install_debian.sh 10.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371
  1. #!/usr/bin/env bash
  2. set -euo pipefail
  3. timestamp() {
  4. date '+%Y-%m-%d %H:%M:%S'
  5. }
  6. log() {
  7. printf '[%s] %s\n' "$(timestamp)" "$*"
  8. }
  9. log_err() {
  10. printf '[%s] %s\n' "$(timestamp)" "$*" >&2
  11. }
  12. SERVICE_NAME="vmess-domain-rotator"
  13. RUN_USER=""
  14. RUN_GROUP=""
  15. RUN_USER_SET="0"
  16. RUN_GROUP_SET="0"
  17. RUN_HOME=""
  18. INTERVAL="30min"
  19. INSTALL_DEPS="1"
  20. CONFIG_PATH=""
  21. GIT_PUSH_ENABLED="1"
  22. GIT_PUSH_REMOTE="origin"
  23. GIT_HTTP_USERNAME="git"
  24. GIT_HTTP_TOKEN=""
  25. GIT_HTTP_TOKEN_FILE=""
  26. GIT_USE_CREDENTIAL_STORE="1"
  27. GIT_CREDENTIALS_FILE=""
  28. usage() {
  29. cat <<'EOF'
  30. Usage: sudo bash scripts/install_debian.sh [options]
  31. Default behavior:
  32. - Uses current git repository directory as working directory (in-place mode)
  33. - Uses the user executing sudo as service user
  34. - Enables git push after runtime-state commits
  35. Options:
  36. --user <name> Service user (default: current sudo user)
  37. --group <name> Service group (default: current sudo user's group)
  38. --interval <value> Timer interval, e.g. 1h/30min (default: 30min)
  39. --config <path> Config file path (default: <repo>/config.server.json)
  40. --git-push <0|1> Enable/disable push to remote (default: 1)
  41. --git-push-remote <name> Remote name for push (default: origin)
  42. --git-http-username <u> Username for HTTPS auth (default: git)
  43. --git-http-token <t> HTTPS token for non-interactive push
  44. --git-http-token-file <f> Read HTTPS token from file
  45. --git-use-credential-store <0|1> Use git credential.helper store (default: 1)
  46. --git-credentials-file <f> Custom credentials file for helper store
  47. --no-install-deps Skip apt dependency install
  48. -h, --help Show help
  49. Examples:
  50. sudo bash scripts/install_debian.sh
  51. sudo bash scripts/install_debian.sh --config /opt/vmess-domain-rotator/config.server.json
  52. sudo bash scripts/install_debian.sh --interval 10min
  53. sudo bash scripts/install_debian.sh --git-push 0
  54. sudo bash scripts/install_debian.sh --git-http-username aurora --git-http-token-file /root/.config/vmess-token
  55. sudo bash scripts/install_debian.sh --git-use-credential-store 1 --git-credentials-file /home/aurora/.git-credentials
  56. EOF
  57. }
  58. run_as_service_user() {
  59. runuser -u "$RUN_USER" -- env HOME="$RUN_HOME" "$@"
  60. }
  61. while [[ $# -gt 0 ]]; do
  62. case "$1" in
  63. --user)
  64. RUN_USER="$2"
  65. RUN_USER_SET="1"
  66. shift 2
  67. ;;
  68. --group)
  69. RUN_GROUP="$2"
  70. RUN_GROUP_SET="1"
  71. shift 2
  72. ;;
  73. --interval)
  74. INTERVAL="$2"
  75. shift 2
  76. ;;
  77. --config)
  78. CONFIG_PATH="$2"
  79. shift 2
  80. ;;
  81. --git-push)
  82. GIT_PUSH_ENABLED="$2"
  83. shift 2
  84. ;;
  85. --git-push-remote)
  86. GIT_PUSH_REMOTE="$2"
  87. shift 2
  88. ;;
  89. --git-http-username)
  90. GIT_HTTP_USERNAME="$2"
  91. shift 2
  92. ;;
  93. --git-http-token)
  94. GIT_HTTP_TOKEN="$2"
  95. shift 2
  96. ;;
  97. --git-http-token-file)
  98. GIT_HTTP_TOKEN_FILE="$2"
  99. shift 2
  100. ;;
  101. --git-use-credential-store)
  102. GIT_USE_CREDENTIAL_STORE="$2"
  103. shift 2
  104. ;;
  105. --git-credentials-file)
  106. GIT_CREDENTIALS_FILE="$2"
  107. shift 2
  108. ;;
  109. --no-install-deps)
  110. INSTALL_DEPS="0"
  111. shift
  112. ;;
  113. -h|--help)
  114. usage
  115. exit 0
  116. ;;
  117. *)
  118. log_err "Unknown option: $1"
  119. usage
  120. exit 1
  121. ;;
  122. esac
  123. done
  124. if [[ "$(id -u)" -ne 0 ]]; then
  125. log_err "Please run as root (use sudo)."
