add tools/firewall-routing.sh, fix .env Permission denied, apply firewall from cloned repo
This commit is contained in:
parent
e92382266f
commit
b060e23a1d
2 changed files with 77 additions and 29 deletions
51
tools/firewall-routing.sh
Executable file
51
tools/firewall-routing.sh
Executable file
|
|
@ -0,0 +1,51 @@
|
||||||
|
#!/bin/bash
|
||||||
|
# =====================================================================
|
||||||
|
# VM LOCAL FIREWALL & PORT REDIRECTION SCRIPT
|
||||||
|
# VM IP: 172.16.9.10 | Internal Interface: eth0 (or similar)
|
||||||
|
# Redirects inbound 80/443 to non-root Caddy on 8080/8443
|
||||||
|
# =====================================================================
|
||||||
|
|
||||||
|
# 1. CLEAN SLATE
|
||||||
|
# Flush all rules and delete custom chains across filter and NAT tables
|
||||||
|
iptables -P INPUT ACCEPT
|
||||||
|
iptables -P FORWARD ACCEPT
|
||||||
|
iptables -P OUTPUT ACCEPT
|
||||||
|
iptables -t nat -F
|
||||||
|
iptables -F
|
||||||
|
iptables -X
|
||||||
|
iptables -t nat -X
|
||||||
|
|
||||||
|
# 2. LOCAL PORT REDIRECTION (Caddy Non-Root Helper)
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
# A. Inbound traffic coming from outside the VM (e.g., forwarded from Proxmox)
|
||||||
|
iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 8080
|
||||||
|
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 8443
|
||||||
|
|
||||||
|
# B. Local traffic generated inside the VM aimed strictly at localhost/127.0.0.1
|
||||||
|
# Note: By specifying '-o lo', you leave your outbound internet (GitHub, Google) untouched!
|
||||||
|
iptables -t nat -A OUTPUT -o lo -p tcp --dport 80 -j REDIRECT --to-ports 8080
|
||||||
|
iptables -t nat -A OUTPUT -o lo -p tcp --dport 443 -j REDIRECT --to-ports 8443
|
||||||
|
|
||||||
|
# 3. VM INPUT FIREWALL RULES
|
||||||
|
# ---------------------------------------------------------------------
|
||||||
|
# Allow everything on loopback
|
||||||
|
iptables -A INPUT -i lo -j ACCEPT
|
||||||
|
|
||||||
|
# Allow established connections (allows responses to your outbound traffic like curl)
|
||||||
|
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||||
|
|
||||||
|
# Allow SSH (Port 22) - Important for your Proxmox port forward (22910 -> 22)
|
||||||
|
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
|
||||||
|
|
||||||
|
# Allow the actual redirected Caddy ports from outside (just in case)
|
||||||
|
iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
|
||||||
|
iptables -A INPUT -p tcp --dport 8443 -j ACCEPT
|
||||||
|
|
||||||
|
# Allow alternative app ports (like the 8000 you have forwarded in Proxmox)
|
||||||
|
iptables -A INPUT -p tcp --dport 8000 -j ACCEPT
|
||||||
|
|
||||||
|
# 4. GLOBAL SECURITY DROP RULE
|
||||||
|
# Drop all other unsolicited inbound traffic targeting this VM
|
||||||
|
iptables -A INPUT -j DROP
|
||||||
|
|
||||||
|
echo "VM Firewall and Caddy Redirection Applied Successfully."
