Last active 1748426794

Init a server from cloud provider

Revision 269e7653a16affe41552e6b84c0a79fe32ffa69e

init.sh Raw
1#!/usr/bin/env bash
2#===============================================================================
3# Concise server preparation script with error confirmation (idempotent)
4#===============================================================================
5
6set -euo pipefail
7export LC_ALL=C
8export LANG=en_US.UTF-8
9export DEBIAN_FRONTEND=noninteractive
10
11#-----------------------------------
12# Colors & Prompts
13#-----------------------------------
14Green="\033[32m"; Red="\033[31m"; Yellow="\033[33m"; Blue="\033[36m"; Font="\033[0m"
15OK="${Green}[ OK ]${Font}"; ERROR="${Red}[FAILED]${Font}"; WARN="${Yellow}[ WARN ]${Font}"
16
17print_ok(){ echo -e "${OK} $1"; }
18print_error(){ echo -e "${ERROR} $1"; }
19print_warn(){ echo -e "${WARN} $1"; }
20
21#-----------------------------------
22# Error handling & confirmation
23#-----------------------------------
24on_error(){ print_error "Error at line $1."; areYouSure; }
25trap 'on_error $LINENO' ERR
26
27areYouSure(){
28 print_warn "Continue despite errors? [y/N]"
29 read -r ans
30 case $ans in [yY]*) print_ok "Continuing...";; *) print_error "Aborted."; exit 1;; esac
31}
32
33#-----------------------------------
34# Helpers
35#-----------------------------------
36run_local(){ print_ok "Local: $*"; "$@"; }
37run_remote(){ sshpass -p "$REMOTE_PASS" ssh -o StrictHostKeyChecking=no "$REMOTE_USER@$SERVER" "$*"; }
38wait_ssh(){
39 print_ok "Waiting for SSH on $SERVER... (Running ssh $REMOTE_USER@$SERVER)"
40 until sshpass -p "$REMOTE_PASS" ssh -q \
41 -o StrictHostKeyChecking=no \
42 -o ConnectTimeout=5 \
43 "$REMOTE_USER@$SERVER" exit; do
44 print_warn "SSH not ready, retrying in 5s..."
45 sleep 5
46 done
47 print_ok "SSH available."
48}
49
50usage(){ echo "Usage: $0 <orig_user> <orig_pass> <server> <new_hostname> <new_user>"; exit 1; }
51
52#-----------------------------------
53# Main
54#-----------------------------------
55[ $# -ne 5 ] && usage
56USER="$1"; PASS="$2"; SERVER="$3"; HOSTNAME="$4"; NEWUSER="$5"
57REMOTE_USER="$USER"; REMOTE_PASS="$PASS"
58
59# 1) Install sshpass locally
60run_local sudo apt-get update -y
61run_local sudo apt-get install -y sshpass
62
63# 2) Clear known_hosts, wait for SSH
64run_local ssh-keygen -R "$SERVER" -f ~/.ssh/known_hosts
65wait_ssh
66
67# 3) Hostname & reboot (only if changed)
68CURRENT_HOST=$(run_remote "hostname")
69if [[ "$CURRENT_HOST" != "$HOSTNAME" ]]; then
70 print_ok "Setting hostname to $HOSTNAME"
71 run_remote "sudo hostnamectl set-hostname $HOSTNAME"
72 run_remote "sudo reboot" || true
73 print_ok "Server rebooting..."
74 sleep 5
75 wait_ssh
76else
77 print_ok "Hostname already '$HOSTNAME', skipping"
78fi
79
80# 4) Create or verify new user
81if run_remote "id -u $NEWUSER" &>/dev/null; then
82 print_ok "User $NEWUSER exists"
83else
84 print_ok "Creating user $NEWUSER"
85 run_remote "sudo adduser --disabled-password --gecos '' $NEWUSER"
86fi
87
88# 5) Grant sudo & set up passwordless
89print_ok "Granting sudo to $NEWUSER"
90run_remote "sudo usermod -aG sudo $NEWUSER"
91print_ok "Setting passwordless sudo for $NEWUSER"
92run_remote "echo '$NEWUSER ALL=(ALL) NOPASSWD:ALL' | sudo tee /etc/sudoers.d/$NEWUSER"
93
94# 6) Generate & persist random password (once)
95if run_remote "[ -f /etc/$NEWUSER.pass ]" &>/dev/null; then
96 # In this case, the password is already set
97 print_ok "Don't have to change password. Reusing existing password for $NEWUSER"
98 PASS_NEW=$(run_remote "sudo cat /etc/$NEWUSER.pass")
99else
100 PASS_NEW=$(uuidgen)
101 print_ok "Setting password for $NEWUSER"
102 run_remote "echo '$NEWUSER:$PASS_NEW' | sudo chpasswd"
103 run_remote "echo '$PASS_NEW' | sudo tee /etc/$NEWUSER.pass > /dev/null"
104 run_remote "sudo chmod 600 /etc/$NEWUSER.pass"
105 run_remote "sudo chown root:root /etc/$NEWUSER.pass"
106 print_ok "New password generated for $NEWUSER and persisted at /etc/$NEWUSER.pass. Please back it up! It can still be used to log in via serial console or rescue mode!"