  126. exit 1
  127. fi
  128. if ! command -v runuser >/dev/null 2>&1; then
  129. log_err "Error: runuser is required on Debian for configuring service-user git credentials"
  130. exit 1
  131. fi
  132. SOURCE_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
  133. if ! git -C "$SOURCE_DIR" rev-parse --is-inside-work-tree >/dev/null 2>&1; then
  134. log_err "Error: Current directory is not a git repository."
  135. log_err "This script must be run from within a git repository."
  136. exit 1
  137. fi
  138. APP_DIR="$SOURCE_DIR"
  139. if [[ -z "$CONFIG_PATH" ]]; then
  140. CONFIG_PATH="${APP_DIR}/config.server.json"
  141. elif [[ "$CONFIG_PATH" != /* ]]; then
  142. CONFIG_PATH="${APP_DIR}/${CONFIG_PATH}"
  143. fi
  144. if [[ ! -r "$CONFIG_PATH" ]]; then
  145. log_err "Error: config file not found or unreadable: $CONFIG_PATH"
  146. exit 1
  147. fi
  148. if [[ -n "${SUDO_USER:-}" ]] && [[ "$RUN_USER_SET" != "1" ]]; then
  149. RUN_USER="$SUDO_USER"
  150. fi
  151. if [[ -n "${SUDO_USER:-}" ]] && [[ "$RUN_GROUP_SET" != "1" ]]; then
  152. RUN_GROUP="$(id -gn "$SUDO_USER")"
  153. fi
  154. if [[ -z "$RUN_USER" ]]; then
  155. log_err "Error: Could not determine service user. Please run with sudo or specify --user"
  156. exit 1
  157. fi
  158. if [[ -z "$RUN_GROUP" ]]; then
  159. log_err "Error: Could not determine service group. Please run with sudo or specify --group"
  160. exit 1
  161. fi
  162. if [[ ! "$GIT_PUSH_ENABLED" =~ ^[01]$ ]]; then
  163. log_err "Error: --git-push must be 0 or 1"
  164. exit 1
  165. fi
  166. if [[ ! "$GIT_USE_CREDENTIAL_STORE" =~ ^[01]$ ]]; then
  167. log_err "Error: --git-use-credential-store must be 0 or 1"
  168. exit 1
  169. fi
  170. if [[ -z "$GIT_PUSH_REMOTE" ]]; then
  171. log_err "Error: --git-push-remote cannot be empty"
  172. exit 1
  173. fi
  174. if [[ -n "$GIT_HTTP_TOKEN" ]] && [[ -n "$GIT_HTTP_TOKEN_FILE" ]]; then
  175. log_err "Error: provide either --git-http-token or --git-http-token-file, not both"
  176. exit 1
  177. fi
  178. if [[ -n "$GIT_HTTP_TOKEN_FILE" ]] && [[ ! -r "$GIT_HTTP_TOKEN_FILE" ]]; then
  179. log_err "Error: cannot read token file: $GIT_HTTP_TOKEN_FILE"
  180. exit 1
  181. fi
  182. if [[ -n "$GIT_HTTP_TOKEN_FILE" ]]; then
  183. GIT_HTTP_TOKEN="$(tr -d '\r\n' < "$GIT_HTTP_TOKEN_FILE")"
  184. fi
  185. if [[ -n "$GIT_HTTP_TOKEN" ]] && [[ -z "$GIT_HTTP_USERNAME" ]]; then
  186. log_err "Error: --git-http-username cannot be empty when token is set"
  187. exit 1
  188. fi
  189. if [[ -n "$GIT_HTTP_TOKEN" ]] && [[ "$RUN_USER" == "root" ]]; then