|
||||||
|
|
@ -26,10 +26,10 @@ maybe_sudo() {
|
||||||
if [ "$(id -u)" -eq 0 ]; then "$@"; else sudo "$@"; fi
|
if [ "$(id -u)" -eq 0 ]; then "$@"; else sudo "$@"; fi
|
||||||
}
|
}
|
||||||
|
|
||||||
# --- Load existing env (if any) ---
|
# --- Load existing env (if any), skip if unreadable ---
|
||||||
if [ -f "$BACKUP_DIR/.env" ]; then
|
if [ -r "$BACKUP_DIR/.env" ]; then
|
||||||
set -a; source "$BACKUP_DIR/.env"; set +a
|
set -a; source "$BACKUP_DIR/.env"; set +a
|
||||||
elif [ -f "$TARGET_DIR/.env" ]; then
|
elif [ -r "$TARGET_DIR/.env" ]; then
|
||||||
set -a; source "$TARGET_DIR/.env"; set +a
|
set -a; source "$TARGET_DIR/.env"; set +a
|
||||||
fi
|
fi
|
||||||
DOMAIN="${DOMAIN:-nextwks.eu}"
|
DOMAIN="${DOMAIN:-nextwks.eu}"
|
||||||
|
|
@ -66,24 +66,6 @@ if [ "$MODE" = "install" ]; then
|
||||||
maybe_sudo podman rm caddy authelia launcher 2>/dev/null || true
|
maybe_sudo podman rm caddy authelia launcher 2>/dev/null || true
|
||||||
maybe_sudo podman network rm "$NETWORK_NAME" 2>/dev/null || true
|
maybe_sudo podman network rm "$NETWORK_NAME" 2>/dev/null || true
|
||||||
|
|
||||||
# Set up iptables: redirect 80→8080, 443→8443 for rootless Caddy
|
|
||||||
echo "[*] Setting up iptables port redirects (80→8080, 443→8443)..."
|
|
||||||
maybe_sudo iptables -t nat -C PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080 2>/dev/null || \
|
|
||||||
maybe_sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080
|
|
||||||
maybe_sudo iptables -t nat -C PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 8443 2>/dev/null || \
|
|
||||||
maybe_sudo iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 8443
|
|
||||||
maybe_sudo iptables -t nat -C OUTPUT -p tcp --dport 80 -j REDIRECT --to-port 8080 2>/dev/null || \
|
|
||||||
maybe_sudo iptables -t nat -A OUTPUT -p tcp --dport 80 -j REDIRECT --to-port 8080
|
|
||||||
maybe_sudo iptables -t nat -C OUTPUT -p tcp --dport 443 -j REDIRECT --to-port 8443 2>/dev/null || \
|
|
||||||
maybe_sudo iptables -t nat -A OUTPUT -p tcp --dport 443 -j REDIRECT --to-port 8443
|
|
||||||
# Persist across reboots
|
|
||||||
if command -v netfilter-persistent &>/dev/null; then
|
|
||||||
maybe_sudo netfilter-persistent save 2>/dev/null || true
|
|
||||||
else
|
|
||||||
maybe_sudo mkdir -p /etc/iptables
|
|
||||||
maybe_sudo sh -c 'iptables-save > /etc/iptables/rules.v4'
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "--- NextWorkspace Configuration ---"
|
echo "--- NextWorkspace Configuration ---"
|
||||||
read -p "Domain [nextwks.eu]: " input; DOMAIN="${input:-$DOMAIN}"
|
read -p "Domain [nextwks.eu]: " input; DOMAIN="${input:-$DOMAIN}"
|
||||||
|
|
@ -147,14 +129,29 @@ if [ "$MODE" = "install" ]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 3. BUILD static binary
|
# 3. FIREWALL SETUP (install mode only)
|
||||||
|
# ============================================================
|
||||||
|
if [ "$MODE" = "install" ]; then
|
||||||
|
echo "[*] Applying firewall and port redirects (80→8080, 443→8443)..."
|
||||||
|
maybe_sudo bash "$BUILD_DIR/tools/firewall-routing.sh"
|
||||||
|
# Persist across reboots
|
||||||
|
if command -v netfilter-persistent &>/dev/null; then
|
||||||
|
maybe_sudo netfilter-persistent save 2>/dev/null || true
|
||||||
|
else
|
||||||
|
maybe_sudo mkdir -p /etc/iptables
|
||||||
|
maybe_sudo sh -c 'iptables-save > /etc/iptables/rules.v4'
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# 4. BUILD static binary
|
||||||
# ============================================================
|
# ============================================================
|
||||||
echo "[*] Building static binary..."
|
echo "[*] Building static binary..."
|
||||||
export PATH=$PATH:/usr/local/go/bin
|
export PATH=$PATH:/usr/local/go/bin
|
||||||
CGO_ENABLED=0 go build -o nextworkspace .
|
CGO_ENABLED=0 go build -o nextworkspace .
