vaultwarden-install.sh 5.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184
  1. #!/usr/bin/env bash
  2. YW=`echo "\033[33m"`
  3. RD=`echo "\033[01;31m"`
  4. BL=`echo "\033[36m"`
  5. GN=`echo "\033[1;92m"`
  6. CL=`echo "\033[m"`
  7. RETRY_NUM=10
  8. RETRY_EVERY=3
  9. NUM=$RETRY_NUM
  10. CM="${GN}✓${CL}"
  11. CROSS="${RD}✗${CL}"
  12. BFR="\\r\\033[K"
  13. HOLD="-"
  14. set -o errexit
  15. set -o errtrace
  16. set -o nounset
  17. set -o pipefail
  18. shopt -s expand_aliases
  19. alias die='EXIT=$? LINE=$LINENO error_exit'
  20. trap die ERR
  21. function error_exit() {
  22. trap - ERR
  23. local reason="Unknown failure occured."
  24. local msg="${1:-$reason}"
  25. local flag="${RD}‼ ERROR ${CL}$EXIT@$LINE"
  26. echo -e "$flag $msg" 1>&2
  27. exit $EXIT
  28. }
  29. function msg_info() {
  30. local msg="$1"
  31. echo -ne " ${HOLD} ${YW}${msg}..."
  32. }
  33. function msg_ok() {
  34. local msg="$1"
  35. echo -e "${BFR} ${CM} ${GN}${msg}${CL}"
  36. }
  37. msg_info "Setting up Container OS "
  38. sed -i "/$LANG/ s/\(^# \)//" /etc/locale.gen
  39. locale-gen >/dev/null
  40. while [ "$(hostname -I)" = "" ]; do
  41. 1>&2 echo -en "${CROSS}${RD} No Network! "
  42. sleep $RETRY_EVERY
  43. ((NUM--))
  44. if [ $NUM -eq 0 ]
  45. then
  46. 1>&2 echo -e "${CROSS}${RD} No Network After $RETRY_NUM Tries${CL}"
  47. exit 1
  48. fi
  49. done
  50. msg_ok "Set up Container OS"
  51. msg_ok "Network Connected: ${BL}$(hostname -I)"
  52. wget -q --tries=10 --timeout=5 --spider https://google.com
  53. if [[ $? -eq 0 ]]; then
  54. msg_ok "Internet Online"
  55. else
  56. echo -e "{CROSS}${RD} Internet Offline"
  57. fi
  58. msg_info "Updating Container OS"
  59. apt update &>/dev/null
  60. apt-get -qqy upgrade &>/dev/null
  61. msg_ok "Updated Container OS"
  62. msg_info "Installing Dependencies"
  63. apt-get update &>/dev/null
  64. apt-get -qqy install \
  65. git \
  66. nano \
  67. wget \
  68. htop \
  69. pkg-config \
  70. openssl \
  71. libssl1.1 \
  72. libssl-dev \
  73. curl \
  74. sudo &>/dev/null
  75. msg_ok "Installed Dependencies"
  76. msg_info "Installing Build Essentials"
  77. apt-get install -y build-essential &>/dev/null
  78. msg_ok "Installed Build Essentials"
  79. msg_info "Installing Rust"
  80. curl https://sh.rustup.rs -sSf | sh -s -- -y &>/dev/null
  81. echo 'export PATH=~/.cargo/bin:$PATH' >> ~/.bashrc &>/dev/null
  82. export PATH=~/.cargo/bin:$PATH &>/dev/null
  83. which rustc &>/dev/null
  84. msg_ok "Installed Rust"
  85. msg_info "Installing Node.js"
  86. curl -fsSL https://deb.nodesource.com/setup_16.x | bash - &>/dev/null
  87. apt-get install -y nodejs &>/dev/null
  88. npm -g install npm@7 &>/dev/null
  89. which npm &>/dev/null
  90. npm i npm@latest -g &>/dev/null
  91. msg_ok "Installed Node.js"
  92. msg_info "Building Vaultwarden (Patience)"
  93. git clone https://github.com/dani-garcia/vaultwarden &>/dev/null
  94. pushd vaultwarden &>/dev/null
  95. cargo clean &>/dev/null
  96. cargo build --features sqlite --release &>/dev/null
  97. file target/release/vaultwarden &>/dev/null
  98. msg_ok "Built Vaultwarden"
  99. msg_info "Building Web-Vault"
  100. pushd target/release/ &>/dev/null
  101. git clone --recurse-submodules https://github.com/bitwarden/web.git web-vault.git &>/dev/null
  102. cd web-vault.git &>/dev/null
  103. git checkout v2.25.1 &>/dev/null
  104. git submodule update --init --recursive &>/dev/null
  105. wget https://raw.githubusercontent.com/dani-garcia/bw_web_builds/master/patches/v2.25.0.patch &>/dev/null
  106. git apply v2.25.0.patch &>/dev/null
  107. npm ci --silent --legacy-peer-deps &>/dev/null
  108. npm audit fix --silent --legacy-peer-deps || true &>/dev/null
  109. npm run --silent dist:oss:selfhost &>/dev/null
  110. cp -a build ../web-vault &>/dev/null
  111. cd ..
