diff --git a/setup.sh b/setup.sh index cc4b3f0..4376c14 100644 --- a/setup.sh +++ b/setup.sh @@ -1,5 +1,7 @@ #!/bin/bash +set -e # Exit on any error + # Check if all required parameters are provided if [ "$#" -ne 3 ]; then echo "Usage: $0 " @@ -11,12 +13,22 @@ USERNAME="$1" DOMAIN="$2" ID="$3" +echo "Starting server initialization..." +echo "Username: $USERNAME" +echo "Domain: $DOMAIN" +echo "ID: $ID" + # Install required packages -sudo apt install cron nginx -y +echo "Installing required packages..." +sudo apt install cron nginx wget unzip openssl -y # Configure web server permissions and files +echo "Configuring web server..." sudo chown -R "$USERNAME:$USERNAME" /var/www -rm /var/www/html/index.nginx-debian.html +sudo mkdir -p /var/www/html/.well-known/acme-challenge +sudo chown -R www-data:www-data /var/www/html +sudo chmod 755 /var/www/html/.well-known/acme-challenge +rm -f /var/www/html/index.nginx-debian.html # Create index.html cat >/var/www/html/index.html <<'EOF' @@ -264,15 +276,20 @@ EOF sudo systemctl reload nginx # Install and configure acme.sh +echo "Installing and configuring acme.sh..." curl https://get.acme.sh | sh ~/.acme.sh/acme.sh --upgrade --auto-upgrade ~/.acme.sh/acme.sh --set-default-ca --server letsencrypt + +echo "Issuing SSL certificate for $DOMAIN..." ~/.acme.sh/acme.sh --issue -d "$DOMAIN" -w /var/www/html --keylength ec-256 --force # Install X +echo "Installing X..." sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install # Setup certificates +echo "Setting up certificates..." mkdir ~/cert ~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key chmod +r ~/cert/x.key @@ -280,23 +297,53 @@ chmod +r ~/cert/x.key # Create certificate renewal script cat >~/cert/cert-renew.sh <&1) +RENEW_EXIT_CODE=\$? + +echo "\$RENEW_OUTPUT" + +# If renewal was successful (exit code 0) or skipped (exit code 2), proceed with installation +if [ \$RENEW_EXIT_CODE -eq 0 ] || [ \$RENEW_EXIT_CODE -eq 2 ]; then + # Install/reinstall the certificate + /home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc \\ + --fullchain-file /home/$USERNAME/cert/x.crt \\ + --key-file /home/$USERNAME/cert/x.key + + echo "X Certificates Renewed/Reinstalled" + + # Set proper permissions for the private key + chmod +r /home/$USERNAME/cert/x.key + echo "Read Permission Granted for Private Key" + + # Restart x service to use the certificate + sudo systemctl restart xray + echo "X Restarted" + + # Verify the certificate + echo "Certificate details:" + openssl x509 -in /home/$USERNAME/cert/x.crt -text -noout | grep -E "(Subject:|Issuer:|Not Before|Not After)" + + echo "Certificate renewal/installation completed successfully!" +else + echo "Certificate renewal failed with exit code \$RENEW_EXIT_CODE" + exit 1 +fi EOF chmod +x ~/cert/cert-renew.sh -# Setup cron job -crontab -l >temp_cron -echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron -crontab temp_cron -rm temp_cron +# Setup cron jobs +(crontab -l 2>/dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/cert-renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab - # Configure X +echo "Configuring X..." sudo tee /usr/local/etc/xray/config.json >/dev/null </dev/null </dev/null <<'EOF' net.core.default_qdisc=fq net.ipv4.tcp_congestion_control=bbr EOF -# Final nginx configuration +# Final nginx configuration with ACME challenge support sudo tee /etc/nginx/nginx.conf >/dev/null <