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 4. CREATE target & backup directories (as root)
|
# 5. CREATE target & backup directories (as root)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
maybe_sudo mkdir -p "$TARGET_DIR/config/caddy" "$TARGET_DIR/config/authelia" \
|
maybe_sudo mkdir -p "$TARGET_DIR/config/caddy" "$TARGET_DIR/config/authelia" \
|
||||||
"$TARGET_DIR/data/caddy" "$TARGET_DIR/data/authelia" \
|
"$TARGET_DIR/data/caddy" "$TARGET_DIR/data/authelia" \
|
||||||
|
|
@ -163,7 +160,7 @@ maybe_sudo mkdir -p "$TARGET_DIR/config/caddy" "$TARGET_DIR/config/authelia" \
|
||||||
"$BACKUP_DIR"
|
"$BACKUP_DIR"
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 5. TEARDOWN (destroy mode only — wipes target dir)
|
# 6. TEARDOWN (destroy mode only — wipes target dir)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
if [ "$MODE" = "destroy" ]; then
|
if [ "$MODE" = "destroy" ]; then
|
||||||
echo "[*] Full teardown..."
|
echo "[*] Full teardown..."
|
||||||
|
|
@ -180,7 +177,7 @@ if [ "$MODE" = "destroy" ]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 6. COPY artifacts to target (as root)
|
# 7. COPY artifacts to target (as root)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
echo "[*] Copying artifacts..."
|
echo "[*] Copying artifacts..."
|
||||||
maybe_sudo cp nextworkspace "$TARGET_DIR/nextworkspace"
|
maybe_sudo cp nextworkspace "$TARGET_DIR/nextworkspace"
|
||||||
|
|
@ -202,7 +199,7 @@ if [ -f "$BACKUP_DIR/.env" ]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 7. GENERATE config files with placeholder substitution
|
# 8. GENERATE config files with placeholder substitution
|
||||||
# Write to /tmp first, then sudo cp to target
|
# Write to /tmp first, then sudo cp to target
|
||||||
# ============================================================
|
# ============================================================
|
||||||
GEN_DIR=$(mktemp -d)
|
GEN_DIR=$(mktemp -d)
|
||||||
|
|
@ -251,7 +248,7 @@ if [ "$MODE" != "update" ]; then
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 8. FIX OWNERSHIP — all files in TARGET_DIR/BACKUP_DIR to user
|
# 9. FIX OWNERSHIP — all files in TARGET_DIR/BACKUP_DIR to user
|
||||||
# ============================================================
|
# ============================================================
|
||||||
RUN_USER="${SUDO_USER:-${USER}}"
|
RUN_USER="${SUDO_USER:-${USER}}"
|
||||||
echo "[*] Setting file ownership to $RUN_USER..."
|
echo "[*] Setting file ownership to $RUN_USER..."
|
||||||
|
|
@ -259,7 +256,7 @@ maybe_sudo chown -R "$RUN_USER:" "$TARGET_DIR" 2>/dev/null || true
|
||||||
maybe_sudo chown -R "$RUN_USER:" "$BACKUP_DIR" 2>/dev/null || true
|
maybe_sudo chown -R "$RUN_USER:" "$BACKUP_DIR" 2>/dev/null || true
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 9. DEPLOY stack (rootless podman — no sudo!)
|
# 10. DEPLOY stack (rootless podman — no sudo!)
|
||||||
# ============================================================
|
# ============================================================
|
||||||
echo "[*] Deploying containers on $NETWORK_NAME..."
|
echo "[*] Deploying containers on $NETWORK_NAME..."
|
||||||
|
|
||||||
|
|
@ -282,7 +279,7 @@ sleep 1
|
||||||
podman-compose -f "$TARGET_DIR/compose/stack.yaml" up -d 2>&1 || echo "[WARN] Stack deploy had issues"
|
podman-compose -f "$TARGET_DIR/compose/stack.yaml" up -d 2>&1 || echo "[WARN] Stack deploy had issues"
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# 10. HEALTH CHECK
|
# 11. HEALTH CHECK
|
||||||
# ============================================================
|
# ============================================================
|
||||||
echo "[*] Running health check..."
|
echo "[*] Running health check..."
|
||||||
for i in $(seq 1 $HEALTH_CHECK_RETRIES); do
|
for i in $(seq 1 $HEALTH_CHECK_RETRIES); do
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue