From 666cf47da46277d5173179d3e54bce8b6c825c5d Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Mon, 1 Sep 2025 12:37:34 +0800 Subject: [PATCH] Revamp setup script and README for X-WebUI Updated the README to reflect the new X-WebUI setup, replacing the previous portfolio-focused documentation with instructions for deploying a secure server environment using Nginx, Docker, X, and Open WebUI. The setup.sh script now installs additional dependencies (ca-certificates, curl), sets up Docker and Open WebUI, and updates Xray and Nginx configurations for improved security and compatibility. The default index.html was simplified to a clean, static portfolio template without Tailwind or external dependencies. --- README.md | 193 +++++++++--------------- setup.sh | 444 ++++++++++++++++++++++++++++-------------------------- 2 files changed, 302 insertions(+), 335 deletions(-) diff --git a/README.md b/README.md index 186c5a3..3bfefd0 100644 --- a/README.md +++ b/README.md @@ -1,149 +1,104 @@ -# Automated Web Deployment Script +# X-WebUI -A comprehensive automation script for deploying professional portfolio websites with SSL certificates and optimized web server configuration. +A comprehensive setup script for deploying a secure server environment with Nginx, Docker, X, and Open WebUI. -## 🚀 Features +## Overview -- **Automated Web Server Setup**: Configures Nginx with optimized settings -- **SSL Certificate Management**: Automatic SSL certificate provisioning and renewal using acme.sh -- **Professional Portfolio Template**: Includes a beautiful, responsive portfolio website -- **System Optimization**: Configures BBR congestion control and other performance optimizations -- **Certificate Auto-Renewal**: Sets up automated certificate renewal via cron jobs -- **Security Headers**: Implements HSTS and other security best practices +This repository contains a bash script that automates the setup of a complete server environment on a Debian system. The script sets up: -## 📋 Prerequisites +- Nginx web server +- SSL/TLS certificates via acme.sh +- Docker and Docker Compose +- Open WebUI (running in Docker) +- X proxy server with secure configuration +- Automatic certificate renewal -- Ubuntu/Debian-based Linux server -- Root or sudo access -- Domain name pointing to your server's IP address -- Open ports 80 and 443 +## Requirements -## 🛠️ Usage +- Debian 10+ 64-bit system +- Sudo privileges +- Domain name pointing to your server +- Inbound traffic on TCP ports 80 and 443 from 0.0.0.0/0 allowed -1. Log in as a non-root user and update your system: +## Usage - ```bash - sudo apt update && sudo apt upgrade -y - ``` - -2. Run the setup script with required parameters: - - ```bash - curl -L https://github.com/xixu-me/automated-web-deployment/raw/main/setup.sh | bash -s - ``` - -3. If you encounter the following error: - - ```text - bash: curl: command not found - ``` - - Please install `curl` and `bash` first: - - ```bash - sudo apt install curl bash -y - ``` - -### Parameters - -- ``: Your system username -- ``: Your domain name (e.g., example.com) -- ``: A unique identifier (UUID format recommended) - -### Example +Log in as a non-root user and update your system: ```bash -./setup.sh john example.com 12345678-1234-1234-1234-123456789abc +sudo apt update && sudo apt upgrade -y ``` -## 🎨 Portfolio Features - -The included portfolio template features: - -- **Responsive Design**: Works on all devices and screen sizes -- **Modern UI**: Clean, professional design with CSS Grid and Flexbox -- **Contact Form**: Ready-to-use contact form structure -- **Project Showcase**: Grid layout for displaying projects -- **Skills Section**: Tag-based skills display -- **SEO Optimized**: Proper HTML structure and meta tags - -### Customization - -To customize the portfolio: - -1. Edit `/var/www/html/index.html` after installation -2. Modify the personal information, projects, and skills -3. Update the color scheme by changing CSS custom properties - -## 🔧 What the Script Does - -1. **Package Installation**: Installs required packages (cron, nginx) -2. **Web Server Configuration**: Sets up Nginx with optimized configuration -3. **SSL Certificate Setup**: Provisions SSL certificates using Let's Encrypt -4. **Portfolio Deployment**: Creates and deploys a professional portfolio website -5. **Auto-Renewal Setup**: Configures automatic certificate renewal -6. **System Optimization**: Applies performance optimizations -7. **Security Configuration**: Implements security headers and HTTPS redirect - -## 📁 File Structure - -```text -/var/www/html/ # Web root directory -├── index.html # Portfolio website -~/cert/ # SSL certificates directory -├── x.crt # SSL certificate -├── x.key # Private key -└── cert-renew.sh # Certificate renewal script -``` - -## 🔒 Security Features - -- **HTTPS Redirect**: Automatic HTTP to HTTPS redirection -- **HSTS Headers**: Strict Transport Security implementation -- **SSL Configuration**: Modern TLS protocols and cipher suites -- **Secure File Permissions**: Proper file ownership and permissions - -## 🔄 Maintenance - -### Certificate Renewal - -Certificates are automatically renewed monthly via cron job. To manually renew: +Run the script: ```bash -bash ~/cert/cert-renew.sh +curl -L https://github.com/xixu-me/X-WebUI/raw/main/setup.sh | bash -s ``` -### Nginx Configuration +Replace the following: -Main configuration file: `/etc/nginx/nginx.conf` +- ``: Your login username +- ``: Your domain name (must be pointed to this server) +- ``: A unique ID for the X configuration -To reload Nginx after changes: +If you encounter the following error: ```bash -sudo systemctl reload nginx +bash: curl: command not found ``` -## 🐛 Troubleshooting +Please install `curl` and `bash` first: -### Common Issues +```bash +sudo apt update && sudo apt install -y curl bash +``` -1. **Domain not pointing to server**: Ensure DNS A record points to your server's IP -2. **Firewall blocking ports**: Make sure ports 80 and 443 are open -3. **Permission errors**: Ensure script is run with appropriate privileges +## Features -### Log Files +### Web Server -- Nginx access logs: `/var/log/nginx/access.log` -- Nginx error logs: `/var/log/nginx/error.log` -- System logs: `journalctl -u nginx` +- Configures Nginx +- Sets up automatic HTTPS redirection +- Implements proper security headers -## 📝 License +### SSL/TLS Certificates -This project is licensed under the GNU General Public License v3.0 - see the [LICENSE](LICENSE) file for details. +- Automatically obtains and configures Let's Encrypt certificates +- Sets up automatic renewal via cron job -## ⚠️ Important Notes +### Docker Environment -- This script will reboot the server at the end of installation -- Backup any existing Nginx configuration before running -- The script is designed for fresh server installations -- Domain validation is required for SSL certificate issuance +- Installs Docker and Docker Compose +- Configures Open WebUI in a Docker container +- Sets up proper restart policies + +### Proxy Configuration + +- Installs and configures X +- Implements secure TLS settings +- Configures proper routing rules + +## Security Considerations + +This script implements several security best practices: + +- Uses TLS 1.2+ for all connections +- Implements proper certificate handling +- Configures firewall rules to block unwanted traffic +- Sets up proper user permissions + +## Disclaimer + +1. This repository is strictly for educational and research purposes. +2. Use at your own risk. The repository assumes no responsibility for potential issues. +3. No guarantee of accuracy, completeness, or reliability. +4. Not liable for data loss or damages. +5. Ensure compliance with relevant licenses and legal regulations. +6. No endorsement of third-party hardware/software. +7. User modifications are their own responsibility. +8. Terms may change at any time. By using this repository, you agree to these terms. + +## License + +Copyright © [Xi Xu](https://xi-xu.me). All rights reserved. + +Licensed under the [GPL-3.0](LICENSE) license. diff --git a/setup.sh b/setup.sh index f314cbd..8982378 100644 --- a/setup.sh +++ b/setup.sh @@ -12,7 +12,7 @@ DOMAIN="$2" ID="$3" # Install required packages -sudo apt install cron nginx -y +sudo apt install cron nginx ca-certificates curl -y # Configure web server permissions and files sudo chown -R "$USERNAME:$USERNAME" /var/www @@ -21,220 +21,212 @@ rm /var/www/html/index.nginx-debian.html # Create index.html cat >/var/www/html/index.html <<'EOF' - - - - - John Doe - Professional Portfolio - - - - - - - - - -
-
-
-
- JD -
- -
- -
-
-
- - -
- -
- -
-
- Your Name -