107fi
108
109local_pass_file="./password_${NEWUSER}_at_${SERVER}.txt"
110rm -f "$local_pass_file" 2>/dev/null || true
111sshpass -p "$REMOTE_PASS" ssh -q -o StrictHostKeyChecking=no \
112 "$REMOTE_USER@$SERVER" "sudo cat /etc/$NEWUSER.pass" \
113 > "$local_pass_file"
114chmod 600 "$local_pass_file"
115chown "$USER:$USER" "$local_pass_file"
116print_ok "Password for $NEWUSER saved locally at $local_pass_file [DO NOT SHARE THIS FILE! IT CAN BE USED TO LOG IN VIA SERIAL CONSOLE OR RESCUE MODE!]"
117
118# 7) Copy SSH key (only if absent)
119[ ! -f ~/.ssh/id_rsa.pub ] && run_local ssh-keygen -t rsa -N "" -f ~/.ssh/id_rsa
120PUBKEY=$(<~/.ssh/id_rsa.pub)
121print_ok "Ensuring SSH key in authorized_keys"
122run_remote "mkdir -p /home/$NEWUSER/.ssh && \
123 sudo bash -c 'grep -qxF \"$PUBKEY\" /home/$NEWUSER/.ssh/authorized_keys 2>/dev/null || \
124 echo \"$PUBKEY\" >> /home/$NEWUSER/.ssh/authorized_keys' && \
125 sudo chown -R $NEWUSER:$NEWUSER /home/$NEWUSER/.ssh && \
126 sudo chmod 700 /home/$NEWUSER/.ssh && \
127 sudo chmod 600 /home/$NEWUSER/.ssh/authorized_keys"
128
129# Switch to new user for subsequent operations
130print_ok "Switching to new user $NEWUSER"
131REMOTE_USER="$NEWUSER"; REMOTE_PASS="$PASS_NEW"
132wait_ssh
133
134# 8) Harden SSH
135print_ok "Hardening SSH settings"
136run_remote "sudo sed -i 's/PermitRootLogin yes/PermitRootLogin no/; \
137 s/PasswordAuthentication yes/PasswordAuthentication no/; \
138 s/#PubkeyAuthentication yes/PubkeyAuthentication yes/' /etc/ssh/sshd_config && \
139 sudo systemctl restart sshd || sudo systemctl restart ssh"
140
141# 9) Remove other non-system users
142print_ok "Removing other users"
143others=$(run_remote "awk -F: -v skip='$NEWUSER' '\$3>=1000 && \$1!=skip {print \$1}' /etc/passwd")
144for u in $others; do
145 print_warn "Deleting user $u"
146 run_remote "sudo pkill -u $u || true; sudo deluser --remove-home $u"
147done
148
149# 10) Reset machine-id
150print_ok "Resetting machine-id"
151run_remote "sudo rm -f /etc/machine-id /var/lib/dbus/machine-id && \
152 sudo systemd-machine-id-setup && \
153 sudo cp /etc/machine-id /var/lib/dbus/machine-id"
154
155# 11) Enable UFW & OpenSSH
156print_ok "Enabling UFW firewall"
157run_remote "sudo apt-get install -y ufw && sudo ufw allow OpenSSH && echo y | sudo ufw enable"
158
159# 12) Install & configure Fail2Ban
160print_ok "Installing Fail2Ban"
161run_remote "sudo apt-get update && sudo apt-get install -y fail2ban"
162print_ok "Configuring Fail2Ban"
163run_remote <<'EOF'
164sudo tee /etc/fail2ban/jail.local > /dev/null <<EOJ
165[sshd]
166enabled = true
167port = ssh
168filter = sshd
169backend = systemd
170logpath = journal
171maxretry = 3
172findtime = 600
173bantime = 3600
174EOJ
175sudo systemctl restart fail2ban
176EOF
177print_ok "Fail2Ban setup complete"
178
179# 13) Enable BBR (only once)
180print_ok "Enabling BBR congestion control"
181run_remote <<'EOF'
182grep -q 'net.ipv4.tcp_congestion_control = bbr' /etc/sysctl.d/99-bbr.conf 2>/dev/null || {
183 sudo tee /etc/sysctl.d/99-bbr.conf > /dev/null <<SYSCTL
184net.core.default_qdisc = fq
185net.ipv4.tcp_congestion_control = bbr
186SYSCTL
187 sudo sysctl --system
188}
189EOF
190
191# 14) Select best mirror & update
