diff --git a/README.md b/README.md index 186c5a3..7b3c5c3 100644 --- a/README.md +++ b/README.md @@ -1,24 +1,34 @@ # Automated Web Deployment Script -A comprehensive automation script for deploying professional portfolio websites with SSL certificates and optimized web server configuration. +A bash script for automating the deployment of a professional portfolio website with SSL certificate management on Ubuntu/Debian servers. -## 🚀 Features +## Overview -- **Automated Web Server Setup**: Configures Nginx with optimized settings -- **SSL Certificate Management**: Automatic SSL certificate provisioning and renewal using acme.sh -- **Professional Portfolio Template**: Includes a beautiful, responsive portfolio website -- **System Optimization**: Configures BBR congestion control and other performance optimizations -- **Certificate Auto-Renewal**: Sets up automated certificate renewal via cron jobs -- **Security Headers**: Implements HSTS and other security best practices +This repository contains an automated deployment script that sets up a complete web server environment with: -## 📋 Prerequisites +- **Nginx web server** with optimized configuration +- **SSL certificate management** using acme.sh and Let's Encrypt +- **Professional portfolio website** with modern, responsive design +- **Automatic certificate renewal** via cron jobs +- **Security optimizations** and best practices + +## Features + +- 🚀 **One-command deployment** - Deploy everything with a single script +- 🔒 **Automatic SSL** - Generates and manages SSL certificates +- 📱 **Responsive design** - Mobile-friendly portfolio website +- 🔄 **Auto-renewal** - Certificates renew automatically +- ⚡ **Performance optimized** - BBR congestion control and optimized settings +- 🛡️ **Security hardened** - HTTPS redirects and security headers + +## Prerequisites - Ubuntu/Debian-based Linux server - Root or sudo access - Domain name pointing to your server's IP address - Open ports 80 and 443 -## 🛠️ Usage +## Usage 1. Log in as a non-root user and update your system: @@ -53,97 +63,111 @@ A comprehensive automation script for deploying professional portfolio websites ### Example ```bash -./setup.sh john example.com 12345678-1234-1234-1234-123456789abc +curl -L https://github.com/xixu-me/automated-web-deployment/raw/main/setup.sh | bash -s john example.com 550e8400-e29b-41d4-a716-446655440000 ``` -## 🎨 Portfolio Features +## What Gets Installed -The included portfolio template features: +The script automatically installs and configures: -- **Responsive Design**: Works on all devices and screen sizes -- **Modern UI**: Clean, professional design with CSS Grid and Flexbox -- **Contact Form**: Ready-to-use contact form structure -- **Project Showcase**: Grid layout for displaying projects -- **Skills Section**: Tag-based skills display -- **SEO Optimized**: Proper HTML structure and meta tags +1. **System packages**: nginx, wget, unzip, openssl, cron +2. **Web server**: Nginx with optimized configuration +3. **SSL certificates**: Let's Encrypt certificates via acme.sh +4. **Portfolio website**: Professional HTML/CSS portfolio template +5. **Security settings**: System optimizations and security headers -### Customization +## Post-Installation -To customize the portfolio: +After the script completes: -1. Edit `/var/www/html/index.html` after installation -2. Modify the personal information, projects, and skills -3. Update the color scheme by changing CSS custom properties +- Your website will be accessible at `https://yourdomain.com` +- SSL certificates will auto-renew weekly +- The server will reboot automatically to apply all changes -## 🔧 What the Script Does - -1. **Package Installation**: Installs required packages (cron, nginx) -2. **Web Server Configuration**: Sets up Nginx with optimized configuration -3. **SSL Certificate Setup**: Provisions SSL certificates using Let's Encrypt -4. **Portfolio Deployment**: Creates and deploys a professional portfolio website -5. **Auto-Renewal Setup**: Configures automatic certificate renewal -6. **System Optimization**: Applies performance optimizations -7. **Security Configuration**: Implements security headers and HTTPS redirect - -## 📁 File Structure +## File Structure ```text -/var/www/html/ # Web root directory -├── index.html # Portfolio website -~/cert/ # SSL certificates directory -├── x.crt # SSL certificate -├── x.key # Private key -└── cert-renew.sh # Certificate renewal script +/var/www/html/ # Website files +~/cert/ # SSL certificates +~/cert/renew.sh # Certificate renewal script ``` -## 