vaultwarden-v5-install.sh 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204
  1. #!/usr/bin/env bash
  2. if [ "$VERBOSE" == "yes" ]; then set -x; fi
  3. YW=$(echo "\033[33m")
  4. RD=$(echo "\033[01;31m")
  5. BL=$(echo "\033[36m")
  6. GN=$(echo "\033[1;92m")
  7. CL=$(echo "\033[m")
  8. RETRY_NUM=10
  9. RETRY_EVERY=3
  10. NUM=$RETRY_NUM
  11. CM="${GN}✓${CL}"
  12. CROSS="${RD}✗${CL}"
  13. BFR="\\r\\033[K"
  14. HOLD="-"
  15. set -o errexit
  16. set -o errtrace
  17. set -o nounset
  18. set -o pipefail
  19. shopt -s expand_aliases
  20. alias die='EXIT=$? LINE=$LINENO error_exit'
  21. trap die ERR
  22. silent() { "$@" > /dev/null 2>&1; }
  23. function error_exit() {
  24. trap - ERR
  25. local reason="Unknown failure occurred."
  26. local msg="${1:-$reason}"
  27. local flag="${RD}‼ ERROR ${CL}$EXIT@$LINE"
  28. echo -e "$flag $msg" 1>&2
  29. exit $EXIT
  30. }
  31. function msg_info() {
  32. local msg="$1"
  33. echo -ne " ${HOLD} ${YW}${msg}..."
  34. }
  35. function msg_ok() {
  36. local msg="$1"
  37. echo -e "${BFR} ${CM} ${GN}${msg}${CL}"
  38. }
  39. function msg_error() {
  40. local msg="$1"
  41. echo -e "${BFR} ${CROSS} ${RD}${msg}${CL}"
  42. }
  43. msg_info "Setting up Container OS "
  44. sed -i "/$LANG/ s/\(^# \)//" /etc/locale.gen
  45. locale-gen >/dev/null
  46. while [ "$(hostname -I)" = "" ]; do
  47. echo 1>&2 -en "${CROSS}${RD} No Network! "
  48. sleep $RETRY_EVERY
  49. ((NUM--))
  50. if [ $NUM -eq 0 ]; then
  51. echo 1>&2 -e "${CROSS}${RD} No Network After $RETRY_NUM Tries${CL}"
  52. exit 1
  53. fi
  54. done
  55. msg_ok "Set up Container OS"
  56. msg_ok "Network Connected: ${BL}$(hostname -I)"
  57. set +e
  58. alias die=''
  59. if nc -zw1 8.8.8.8 443; then msg_ok "Internet Connected"; else
  60. msg_error "Internet NOT Connected"
  61. read -r -p "Would you like to continue anyway? <y/N> " prompt
  62. if [[ $prompt == "y" || $prompt == "Y" || $prompt == "yes" || $prompt == "Yes" ]]; then
  63. echo -e " ⚠️ ${RD}Expect Issues Without Internet${CL}"
  64. else
  65. echo -e " 🖧 Check Network Settings"
  66. exit 1
  67. fi
  68. fi
  69. RESOLVEDIP=$(nslookup "github.com" | awk -F':' '/^Address: / { matched = 1 } matched { print $2}' | xargs)
  70. if [[ -z "$RESOLVEDIP" ]]; then msg_error "DNS Lookup Failure"; else msg_ok "DNS Resolved github.com to $RESOLVEDIP"; fi
  71. alias die='EXIT=$? LINE=$LINENO error_exit'
  72. set -e
  73. msg_info "Updating Container OS"
  74. $STD apt-get update
  75. $STD apt-get -y upgrade
  76. msg_ok "Updated Container OS"
  77. msg_info "Installing Dependencies"
  78. $STD apt-get update
  79. $STD apt-get -qqy install \
  80. git \
  81. build-essential \
  82. pkgconf \
  83. libssl-dev \
  84. libmariadb-dev-compat \
  85. libpq-dev \
  86. curl \
  87. sudo
  88. msg_ok "Installed Dependencies"
  89. WEBVAULT=$(curl -s https://api.github.com/repos/dani-garcia/bw_web_builds/releases/latest |
  90. grep "tag_name" |
  91. awk '{print substr($2, 2, length($2)-3) }')
  92. VAULT=$(curl -s https://api.github.com/repos/dani-garcia/vaultwarden/releases/latest |
  93. grep "tag_name" |
  94. awk '{print substr($2, 2, length($2)-3) }')
  95. msg_info "Installing Rust"
  96. wget -qL https://sh.rustup.rs
  97. $STD bash index.html -y --profile minimal
  98. echo 'export PATH=~/.cargo/bin:$PATH' >>~/.bashrc
  99. export PATH=~/.cargo/bin:$PATH
  100. rm index.html
  101. msg_ok "Installed Rust"
  102. msg_info "Building Vaultwarden ${VAULT} (Patience)"