  190. log_err "Error: refusing to store git token for root service user"
  191. log_err "Use --user <non-root> or disable push with --git-push 0"
  192. exit 1
  193. fi
  194. RUN_HOME="$(getent passwd "$RUN_USER" | cut -d: -f6)"
  195. if [[ -z "$RUN_HOME" ]]; then
  196. log_err "Error: could not determine home directory for user: $RUN_USER"
  197. exit 1
  198. fi
  199. if [[ "$INSTALL_DEPS" == "1" ]]; then
  200. export DEBIAN_FRONTEND=noninteractive
  201. apt-get update -y
  202. apt-get install -y python3 ca-certificates git
  203. fi
  204. RUNTIME_DIR="$(/usr/bin/python3 "${APP_DIR}/scripts/domain_updater.py" --config "$CONFIG_PATH" --print-output-settings | /usr/bin/python3 -c 'import json,sys; print(json.load(sys.stdin)["runtime_dir"])')"
  205. mkdir -p "$RUNTIME_DIR"
  206. chmod +x "$APP_DIR/scripts/run_update_and_commit.sh" || true
  207. chown -R "$RUN_USER:$RUN_GROUP" "$RUNTIME_DIR"
  208. SERVICE_STATE_DIR="/var/lib/${SERVICE_NAME}"
  209. ENV_FILE="/etc/${SERVICE_NAME}.env"
  210. TOKEN_FILE=""
  211. REMOTE_URL=""
  212. AUTH_MODE="header"
  213. if [[ "$GIT_USE_CREDENTIAL_STORE" == "1" ]]; then
  214. AUTH_MODE="credential-helper-store"
  215. fi
  216. mkdir -p "$SERVICE_STATE_DIR"
  217. chown "$RUN_USER:$RUN_GROUP" "$SERVICE_STATE_DIR"
  218. chmod 750 "$SERVICE_STATE_DIR"
  219. if [[ "$GIT_PUSH_ENABLED" == "1" ]]; then
  220. REMOTE_URL="$(git -C "$APP_DIR" remote get-url "$GIT_PUSH_REMOTE" 2>/dev/null || true)"
  221. if [[ -z "$REMOTE_URL" ]]; then
  222. log_err "Warning: remote '$GIT_PUSH_REMOTE' not found now. Push may fail until remote is configured."
  223. fi
  224. fi
  225. if [[ -n "$GIT_HTTP_TOKEN" ]]; then
  226. if [[ "$GIT_USE_CREDENTIAL_STORE" == "1" ]]; then
  227. if [[ "$REMOTE_URL" =~ ^https:// ]]; then
  228. helper_value="store"
  229. if [[ -n "$GIT_CREDENTIALS_FILE" ]]; then
  230. helper_value="store --file ${GIT_CREDENTIALS_FILE}"
  231. mkdir -p "$(dirname "$GIT_CREDENTIALS_FILE")"
  232. touch "$GIT_CREDENTIALS_FILE"
  233. chown "$RUN_USER:$RUN_GROUP" "$GIT_CREDENTIALS_FILE"
  234. chmod 600 "$GIT_CREDENTIALS_FILE"
  235. fi
  236. run_as_service_user git config --global credential.helper "$helper_value"
  237. printf 'url=%s\nusername=%s\npassword=%s\n\n' "$REMOTE_URL" "$GIT_HTTP_USERNAME" "$GIT_HTTP_TOKEN" | run_as_service_user git credential approve
  238. else
  239. log_err "Warning: token provided but remote is not HTTPS; credential.helper store setup skipped."
  240. log_err "Warning: fallback to header-token-file auth mode for this install."
