Jailman v1.1.0 (#24)
* set branch (+2 squashed commit) Squashed commit: [e322f24] remove placeholder [8647131] palceholder * Code cleanup and (primarily) consolidation (#21) * set branch * Exit 1 on iocage create failure * - Move jailcreate to global function - Remove Jailcreate.sh * Add dataset creation function * - add test script to test new global changes - also create folder in jail with createmount * fix * make test executable * more verbosity, fixing folder creation * moving global dataset create * move jails to new dataset-mount creation function * remove test jail and test branch-ref * Add Nextcloud (#22) * Basic working nextcloud integration * Enable persistent reinstall of Nextcloud * prepare for dev merge * Licence alert * Add external database and integrated jail * small improvements and update script * Add mariadb to dev (#31) * Working MariaDB config * - Set ZFS settings for DB on Nextcloud and MariaDB - Cleanup MariaDB * prepare for dev merge * Niceify Readme (#34) * put content from master into it * Some readme itteration * more niceification * [WIP} Wiki workflow test (#37) introduce automatic wiki generation * Add Bitwarden support (#35) * Nextcloud-Cleanup for v1.1.0 (#40) * Nextcloud cleanup - add db-type sanity check - remove some integrated db checks - Move ssl to /config/ssl - remove integrated databases * slight default tweaking * fix mariadb install bug * QA cycle
This commit is contained in:
committed by
GitHub
parent
b54921f97e
commit
cd5adfd94b
17
jails/bitwarden/includes/bitwarden.rc
Executable file
17
jails/bitwarden/includes/bitwarden.rc
Executable file
@ -0,0 +1,17 @@
|
||||
#!/bin/sh
|
||||
|
||||
# PROVIDE: bitwarden
|
||||
# REQUIRE: LOGIN DAEMON NETWORKING FILESYSTEMS
|
||||
# KEYWORD: jail rust
|
||||
|
||||
. /etc/rc.subr
|
||||
|
||||
name="bitwarden"
|
||||
|
||||
|
||||
rcvar=${name}_enable
|
||||
pidfile="/var/run/${name}.pid"
|
||||
command="/usr/sbin/daemon"
|
||||
command_args="-u bitwarden -c -f -P ${pidfile} -r /usr/local/share/bitwarden/bin/bitwarden_rs"
|
||||
load_rc_config $name
|
||||
run_rc_command "$1"
|
13
jails/bitwarden/includes/bitwarden.rc.conf
Executable file
13
jails/bitwarden/includes/bitwarden.rc.conf
Executable file
@ -0,0 +1,13 @@
|
||||
export DATA_FOLDER="/config"
|
||||
export ENABLE_DB_WAL="false"
|
||||
export ROCKET_TLS="{certs="/config/ssl/bitwarden-ssl.crt",key="/config/ssl/bitwarden-ssl.key"}"
|
||||
export LOG_FILE="/config/bitwarden.log"
|
||||
export WEB_VAULT_FOLDER="/usr/local/share/bitwarden/web-vault"
|
||||
export LOG_LEVEL="trace"
|
||||
export WEBSOCKET_ENABLED="true"
|
||||
export DISABLE_ICON_DOWNLOAD=false
|
||||
export ICON_CACHE_FOLDER="/config/icon_cache"
|
||||
export ICON_CACHE_TTL=2592000
|
||||
export ICON_CACHE_NEGTTL=259200
|
||||
export ROCKET_WORKERS=20
|
||||
export ROCKET_PORT=8000
|
86
jails/bitwarden/install.sh
Executable file
86
jails/bitwarden/install.sh
Executable file
@ -0,0 +1,86 @@
|
||||
#!/usr/local/bin/bash
|
||||
# This file contains the install script for bitwarden
|
||||
|
||||
# Initialise defaults
|
||||
JAIL_NAME="bitwarden"
|
||||
DB_DATABASE=${JAIL_NAME}
|
||||
DB_USER=${JAIL_NAME}
|
||||
INSTALL_TYPE=${bitwarden_type}
|
||||
DB_HOST="$(sed 's|\(.*\)/.*|\1|' <<<"${mariadb_ip4_addr}"):3306"
|
||||
DB_PASSWORD="${bitwarden_db_password}"
|
||||
DB_STRING="mysql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}/${DB_DATABASE}"
