Fix SSH prompt and add automatic Caddy configuration for Keycloak

FIXES:
1. SSH key import now properly accepts "n" as answer
   - Added y/n prompt before asking for usernames
   - Clearer flow: "Import SSH keys?" → "Which service?"
   - No more confusion about entering "n" vs leaving blank

2. Automatic Caddy configuration for Keycloak
   - Detects if Caddy is installed or being installed
   - Offers to configure Caddy reverse proxy for Keycloak
   - Backs up Caddyfile before changes
   - Adds Keycloak configuration automatically
   - Reloads Caddy after adding configuration
   - Keycloak starts AFTER Caddy is configured
   - Prevents "container won't come up" issue

CADDY AUTO-CONFIGURATION:
When both Keycloak and Caddy are selected:
- Script asks: "Configure Caddy reverse proxy for Keycloak?"
- Prompts for domain (e.g., auth.yourdomain.com)
- Backs up existing Caddyfile
- Adds Keycloak block with:
  * JSON logging for fail2ban
  * Reverse proxy to localhost:8180
  * Security headers (HSTS, X-Frame-Options, etc.)
- Formats and reloads Caddy
- Confirms Keycloak will be available at domain

This ensures correct startup order: Caddy configured → Caddy reloaded → Keycloak starts
This commit is contained in:
Claude
2026-01-12 04:30:58 +00:00
parent 4c69294c65
commit 9d1cbadce9
+84 -2
View File
@@ -1517,10 +1517,18 @@ fi
# Import SSH keys from GitHub/Launchpad
echo ""
prompt_text "Import SSH keys from GitHub? (enter username or leave blank to skip):" "" GITHUB_USER
prompt_text "Import SSH keys from Launchpad? (enter username or leave blank to skip):" "" LAUNCHPAD_USER
echo "You can import SSH public keys from GitHub or Launchpad for easier SSH access."
echo ""
prompt_yn "Import SSH keys from GitHub or Launchpad? (y/n):" "n" IMPORT_SSH_KEYS
KEYS_IMPORTED=false
GITHUB_USER=""
LAUNCHPAD_USER=""
if [ "$IMPORT_SSH_KEYS" = "y" ] || [ "$IMPORT_SSH_KEYS" = "Y" ]; then
prompt_text "GitHub username (or leave blank to skip):" "" GITHUB_USER
prompt_text "Launchpad username (or leave blank to skip):" "" LAUNCHPAD_USER
fi
# Create .ssh directory if it doesn't exist
mkdir -p "$ACTUAL_HOME/.ssh"
@@ -3144,6 +3152,80 @@ KC_COMPOSE
echo " ✓ Keycloak configured at $KC_DIR"
# If Caddy is installed/being installed, offer to configure it for Keycloak
if [ "$INSTALL_CADDY" = "y" ] || [ "$INSTALL_CADDY" = "Y" ] || [ -d "$DOCKER_DIR/caddy" ]; then
echo ""
prompt_yn "Configure Caddy reverse proxy for Keycloak? (y/n):" "y" CONFIGURE_CADDY_KC
if [ "$CONFIGURE_CADDY_KC" = "y" ] || [ "$CONFIGURE_CADDY_KC" = "Y" ]; then
CADDY_DIR="$DOCKER_DIR/caddy"
# Ask for domain
prompt_text " Domain for Keycloak (e.g., auth.yourdomain.com):" "auth.localhost" KC_CADDY_DOMAIN
if [ -f "$CADDY_DIR/Caddyfile" ]; then
# Backup existing Caddyfile
mkdir -p "$CADDY_DIR/backups"
cp "$CADDY_DIR/Caddyfile" "$CADDY_DIR/backups/Caddyfile.backup.$(date +%Y%m%d_%H%M%S)"
echo " ✓ Backed up existing Caddyfile"
# Check if Keycloak config already exists
if ! grep -q "$KC_CADDY_DOMAIN" "$CADDY_DIR/Caddyfile"; then
# Add Keycloak configuration
cat >> "$CADDY_DIR/Caddyfile" << EOF
# Keycloak - Identity and Access Management
$KC_CADDY_DOMAIN {
log {
output file /var/log/caddy/keycloak-access.log
format json
level INFO
}
reverse_proxy localhost:8180
# Security headers
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Frame-Options "SAMEORIGIN"
X-Content-Type-Options "nosniff"
X-XSS-Protection "1; mode=block"
Referrer-Policy "strict-origin-when-cross-origin"
}
}
EOF
echo " ✓ Added Keycloak configuration to Caddyfile"
# Reload Caddy if it's running
if docker ps --format '{{.Names}}' | grep -q "caddy"; then
CADDY_CONTAINER=$(docker ps --format '{{.Names}}' | grep "caddy" | head -1)
echo " Reloading Caddy configuration..."
if docker exec -w /etc/caddy "$CADDY_CONTAINER" caddy fmt --overwrite 2>/dev/null; then
echo " ✓ Formatted Caddyfile"
fi
if docker exec -w /etc/caddy "$CADDY_CONTAINER" caddy reload 2>/dev/null; then
echo " ✓ Caddy reloaded successfully"
echo ""
echo " Keycloak will be available at: https://$KC_CADDY_DOMAIN"
else
echo " ⚠ Failed to reload Caddy - check logs"
echo " Manual reload: cd $CADDY_DIR && docker exec -w /etc/caddy caddy caddy reload"
fi
else
echo " ⚠ Caddy container not running - start it to use this configuration"
fi
else
echo " Keycloak configuration already exists in Caddyfile"
fi
else
echo " ⚠ Caddyfile not found at $CADDY_DIR/Caddyfile"
echo " You can configure Caddy manually later"
fi
fi
fi
prompt_yn "Start Keycloak now? (y/n):" "y" START_KC
if [ "$START_KC" = "y" ] || [ "$START_KC" = "Y" ]; then
echo " Starting Keycloak (this may take a minute)..."