vaultwarden-install.sh 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. #!/usr/bin/env bash
  2. YW=`echo "\033[33m"`
  3. RD=`echo "\033[01;31m"`
  4. BL=`echo "\033[36m"`
  5. GN=`echo "\033[1;92m"`
  6. CL=`echo "\033[m"`
  7. RETRY_NUM=10
  8. RETRY_EVERY=3
  9. NUM=$RETRY_NUM
  10. CM="${GN}✓${CL}"
  11. CROSS="${RD}✗${CL}"
  12. BFR="\\r\\033[K"
  13. HOLD="-"
  14. set -o errexit
  15. set -o errtrace
  16. set -o nounset
  17. set -o pipefail
  18. shopt -s expand_aliases
  19. alias die='EXIT=$? LINE=$LINENO error_exit'
  20. trap die ERR
  21. function error_exit() {
  22. trap - ERR
  23. local reason="Unknown failure occured."
  24. local msg="${1:-$reason}"
  25. local flag="${RD}‼ ERROR ${CL}$EXIT@$LINE"
  26. echo -e "$flag $msg" 1>&2
  27. exit $EXIT
  28. }
  29. function msg_info() {
  30. local msg="$1"
  31. echo -ne " ${HOLD} ${YW}${msg}..."
  32. }
  33. function msg_ok() {
  34. local msg="$1"
  35. echo -e "${BFR} ${CM} ${GN}${msg}${CL}"
  36. }
  37. msg_info "Setting up Container OS "
  38. sed -i "/$LANG/ s/\(^# \)//" /etc/locale.gen
  39. locale-gen >/dev/null
  40. while [ "$(hostname -I)" = "" ]; do
  41. 1>&2 echo -en "${CROSS}${RD} No Network! "
  42. sleep $RETRY_EVERY
  43. ((NUM--))
  44. if [ $NUM -eq 0 ]
  45. then
  46. 1>&2 echo -e "${CROSS}${RD} No Network After $RETRY_NUM Tries${CL}"
  47. exit 1
  48. fi
  49. done
  50. msg_ok "Set up Container OS"
  51. msg_ok "Network Connected: ${BL}$(hostname -I)"
  52. msg_info "Updating Container OS"
  53. apt update &>/dev/null
  54. apt-get -qqy upgrade &>/dev/null
  55. msg_ok "Updated Container OS"
  56. msg_info "Installing Dependencies"
  57. apt-get update &>/dev/null
  58. apt-get -qqy install \
  59. git \
  60. nano \
  61. wget \
  62. htop \
  63. pkg-config \
  64. openssl \
  65. libssl1.1 \
  66. libssl-dev \
  67. curl \
  68. sudo &>/dev/null
  69. msg_ok "Installed Dependencies"
  70. msg_info "Installing Build Essentials"
  71. apt-get install -y build-essential &>/dev/null
  72. msg_ok "Installed Build Essentials"
  73. msg_info "Installing Rust"
  74. curl https://sh.rustup.rs -sSf | sh -s -- -y &>/dev/null
  75. echo 'export PATH=~/.cargo/bin:$PATH' >> ~/.bashrc &>/dev/null
  76. export PATH=~/.cargo/bin:$PATH &>/dev/null
  77. which rustc &>/dev/null
  78. msg_ok "Installed Rust"
  79. msg_info "Installing Node.js"
  80. curl -fsSL https://deb.nodesource.com/setup_16.x | bash - &>/dev/null
  81. apt-get install -y nodejs &>/dev/null
  82. npm -g install npm@7 &>/dev/null
  83. which npm &>/dev/null
  84. npm i npm@latest -g &>/dev/null
  85. msg_ok "Installed Node.js"
  86. msg_info "Building Vaultwarden (Patience)"
  87. git clone https://github.com/dani-garcia/vaultwarden &>/dev/null
  88. pushd vaultwarden &>/dev/null
  89. cargo clean &>/dev/null
  90. cargo build --features sqlite --release &>/dev/null
  91. file target/release/vaultwarden &>/dev/null
  92. msg_ok "Built Vaultwarden"
  93. msg_info "Building Web-Vault"
  94. pushd target/release/ &>/dev/null
  95. git clone --recurse-submodules https://github.com/bitwarden/web.git web-vault.git &>/dev/null
  96. cd web-vault.git &>/dev/null
  97. git checkout v2.25.1 &>/dev/null
  98. git submodule update --init --recursive &>/dev/null
  99. wget https://raw.githubusercontent.com/dani-garcia/bw_web_builds/master/patches/v2.25.0.patch &>/dev/null
  100. git apply v2.25.0.patch &>/dev/null
  101. npm ci --silent --legacy-peer-deps &>/dev/null
  102. npm audit fix --silent --legacy-peer-deps || true &>/dev/null
  103. npm run --silent dist:oss:selfhost &>/dev/null
  104. cp -a build ../web-vault &>/dev/null
  105. cd ..