|
||||
ADMIN_TOKEN=${bitwarden_admin_token}
|
||||
|
||||
if [ -z "${ADMIN_TOKEN}" ]; then
|
||||
ADMIN_TOKEN=$(openssl rand -base64 16)
|
||||
fi
|
||||
|
||||
# install latest rust version, pkg version is outdated and can't build bitwarden_rs
|
||||
iocage exec ${JAIL_NAME} "curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y"
|
||||
|
||||
# Install Bitwarden_rs
|
||||
iocage exec ${JAIL_NAME} mkdir -p /usr/local/share/bitwarden/src
|
||||
iocage exec ${JAIL_NAME} git clone https://github.com/dani-garcia/bitwarden_rs/ /usr/local/share/bitwarden/src
|
||||
TAG=$(iocage exec ${JAIL_NAME} "git -C /usr/local/share/bitwarden/src tag --sort=v:refname | tail -n1")
|
||||
iocage exec ${JAIL_NAME} "git -C /usr/local/share/bitwarden/src checkout ${TAG}"
|
||||
#TODO replace with: cargo build --features mysql --release
|
||||
if [ "${INSTALL_TYPE}" == "mariadb" ]; then
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo build --features mysql --release"
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo install diesel_cli --no-default-features --features mysql"
|
||||
else
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo build --features sqlite --release"
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo install diesel_cli --no-default-features --features sqlite-bundled"
|
||||
fi
|
||||
|
||||
|
||||
iocage exec ${JAIL_NAME} cp -r /usr/local/share/bitwarden/src/target/release /usr/local/share/bitwarden/bin
|
||||
|
||||
# Download and install webvault
|
||||
WEB_RELEASE_URL=$(curl -Ls -o /dev/null -w %{url_effective} https://github.com/dani-garcia/bw_web_builds/releases/latest)
|
||||
WEB_TAG="${WEB_RELEASE_URL##*/}"
|
||||
iocage exec ${JAIL_NAME} "fetch http://github.com/dani-garcia/bw_web_builds/releases/download/$WEB_TAG/bw_web_$WEB_TAG.tar.gz -o /usr/local/share/bitwarden"
|
||||
iocage exec ${JAIL_NAME} "tar -xzvf /usr/local/share/bitwarden/bw_web_$WEB_TAG.tar.gz -C /usr/local/share/bitwarden/"
|
||||
iocage exec ${JAIL_NAME} rm /usr/local/share/bitwarden/bw_web_$WEB_TAG.tar.gz
|
||||
|
||||
if [ -f "/mnt/${global_dataset_config}/${JAIL_NAME}/ssl/bitwarden-ssl.crt" ]; then
|
||||
echo "certificate exist... Skipping cert generation"
|
||||
else
|
||||
"No ssl certificate present, generating self signed certificate"
|
||||
if [ ! -d "/mnt/${global_dataset_config}/${JAIL_NAME}/ssl" ]; then
|
||||
echo "cert folder not existing... creating..."
|
||||
iocage exec ${JAIL_NAME} mkdir /config/ssl
|
||||
fi
|
||||
openssl req -new -newkey rsa:2048 -days 365 -nodes -x509 -subj "/C=US/ST=Denial/L=Springfield/O=Dis/CN=localhost" -keyout /mnt/${global_dataset_config}/${JAIL_NAME}/ssl/bitwarden-ssl.key -out /mnt/${global_dataset_config}/${JAIL_NAME}/ssl/bitwarden-ssl.crt
|
||||
fi
|
||||
|
||||
if [ -f "/mnt/${global_dataset_config}/${JAIL_NAME}/bitwarden.log" ]; then
|
||||
echo "Reinstall of Bitwarden detected... using existing config and database"
|
||||
elif [ "${INSTALL_TYPE}" == "mariadb" ]; then
|
||||
echo "No config detected, doing clean install, utilizing the Mariadb database ${DB_HOST}"
|
||||
iocage exec "mariadb" mysql -u root -e "CREATE DATABASE ${DB_DATABASE};"
|
||||
iocage exec "mariadb" mysql -u root -e "GRANT ALL ON ${DB_DATABASE}.* TO ${DB_USER}@${JAIL_IP} IDENTIFIED BY '${DB_PASSWORD}';"
|
||||
iocage exec "mariadb" mysqladmin reload
|
||||
else
|
||||
echo "No config detected, doing clean install."
