2024-01-07 16:18:27 +03:00
|
|
|
#!/usr/bin/bash
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
cd $(dirname $0)
|
|
|
|
|
PATH=$PATH:$(dirname "$(pwd)")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
source ../.pct-helpers
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
readConfig
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
DFL_ID=${DFL_ID:=300}
|
|
|
|
|
DFL_CTHOSTNAME=${DFL_CTHOSTNAME:=nextcloud}
|
|
|
|
|
|
2024-01-07 16:34:47 +03:00
|
|
|
DFL_CORES=${DFL_CORES:=2}
|
2024-01-07 16:18:27 +03:00
|
|
|
DFL_RAM=${DFL_RAM:=2048}
|
|
|
|
|
DFL_SWAP=${DFL_SWAP:=${DFL_RAM:=2048}}
|
|
|
|
|
DFL_DRIVE=${DFL_DRIVE:=40}
|
|
|
|
|
|
|
|
|
|
WAN_IP=-
|
|
|
|
|
WAN_GATE=-
|
|
|
|
|
ADMIN_IP=-
|
|
|
|
|
ADMIN_GATE=-
|
|
|
|
|
LAN_IP=-
|
|
|
|
|
LAN_GATE=-
|
|
|
|
|
|
|
|
|
|
REBOOT=${REBOOT:=1}
|
|
|
|
|
|
|
|
|
|
readVars
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
2024-01-08 02:40:38 +03:00
|
|
|
# NOTE: TKL gui will not function correctly without nesting enabled...
|
2024-01-07 16:18:27 +03:00
|
|
|
OPTS_STAGE_1="\
|
|
|
|
|
--hostname $CTHOSTNAME \
|
2024-01-07 16:34:47 +03:00
|
|
|
--cores $CORES \
|
2024-01-07 16:18:27 +03:00
|
|
|
--memory $RAM \
|
|
|
|
|
--swap $SWAP \
|
|
|
|
|
--net0 name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1,ip=dhcp,type=veth \
|
|
|
|
|
--storage local-lvm \
|
|
|
|
|
--rootfs local-lvm:$DRIVE \
|
|
|
|
|
--unprivileged 1 \
|
2024-01-08 02:40:38 +03:00
|
|
|
--features nesting=1
|
2024-01-07 16:18:27 +03:00
|
|
|
${PCT_EXTRA} \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_2="\
|
|
|
|
|
--onboot 1 \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
echo "# Building config..."
|
|
|
|
|
buildAssets "$TEMPLATE_DIR" "$ASSETS_DIR"
|
|
|
|
|
|
|
|
|
|
echo "# Creating CT..."
|
|
|
|
|
getLatestTemplate '.*-turnkey-nextcloud' TEMPLATE
|
|
|
|
|
pctCreate $ID "$TEMPLATE" "$OPTS_STAGE_1" "$PASS"
|
2024-01-07 16:34:47 +03:00
|
|
|
sleep ${TIMEOUT:=5}
|
2024-01-07 16:18:27 +03:00
|
|
|
|
2024-01-08 00:28:42 +03:00
|
|
|
# hooking into tkl init process:
|
|
|
|
|
# - wait for /etc/inithooks.conf to be generated by:
|
|
|
|
|
# /usr/lib/inithooks/firstboot.d/29preseed
|
|
|
|
|
# this file existion would mean that the first stage of setup is
|
|
|
|
|
# done and we can do:
|
|
|
|
|
# lxc-attach $ID -- bash --login exit
|
|
|
|
|
# to launch interactive setup...
|
|
|
|
|
# XXX can we get console/log output while poling???
|
|
|
|
|
# - inject a script into the chain to do our stuff
|
|
|
|
|
# Q: can we reuse tkl's scripts???
|
|
|
|
|
#
|
|
|
|
|
# * another strategy would be generate our own inithooks.conf but
|
|
|
|
|
# this would require us to mount the ct volume before first boot...
|
|
|
|
|
# see:
|
|
|
|
|
# https://forum.proxmox.com/threads/pct-push-when-lxc-is-offline.116786/
|
|
|
|
|
# * might be usefull to do both to:
|
|
|
|
|
# - maximize compatibility / change tolerance (tkl ui) (???)
|
|
|
|
|
# - skip dialogs we do not use...
|
|
|
|
|
# ...i.e. poll-patch-ui
|
|
|
|
|
#
|
2024-01-08 00:03:09 +03:00
|
|
|
# for tkl inithooks doc see:
|
|
|
|
|
# https://www.turnkeylinux.org/docs/inithooks
|
|
|
|
|
|
2024-01-08 02:40:38 +03:00
|
|
|
tklWaitForSetup
|
2024-01-08 02:26:47 +03:00
|
|
|
|
2024-01-08 01:46:13 +03:00
|
|
|
echo "# Starting TKL UI..."
|
2024-01-08 03:58:37 +03:00
|
|
|
@ lxc-attach $ID -- bash -c "HUB_APIKEY=SKIP SEC_UPDATES=SKIP /usr/sbin/turnkey-init"
|
2024-01-08 01:12:13 +03:00
|
|
|
|
2024-01-08 03:11:55 +03:00
|
|
|
echo "# Updating config..."
|
2024-01-08 03:58:37 +03:00
|
|
|
@ lxc-attach $ID -- sed -i \
|
|
|
|
|
-e "/trusted_domains/i\ 'trusted_proxies' =>\n array (\n '${GATE_LAN_IP}/32',\n )," \
|
|
|
|
|
-e "/trusted_domains[^(]*([^)]*)/i\ 'trusted_proxies' =>\n array (\n '${GATE_LAN_IP}/32',\n )," \
|
|
|
|
|
/var/www/nextcloud/config/config.php
|
|
|
|
|
IP=${DRY_RUN:=$(lxc-attach $ID -- hostname -I)}
|
|
|
|
|
@ lxc-attach $ID -- sed -z -i \
|
|
|
|
|
-e "s/\(trusted_domains[^)]*\)/\1 2 => '${IP/ *}',\n /" \
|
|
|
|
|
/var/www/nextcloud/config/config.php
|
2024-01-07 16:18:27 +03:00
|
|
|
|
|
|
|
|
echo "# Copying assets..."
|
|
|
|
|
@ pct-push-r $ID ./assets /
|
|
|
|
|
|
|
|
|
|
echo "# Disabling fail2ban..."
|
|
|
|
|
# NOTE: we do not need this as we'll be running from behind a reverse proxy...
|
|
|
|
|
@ lxc-attach $ID systemctl stop fail2ban
|
|
|
|
|
@ lxc-attach $ID systemctl disable fail2ban
|
|
|
|
|
|
2024-01-08 03:11:55 +03:00
|
|
|
echo "# Updating system..."
|
|
|
|
|
@ lxc-attach $ID apt update
|
|
|
|
|
@ lxc-attach $ID -- apt upgrade -y
|
|
|
|
|
|
2024-01-07 16:18:27 +03:00
|
|
|
echo "# Post config..."
|
|
|
|
|
pctSet $ID "${OPTS_STAGE_2}" $REBOOT
|
|
|
|
|
|
|
|
|
|
echo "# Done."
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# vim:set ts=4 sw=4 :
|
|
|
|
|
|
|
|
|
|
|