|
|
|
# XXX is the IP actually needed???
|
|
|
|
|
IP=$([ -z $DRY_RUN ] && lxc-attach $ID -- hostname -I)
|
2024-01-18 03:29:51 +03:00
|
|
|
# XXX the gate stuff might not be needed...
|
2024-01-18 01:00:43 +03:00
|
|
|
TRUSTED_DOMAINS=(
|
2024-01-18 00:45:54 +03:00
|
|
|
"${IP/ *}"
|
|
|
|
|
"$CTHOSTNAME"
|
|
|
|
|
"${CTHOSTNAME}.srv"
|
2024-01-18 03:29:51 +03:00
|
|
|
"${GATE_LAN_IP/\/*}"
|
2024-01-18 01:00:43 +03:00
|
|
|
"${GATE_HOSTNAME}"
|
|
|
|
|
"${GATE_HOSTNAME}.srv"
|
2024-01-18 03:29:51 +03:00
|
|
|
"${WAN_IP/\/*}"
|
2024-01-18 00:45:54 +03:00
|
|
|
)
|
|
|
|
|
ADDRS=
|
|
|
|
|
i=2
|
|
|
|
|
for addr in "${TRUSTED_DOMAINS[@]}" ; do
|
2024-01-18 03:29:51 +03:00
|
|
|
if [ -z "$addr" ] || [[ "$addr" == ".srv" ]] ; then
|
2024-01-18 00:45:54 +03:00
|
|
|
continue
|
|
|
|
|
fi
|
2024-01-18 01:05:21 +03:00
|
|
|
ADDRS="${ADDRS}\ \ $i => '${addr//\//\\/}',\\n"
|
2024-01-18 00:45:54 +03:00
|
|
|
i=$(( i + 1 ))
|
|
|
|
|
done
|
|
|
|
|
@ lxc-attach $ID -- bash -c "\
|
|
|
|
|
sed -z -i \
|
|
|
|
|
-e \"s/\\(trusted_domains[^)]*\\)/\\1${ADDRS}/\" \
|
|
|
|
|
/var/www/nextcloud/config/config.php"
|
2024-01-15 16:47:30 +03:00
|
|
|
|
2024-01-15 00:26:10 +03:00
|
|
|
# remove /index.php from urls...
|
|
|
|
|
# for more info see:
|
|
|
|
|
# https://docs.nextcloud.com/server/stable/admin_manual/installation/source_installation.html#pretty-urls
|
|
|
|
|
@ lxc-attach $ID -- bash -c "\
|
2024-01-15 01:05:10 +03:00
|
|
|
sed -i \
|
2024-01-15 00:54:28 +03:00
|
|
|
-e \"/trusted_proxies/i\\ 'htaccess.RewriteBase' => '\\/',\\n\" \
|
2024-01-15 00:26:10 +03:00
|
|
|
/var/www/nextcloud/config/config.php"
|
|
|
|
|
@ lxc-attach $ID -- turnkey-occ maintenance:update:htaccess
|
2024-01-07 16:18:27 +03:00
|
|
|
|
|
|
|
|
echo "# Copying assets..."
|
|
|
|
|
@ pct-push-r $ID ./assets /
|
|
|
|
|
|
|
|
|
|
echo "# Disabling fail2ban..."
|
|
|
|
|
# NOTE: we do not need this as we'll be running from behind a reverse proxy...
|
|
|
|
|
@ lxc-attach $ID systemctl stop fail2ban
|
|
|
|
|
@ lxc-attach $ID systemctl disable fail2ban
|
|
|
|
|
|
2024-01-08 06:03:08 +03:00
|
|
|
echo "# Updating system..."
|
2024-01-10 18:12:24 +03:00
|
|
|
pctUpdateTurnkey $ID
|
2024-01-08 03:11:55 +03:00
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
echo "# Post config..."
|
|
|
|
|
pctSet $ID "${OPTS_STAGE_2}" $REBOOT
|
2024-01-18 03:44:49 +03:00
|
|
|
pctSetNotes $ID
|
2024-01-07 16:18:27 +03:00
|
|
|
|
2024-01-10 17:56:40 +03:00
|
|
|
saveLastRunConfig
|
2024-01-08 05:28:47 +03:00
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
echo "# Done."
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# vim:set ts=4 sw=4 :
|