|
||||
fi
|
||||
|
||||
iocage exec ${JAIL_NAME} "pw user add bitwarden -c bitwarden -u 725 -d /nonexistent -s /usr/bin/nologin"
|
||||
iocage exec ${JAIL_NAME} chown -R bitwarden:bitwarden /usr/local/share/bitwarden /config
|
||||
iocage exec ${JAIL_NAME} mkdir /usr/local/etc/rc.d /usr/local/etc/rc.conf.d
|
||||
cp ${SCRIPT_DIR}/jails/${JAIL_NAME}/includes/bitwarden.rc /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.d/bitwarden
|
||||
cp ${SCRIPT_DIR}/jails/${JAIL_NAME}/includes/bitwarden.rc.conf /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
echo 'export DATABASE_URL="'${DB_STRING}'"' >> /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
echo 'export ADMIN_TOKEN="'${ADMIN_TOKEN}'"' >> /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
|
||||
if [ "${ADMIN_TOKEN}" == "NONE" ]; then
|
||||
echo "Admin_token set to NONE, disabling admin portal"
|
||||
else
|
||||
echo "Admin_token set and admin portal enabled"
|
||||
iocage exec "${JAIL_NAME}" echo "${DB_NAME} Admin Token is ${ADMIN_TOKEN}" > /root/${JAIL_NAME}_admin_token.txt
|
||||
fi
|
||||
|
||||
iocage exec ${JAIL_NAME} chmod u+x /usr/local/etc/rc.d/bitwarden
|
||||
iocage exec ${JAIL_NAME} sysrc "bitwarden_enable=YES"
|
||||
iocage exec ${JAIL_NAME} service bitwarden restart
|
||||
echo "Jail ${JAIL_NAME} finished Bitwarden install."
|
||||
echo "Admin Token is ${ADMIN_TOKEN}"
|
66
jails/bitwarden/readme.md
Executable file
66
jails/bitwarden/readme.md
Executable file
@ -0,0 +1,66 @@
|
||||
# Original README from the Bitwarden_rs github:
|
||||
|
||||
https://github.com/dani-garcia/bitwarden_rs
|
||||
|
||||
# Bitwarden_RS
|
||||
### This is a Bitwarden server API implementation written in Rust compatible with [upstream Bitwarden clients](https://bitwarden.com/#download)*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal.
|
||||
|
||||
---
|
||||
|
||||
[](https://travis-ci.org/dani-garcia/bitwarden_rs)
|
||||
[](https://hub.docker.com/r/bitwardenrs/server)
|
||||
[](https://deps.rs/repo/github/dani-garcia/bitwarden_rs)
|
||||
[](https://github.com/dani-garcia/bitwarden_rs/releases/latest)
|
||||
[](https://github.com/dani-garcia/bitwarden_rs/blob/master/LICENSE.txt)
|
||||
[](https://matrix.to/#/#bitwarden_rs:matrix.org)
|
||||
|
||||
Image is based on [Rust implementation of Bitwarden API](https://github.com/dani-garcia/bitwarden_rs).
|
||||
|
||||
**This project is not associated with the [Bitwarden](https://bitwarden.com/) project nor 8bit Solutions LLC.**
|
||||
|
||||
#### ⚠️**IMPORTANT**⚠️: When using this server, please report any bugs or suggestions to us directly (look at the bottom of this page for ways to get in touch), regardless of whatever clients you are using (mobile, desktop, browser...). DO NOT use the official support channels.
