From dcc7d5e218089970491e69c6056830b33f883183 Mon Sep 17 00:00:00 2001 From: Zakhar Izmaylov Date: Sat, 16 Nov 2024 21:03:39 +0300 Subject: [PATCH] Update --- .gitignore | 2 + nginx.conf | 62 +++++++++ scripts/nginx.sh | 215 +++++++++++++++++++++++++++++++ node/setup.sh => scripts/node.sh | 0 scripts/postgres.sh | 108 ++++++++++++++++ 5 files changed, 387 insertions(+) create mode 100644 scripts/nginx.sh rename node/setup.sh => scripts/node.sh (100%) create mode 100644 scripts/postgres.sh diff --git a/.gitignore b/.gitignore index 70485cdc..2c9c052d 100644 --- a/.gitignore +++ b/.gitignore @@ -49,3 +49,5 @@ handlers/texts.py .DS_Store Thumbs.db +nginx.conf +scripts/nginx.sh diff --git a/nginx.conf b/nginx.conf index 5c671969..d02c5dfb 100644 --- a/nginx.conf +++ b/nginx.conf @@ -103,3 +103,65 @@ server { proxy_read_timeout 60s; } } + + + + location /sub/ { + proxy_pass http://localhost:$PROXY_PORT; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + add_header Content-Type text/plain; + add_header Content-Disposition inline; + add_header Cache-Control no-store; + add_header Pragma no-cache; + } + + location /yookassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/yookassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /freekassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/freekassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /cryptobot/webhook { + proxy_pass http://localhost:$PROXY_PORT/cryptobot/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /robokassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/robokassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } diff --git a/scripts/nginx.sh b/scripts/nginx.sh new file mode 100644 index 00000000..2b05431f --- /dev/null +++ b/scripts/nginx.sh @@ -0,0 +1,215 @@ +#!/bin/bash + +# Цвета для вывода +GREEN='\033[0;32m' +BLUE='\033[0;34m' +RED='\033[0;31m' +NC='\033[0m' # No Color + +echo -e "${BLUE}Nginx Installation and Setup Script by izzzzzi${NC}" +echo "----------------------------------------" + +# Проверка root прав +if [[ $EUID -ne 0 ]]; then + echo -e "${RED}This script must be run as root${NC}" + exit 1 +fi + +# Запрос данных у пользователя +read -p "Enter your domain name: " DOMAIN +read -p "Enter HTTP port (default: 80): " HTTP_PORT +read -p "Enter proxy pass port (default: 3001): " PROXY_PORT + +# Использование значений по умолчанию +HTTP_PORT=${HTTP_PORT:-80} +PROXY_PORT=${PROXY_PORT:-3001} + +# Проверка занятости портов +check_port() { + if lsof -Pi :$1 -sTCP:LISTEN -t >/dev/null ; then + echo -e "${RED}Port $1 is already in use!${NC}" + exit 1 + fi +} + +echo -e "${GREEN}Checking ports availability...${NC}" +check_port $HTTP_PORT + +# Установка необходимых пакетов +echo -e "${GREEN}Installing required packages...${NC}" +apt-get update +apt-get install nginx certbot python3-certbot-nginx wget openssl -y + +# Создание директории для статического сайта и валидации сертификата +echo -e "${GREEN}Creating directories...${NC}" +mkdir -p /var/www/certbot +mkdir -p /var/www/mywebsite + +# Создание HTTP-конфигурации для Nginx +echo -e "${GREEN}Creating initial Nginx configuration...${NC}" +cat > /etc/nginx/sites-available/$DOMAIN << EOF +server { + listen $HTTP_PORT; + server_name $DOMAIN; + + location / { + return 301 https://\$host\$request_uri; + } + + location /.well-known/acme-challenge/ { + root /var/www/certbot; + } +} +EOF + +ln -sf /etc/nginx/sites-available/$DOMAIN /etc/nginx/sites-enabled/ +rm -f /etc/nginx/sites-enabled/default + +# Проверка конфигурации и перезапуск Nginx +echo -e "${GREEN}Testing Nginx configuration...