Update
This commit is contained in:
@@ -0,0 +1,215 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Цвета для вывода
|
||||
GREEN='\033[0;32m'
|
||||
BLUE='\033[0;34m'
|
||||
RED='\033[0;31m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
echo -e "${BLUE}Nginx Installation and Setup Script by izzzzzi${NC}"
|
||||
echo "----------------------------------------"
|
||||
|
||||
# Проверка root прав
|
||||
if [[ $EUID -ne 0 ]]; then
|
||||
echo -e "${RED}This script must be run as root${NC}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Запрос данных у пользователя
|
||||
read -p "Enter your domain name: " DOMAIN
|
||||
read -p "Enter HTTP port (default: 80): " HTTP_PORT
|
||||
read -p "Enter proxy pass port (default: 3001): " PROXY_PORT
|
||||
|
||||
# Использование значений по умолчанию
|
||||
HTTP_PORT=${HTTP_PORT:-80}
|
||||
PROXY_PORT=${PROXY_PORT:-3001}
|
||||
|
||||
# Проверка занятости портов
|
||||
check_port() {
|
||||
if lsof -Pi :$1 -sTCP:LISTEN -t >/dev/null ; then
|
||||
echo -e "${RED}Port $1 is already in use!${NC}"
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
echo -e "${GREEN}Checking ports availability...${NC}"
|
||||
check_port $HTTP_PORT
|
||||
|
||||
# Установка необходимых пакетов
|
||||
echo -e "${GREEN}Installing required packages...${NC}"
|
||||
apt-get update
|
||||
apt-get install nginx certbot python3-certbot-nginx wget openssl -y
|
||||
|
||||
# Создание директории для статического сайта и валидации сертификата
|
||||
echo -e "${GREEN}Creating directories...${NC}"
|
||||
mkdir -p /var/www/certbot
|
||||
mkdir -p /var/www/mywebsite
|
||||
|
||||
# Создание HTTP-конфигурации для Nginx
|
||||
echo -e "${GREEN}Creating initial Nginx configuration...${NC}"
|
||||
cat > /etc/nginx/sites-available/$DOMAIN << EOF
|
||||
server {
|
||||
listen $HTTP_PORT;
|
||||
server_name $DOMAIN;
|
||||
|
||||
location / {
|
||||
return 301 https://\$host\$request_uri;
|
||||
}
|
||||
|
||||
location /.well-known/acme-challenge/ {
|
||||
root /var/www/certbot;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
ln -sf /etc/nginx/sites-available/$DOMAIN /etc/nginx/sites-enabled/
|
||||
rm -f /etc/nginx/sites-enabled/default
|
||||
|
||||
# Проверка конфигурации и перезапуск Nginx
|
||||
echo -e "${GREEN}Testing Nginx configuration...${NC}"
|
||||
nginx -t
|
||||
if [ $? -ne 0 ]; then
|
||||
echo -e "${RED}Error in Nginx configuration. Please check the logs.${NC}"
|
||||
exit 1
|
||||
fi
|
||||
systemctl reload nginx
|
||||
|
||||
# Получение сертификата
|
||||
echo -e "${GREEN}Obtaining SSL certificate...${NC}"
|
||||
certbot certonly --webroot --webroot-path /var/www/certbot -d $DOMAIN --agree-tos --no-eff-email --register-unsafely-without-email
|
||||
if [ $? -ne 0 ]; then
|
||||
echo -e "${RED}Failed to obtain SSL certificate. Please check certbot logs.${NC}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Установка недостающих файлов для SSL
|
||||
echo -e "${GREEN}Ensuring required SSL files exist...${NC}"
|
||||
if [ ! -f /etc/letsencrypt/options-ssl-nginx.conf ]; then
|
||||
wget -O /etc/letsencrypt/options-ssl-nginx.conf https://raw.githubusercontent.com/certbot/certbot/main/certbot_nginx/certbot_nginx/options-ssl-nginx.conf
|
||||
fi
|
||||