  112. mkdir data
  113. msg_ok "Built Web-Vault"
  114. msg_info "Creating Service"
  115. cp ../../.env.template /etc/vaultwarden.env &>/dev/null
  116. cp vaultwarden /usr/bin/vaultwarden &>/dev/null
  117. chmod +x /usr/bin/vaultwarden &>/dev/null
  118. useradd -m -d /var/lib/vaultwarden vaultwarden &>/dev/null
  119. sudo cp -R data /var/lib/vaultwarden/ &>/dev/null
  120. cp -R web-vault /var/lib/vaultwarden/ &>/dev/null
  121. chown -R vaultwarden:vaultwarden /var/lib/vaultwarden &>/dev/null
  122. service_path="/etc/systemd/system/vaultwarden.service" &>/dev/null
  123. echo "[Unit]
  124. Description=Bitwarden Server (Powered by Vaultwarden)
  125. Documentation=https://github.com/dani-garcia/vaultwarden
  126. After=network.target
  127. [Service]
  128. User=vaultwarden
  129. Group=vaultwarden
  130. EnvironmentFile=/etc/vaultwarden.env
  131. ExecStart=/usr/bin/vaultwarden
  132. LimitNOFILE=1048576
  133. PrivateTmp=true
  134. PrivateDevices=true
  135. ProtectHome=true
  136. ProtectSystem=strict
  137. WorkingDirectory=/var/lib/vaultwarden
  138. ReadWriteDirectories=/var/lib/vaultwarden
  139. AmbientCapabilities=CAP_NET_BIND_SERVICE
  140. [Install]
  141. WantedBy=multi-user.target" > $service_path
  142. systemctl daemon-reload
  143. systemctl enable vaultwarden.service &>/dev/null
  144. systemctl start vaultwarden.service &>/dev/null
  145. msg_ok "Created Service"
  146. PASS=$(grep -w "root" /etc/shadow | cut -b6);
  147. if [[ $PASS != $ ]]; then
  148. msg_info "Customizing Container"
  149. rm /etc/motd
  150. rm /etc/update-motd.d/10-uname
  151. touch ~/.hushlogin
  152. GETTY_OVERRIDE="/etc/systemd/system/container-getty@1.service.d/override.conf"
  153. mkdir -p $(dirname $GETTY_OVERRIDE)
  154. cat << EOF > $GETTY_OVERRIDE
  155. [Service]
  156. ExecStart=
  157. ExecStart=-/sbin/agetty --autologin root --noclear --keep-baud tty%I 115200,38400,9600 \$TERM
  158. EOF
  159. systemctl daemon-reload
  160. systemctl restart $(basename $(dirname $GETTY_OVERRIDE) | sed 's/\.d//')
  161. msg_ok "Customized Container"
  162. fi
  163. msg_info "Cleaning up"
  164. apt-get autoremove >/dev/null
  165. apt-get autoclean >/dev/null
  166. rm -rf /var/{cache,log}/* /var/lib/apt/lists/*
  167. msg_ok "Cleaned"