192print_ok "Selecting best mirror & updating"
193run_remote "curl -s https://gist.aiursoft.cn/anduin/879917820a6c4b268fc12c21f1b3fe7a/raw/HEAD/mirror.sh | bash"
194run_remote "sudo apt-get update"
195
196# 15) Install or upgrade latest HWE kernel if needed
197print_ok "Checking HWE kernel package on remote"
198run_remote <<'EOF'
199set -euo pipefail
200
201HWE_PKG="$(apt search linux-generic-hwe- \
202 | awk -F/ '/linux-generic-hwe-/{print $1; exit}')"
203
204inst="\$(apt-cache policy \$HWE_PKG | awk '/Installed:/ {print \$2}')"
205cand="\$(apt-cache policy \$HWE_PKG | awk '/Candidate:/ {print \$2}')"
206
207if dpkg -s "\$HWE_PKG" &>/dev/null; then
208 if [ "\$inst" != "\$cand" ]; then
209 echo "[ OK ] Upgrading \$HWE_PKG from \$inst to \$cand"
210 sudo apt-get update
211 sudo apt-get install -y "\$HWE_PKG"
212 echo reboot_required > /tmp/.reboot_flag
213 else
214 echo "[ OK ] \$HWE_PKG is already at latest version (\$inst), skipping"
215 fi
216else
217 echo "[ OK ] Installing \$HWE_PKG (\$cand)"
218 sudo apt-get update
219 sudo apt-get install -y "\$HWE_PKG"
220 echo reboot_required > /tmp/.reboot_flag
221fi
222EOF
223
224# 16) Conditionally reboot & wait
225if run_remote 'test -f /tmp/.reboot_flag'; then
226 print_ok "Rebooting server to apply new kernel"
227 run_remote "rm -f /tmp/.reboot_flag"
228 run_remote "sudo reboot" || true
229 sleep 5
230 wait_ssh
231else
232 print_ok "No new kernel installed, skipping reboot"
233fi
234
235# 17) Final updates & cleanup
236print_ok "Installing upgrades & cleanup"
237run_remote "sudo apt-get update && sudo apt-get upgrade -y && sudo apt-get autoremove -y"
238
239# 18) Performance tuning
240print_ok "Tuning CPU performance & timezone"
241run_remote "sudo apt-get install -y linux-tools-$(uname -r) cpupower && \
242 sudo cpupower frequency-set -g performance || true && \
243 sudo timedatectl set-timezone GMT"
244
245# 19) Remove snap
246print_ok "Removing snapd"
247run_remote <<'EOF'
248# 1) 如果 snapd.service 存在,就 disable 一下;否则跳过
249if systemctl list-unit-files | grep -q '^snapd\.service'; then
250 sudo systemctl disable --now snapd || true
251else
252 echo "[ OK ] snapd.service not found, skipping disable"
253fi
254
255# 2) 如果 dpkg 里检测到 snapd 包,就 purge 并清理数据目录
256if dpkg -l snapd &>/dev/null; then
257 sudo apt-get purge -y snapd
258 sudo rm -rf /snap /var/lib/snapd /var/cache/snapd
259else
260 echo "[ OK ] snapd package not installed, skipping purge"
261fi
262
263# 3) 在所有机器都写上 no-snap 的 pin
264sudo tee /etc/apt/preferences.d/no-snap.pref > /dev/null <<EOP
265Package: snapd
266Pin: release a=*
267Pin-Priority: -10
268EOP
269EOF
270
271# 20) Final cleanup & benchmark
272print_ok "Final autoremove & benchmark"
273run_remote "sudo apt-get autoremove -y --purge && \
274 sudo apt-get install -y sysbench && sysbench cpu --threads=$(nproc) run && \
275 sudo apt-get autoremove -y sysbench --purge"
276
277print_ok "Setup complete. Connect via: ssh $NEWUSER@$SERVER"
278
279# After this script, server will:
280
281# * Only allow SSH key login
282# * Root login disabled, password authentication disabled
283# * Have a new hostname set
284# * Have a new user with sudo privileges and can log in via SSH
285# * Have a random password stored securely at /etc/<new_user>.pass