|
||||
|
||||
---
|
||||
|
||||
## Features
|
||||
|
||||
Basically full implementation of Bitwarden API is provided including:
|
||||
|
||||
* Single user functionality
|
||||
* Organizations support
|
||||
* Attachments
|
||||
* Vault API support
|
||||
* Serving the static files for Vault interface
|
||||
* Website icons API
|
||||
* Authenticator and U2F support
|
||||
* YubiKey and Duo support
|
||||
|
||||
## Installation
|
||||
Pull the docker image and mount a volume from the host for persistent storage:
|
||||
|
||||
```sh
|
||||
docker pull bitwardenrs/server:latest
|
||||
docker run -d --name bitwarden -v /bw-data/:/data/ -p 80:80 bitwardenrs/server:latest
|
||||
```
|
||||
This will preserve any persistent data under /bw-data/, you can adapt the path to whatever suits you.
|
||||
|
||||
**IMPORTANT**: Some web browsers, like Chrome, disallow the use of Web Crypto APIs in insecure contexts. In this case, you might get an error like `Cannot read property 'importKey'`. To solve this problem, you need to access the web vault from HTTPS.
|
||||
|
||||
This can be configured in [bitwarden_rs directly](https://github.com/dani-garcia/bitwarden_rs/wiki/Enabling-HTTPS) or using a third-party reverse proxy ([some examples](https://github.com/dani-garcia/bitwarden_rs/wiki/Proxy-examples)).
|
||||
|
||||
If you have an available domain name, you can get HTTPS certificates with [Let's Encrypt](https://letsencrypt.org/), or you can generate self-signed certificates with utilities like [mkcert](https://github.com/FiloSottile/mkcert). Some proxies automatically do this step, like Caddy (see examples linked above).
|
||||
|
||||
## Usage
|
||||
See the [bitwarden_rs wiki](https://github.com/dani-garcia/bitwarden_rs/wiki) for more information on how to configure and run the bitwarden_rs server.
|
||||
|
||||
## Get in touch
|
||||
To ask a question, offer suggestions or new features or to get help configuring or installing the software, please [use the forum](https://bitwardenrs.discourse.group/).
|
||||
|
||||
If you spot any bugs or crashes with bitwarden_rs itself, please [create an issue](https://github.com/dani-garcia/bitwarden_rs/issues/). Make sure there aren't any similar issues open, though!
|
||||
|
||||
If you prefer to chat, we're usually hanging around at [#bitwarden_rs:matrix.org](https://matrix.to/#/#bitwarden_rs:matrix.org) room on Matrix. Feel free to join us!
|
||||
|
||||
### Sponsors
|
||||
Thanks for your contribution to the project!
|
||||
|
||||
- [@ChonoN](https://github.com/ChonoN)
|
65
jails/bitwarden/update.sh
Executable file
65
jails/bitwarden/update.sh
Executable file
@ -0,0 +1,65 @@
|
||||
#!/usr/local/bin/bash
|
||||
# This file contains the update script for bitwarden
|
||||
# Due to it being build from scratch or downloaded directly to execution dir,
|
||||
# Update for Bitwarden is pretty similair to installation
|
||||
|
||||
# Initialise defaults
|
||||
JAIL_NAME="bitwarden"
|
||||
DB_DATABASE=${JAIL_NAME}
|
||||
DB_USER=${JAIL_NAME}
|
||||
INSTALL_TYPE=${bitwarden_type}
|
||||
DB_HOST="$(sed 's|\(.*\)/.*|\1|' <<<"${mariadb_ip4_addr}"):3306"
|
||||
DB_PASSWORD="${bitwarden_db_password}"
|
||||
DB_STRING="mysql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}/${DB_DATABASE}"