if [ ! -f /etc/letsencrypt/ssl-dhparams.pem ]; then
|
||||
openssl dhparam -out /etc/letsencrypt/ssl-dhparams.pem 2048
|
||||
fi
|
||||
|
||||
# Обновление конфигурации для HTTPS
|
||||
echo -e "${GREEN}Creating HTTPS configuration...${NC}"
|
||||
cat > /etc/nginx/sites-available/$DOMAIN << EOF
|
||||
server {
|
||||
listen $HTTP_PORT;
|
||||
server_name $DOMAIN;
|
||||
|
||||
location / {
|
||||
return 301 https://\$host\$request_uri;
|
||||
}
|
||||
|
||||
location /.well-known/acme-challenge/ {
|
||||
root /var/www/certbot;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name $DOMAIN;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/$DOMAIN/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/$DOMAIN/privkey.pem;
|
||||
include /etc/letsencrypt/options-ssl-nginx.conf;
|
||||
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
|
||||
|
||||
root /var/www/mywebsite;
|
||||
index index.html;
|
||||
|
||||
location / {
|
||||
try_files \$uri \$uri/ =404;
|
||||
}
|
||||
|
||||
location /webhook {
|
||||
proxy_pass http://localhost:$PROXY_PORT/webhook;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
}
|
||||
|
||||
location /sub/ {
|
||||
proxy_pass http://localhost:$PROXY_PORT;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
add_header Content-Type text/plain;
|
||||
add_header Content-Disposition inline;
|
||||
add_header Cache-Control no-store;
|
||||
add_header Pragma no-cache;
|
||||
}
|
||||
|
||||
location /yookassa/webhook {
|
||||
proxy_pass http://localhost:$PROXY_PORT/yookassa/webhook;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
|
||||
proxy_connect_timeout 60s;
|
||||
proxy_send_timeout 60s;
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
|
||||
location /freekassa/webhook {
|
||||
proxy_pass http://localhost:$PROXY_PORT/freekassa/webhook;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
|
||||
proxy_connect_timeout 60s;
|
||||
proxy_send_timeout 60s;
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
|
||||
location /cryptobot/webhook {
|
||||
proxy_pass http://localhost:$PROXY_PORT/cryptobot/webhook;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
|
||||
proxy_connect_timeout 60s;
|
||||
proxy_send_timeout 60s;
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
|
||||
location /robokassa/webhook {
|
||||
proxy_pass http://localhost:$PROXY_PORT/robokassa/webhook;
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
|
||||
proxy_connect_timeout 60s;
|
||||
proxy_send_timeout 60s;
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
# Проверка конфигурации и перезапуск Nginx
|
||||
echo -e "${GREEN}Testing Nginx configuration...${NC}"
|
||||
nginx -t
|
||||
if [ $? -ne 0 ]; then
|
||||
echo -e "${RED}Error in updated Nginx configuration. Please check the logs.${NC}"
|
||||
exit 1
|
||||
fi
|
||||
systemctl reload nginx
|
||||
|
||||
# Настройка автообновления сертификата
|
||||
echo -e "${GREEN}Setting up certificate auto-renewal...${NC}"
|
||||
(crontab -l 2>/dev/null; echo "0 12 * * * /usr/bin/certbot renew --quiet && systemctl reload nginx") | crontab -
|
||||
|
||||
# Завершение
|
||||
echo -e "${GREEN}Setup completed!${NC}"
|
||||
echo -e "${BLUE}Domain: ${DOMAIN}${NC}"
|
||||
echo -e "${BLUE}HTTP port: ${HTTP_PORT}${NC}"
|
