setup.sh 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. #!/bin/bash
  2. echo "
  3. ____ __ _ _
  4. / ___| __ _ / _| ___ | | (_) _ __ ___
  5. \___ \ / _\` | | |_ / _ \ | | | | | '_ \ / _ \\
  6. ___) | | (_| | | _| | __/ | |___ | | | | | | | __/
  7. |____/ \__,_| |_| \___| |_____| |_| |_| |_| \___|
  8. "
  9. qrcode() {
  10. echo "█████████████████████████████████████████"
  11. echo "█████████████████████████████████████████"
  12. echo "████ ▄▄▄▄▄ █▀ █▀▀██▀▄▀▀▄▀▄▀▄██ ▄▄▄▄▄ ████"
  13. echo "████ █ █ █▀ ▄ █▀▄▄▀▀ ▄█▄ ▀█ █ █ ████"
  14. echo "████ █▄▄▄█ █▀█ █▄█▄▀▀▄▀▄ ▀▀▄▄█ █▄▄▄█ ████"
  15. echo "████▄▄▄▄▄▄▄█▄█▄█ █▄▀ █ ▀▄▀ █▄█▄▄▄▄▄▄▄████"
  16. echo "████▄ ▄▄ █▄▄ ▄█▄▄▄▄▀▄▀▀▄██ ▄▄▀▄█▄▀ ▀████"
  17. echo "████▄ ▄▀▄ ▄▀▄ ▀ ▄█▀ ▀▄ █▀▀ ▀█▀▄██▄▀▄█████"
  18. echo "█████ ▀▄█ ▄ ▄▄▀▄▀▀█▄▀▄▄▀▄▀▄ ▄ ▀▄▄▄█▀▀████"
  19. echo "████ █▀▄▀ ▄▀▄▄▀█▀ ▄▄ █▄█▀▀▄▀▀█▄█▄█▀▄█████"
  20. echo "████ █ ▀ ▄▀▀ ██▄█▄▄▄▄▄▀▄▀▀▀▄▄▀█▄▀█ ▀████"
  21. echo "████ █ ▀▄ ▄██▀▀ ▄█▀ ▀███▄ ▀▄▀▄▄ ▄▀▄█████"
  22. echo "████▀▄▄█ ▄▀▄▀ ▄▀▀▀▄▀▄▀ ▄▀▄ ▄▀ ▄▀█ ▀████"
  23. echo "████ █ █ █▄▀ █▄█▀ ▄▄███▀▀▀▄█▀▄ ▀ ▀▄█████"
  24. echo "████▄███▄█▄▄▀▄ █▄█▄▄▄▄▀▀▄█▀▀ ▄▄▄ ▀█ ████"
  25. echo "████ ▄▄▄▄▄ █▄▀█ ▄█▀▄ █▀█▄ ▀ █▄█ ▀▄▀████"
  26. echo "████ █ █ █ █▄▀▀▀▄▄▄▀▀▀▀▀▀ ▄▄ ▀█ ████"
  27. echo "████ █▄▄▄█ █ ▀█▀ ▄▄▄▄ ▀█ ▀▀▄▀ ▀▀ ▀██████"
  28. echo "████▄▄▄▄▄▄▄█▄▄██▄█▄▄█▄██▄██▄▄█▄▄█▄█▄█████"
  29. echo "█████████████████████████████████████████"
  30. echo "█████████████████████████████████████████"
  31. echo
  32. echo "微信扫描上方二维码加入雷池项目讨论组"
  33. }
  34. command_exists() {
  35. command -v "$1" 2>&1
  36. }
  37. space_left() {
  38. dir="$1"
  39. while [ ! -d "$dir" ]; do
  40. dir=`dirname "$dir"`;
  41. done
  42. echo `df -h "$dir" --output='avail' | tail -n 1`
  43. }
  44. start_docker() {
  45. systemctl start docker && systemctl enable docker
  46. }
  47. confirm() {
  48. echo -e -n "\033[34m[SafeLine] $* \033[1;36m(Y/n)\033[0m"
  49. read -n 1 -s opt
  50. [[ "$opt" == $'\n' ]] || echo
  51. case "$opt" in
  52. 'y' | 'Y' ) return 0;;
  53. 'n' | 'N' ) return 1;;
  54. *) confirm "$1";;
  55. esac
  56. }
  57. info() {
  58. echo -e "\033[37m[SafeLine] $*\033[0m"
  59. }
  60. warning() {
  61. echo -e "\033[33m[SafeLine] $*\033[0m"
  62. }
  63. abort() {
  64. qrcode
  65. echo -e "\033[31m[SafeLine] $*\033[0m"
  66. exit 1
  67. }
  68. trap 'onexit' INT
  69. onexit() {
  70. echo
  71. abort "用户手动结束安装"
  72. }
  73. # CPU ssse3 指令集检查
  74. support_ssse3=1
  75. lscpu | grep ssse3 > /dev/null 2>&1
  76. if [ $? -ne "0" ]; then
  77. echo "not found info in lscpu"
  78. support_ssse3=0
  79. fi
  80. cat /proc/cpuinfo | grep ssse3 > /dev/null 2>&1
  81. if [ $support_ssse3 -eq "0" -a $? -ne "0" ]; then
  82. abort "雷池需要运行在支持 ssse3 指令集的 CPU 上,虚拟机请自行配置开启 CPU ssse3 指令集支持"
  83. fi
  84. safeline_path='/data/safeline'
  85. if [ -z "$BASH" ]; then
  86. abort "请用 bash 执行本脚本,请参考最新的官方技术文档 https://waf-ce.chaitin.cn/"
  87. fi
  88. if [ ! -t 0 ]; then
  89. abort "STDIN 不是标准的输入设备,请参考最新的官方技术文档 https://waf-ce.chaitin.cn/"
  90. fi
  91. if [ "$#" -ne "0" ]; then