|
||||
ADMIN_TOKEN=${bitwarden_admin_token}
|
||||
|
||||
if [ -z "${ADMIN_TOKEN}" ]; then
|
||||
ADMIN_TOKEN=$(openssl rand -base64 16)
|
||||
fi
|
||||
|
||||
iocage exec ${JAIL_NAME} service bitwarden stop
|
||||
|
||||
# install latest rust version, pkg version is outdated and can't build bitwarden_rs
|
||||
iocage exec ${JAIL_NAME} "curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y"
|
||||
|
||||
# Install Bitwarden_rs
|
||||
iocage exec ${JAIL_NAME} "git -C /usr/local/share/bitwarden/src fetch"
|
||||
TAG=$(iocage exec ${JAIL_NAME} "git -C /usr/local/share/bitwarden/src tag --sort=v:refname | tail -n1")
|
||||
iocage exec ${JAIL_NAME} "git -C /usr/local/share/bitwarden/src checkout ${TAG}"
|
||||
#TODO replace with: cargo build --features mysql --release
|
||||
if [ "${INSTALL_TYPE}" == "mariadb" ]; then
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo build --features mysql --release"
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo install diesel_cli --no-default-features --features mysql"
|
||||
else
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo build --features sqlite --release"
|
||||
iocage exec ${JAIL_NAME} "cd /usr/local/share/bitwarden/src && $HOME/.cargo/bin/cargo install diesel_cli --no-default-features --features sqlite-bundled"
|
||||
fi
|
||||
|
||||
|
||||
iocage exec ${JAIL_NAME} cp -r /usr/local/share/bitwarden/src/target/release /usr/local/share/bitwarden/bin
|
||||
|
||||
# Download and install webvault
|
||||
WEB_RELEASE_URL=$(curl -Ls -o /dev/null -w %{url_effective} https://github.com/dani-garcia/bw_web_builds/releases/latest)
|
||||
WEB_TAG="${WEB_RELEASE_URL##*/}"
|
||||
iocage exec ${JAIL_NAME} "fetch http://github.com/dani-garcia/bw_web_builds/releases/download/$WEB_TAG/bw_web_$WEB_TAG.tar.gz -o /usr/local/share/bitwarden"
|
||||
iocage exec ${JAIL_NAME} "tar -xzvf /usr/local/share/bitwarden/bw_web_$WEB_TAG.tar.gz -C /usr/local/share/bitwarden/"
|
||||
iocage exec ${JAIL_NAME} rm /usr/local/share/bitwarden/bw_web_$WEB_TAG.tar.gz
|
||||
|
||||
iocage exec ${JAIL_NAME} chown -R bitwarden:bitwarden /usr/local/share/bitwarden /config
|
||||
cp ${SCRIPT_DIR}/jails/${JAIL_NAME}/includes/bitwarden.rc /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.d/bitwarden
|
||||
cp ${SCRIPT_DIR}/jails/${JAIL_NAME}/includes/bitwarden.rc.conf /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
echo 'export DATABASE_URL="'${DB_STRING}'"' >> /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
echo 'export ADMIN_TOKEN="'${ADMIN_TOKEN}'"' >> /mnt/${global_dataset_iocage}/jails/${JAIL_NAME}/root/usr/local/etc/rc.conf.d/bitwarden
|
||||
|
||||
if [ "${ADMIN_TOKEN}" == "NONE" ]; then
|
||||
echo "Admin_token set to NONE, disabling admin portal"
|
||||
else
|
||||
echo "Admin_token set and admin portal enabled"
|
||||
iocage exec "${JAIL_NAME}" echo "${DB_NAME} Admin Token is ${ADMIN_TOKEN}" > /root/${JAIL_NAME}_admin_token.txt
|
||||
fi
|
||||
|
||||
|
||||
iocage exec ${JAIL_NAME} chmod u+x /usr/local/etc/rc.d/bitwarden
|
||||
iocage exec ${JAIL_NAME} service bitwarden restart
|
||||
echo "Jail ${JAIL_NAME} finished Bitwarden update."
|
||||
echo "Admin Token is ${ADMIN_TOKEN}"
|
Reference in New Issue
Block a user