  103. $STD git clone https://github.com/dani-garcia/vaultwarden
  104. cd vaultwarden
  105. $STD cargo build --features "sqlite,mysql,postgresql" --release
  106. msg_ok "Built Vaultwarden ${VAULT}"
  107. $STD addgroup --system vaultwarden
  108. $STD adduser --system --home /opt/vaultwarden --shell /usr/sbin/nologin --no-create-home --gecos 'vaultwarden' --ingroup vaultwarden --disabled-login --disabled-password vaultwarden
  109. mkdir -p /opt/vaultwarden/bin
  110. mkdir -p /opt/vaultwarden/data
  111. cp target/release/vaultwarden /opt/vaultwarden/bin/
  112. msg_info "Downloading Web-Vault ${WEBVAULT}"
  113. $STD curl -fsSLO https://github.com/dani-garcia/bw_web_builds/releases/download/$WEBVAULT/bw_web_$WEBVAULT.tar.gz
  114. $STD tar -xzf bw_web_$WEBVAULT.tar.gz -C /opt/vaultwarden/
  115. msg_ok "Downloaded Web-Vault ${WEBVAULT}"
  116. cat <<EOF >/opt/vaultwarden/.env
  117. ADMIN_TOKEN=$(openssl rand -base64 48)
  118. ROCKET_ADDRESS=0.0.0.0
  119. DATA_FOLDER=/opt/vaultwarden/data
  120. DATABASE_MAX_CONNS=10
  121. WEB_VAULT_FOLDER=/opt/vaultwarden/web-vault
  122. WEB_VAULT_ENABLED=true
  123. EOF
  124. msg_info "Creating Service"
  125. chown -R vaultwarden:vaultwarden /opt/vaultwarden/
  126. chown root:root /opt/vaultwarden/bin/vaultwarden
  127. chmod +x /opt/vaultwarden/bin/vaultwarden
  128. chown -R root:root /opt/vaultwarden/web-vault/
  129. chmod +r /opt/vaultwarden/.env
  130. service_path="/etc/systemd/system/vaultwarden.service"
  131. echo "[Unit]
  132. Description=Bitwarden Server (Powered by Vaultwarden)
  133. Documentation=https://github.com/dani-garcia/vaultwarden
  134. After=network.target
  135. [Service]
  136. User=vaultwarden
  137. Group=vaultwarden
  138. EnvironmentFile=-/opt/vaultwarden/.env
  139. ExecStart=/opt/vaultwarden/bin/vaultwarden
  140. LimitNOFILE=65535
  141. LimitNPROC=4096
  142. PrivateTmp=true
  143. PrivateDevices=true
  144. ProtectHome=true
  145. ProtectSystem=strict
  146. DevicePolicy=closed
  147. ProtectControlGroups=yes
  148. ProtectKernelModules=yes
  149. ProtectKernelTunables=yes
  150. RestrictNamespaces=yes
  151. RestrictRealtime=yes
  152. MemoryDenyWriteExecute=yes
  153. LockPersonality=yes
  154. WorkingDirectory=/opt/vaultwarden
  155. ReadWriteDirectories=/opt/vaultwarden/data
  156. AmbientCapabilities=CAP_NET_BIND_SERVICE
  157. [Install]
  158. WantedBy=multi-user.target" >$service_path
  159. systemctl daemon-reload
  160. $STD systemctl enable --now vaultwarden.service
  161. msg_ok "Created Service"
  162. PASS=$(grep -w "root" /etc/shadow | cut -b6)
  163. if [[ $PASS != $ ]]; then
  164. msg_info "Customizing Container"
  165. rm /etc/motd
  166. rm /etc/update-motd.d/10-uname
  167. touch ~/.hushlogin
  168. GETTY_OVERRIDE="/etc/systemd/system/container-getty@1.service.d/override.conf"
  169. mkdir -p $(dirname $GETTY_OVERRIDE)
  170. cat <<EOF >$GETTY_OVERRIDE
  171. [Service]
  172. ExecStart=
  173. ExecStart=-/sbin/agetty --autologin root --noclear --keep-baud tty%I 115200,38400,9600 \$TERM
  174. EOF
  175. systemctl daemon-reload
  176. systemctl restart $(basename $(dirname $GETTY_OVERRIDE) | sed 's/\.d//')
  177. msg_ok "Customized Container"
  178. fi
  179. if [[ "${SSH_ROOT}" == "yes" ]]; then
  180. sed -i "s/#PermitRootLogin prohibit-password/PermitRootLogin yes/g" /etc/ssh/sshd_config
  181. systemctl restart sshd
  182. fi
  183. msg_info "Cleaning up"
  184. $STD apt-get autoremove
  185. $STD apt-get autoclean
  186. msg_ok "Cleaned"