||||
echo -e "${BLUE}Proxy pass port: ${PROXY_PORT}${NC}"
|
||||
echo
|
||||
echo -e "${RED}Important: Ensure DNS points to this server's IP!${NC}"
|
||||
+164
@@ -0,0 +1,164 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Цвета для вывода
|
||||
GREEN='\033[0;32m'
|
||||
BLUE='\033[0;34m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
echo -e "${BLUE}3x-ui Installation Script by izzzzzi${NC}"
|
||||
echo "----------------------------------------"
|
||||
|
||||
# Запрос данных у пользователя
|
||||
read -p "Enter your domain (e.g., example.com): " DOMAIN
|
||||
read -p "Enter desired admin panel port (default: 2053): " PANEL_PORT
|
||||
read -p "Enter desired sub panel port (default: 2054): " SUB_PANEL_PORT
|
||||
|
||||
# Использование значения по умолчанию для порта, если не указано
|
||||
PANEL_PORT=${PANEL_PORT:-2053}
|
||||
SUB_PANEL_PORT=${SUB_PANEL_PORT:-2054}
|
||||
|
||||
# Создание необходимых директорий
|
||||
echo -e "${GREEN}Creating directories...${NC}"
|
||||
mkdir -p nginx/conf.d db cert
|
||||
|
||||
# Установка certbot
|
||||
echo -e "${GREEN}Installing certbot...${NC}"
|
||||
apt-get update
|
||||
apt-get install certbot -y
|
||||
|
||||
# Остановка nginx если он запущен
|
||||
echo -e "${GREEN}Stopping nginx if running...${NC}"
|
||||
docker-compose down 2>/dev/null
|
||||
systemctl stop nginx 2>/dev/null
|
||||
|
||||
# Получение сертификата
|
||||
echo -e "${GREEN}Obtaining SSL certificate...${NC}"
|
||||
certbot certonly --standalone --agree-tos --register-unsafely-without-email -d $DOMAIN
|
||||
|
||||
# Проверка успешности получения сертификата
|
||||
if [ ! -d "/etc/letsencrypt/live/$DOMAIN" ]; then
|
||||
echo "Failed to obtain SSL certificate. Please check your domain settings."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Тестирование автообновления
|
||||
echo -e "${GREEN}Testing certificate renewal...${NC}"
|
||||
certbot renew --dry-run
|
||||
|
||||
# Создание docker-compose.yml
|
||||
echo -e "${GREEN}Creating docker-compose.yml...${NC}"
|
||||
cat > docker-compose.yml << EOL
|
||||
version: "3"
|
||||
|
||||
services:
|
||||
nginx:
|
||||
image: nginx:alpine
|
||||
container_name: nginx
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
volumes:
|
||||
- ./nginx/conf.d:/etc/nginx/conf.d
|
||||
- /etc/letsencrypt:/etc/letsencrypt
|
||||
- /var/lib/letsencrypt:/var/lib/letsencrypt
|
||||
networks:
|
||||
- proxy-network
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
- 3x-ui
|
||||
|
||||
3x-ui:
|
||||
image: ghcr.io/mhsanaei/3x-ui:latest
|
||||
container_name: 3x-ui
|
||||
hostname: ${DOMAIN}
|
||||
volumes:
|
||||
- \$PWD/db/:/etc/x-ui/
|
||||
- \$PWD/cert/:/root/cert/
|
||||
- /etc/letsencrypt:/etc/letsencrypt:ro
|
||||
environment:
|
||||
XRAY_VMESS_AEAD_FORCED: "false"
|
||||
tty: true
|
||||
networks:
|
||||
- proxy-network
|
||||
restart: unless-stopped
|
||||
|
||||
networks:
|
||||
proxy-network:
|
||||
driver: bridge
|
||||
EOL
|
||||
|
||||
# Создание конфигурации Nginx
|
||||
echo -e "${GREEN}Creating Nginx configuration...${NC}"
|
||||
cat > nginx/conf.d/default.conf << EOL
|
||||
server {
|
||||
listen 80;
|
||||
server_name ${DOMAIN};
|
||||
|
||||
location / {
|
||||