  241. GIT_USE_CREDENTIAL_STORE="0"
  242. fi
  243. fi
  244. if [[ "$GIT_USE_CREDENTIAL_STORE" != "1" ]]; then
  245. TOKEN_FILE="${SERVICE_STATE_DIR}/git_http_token"
  246. printf '%s\n' "$GIT_HTTP_TOKEN" >"$TOKEN_FILE"
  247. chown "$RUN_USER:$RUN_GROUP" "$TOKEN_FILE"
  248. chmod 600 "$TOKEN_FILE"
  249. AUTH_MODE="header-token-file"
  250. fi
  251. fi
  252. run_as_service_user git config --global --add safe.directory "$APP_DIR" || true
  253. cat >"$ENV_FILE" <<EOF
  254. GIT_PUSH_ENABLED=${GIT_PUSH_ENABLED}
  255. GIT_PUSH_REQUIRED=${GIT_PUSH_ENABLED}
  256. GIT_PUSH_REMOTE=${GIT_PUSH_REMOTE}
  257. GIT_RUNTIME_BRANCH=runtime-state
  258. GIT_HTTP_USERNAME=${GIT_HTTP_USERNAME}
  259. HOME=${RUN_HOME}
  260. EOF
  261. if [[ "$GIT_USE_CREDENTIAL_STORE" == "1" ]]; then
  262. if [[ -n "$GIT_CREDENTIALS_FILE" ]]; then
  263. printf 'GIT_CREDENTIAL_HELPER=store --file %s\n' "$GIT_CREDENTIALS_FILE" >>"$ENV_FILE"
  264. else
  265. printf 'GIT_CREDENTIAL_HELPER=store\n' >>"$ENV_FILE"
  266. fi
  267. fi
  268. if [[ -n "$TOKEN_FILE" ]]; then
  269. printf 'GIT_HTTP_TOKEN_FILE=%s\n' "$TOKEN_FILE" >>"$ENV_FILE"
  270. fi
  271. chown root:root "$ENV_FILE"
  272. chmod 600 "$ENV_FILE"
  273. cat >"/etc/systemd/system/${SERVICE_NAME}.service" <<EOF
  274. [Unit]
  275. Description=VMess Domain Rotator updater
  276. After=network-online.target
  277. Wants=network-online.target
  278. [Service]
  279. Type=oneshot
  280. User=${RUN_USER}
  281. Group=${RUN_GROUP}
  282. WorkingDirectory=${APP_DIR}
  283. EnvironmentFile=-${ENV_FILE}
  284. UMask=0077
  285. ExecStart=/bin/bash ${APP_DIR}/scripts/run_update_and_commit.sh ${CONFIG_PATH}
  286. EOF
  287. cat >"/etc/systemd/system/${SERVICE_NAME}.timer" <<EOF
  288. [Unit]
  289. Description=Run VMess Domain Rotator every ${INTERVAL}
  290. [Timer]
  291. OnBootSec=2min
  292. OnUnitActiveSec=${INTERVAL}
  293. AccuracySec=30s
  294. Unit=${SERVICE_NAME}.service
  295. Persistent=true
  296. [Install]
  297. WantedBy=timers.target
  298. EOF
  299. systemctl daemon-reload
  300. systemctl enable --now "${SERVICE_NAME}.timer"
  301. systemctl start "${SERVICE_NAME}.service"
  302. log ""
  303. log "✓ Installation complete!"
  304. log ""
  305. log "Configuration:"
  306. log " Working directory: ${APP_DIR}"
  307. log " Config path: ${CONFIG_PATH}"
  308. log " Service user: ${RUN_USER}"
  309. log " Service group: ${RUN_GROUP}"
  310. log " Timer interval: ${INTERVAL}"
  311. log " Push enabled: ${GIT_PUSH_ENABLED}"
  312. log " Push remote: ${GIT_PUSH_REMOTE}"
  313. log " Auth mode: ${AUTH_MODE}"
  314. log " Env file: ${ENV_FILE}"
  315. log ""
  316. log "Commands:"
  317. log " Check status: systemctl status ${SERVICE_NAME}.timer"
  318. log " View logs: journalctl -u ${SERVICE_NAME}.service -n 50 --no-pager"
  319. log " Manual run: sudo systemctl start ${SERVICE_NAME}.service"
  320. log " Force commit: sudo -u ${RUN_USER} /bin/bash ${APP_DIR}/scripts/run_update_and_commit.sh --force-commit ${CONFIG_PATH}"
  321. log ""