  106. mkdir data
  107. msg_ok "Built Web-Vault"
  108. msg_info "Creating Service"
  109. cp ../../.env.template /etc/vaultwarden.env &>/dev/null
  110. cp vaultwarden /usr/bin/vaultwarden &>/dev/null
  111. chmod +x /usr/bin/vaultwarden &>/dev/null
  112. useradd -m -d /var/lib/vaultwarden vaultwarden &>/dev/null
  113. sudo cp -R data /var/lib/vaultwarden/ &>/dev/null
  114. cp -R web-vault /var/lib/vaultwarden/ &>/dev/null
  115. chown -R vaultwarden:vaultwarden /var/lib/vaultwarden &>/dev/null
  116. service_path="/etc/systemd/system/vaultwarden.service" &>/dev/null
  117. echo "[Unit]
  118. Description=Bitwarden Server (Powered by Vaultwarden)
  119. Documentation=https://github.com/dani-garcia/vaultwarden
  120. After=network.target
  121. [Service]
  122. User=vaultwarden
  123. Group=vaultwarden
  124. EnvironmentFile=/etc/vaultwarden.env
  125. ExecStart=/usr/bin/vaultwarden
  126. LimitNOFILE=1048576
  127. PrivateTmp=true
  128. PrivateDevices=true
  129. ProtectHome=true
  130. ProtectSystem=strict
  131. WorkingDirectory=/var/lib/vaultwarden
  132. ReadWriteDirectories=/var/lib/vaultwarden
  133. AmbientCapabilities=CAP_NET_BIND_SERVICE
  134. [Install]
  135. WantedBy=multi-user.target" > $service_path
  136. systemctl daemon-reload
  137. systemctl enable vaultwarden.service &>/dev/null
  138. systemctl start vaultwarden.service &>/dev/null
  139. msg_ok "Created Service"
  140. PASS=$(grep -w "root" /etc/shadow | cut -b6);
  141. if [[ $PASS != $ ]]; then
  142. msg_info "Customizing Container"
  143. rm /etc/motd
  144. rm /etc/update-motd.d/10-uname
  145. touch ~/.hushlogin
  146. GETTY_OVERRIDE="/etc/systemd/system/container-getty@1.service.d/override.conf"
  147. mkdir -p $(dirname $GETTY_OVERRIDE)
  148. cat << EOF > $GETTY_OVERRIDE
  149. [Service]
  150. ExecStart=
  151. ExecStart=-/sbin/agetty --autologin root --noclear --keep-baud tty%I 115200,38400,9600 \$TERM
  152. EOF
  153. systemctl daemon-reload
  154. systemctl restart $(basename $(dirname $GETTY_OVERRIDE) | sed 's/\.d//')
  155. msg_ok "Customized Container"
  156. fi
  157. msg_info "Cleaning up"
  158. apt-get autoremove >/dev/null
  159. apt-get autoclean >/dev/null
  160. rm -rf /var/{cache,log}/* /var/lib/apt/lists/*
  161. msg_ok "Cleaned"