Files
nx9-wg/scripts/deploy.sh
T

217 lines
6.5 KiB
Bash
Executable File

#!/usr/bin/env bash
# ==============================================================================
# nx9-wg Production Deployment Tool
# ==============================================================================
# PURPOSE:
# Deploys the compiled release binary target/release/nx9-wg to the production
# system path (/usr/local/bin/nx9-wg) with validated controlled replacement,
# automatic backup of the previous binary, and controlled systemd service management.
#
# PREREQUISITES:
# - Root privileges (or sudo)
# - Pre-compiled release binary at target/release/nx9-wg
# - Linux with systemd
#
# SAFETY INVARIANTS:
# - Never overwrites the existing production binary without creating a timestamped backup.
# - Never modifies or overwrites database files (/var/lib/nx9-wg/nx9-wg.db).
# - Never deletes WireGuard interfaces or kills processes automatically on port conflict.
# - Uses the standard 'install' command for controlled binary replacement and strict permissions.
# - Returns non-zero exit code on failure.
#
# USAGE:
# sudo bash scripts/deploy.sh [OPTIONS]
#
# OPTIONS:
# --no-restart Install binary without restarting nx9-wg.service
# --dry-run Simulate deployment actions without applying changes
# -h, --help Show this help message
# ==============================================================================
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
ROOT_DIR="$(cd "${SCRIPT_DIR}/.." && pwd)"
SOURCE_BIN="${ROOT_DIR}/target/release/nx9-wg"
DEST_BIN="/usr/local/bin/nx9-wg"
CONF_DIR="/etc/nx9-wg"
DATA_DIR="/var/lib/nx9-wg"
BACKUP_DIR="${DATA_DIR}/backups"
LOG_DIR="/var/log/nx9-wg"
SERVICE_DEST="/etc/systemd/system/nx9-wg.service"
SERVICE_SRC="${ROOT_DIR}/nx9-wg.service"
DRY_RUN=0
NO_RESTART=0
usage() {
cat <<EOF
nx9-wg Production Deployment Tool
Usage:
sudo bash scripts/deploy.sh [OPTIONS]
Options:
--no-restart Install binary without restarting nx9-wg.service
--dry-run Simulate deployment actions without applying changes
-h, --help Show this help message
EOF
exit 0
}
while [[ $# -gt 0 ]]; do
case "$1" in
--dry-run)
DRY_RUN=1
shift
;;
--no-restart)
NO_RESTART=1
shift
;;
-h|--help)
usage
;;
*)
echo "Unknown option: $1" >&2
usage
;;
esac
done
log() {
echo -e "\033[1;34m[DEPLOY]\033[0m \033[1;37m$*\033[0m"
}
success() {
echo -e "\033[1;32m[SUCCESS]\033[0m $*"
}
warn() {
echo -e "\033[1;33m[WARN]\033[0m $*"
}
error() {
echo -e "\033[1;31m[ERROR]\033[0m $*" >&2
exit 1
}
# 1. Privilege Verification
if [[ "${EUID}" -ne 0 && "${DRY_RUN}" -eq 0 ]]; then
error "Deployment must be run as root (or via sudo)."
fi
# 2. Source Binary Verification
if [[ ! -f "${SOURCE_BIN}" ]]; then
error "Source binary not found at ${SOURCE_BIN}. Run 'bash scripts/build-release.sh' first."
fi
if [[ ! -x "${SOURCE_BIN}" ]]; then
error "Source binary at ${SOURCE_BIN} is not executable."
fi
SOURCE_SIZE="$(du -h "${SOURCE_BIN}" | cut -f1)"
SOURCE_SHA="$(sha256sum "${SOURCE_BIN}" | awk '{print $1}')"
SOURCE_DATE="$(date -r "${SOURCE_BIN}" '+%Y-%m-%d %H:%M:%S')"
log "Source binary verified:"
echo " Path: ${SOURCE_BIN}"
echo " Size: ${SOURCE_SIZE}"
echo " Timestamp: ${SOURCE_DATE}"
echo " SHA-256: ${SOURCE_SHA}"
# 3. Create Filesystem Layout with Strict Permissions
log "Ensuring directory permissions..."