John Doe

-

Software Engineer & Web Developer

-

- I build elegant, responsive, and user-friendly web applications. Passionate about clean code and modern web technologies. + + + + + John Doe - Professional Portfolio + + + +

+

John Doe

+

Full Stack Developer

+
+ +
+
+

About Me

+

+ Passionate full-stack developer with 5+ years of experience + building scalable web applications. I specialize in modern + JavaScript frameworks and cloud architecture.

- -
-
- - -
-
-
-

About Me

-

A little bit about my journey and skills.

-
-
-
-

Who I Am

-

- Hello! I'm John Doe, a software engineer based in [Your City]. I have a passion for creating beautiful and functional websites and applications. My journey into tech started with a simple "Hello World" and has since grown into a full-fledged career where I get to solve complex problems and build amazing things. -

-

- When I'm not coding, you can find me exploring new hiking trails, reading a good book, or experimenting with new recipes in the kitchen. +

+
+

Featured Projects

+
+
+

E-commerce Platform

+

+ A full-featured e-commerce solution built with React + and Node.js, featuring real-time inventory + management and secure payment processing.

-
-

My Skills

-
- HTML - CSS - JavaScript - React - Node.js - Tailwind CSS - Git & GitHub - Firebase -
+
+

Task Management App

+

+ A collaborative task management application using + Vue.js and Firebase, with real-time updates and team + collaboration features. +

+
+
+

Analytics Dashboard

+

+ A responsive analytics dashboard built with D3.js + and Express, providing real-time data visualization + and reporting capabilities. +

-
-
- - -
-
-
-

My Projects

-

A selection of my work. Feel free to explore.

+
+
+

Skills

+
+ JavaScript + React + Node.js + Python + SQL + AWS + Docker + Git
-
- -
- Project 1 -
-

Project Title One

-

A brief description of the project, the technologies used, and the problem it solves.

- -
+
+
+

Contact Me

+
+
+ +
- -
- Project 2 -
-

Project Title Two

-

A brief description of the project, the technologies used, and the problem it solves.

- -
+
+ +
- -
- Project 3 -
-

Project Title Three

-

A brief description of the project, the technologies used, and the problem it solves.

- -
+
+ +
-
-
-
- - -
-
-
-

Get In Touch

-

I'm open to new opportunities. Let's connect!

-
-
- -
- - -
-
- - -
-
- - -
-
- -
- -
-
-
-
- - -
-
-

© John Doe. All Rights Reserved.

-
-
- - - + + + + +

© 2025 John Doe. All rights reserved.

+ EOF @@ -277,6 +269,26 @@ curl https://get.acme.sh | sh ~/.acme.sh/acme.sh --set-default-ca --server letsencrypt ~/.acme.sh/acme.sh --issue -d "$DOMAIN" -w /var/www/html --keylength ec-256 --force +# Add Docker's official GPG key +sudo install -m 0755 -d /etc/apt/keyrings +sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc +sudo chmod a+r /etc/apt/keyrings/docker.asc + +# Add the repository to Apt sources +echo \ + "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian \ + $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \ + sudo tee /etc/apt/sources.list.d/docker.list > /dev/null +sudo apt update + +# Install Docker +sudo apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y + +# Install Open WebUI +sudo docker pull ghcr.io/open-webui/open-webui:main +sudo docker run -d -p 8888:8080 -v open-webui:/app/backend/data --name open-webui ghcr.io/open-webui/open-webui:main +sudo docker update --restart=unless-stopped open-webui + # Install X sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install @@ -344,8 +356,8 @@ sudo tee /usr/local/etc/xray/config.json >/dev/null </dev/null <