286# * Have SSH key copied to authorized_keys so you can log in without a password
287# * Be hardened with UFW, Fail2Ban and allowed SSH connections(only)
288# * Have BBR enabled for better network performance
289# * Have the latest HWE kernel installed
290# * Have the best mirror selected for package updates
291# * Have snap removed
292# * Have CPU performance tuned to 'performance' mode
293# * Have timezone set to GMT
294# * Have all unnecessary users removed (Check /etc/passwd for remaining users)
295# * Have all unnecessary packages removed
296# * Have the latest updates installed
297# * Have sysbench installed for performance testing
298# * Have a final benchmark run to verify CPU performance
299# * Have a final cleanup of unnecessary packages
install_fail2ban.sh Raw
1#!/usr/bin/env bash
2set -euo pipefail
3
4echo "[+] Updating package index and installing fail2ban..."
5sudo apt update
6sudo apt install -y fail2ban
7
8echo "[+] Writing /etc/fail2ban/jail.local..."
9sudo tee /etc/fail2ban/jail.local > /dev/null <<'EOF'
10[sshd]
11enabled = true
12port = ssh
13filter = sshd
14logpath = /var/log/auth.log
15maxretry = 3
16findtime = 600
17bantime = 3600
18EOF
19sleep 1
20
21echo "[+] Restarting fail2ban service..."
22sudo systemctl restart fail2ban
23
24echo "=== Fail2Ban global status ==="
25# Allow script to continue even if fail2ban-client status fails (e.g., socket not yet ready)
26sudo fail2ban-client status || true
27
28echo "=== SSHD jail status ==="
29sudo fail2ban-client status sshd || true
30
31echo "Tip: To view the currently banned IP list again, run:"
32echo "sudo fail2ban-client status sshd"
33
34echo "Tip: To unban an IP address, run:"
35echo "sudo fail2ban-client set sshd unbanip <IP_ADDRESS>"
36
37echo "Tip: To ban an IP address manually, run:"
38echo "sudo fail2ban-client set sshd banip <IP_ADDRESS>"
39
40echo "Tip: To view the fail2ban logs, run:"
41echo "sudo journalctl -u fail2ban"
42
mirror.sh Raw
1#!/usr/bin/env bash
2# Step 1: Ensure required packages are installed
3sudo apt update
4sudo apt install -y curl apt-transport-https lsb-release
5
6function switchSource() {
7 # Get current Ubuntu codename (e.g., jammy, focal, bionic)
8 codename=$(lsb_release -cs)
9
10 # Define a list of potential mirrors
11 mirrors=(
12 "https://archive.ubuntu.com/ubuntu/"
13 "https://mirror.aarnet.edu.au/pub/ubuntu/archive/" # Australia
14 "https://mirror.fsmg.org.nz/ubuntu/" # New Zealand
15 "https://mirrors.neterra.net/ubuntu/archive/" # Bulgaria
16 "https://mirror.csclub.uwaterloo.ca/ubuntu/" # Canada
17 "https://mirrors.dotsrc.org/ubuntu/" # Denmark
18 "https://mirrors.nic.funet.fi/ubuntu/" # Finland
19 "https://mirror.ubuntu.ikoula.com/" # France
20 "https://mirror.xtom.com.hk/ubuntu/" # Hong Kong
21 "https://mirrors.piconets.webwerks.in/ubuntu-mirror/ubuntu/" # India
22 "https://ftp.udx.icscoe.jp/Linux/ubuntu/" # Japan
23 "https://ftp.kaist.ac.kr/ubuntu/" # Korea
24 "https://ubuntu.mirror.garr.it/ubuntu/" # Italy
25 "https://ftp.uni-stuttgart.de/ubuntu/" # Germany
26 "https://mirror.i3d.net/pub/ubuntu/" # Netherlands
27 "https://mirroronet.pl/pub/mirrors/ubuntu/" # Poland
28 "https://ubuntu.mobinhost.com/ubuntu/" # Iran