if [[ "${DRY_RUN}" -eq 0 ]]; then
install -d -m 0750 "${CONF_DIR}"
install -d -m 0700 "${DATA_DIR}"
install -d -m 0700 "${BACKUP_DIR}"
install -d -m 0750 "${LOG_DIR}"
else
echo " [DRY-RUN] install -d directories: ${CONF_DIR}, ${DATA_DIR}, ${BACKUP_DIR}, ${LOG_DIR}"
fi
# 4. Backup Existing Production Binary
if [[ -f "${DEST_BIN}" ]]; then
TIMESTAMP="$(date +%Y%m%d_%H%M%S)"
BACKUP_DEST="${DEST_BIN}.backup.${TIMESTAMP}"
log "Backing up active binary to ${BACKUP_DEST}..."
if [[ "${DRY_RUN}" -eq 0 ]]; then
cp -p "${DEST_BIN}" "${BACKUP_DEST}"
chmod 0755 "${BACKUP_DEST}"
success "Backup created: ${BACKUP_DEST}"
else
echo " [DRY-RUN] cp -p ${DEST_BIN} ${BACKUP_DEST}"
fi
fi
# 5. Controlled Installation of New Binary
log "Installing new release binary to ${DEST_BIN}..."
if [[ "${DRY_RUN}" -eq 0 ]]; then
install -m 0755 "${SOURCE_BIN}" "${DEST_BIN}"
success "Binary installed to ${DEST_BIN}"
else
echo " [DRY-RUN] install -m 0755 ${SOURCE_BIN} ${DEST_BIN}"
fi
# 6. Install or Update systemd Service Unit
if [[ -f "${SERVICE_SRC}" && -d "/etc/systemd/system" ]]; then
log "Installing/updating systemd service unit..."
if [[ "${DRY_RUN}" -eq 0 ]]; then
install -m 0644 "${SERVICE_SRC}" "${SERVICE_DEST}"
if command -v systemctl >/dev/null 2>&1; then
systemctl daemon-reload
fi
success "systemd service unit updated at ${SERVICE_DEST}"
else
echo " [DRY-RUN] install -m 0644 ${SERVICE_SRC} ${SERVICE_DEST}"
fi
fi
# 7. Safe Socket Inspection
if command -v ss >/dev/null 2>&1; then
log "Inspecting active UDP listen sockets without modifying the host..."
ACTIVE_UDP_SOCKETS="$(ss -lunp 2>/dev/null | grep -v '^State' || true)"
if [[ -n "${ACTIVE_UDP_SOCKETS}" ]]; then
echo "${ACTIVE_UDP_SOCKETS}"
else
echo " No UDP listeners reported by ss."
fi
fi
# 8. Service Restart & Verification
if [[ "${NO_RESTART}" -eq 0 && "${DRY_RUN}" -eq 0 ]]; then
if command -v systemctl >/dev/null 2>&1; then
log "Restarting nx9-wg.service..."
systemctl restart nx9-wg || error "Failed to restart nx9-wg service."
sleep 1
if systemctl is-active --quiet nx9-wg; then
success "nx9-wg.service is active and running."
else
warn "nx9-wg.service is not in active state. Inspecting journal..."
journalctl -u nx9-wg -n 20 --no-pager || true
error "Service failed to start."
fi
fi
elif [[ "${NO_RESTART}" -eq 1 ]]; then
log "Skipping service restart as requested (--no-restart)."
fi
# 9. Final Deployment Verification
log "Verifying deployed binary version..."
if [[ "${DRY_RUN}" -eq 0 ]]; then
DEPLOYED_VER="$("${DEST_BIN}" version | head -n 1)"
success "Deployed binary active: ${DEPLOYED_VER}"
fi
echo -e "\n================================================================="
echo -e "\033[1;32m DEPLOYMENT COMPLETED SUCCESSFULLY!\033[0m"
echo -e "================================================================="
echo " Installed Binary: ${DEST_BIN}"
echo " Configuration: ${CONF_DIR}/config.toml"
echo " Database: ${DATA_DIR}/nx9-wg.db"
echo " Service Status: systemctl status nx9-wg"
echo -e "=================================================================\n"