return 301 https://\$host\$request_uri;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name ${DOMAIN};
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/${DOMAIN}/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/${DOMAIN}/privkey.pem;
|
||||
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_prefer_server_ciphers off;
|
||||
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
|
||||
|
||||
location / {
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_set_header Host \$http_host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header Range \$http_range;
|
||||
proxy_set_header If-Range \$http_if_range;
|
||||
proxy_redirect off;
|
||||
proxy_pass http://3x-ui:${PANEL_PORT};
|
||||
}
|
||||
|
||||
location /sub {
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_set_header Host \$http_host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header Range \$http_range;
|
||||
proxy_set_header If-Range \$http_if_range;
|
||||
proxy_redirect off;
|
||||
proxy_pass http://3x-ui:${SUB_PANEL_PORT};
|
||||
}
|
||||
}
|
||||
EOL
|
||||
|
||||
# Проверка наличия Docker и Docker Compose
|
||||
if ! command -v docker &> /dev/null || ! command -v docker-compose &> /dev/null; then
|
||||
echo -e "${GREEN}Installing Docker and Docker Compose...${NC}"
|
||||
curl -fsSL https://get.docker.com | sh
|
||||
curl -L "https://github.com/docker/compose/releases/download/v2.12.2/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose
|
||||
chmod +x /usr/local/bin/docker-compose
|
||||
fi
|
||||
|
||||
# Настройка автообновления сертификатов
|
||||
echo -e "${GREEN}Setting up certificate auto-renewal...${NC}"
|
||||
cat > /etc/cron.d/certbot-renew << EOL
|
||||
0 */12 * * * root certbot renew --quiet --deploy-hook "docker-compose -f $(pwd)/docker-compose.yml restart nginx"
|
||||
EOL
|
||||
|
||||
# Запуск сервисов
|
||||
echo -e "${GREEN}Starting all services...${NC}"
|
||||
docker-compose up -d
|
||||
|
||||
echo -e "${GREEN}Installation completed!${NC}"
|
||||
echo -e "${BLUE}You can access your 3x-ui panel at: https://${DOMAIN}${NC}"
|
||||
echo -e "${YELLOW}Important: Default access to 3x-ui panel - ${NC}"
|
||||
echo -e "${YELLOW}Login: admin${NC}"
|
||||
echo -e "${YELLOW}Password: admin${NC}"
|
||||
echo -e "${YELLOW}For security, it is recommended to change the password at: https://${DOMAIN}/panel/settings${NC}"
|
||||
echo "Please wait a few minutes for all services to start properly."
|
||||
echo "Default credentials can be found in the 3x-ui documentation."
|
||||
|
||||
EOL
|
||||
@@ -0,0 +1,108 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Цвета для вывода
|
||||
GREEN='\033[0;32m'
|
||||
BLUE='\033[0;34m'
|
||||
RED='\033[0;31m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
echo -e "${BLUE}PostgreSQL Installation and Setup Script by izzzzzi${NC}"
|
||||
echo "----------------------------------------"
|
||||
|
||||
# Запрос данных у пользователя
|
||||
read -p "Enter PostgreSQL port (default: 5432): " DB_PORT
|
||||
read -p "Enter database name: " DB_NAME
|
||||
read -p "Enter database user: " DB_USER
|
||||
read -s -p "Enter database password: " DB_PASS
|
||||
echo
|
||||
read -s -p "Confirm database password: " DB_PASS_CONFIRM
|
||||
echo
|
||||
|
||||
# Проверка паролей
|
||||