🔒 Security Features +## Certificate Management -- **HTTPS Redirect**: Automatic HTTP to HTTPS redirection -- **HSTS Headers**: Strict Transport Security implementation -- **SSL Configuration**: Modern TLS protocols and cipher suites -- **Secure File Permissions**: Proper file ownership and permissions +- **Location**: `~/cert/x.crt` and `~/cert/x.key` +- **Renewal**: Automatic weekly check via cron +- **Logs**: Certificate renewal logs in `~/cert/renewal.log` -## 🔄 Maintenance +## Customization -### Certificate Renewal +To customize the portfolio website: -Certificates are automatically renewed monthly via cron job. To manually renew: +1. Edit `/var/www/html/index.html` after installation +2. Modify the content, styling, and information as needed +3. The website uses modern CSS with responsive design -```bash -bash ~/cert/cert-renew.sh -``` - -### Nginx Configuration - -Main configuration file: `/etc/nginx/nginx.conf` - -To reload Nginx after changes: - -```bash -sudo systemctl reload nginx -``` - -## 🐛 Troubleshooting +## Troubleshooting ### Common Issues -1. **Domain not pointing to server**: Ensure DNS A record points to your server's IP +1. **Domain not pointing to server**: Ensure your domain's DNS A record points to your server's IP 2. **Firewall blocking ports**: Make sure ports 80 and 443 are open -3. **Permission errors**: Ensure script is run with appropriate privileges +3. **Permission errors**: Run the script as a non-root user with sudo access -### Log Files +### Service Status -- Nginx access logs: `/var/log/nginx/access.log` -- Nginx error logs: `/var/log/nginx/error.log` -- System logs: `journalctl -u nginx` +Check if services are running: -## 📝 License +```bash +sudo systemctl status nginx +``` + +### Certificate Status + +Check certificate expiration: + +```bash +openssl x509 -in ~/cert/x.crt -text -noout | grep -E "(Not Before|Not After)" +``` + +## Security Considerations + +- The script implements security best practices including HTTPS redirects +- Uses modern TLS protocols (TLSv1.2 and TLSv1.3) +- Applies security headers and optimized configurations +- Regular certificate renewals prevent expiration + +## License This project is licensed under the GNU General Public License v3.0 - see the [LICENSE](LICENSE) file for details. -## ⚠️ Important Notes +## Disclaimer -- This script will reboot the server at the end of installation -- Backup any existing Nginx configuration before running -- The script is designed for fresh server installations -- Domain validation is required for SSL certificate issuance +⚠️ **Important Notice** + +This script is provided for educational and legitimate web deployment purposes only. Users are responsible for: + +- Ensuring compliance with all applicable laws and regulations +- Proper server security and maintenance +- Understanding the configurations being applied to their systems +- Regular security updates and monitoring + +The authors and contributors of this project: + +- Make no warranties about the security, reliability, or suitability of this script +- Are not responsible for any damage, data loss, or security breaches +- Recommend thorough testing in a development environment before production use +- Advise users to review and understand the script before execution + +**Use at your own risk.** Always backup your data and test in a safe environment first. + +## Support + +For issues and questions: + +- Review the troubleshooting section above +- Ensure you're using a supported operating system (Ubuntu/Debian) + +--- + +**Note**: This script automatically reboots the server after installation to apply all system optimizations. diff --git a/setup.sh b/setup.sh index 4376c14..def0c55 100644 --- a/setup.sh +++ b/setup.sh @@ -295,7 +295,7 @@ mkdir ~/cert chmod +r ~/cert/x.key # Create certificate renewal script -cat >~/cert/cert-renew.sh <~/cert/renew.sh </dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/cert-renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab - +(crontab -l 2>/dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab - # Configure X echo "Configuring X..." @@ -499,7 +499,7 @@ echo "ID: $ID" echo "Certificate location: ~/cert/" echo "Nginx configuration: /etc/nginx/nginx.conf" echo "X configuration: /usr/local/etc/xray/config.json" -echo "Certificate renewal script: ~/cert/cert-renew.sh" +echo "Certificate renewal script: ~/cert/renew.sh" echo "Automatic renewal: Configured via cron (weekly check)" echo "==============================================" echo "The system will reboot in 10 seconds..."