${NC}" +nginx -t +if [ $? -ne 0 ]; then + echo -e "${RED}Error in Nginx configuration. Please check the logs.${NC}" + exit 1 +fi +systemctl reload nginx + +# Получение сертификата +echo -e "${GREEN}Obtaining SSL certificate...${NC}" +certbot certonly --webroot --webroot-path /var/www/certbot -d $DOMAIN --agree-tos --no-eff-email --register-unsafely-without-email +if [ $? -ne 0 ]; then + echo -e "${RED}Failed to obtain SSL certificate. Please check certbot logs.${NC}" + exit 1 +fi + +# Установка недостающих файлов для SSL +echo -e "${GREEN}Ensuring required SSL files exist...${NC}" +if [ ! -f /etc/letsencrypt/options-ssl-nginx.conf ]; then + wget -O /etc/letsencrypt/options-ssl-nginx.conf https://raw.githubusercontent.com/certbot/certbot/main/certbot_nginx/certbot_nginx/options-ssl-nginx.conf +fi +if [ ! -f /etc/letsencrypt/ssl-dhparams.pem ]; then + openssl dhparam -out /etc/letsencrypt/ssl-dhparams.pem 2048 +fi + +# Обновление конфигурации для HTTPS +echo -e "${GREEN}Creating HTTPS configuration...${NC}" +cat > /etc/nginx/sites-available/$DOMAIN << EOF +server { + listen $HTTP_PORT; + server_name $DOMAIN; + + location / { + return 301 https://\$host\$request_uri; + } + + location /.well-known/acme-challenge/ { + root /var/www/certbot; + } +} + +server { + listen 443 ssl; + server_name $DOMAIN; + + ssl_certificate /etc/letsencrypt/live/$DOMAIN/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/$DOMAIN/privkey.pem; + include /etc/letsencrypt/options-ssl-nginx.conf; + ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; + + root /var/www/mywebsite; + index index.html; + + location / { + try_files \$uri \$uri/ =404; + } + + location /webhook { + proxy_pass http://localhost:$PROXY_PORT/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + } + + location /sub/ { + proxy_pass http://localhost:$PROXY_PORT; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + add_header Content-Type text/plain; + add_header Content-Disposition inline; + add_header Cache-Control no-store; + add_header Pragma no-cache; + } + + location /yookassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/yookassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /freekassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/freekassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /cryptobot/webhook { + proxy_pass http://localhost:$PROXY_PORT/cryptobot/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } + + location /robokassa/webhook { + proxy_pass http://localhost:$PROXY_PORT/robokassa/webhook; + proxy_set_header Host \$host; + proxy_set_header X-Real-IP \$remote_addr; + proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto \$scheme; + + proxy_connect_timeout 60s; + proxy_send_timeout 60s; + proxy_read_timeout 60s; + } +} +EOF + +# Проверка конфигурации и перезапуск Nginx +echo -e "${GREEN}Testing Nginx configuration...${NC}" +nginx -t +if [ $? -ne 0 ]; then + echo -e "${RED}Error in updated Nginx configuration. Please check the logs.${NC}" + exit 1 +fi +systemctl reload nginx + +# Настройка автообновления сертификата +echo -e "${GREEN}Setting up certificate auto-renewal...${NC}" +(crontab -l 2>/dev/null; echo "0 12 * * * /usr/bin/certbot renew --quiet && systemctl reload nginx") | crontab - + +# Завершение +echo -e "${GREEN}Setup completed!${NC}" +echo -e "${BLUE}Domain: ${DOMAIN}${NC}" +echo -e "${BLUE}HTTP port: ${HTTP_PORT}${NC}" +echo -e "${BLUE}Proxy pass port: ${PROXY_PORT}${NC}" +echo +echo -e "${RED}Important: Ensure DNS points to this server's IP!