  92. abort "当前脚本无需任何参数,请参考最新的官方技术文档 https://waf-ce.chaitin.cn/"
  93. fi
  94. if [ "$EUID" -ne "0" ]; then
  95. abort "请以 root 权限运行"
  96. fi
  97. info "脚本调用方式确认正常"
  98. if [ -z `command_exists docker` ]; then
  99. warning "缺少 Docker 环境"
  100. if confirm "是否需要自动安装 Docker"; then
  101. curl -sSLk https://get.docker.com/ | bash
  102. if [ $? -ne "0" ]; then
  103. abort "Docker 安装失败"
  104. fi
  105. info "Docker 安装完成"
  106. else
  107. abort "中止安装"
  108. fi
  109. fi
  110. info "发现 Docker 环境: '`command -v docker`'"
  111. start_docker
  112. docker version > /dev/null 2>&1
  113. if [ $? -ne "0" ]; then
  114. abort "Docker 服务工作异常"
  115. fi
  116. info "Docker 工作状态正常"
  117. compose_command="docker compose"
  118. if $compose_command version; then
  119. info "发现 Docker Compose Plugin"
  120. else
  121. warning "未发现 Docker Compose Plugin"
  122. compose_command="docker-compose"
  123. if [ -z `command_exists "docker-compose"` ]; then
  124. warning "未发现 docker-compose 组件"
  125. if confirm "是否需要自动安装 Docker Compose Plugin"; then
  126. curl -sSLk https://get.docker.com/ | bash
  127. if [ $? -ne "0" ]; then
  128. abort "Docker Compose Plugin 安装失败"
  129. fi
  130. info "Docker Compose Plugin 安装完成"
  131. compose_command="docker compose"
  132. else
  133. abort "中止安装"
  134. fi
  135. else
  136. info "发现 docker-compose 组件: '`command -v docker-compose`'"
  137. fi
  138. fi
  139. while true; do
  140. echo -e -n "\033[34m[SafeLine] 雷池安装目录 (留空则为 '$safeline_path'): \033[0m"
  141. read input_path
  142. [[ -z "$input_path" ]] && input_path=$safeline_path
  143. if [[ ! $input_path == /* ]]; then
  144. warning "'$input_path' 不是合法的绝对路径"
  145. continue
  146. fi
  147. if [ -f "$input_path" ] || [ -d "$input_path" ]; then
  148. warning "'$input_path' 路径已经存在,请换一个"
  149. continue
  150. fi
  151. safeline_path=$input_path
  152. if confirm "目录 '$safeline_path' 当前剩余存储空间为 `space_left \"$safeline_path\"` ,雷池至少需要 5G,是否确定"; then
  153. break
  154. fi
  155. done
  156. mkdir -p "$safeline_path"
  157. if [ $? -ne "0" ]; then
  158. abort "创建安装目录 '$safeline_path' 失败"
  159. fi
  160. info "创建安装目录 '$safeline_path' 成功"
  161. cd "$safeline_path"
  162. curl -sS -k "https://waf-ce.chaitin.cn/release/beta/compose.yaml" -o compose.yaml
  163. if [ $? -ne "0" ]; then
  164. abort "下载 compose.yaml 脚本失败"
  165. fi
  166. info "下载 compose.yaml 脚本成功"
  167. touch ".env"
  168. if [ $? -ne "0" ]; then
  169. abort "创建 .env 脚本失败"
  170. fi
  171. info "创建 .env 脚本成功"
  172. echo "SAFELINE_DIR=$safeline_path" >> .env
  173. echo "IMAGE_TAG=beta" >> .env
  174. echo "MGT_PORT=9443" >> .env
  175. echo "POSTGRES_PASSWORD=$(LC_ALL=C tr -dc A-Za-z0-9 </dev/urandom | head -c 32)" >> .env
  176. echo "REDIS_PASSWORD=$(LC_ALL=C tr -dc A-Za-z0-9 </dev/urandom | head -c 32)" >> .env
  177. echo "SUBNET_PREFIX=172.22.222" >> .env
  178. info "即将开始下载 Docker 镜像"
  179. $compose_command up -d
  180. if [ $? -ne "0" ]; then
  181. abort "启动 Docker 容器失败"
  182. fi
  183. qrcode
  184. warning "雷池 WAF 社区版安装成功,请访问以下地址访问控制台"
  185. warning "https://0.0.0.0:9443/"