From 53debacae92a08da6233c46d2633a8fefebedec4 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Tue, 15 Jul 2025 19:27:00 +0800 Subject: [PATCH] Enhance setup.sh with improved automation and logging Adds error handling, progress messages, and more robust certificate renewal logic to setup.sh. Improves web server configuration for ACME challenges, automates service checks, and provides clearer output for server initialization. Cron job for certificate renewal is now weekly with logging, and the script includes verification steps for certificates and services. --- setup.sh | 117 ++++++++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 102 insertions(+), 15 deletions(-) diff --git a/setup.sh b/setup.sh index cc4b3f0..4376c14 100644 --- a/setup.sh +++ b/setup.sh @@ -1,5 +1,7 @@ #!/bin/bash +set -e # Exit on any error + # Check if all required parameters are provided if [ "$#" -ne 3 ]; then echo "Usage: $0 " @@ -11,12 +13,22 @@ USERNAME="$1" DOMAIN="$2" ID="$3" +echo "Starting server initialization..." +echo "Username: $USERNAME" +echo "Domain: $DOMAIN" +echo "ID: $ID" + # Install required packages -sudo apt install cron nginx -y +echo "Installing required packages..." +sudo apt install cron nginx wget unzip openssl -y # Configure web server permissions and files +echo "Configuring web server..." sudo chown -R "$USERNAME:$USERNAME" /var/www -rm /var/www/html/index.nginx-debian.html +sudo mkdir -p /var/www/html/.well-known/acme-challenge +sudo chown -R www-data:www-data /var/www/html +sudo chmod 755 /var/www/html/.well-known/acme-challenge +rm -f /var/www/html/index.nginx-debian.html # Create index.html cat >/var/www/html/index.html <<'EOF' @@ -264,15 +276,20 @@ EOF sudo systemctl reload nginx # Install and configure acme.sh +echo "Installing and configuring acme.sh..." curl https://get.acme.sh | sh ~/.acme.sh/acme.sh --upgrade --auto-upgrade ~/.acme.sh/acme.sh --set-default-ca --server letsencrypt + +echo "Issuing SSL certificate for $DOMAIN..." ~/.acme.sh/acme.sh --issue -d "$DOMAIN" -w /var/www/html --keylength ec-256 --force # Install X +echo "Installing X..." sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install # Setup certificates +echo "Setting up certificates..." mkdir ~/cert ~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key chmod +r ~/cert/x.key @@ -280,23 +297,53 @@ chmod +r ~/cert/x.key # Create certificate renewal script cat >~/cert/cert-renew.sh <&1) +RENEW_EXIT_CODE=\$? + +echo "\$RENEW_OUTPUT" + +# If renewal was successful (exit code 0) or skipped (exit code 2), proceed with installation +if [ \$RENEW_EXIT_CODE -eq 0 ] || [ \$RENEW_EXIT_CODE -eq 2 ]; then + # Install/reinstall the certificate + /home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc \\ + --fullchain-file /home/$USERNAME/cert/x.crt \\ + --key-file /home/$USERNAME/cert/x.key + + echo "X Certificates Renewed/Reinstalled" + + # Set proper permissions for the private key + chmod +r /home/$USERNAME/cert/x.key + echo "Read Permission Granted for Private Key" + + # Restart x service to use the certificate + sudo systemctl restart xray + echo "X Restarted" + + # Verify the certificate + echo "Certificate details:" + openssl x509 -in /home/$USERNAME/cert/x.crt -text -noout | grep -E "(Subject:|Issuer:|Not Before|Not After)" + + echo "Certificate renewal/installation completed successfully!" +else + echo "Certificate renewal failed with exit code \$RENEW_EXIT_CODE" + exit 1 +fi EOF chmod +x ~/cert/cert-renew.sh -# Setup cron job -crontab -l >temp_cron -echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron -crontab temp_cron -rm temp_cron +# Setup cron jobs +(crontab -l 2>/dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/cert-renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab - # Configure X +echo "Configuring X..." sudo tee /usr/local/etc/xray/config.json >/dev/null </dev/null </dev/null <<'EOF' net.core.default_qdisc=fq net.ipv4.tcp_congestion_control=bbr EOF -# Final nginx configuration +# Final nginx configuration with ACME challenge support sudo tee /etc/nginx/nginx.conf >/dev/null <