${NC}" diff --git a/node/setup.sh b/scripts/node.sh similarity index 100% rename from node/setup.sh rename to scripts/node.sh diff --git a/scripts/postgres.sh b/scripts/postgres.sh new file mode 100644 index 00000000..ed77314b --- /dev/null +++ b/scripts/postgres.sh @@ -0,0 +1,108 @@ +#!/bin/bash + +# Цвета для вывода +GREEN='\033[0;32m' +BLUE='\033[0;34m' +RED='\033[0;31m' +NC='\033[0m' # No Color + +echo -e "${BLUE}PostgreSQL Installation and Setup Script by izzzzzi${NC}" +echo "----------------------------------------" + +# Запрос данных у пользователя +read -p "Enter PostgreSQL port (default: 5432): " DB_PORT +read -p "Enter database name: " DB_NAME +read -p "Enter database user: " DB_USER +read -s -p "Enter database password: " DB_PASS +echo +read -s -p "Confirm database password: " DB_PASS_CONFIRM +echo + +# Проверка паролей +if [ "$DB_PASS" != "$DB_PASS_CONFIRM" ]; then + echo -e "${RED}Passwords do not match!${NC}" + exit 1 +fi + +# Использование значения по умолчанию для порта +DB_PORT=${DB_PORT:-5432} + +# Установка PostgreSQL +echo -e "${GREEN}Installing PostgreSQL...${NC}" +apt-get update +apt-get install -y postgresql postgresql-contrib + +# Остановка PostgreSQL для изменения конфигурации +systemctl stop postgresql + +# Настройка PostgreSQL для внешних подключений +echo -e "${GREEN}Configuring PostgreSQL...${NC}" + +# Настройка postgresql.conf +PG_VERSION=$(ls /etc/postgresql/) +PG_CONF="/etc/postgresql/$PG_VERSION/main/postgresql.conf" +PG_HBA="/etc/postgresql/$PG_VERSION/main/pg_hba.conf" + +# Backup конфигурационных файлов +cp $PG_CONF "${PG_CONF}.backup" +cp $PG_HBA "${PG_HBA}.backup" + +# Изменение postgresql.conf +sed -i "s/#listen_addresses = 'localhost'/listen_addresses = '*'/" $PG_CONF +sed -i "s/#port = 5432/port = $DB_PORT/" $PG_CONF + +# Изменение pg_hba.conf +cat > $PG_HBA << EOL +# TYPE DATABASE USER ADDRESS METHOD +local all postgres peer +local all all peer +host all all 127.0.0.1/32 md5 +host all all ::1/128 md5 +host all all 0.0.0.0/0 md5 +EOL + +# Запуск PostgreSQL +systemctl start postgresql +systemctl enable postgresql + +# Создание пользователя и базы данных +echo -e "${GREEN}Creating database and user...${NC}" +sudo -u postgres psql << EOF +CREATE USER $DB_USER WITH PASSWORD '$DB_PASS'; +CREATE DATABASE $DB_NAME OWNER $DB_USER; +ALTER USER $DB_USER WITH SUPERUSER; +EOF + +# Настройка файрвола +echo -e "${GREEN}Configuring firewall...${NC}" +if command -v ufw >/dev/null; then + ufw allow $DB_PORT/tcp + ufw status +fi + +# Проверка статуса PostgreSQL +systemctl status postgresql --no-pager + +echo -e "${GREEN}Installation completed!${NC}" +echo -e "${BLUE}PostgreSQL is running on port: ${DB_PORT}${NC}" +echo -e "${BLUE}Database name: ${DB_NAME}${NC}" +echo -e "${BLUE}Database user: ${DB_USER}${NC}" +echo "You can now connect to your database using:" +echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME" +echo +echo "For remote connections use:" +echo "psql -h YOUR_SERVER_IP -p $DB_PORT -U $DB_USER -d $DB_NAME" +echo +echo -e "${RED}Important: Make sure to save these credentials in a secure place!${NC}" + +# Проверка подключения +echo -e "${GREEN}Testing connection...${NC}" +PGPASSWORD=$DB_PASS psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME -c "\conninfo" + +# Добавление информации о создании бэкапов +echo +echo "To create a backup, use:" +echo "pg_dump -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME > backup.sql" +echo +echo "To restore from backup, use:" +echo "psql -h localhost -p $DB_PORT -U $DB_USER -d $DB_NAME < backup.sql" \ No newline at end of file