71 lines
2.7 KiB
Bash
71 lines
2.7 KiB
Bash
|
|
#!/bin/bash
|
||
|
|
# RustDesk Server Pro bootstrap (Amazon Linux 2023, ARM64).
|
||
|
|
# Rendered by lib/rustdesk-server-stack.ts; __RUSTDESK_IMAGE_TAG__ is replaced
|
||
|
|
# at synth time. Idempotent: safe to re-run on instance replacement.
|
||
|
|
set -euxo pipefail
|
||
|
|
|
||
|
|
RUSTDESK_DATA=/var/lib/rustdesk
|
||
|
|
RUSTDESK_IMAGE="rustdesk/rustdesk-server-pro:__RUSTDESK_IMAGE_TAG__"
|
||
|
|
|
||
|
|
# ── Persistent data volume (attached at /dev/xvdf via CfnVolumeAttachment;
|
||
|
|
# surfaces as an nvme device on Nitro). Wait for it, then mount WITHOUT
|
||
|
|
# reformatting if it already holds a filesystem (preserves the server key). ──
|
||
|
|
until lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | grep -q .; do
|
||
|
|
echo 'Waiting for data volume...'
|
||
|
|
sleep 5
|
||
|
|
done
|
||
|
|
DATA_DEVICE=/dev/$(lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | head -1)
|
||
|
|
if ! blkid "$DATA_DEVICE"; then
|
||
|
|
mkfs.ext4 -L rustdesk-data "$DATA_DEVICE"
|
||
|
|
fi
|
||
|
|
mkdir -p "$RUSTDESK_DATA"
|
||
|
|
grep -q 'LABEL=rustdesk-data' /etc/fstab || \
|
||
|
|
echo "LABEL=rustdesk-data $RUSTDESK_DATA ext4 defaults,nofail 0 2" >> /etc/fstab
|
||
|
|
mount -a
|
||
|
|
# Restrict the data dir so the server private key (id_ed25519, created inside the
|
||
|
|
# container at /root) is not readable by any non-root host user even if the
|
||
|
|
# container writes it world-readable.
|
||
|
|
chmod 700 "$RUSTDESK_DATA"
|
||
|
|
|
||
|
|
# ── Docker + compose plugin ──────────────────────────────────────────
|
||
|
|
dnf install -y docker
|
||
|
|
systemctl enable --now docker
|
||
|
|
DOCKER_CLI_PLUGINS=/usr/local/lib/docker/cli-plugins
|
||
|
|
mkdir -p "$DOCKER_CLI_PLUGINS"
|
||
|
|
curl -fsSL "https://github.com/docker/compose/releases/download/v2.29.7/docker-compose-linux-aarch64" \
|
||
|
|
-o "$DOCKER_CLI_PLUGINS/docker-compose"
|
||
|
|
chmod +x "$DOCKER_CLI_PLUGINS/docker-compose"
|
||
|
|
|
||
|
|
# ── Compose definition (host networking; SG is the access control) ───
|
||
|
|
mkdir -p /opt/rustdesk
|
||
|
|
cat > /opt/rustdesk/docker-compose.yml << COMPOSE
|
||
|
|
services:
|
||
|
|
hbbs:
|
||
|
|
container_name: hbbs
|
||
|
|
image: ${RUSTDESK_IMAGE}
|
||
|
|
command: hbbs
|
||
|
|
network_mode: host
|
||
|
|
volumes:
|
||
|
|
- ${RUSTDESK_DATA}:/root
|
||
|
|
depends_on:
|
||
|
|
- hbbr
|
||
|
|
restart: unless-stopped
|
||
|
|
hbbr:
|
||
|
|
container_name: hbbr
|
||
|
|
image: ${RUSTDESK_IMAGE}
|
||
|
|
command: hbbr
|
||
|
|
network_mode: host
|
||
|
|
volumes:
|
||
|
|
- ${RUSTDESK_DATA}:/root
|
||
|
|
restart: unless-stopped
|
||
|
|
COMPOSE
|
||
|
|
|
||
|
|
cd /opt/rustdesk
|
||
|
|
docker compose pull
|
||
|
|
docker compose up -d
|
||
|
|
|
||
|
|
# Activate the Pro license and configure users in the web console at
|
||
|
|
# http://rustdesk.seahaven.com:21114 after first boot. The generated key pair
|
||
|
|
# lives at $RUSTDESK_DATA/id_ed25519{,.pub} -- mirror it into the
|
||
|
|
# rustdesk/server-key-pair secret (see RUNBOOK).
|