if [ "$DB_PASS" != "$DB_PASS_CONFIRM" ]; then
|
||||
echo -e "${RED}Passwords do not match!${NC}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Использование значения по умолчанию для порта
|
||||
DB_PORT=${DB_PORT:-5432}
|
||||
|
||||
# Установка PostgreSQL
|
||||
echo -e "${GREEN}Installing PostgreSQL...${NC}"
|
||||
apt-get update
|
||||
apt-get install -y postgresql postgresql-contrib
|
||||
|
||||
# Остановка PostgreSQL для изменения конфигурации
|
||||
systemctl stop postgresql
|
||||
|
||||
# Настройка PostgreSQL для внешних подключений
|
||||
echo -e "${GREEN}Configuring PostgreSQL...${NC}"
|
||||
|
||||
# Настройка postgresql.conf
|
||||
PG_VERSION=$(ls /etc/postgresql/)
|
||||
PG_CONF="/etc/postgresql/$PG_VERSION/main/postgresql.conf"
|
||||
PG_HBA="/etc/postgresql/$PG_VERSION/main/pg_hba.conf"
|
||||
|
||||
# Backup конфигурационных файлов
|
||||
cp $PG_CONF "${PG_CONF}.backup"
|
||||
cp $PG_HBA "${PG_HBA}.backup"
|
||||
|
||||
# Изменение postgresql.conf
|
||||
sed -i "s/#listen_addresses = 'localhost'/listen_addresses = '*'/" $PG_CONF
|
||||
sed -i "s/#port = 5432/port = $DB_PORT/" $PG_CONF
|
||||
|
||||
# Изменение pg_hba.conf
|
||||
cat > $PG_HBA << EOL
|
||||
# TYPE DATABASE USER ADDRESS METHOD
|
||||
local all postgres peer
|
||||
local all all peer
|
||||
host all all 127.0.0.1/32 md5
|
||||
host all all ::1/128 md5
|
||||
host all all 0.0.0.0/0 md5
|
||||
EOL
|
||||
|
||||
# Запуск PostgreSQL
|
||||
systemctl start postgresql
|
||||
systemctl enable postgresql
|
||||
|
||||
# Создание пользователя и базы данных
|
||||
echo -e "${GREEN}Creating database and user...${NC}"
|
||||
sudo -u postgres psql << EOF
|
||||
CREATE USER $DB_USER WITH PASSWORD '$DB_PASS';
|
||||
CREATE DATABASE $DB_NAME OWNER $DB_USER;
|
||||
ALTER USER $DB_USER WITH SUPERUSER;
|
||||
EOF
|
||||
|
||||
# Настройка файрвола
|
||||
echo -e "${GREEN}Configuring firewall...${NC}"
|
||||
if command -v ufw >/dev/null; then
|
||||
ufw allow $DB_PORT/tcp
|
||||
ufw status
|
||||
fi
|
||||
|
||||
# Проверка статуса PostgreSQL
|
||||
systemctl status postgresql --no-pager
|
||||
|
||||
echo -e "${GREEN}Installation completed!${NC}"
|
||||
echo -e "${BLUE}PostgreSQL is running on port: ${DB_PORT}${NC}"
|
||||
echo -e "${BLUE}Database name: ${DB_NAME}${NC}"
|
||||
echo -e "${BLUE}Database user: ${DB_USER}${NC}"
|
||||
echo "You can now connect to your database using:"
|
||||
echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME"
|
||||
echo
|
||||
echo "For remote connections use:"
|
||||
echo "psql -h YOUR_SERVER_IP -p $DB_PORT -U $DB_USER -d $DB_NAME"
|
||||
echo
|
||||
echo -e "${RED}Important: Make sure to save these credentials in a secure place!${NC}"
|
||||
|
||||
# Проверка подключения
|
||||
echo -e "${GREEN}Testing connection...${NC}"
|
||||
PGPASSWORD=$DB_PASS psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME -c "\conninfo"
|
||||
|
||||
# Добавление информации о создании бэкапов
|
||||
echo
|
||||
echo "To create a backup, use:"
|
||||
echo "pg_dump -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME > backup.sql"
|
||||
echo
|
||||
echo "To restore from backup, use:"
|
||||
echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME < backup.sql"
|
||||
Reference in New Issue
Block a user