29 "http://sg.archive.ubuntu.com/ubuntu/" # Singapore
30 "http://ossmirror.mycloud.services/os/linux/ubuntu/" # Singapore
31 "https://mirror.enzu.com/ubuntu/" # United States
32 "http://jp.archive.ubuntu.com/ubuntu/" # Japan
33 "http://kr.archive.ubuntu.com/ubuntu/" # Korea
34 "http://us.archive.ubuntu.com/ubuntu/" # United States
35 "http://tw.archive.ubuntu.com/ubuntu/" # Taiwan
36 "https://mirror.twds.com.tw/ubuntu/" # Taiwan
37 "https://ubuntu.mirrors.uk2.net/ubuntu/" # United Kingdom
38 "http://mirrors.ustc.edu.cn/ubuntu/" # 中国科学技术大学
39 "http://ftp.sjtu.edu.cn/ubuntu/" # 上海交通大学
40 "http://mirrors.tuna.tsinghua.edu.cn/ubuntu/" # 清华大学
41 "http://mirrors.aliyun.com/ubuntu/" # 阿里云
42 "http://mirrors.163.com/ubuntu/" # 网易
43 "http://mirrors.cloud.tencent.com/ubuntu/" # 腾讯云
44 "http://mirror.aiursoft.cn/ubuntu/" # Aiursoft
45 "http://mirrors.huaweicloud.com/ubuntu/" # 华为云
46 "http://mirrors.zju.edu.cn/ubuntu/" # 浙江大学
47 "http://azure.archive.ubuntu.com/ubuntu/" # Azure
48 "https://mirrors.isu.net.sa/apt-mirror/" # Saudi Arabia
49 "https://mirror.team-host.ru/ubuntu/" # Russia
50 "https://labs.eif.urjc.es/mirror/ubuntu/" # Spain
51 "https://mirror.alastyr.com/ubuntu/ubuntu-archive/" # Turkey
52 "https://ftp.acc.umu.se/ubuntu/" # Sweden
53 "https://mirror.kku.ac.th/ubuntu/" # Thailand
54 "https://mirror.bizflycloud.vn/ubuntu/" # Vietnam
55 )
56
57 declare -A results
58
59 # Function to test speed of a single mirror
60 test_speed() {
61 url="$1"
62 # Attempt to do a quick GET and measure total time
63 response="$(curl -o /dev/null -s -w "%{http_code} %{time_total}\n" \
64 --connect-timeout 1 --max-time 2 "$url")"
65
66 http_code=$(echo "$response" | awk '{print $1}')
67 time_total=$(echo "$response" | awk '{print $2}')
68
69 # If HTTP code == 200, mark the measured time; otherwise use a large value
70 if [ "$http_code" -eq 200 ]; then
71 results["$url"]="$time_total"
72 else
73 echo "Failed to access $url (HTTP code: $http_code)"
74 results["$url"]="9999"
75 fi
76 }
77
78 echo "Testing all mirrors for Ubuntu '$codename'..."
79 for mirror in "${mirrors[@]}"; do
80 test_speed "$mirror"
81 done
82
83 # Sort mirrors by time_total
84 # Example of sorted_mirrors entry: "https://archive.ubuntu.com/ubuntu/ 0.034"
85 sorted_mirrors="$(
86 for url in "${!results[@]}"; do
87 echo "$url ${results[$url]}"
88 done | sort -k2 -n
89 )"
90
91 echo
92 echo "=== Sorted mirrors by response time (ascending) ==="
93 echo "$sorted_mirrors"
94 echo
95
96 # Pick the top (fastest) mirror from the sorted list
97 fastest_mirror="$(echo "$sorted_mirrors" | head -n 1 | awk '{print $1}')"
98
99 echo "Fastest mirror found: $fastest_mirror"
100 echo "Updating /etc/apt/sources.list..."
101
102 # Update /etc/apt/sources.list with the fastest mirror
103 sudo tee /etc/apt/sources.list >/dev/null <<EOF
104deb $fastest_mirror $codename main restricted universe multiverse
105deb $fastest_mirror $codename-updates main restricted universe multiverse
106deb $fastest_mirror $codename-backports main restricted universe multiverse
107deb $fastest_mirror $codename-security main restricted universe multiverse
108EOF
109
110 # Final check
111 sudo apt update
112 echo "All done!"
113}
114
115# Call the main function
116switchSource