This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
rustdesk-server/userdata/bootstrap.sh

71 lines
2.7 KiB
Bash
Raw Normal View History

#!/bin/bash
# RustDesk Server Pro bootstrap (Amazon Linux 2023, ARM64).
# Rendered by lib/rustdesk-server-stack.ts; __RUSTDESK_IMAGE_TAG__ is replaced
# at synth time. Idempotent: safe to re-run on instance replacement.
set -euxo pipefail
RUSTDESK_DATA=/var/lib/rustdesk
RUSTDESK_IMAGE="rustdesk/rustdesk-server-pro:__RUSTDESK_IMAGE_TAG__"
# ── Persistent data volume (attached at /dev/xvdf via CfnVolumeAttachment;
# surfaces as an nvme device on Nitro). Wait for it, then mount WITHOUT
# reformatting if it already holds a filesystem (preserves the server key). ──
until lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | grep -q .; do
echo 'Waiting for data volume...'
sleep 5
done
DATA_DEVICE=/dev/$(lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | head -1)
if ! blkid "$DATA_DEVICE"; then
mkfs.ext4 -L rustdesk-data "$DATA_DEVICE"
fi
mkdir -p "$RUSTDESK_DATA"
grep -q 'LABEL=rustdesk-data' /etc/fstab || \
echo "LABEL=rustdesk-data $RUSTDESK_DATA ext4 defaults,nofail 0 2" >> /etc/fstab
mount -a
# Restrict the data dir so the server private key (id_ed25519, created inside the
# container at /root) is not readable by any non-root host user even if the
# container writes it world-readable.
chmod 700 "$RUSTDESK_DATA"
# ── Docker + compose plugin ──────────────────────────────────────────
dnf install -y docker
systemctl enable --now docker
DOCKER_CLI_PLUGINS=/usr/local/lib/docker/cli-plugins
mkdir -p "$DOCKER_CLI_PLUGINS"
curl -fsSL "https://github.com/docker/compose/releases/download/v2.29.7/docker-compose-linux-aarch64" \
-o "$DOCKER_CLI_PLUGINS/docker-compose"
chmod +x "$DOCKER_CLI_PLUGINS/docker-compose"
# ── Compose definition (host networking; SG is the access control) ───
mkdir -p /opt/rustdesk
cat > /opt/rustdesk/docker-compose.yml << COMPOSE
services:
hbbs:
container_name: hbbs
image: ${RUSTDESK_IMAGE}
command: hbbs
network_mode: host
volumes:
- ${RUSTDESK_DATA}:/root
depends_on:
- hbbr
restart: unless-stopped
hbbr:
container_name: hbbr
image: ${RUSTDESK_IMAGE}
command: hbbr
network_mode: host
volumes:
- ${RUSTDESK_DATA}:/root
restart: unless-stopped
COMPOSE
cd /opt/rustdesk
docker compose pull
docker compose up -d
# Activate the Pro license and configure users in the web console at
# http://rustdesk.seahaven.com:21114 after first boot. The generated key pair
# lives at $RUSTDESK_DATA/id_ed25519{,.pub} -- mirror it into the
# rustdesk/server-key-pair secret (see RUNBOOK).