diff --git a/tools/firewall-routing.sh b/tools/firewall-routing.sh new file mode 100755 index 0000000..5acee63 --- /dev/null +++ b/tools/firewall-routing.sh @@ -0,0 +1,51 @@ +#!/bin/bash +# ===================================================================== +# VM LOCAL FIREWALL & PORT REDIRECTION SCRIPT +# VM IP: 172.16.9.10 | Internal Interface: eth0 (or similar) +# Redirects inbound 80/443 to non-root Caddy on 8080/8443 +# ===================================================================== + +# 1. CLEAN SLATE +# Flush all rules and delete custom chains across filter and NAT tables +iptables -P INPUT ACCEPT +iptables -P FORWARD ACCEPT +iptables -P OUTPUT ACCEPT +iptables -t nat -F +iptables -F +iptables -X +iptables -t nat -X + +# 2. LOCAL PORT REDIRECTION (Caddy Non-Root Helper) +# --------------------------------------------------------------------- +# A. Inbound traffic coming from outside the VM (e.g., forwarded from Proxmox) +iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 8080 +iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 8443 + +# B. Local traffic generated inside the VM aimed strictly at localhost/127.0.0.1 +# Note: By specifying '-o lo', you leave your outbound internet (GitHub, Google) untouched! +iptables -t nat -A OUTPUT -o lo -p tcp --dport 80 -j REDIRECT --to-ports 8080 +iptables -t nat -A OUTPUT -o lo -p tcp --dport 443 -j REDIRECT --to-ports 8443 + +# 3. VM INPUT FIREWALL RULES +# --------------------------------------------------------------------- +# Allow everything on loopback +iptables -A INPUT -i lo -j ACCEPT + +# Allow established connections (allows responses to your outbound traffic like curl) +iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT + +# Allow SSH (Port 22) - Important for your Proxmox port forward (22910 -> 22) +iptables -A INPUT -p tcp --dport 22 -j ACCEPT + +# Allow the actual redirected Caddy ports from outside (just in case) +iptables -A INPUT -p tcp --dport 8080 -j ACCEPT +iptables -A INPUT -p tcp --dport 8443 -j ACCEPT + +# Allow alternative app ports (like the 8000 you have forwarded in Proxmox) +iptables -A INPUT -p tcp --dport 8000 -j ACCEPT + +# 4. GLOBAL SECURITY DROP RULE +# Drop all other unsolicited inbound traffic targeting this VM +iptables -A INPUT -j DROP + +echo "VM Firewall and Caddy Redirection Applied Successfully." diff --git a/tools/nextwks.sh b/tools/nextwks.sh index 7559249..1e0b33c 100755 --- a/tools/nextwks.sh +++ b/tools/nextwks.sh @@ -26,10 +26,10 @@ maybe_sudo() { if [ "$(id -u)" -eq 0 ]; then "$@"; else sudo "$@"; fi } -# --- Load existing env (if any) --- -if [ -f "$BACKUP_DIR/.env" ]; then +# --- Load existing env (if any), skip if unreadable --- +if [ -r "$BACKUP_DIR/.env" ]; then set -a; source "$BACKUP_DIR/.env"; set +a -elif [ -f "$TARGET_DIR/.env" ]; then +elif [ -r "$TARGET_DIR/.env" ]; then set -a; source "$TARGET_DIR/.env"; set +a fi DOMAIN="${DOMAIN:-nextwks.eu}" @@ -66,24 +66,6 @@ if [ "$MODE" = "install" ]; then maybe_sudo podman rm caddy authelia launcher 2>/dev/null || true maybe_sudo podman network rm "$NETWORK_NAME" 2>/dev/null || true - # Set up iptables: redirect 80→8080, 443→8443 for rootless Caddy - echo "[*] Setting up iptables port redirects (80→8080, 443→8443)..." - maybe_sudo iptables -t nat -C PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 2>/dev/null || \ - maybe_sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 - maybe_sudo iptables -t nat -C PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 8443 2>/dev/null || \ - maybe_sudo iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 8443 - maybe_sudo iptables -t nat -C OUTPUT -p tcp --dport 80 -j REDIRECT --to-port 8080 2>/dev/null || \ - maybe_sudo iptables -t nat -A OUTPUT -p tcp --dport 80 -j REDIRECT --to-port 8080 - maybe_sudo iptables -t nat -C OUTPUT -p tcp --dport 443 -j REDIRECT --to-port 8443 2>/dev/null || \ - maybe_sudo iptables -t nat -A OUTPUT -p tcp --dport 443 -j REDIRECT --to-port 8443 - # Persist across reboots - if command -v netfilter-persistent &>/dev/null; then - maybe_sudo netfilter-persistent save 2>/dev/null || true - else - maybe_sudo mkdir -p /etc/iptables - maybe_sudo sh -c 'iptables-save > /etc/iptables/rules.v4' - fi - echo "" echo "--- NextWorkspace Configuration ---" read -p "Domain [nextwks.eu]: " input; DOMAIN="${input:-$DOMAIN}" @@ -147,14 +129,29 @@ if [ "$MODE" = "install" ]; then fi # ============================================================ -# 3. BUILD static binary +# 3. FIREWALL SETUP (install mode only) +# ============================================================ +if [ "$MODE" = "install" ]; then + echo "[*] Applying firewall and port redirects (80→8080, 443→8443)..." + maybe_sudo bash "$BUILD_DIR/tools/firewall-routing.sh" + # Persist across reboots + if command -v netfilter-persistent &>/dev/null; then + maybe_sudo netfilter-persistent save 2>/dev/null || true + else + maybe_sudo mkdir -p /etc/iptables + maybe_sudo sh -c 'iptables-save > /etc/iptables/rules.v4' + fi +fi + +# ============================================================ +# 4. BUILD static binary # ============================================================ echo "[*] Building static binary..." export PATH=$PATH:/usr/local/go/bin CGO_ENABLED=0 go build -o nextworkspace . # ============================================================ -# 4. CREATE target & backup directories (as root) +# 5. CREATE target & backup directories (as root) # ============================================================ maybe_sudo mkdir -p "$TARGET_DIR/config/caddy" "$TARGET_DIR/config/authelia" \ "$TARGET_DIR/data/caddy" "$TARGET_DIR/data/authelia" \ @@ -163,7 +160,7 @@ maybe_sudo mkdir -p "$TARGET_DIR/config/caddy" "$TARGET_DIR/config/authelia" \ "$BACKUP_DIR" # ============================================================ -# 5. TEARDOWN (destroy mode only — wipes target dir) +# 6. TEARDOWN (destroy mode only — wipes target dir) # ============================================================ if [ "$MODE" = "destroy" ]; then echo "[*] Full teardown..." @@ -180,7 +177,7 @@ if [ "$MODE" = "destroy" ]; then fi # ============================================================ -# 6. COPY artifacts to target (as root) +# 7. COPY artifacts to target (as root) # ============================================================ echo "[*] Copying artifacts..." maybe_sudo cp nextworkspace "$TARGET_DIR/nextworkspace" @@ -202,7 +199,7 @@ if [ -f "$BACKUP_DIR/.env" ]; then fi # ============================================================ -# 7. GENERATE config files with placeholder substitution +# 8. GENERATE config files with placeholder substitution # Write to /tmp first, then sudo cp to target # ============================================================ GEN_DIR=$(mktemp -d) @@ -251,7 +248,7 @@ if [ "$MODE" != "update" ]; then fi # ============================================================ -# 8. FIX OWNERSHIP — all files in TARGET_DIR/BACKUP_DIR to user +# 9. FIX OWNERSHIP — all files in TARGET_DIR/BACKUP_DIR to user # ============================================================ RUN_USER="${SUDO_USER:-${USER}}" echo "[*] Setting file ownership to $RUN_USER..." @@ -259,7 +256,7 @@ maybe_sudo chown -R "$RUN_USER:" "$TARGET_DIR" 2>/dev/null || true maybe_sudo chown -R "$RUN_USER:" "$BACKUP_DIR" 2>/dev/null || true # ============================================================ -# 9. DEPLOY stack (rootless podman — no sudo!) +# 10. DEPLOY stack (rootless podman — no sudo!) # ============================================================ echo "[*] Deploying containers on $NETWORK_NAME..." @@ -282,7 +279,7 @@ sleep 1 podman-compose -f "$TARGET_DIR/compose/stack.yaml" up -d 2>&1 || echo "[WARN] Stack deploy had issues" # ============================================================ -# 10. HEALTH CHECK +# 11. HEALTH CHECK # ============================================================ echo "[*] Running health check..." for i in $(seq 1 $HEALTH_CHECK_RETRIES); do