Commit Graph
305 Commits
Author SHA1 Message Date
Claude b6af49f1f1 Add optional ntfy ban alerts to CrowdSec variants
When configuring CrowdSec, optionally wire up an ntfy push notification via
CrowdSec's HTTP notification plugin: writes /etc/crowdsec/notifications/ntfy.yaml
and references it from the default profile in profiles.yaml. Alerts fire on a
ban decision (after repeated failed attempts), not on every failed login.

Document the behavior in SCRIPT-VARIANTS.md, including why Authelia (email-only)
doesn't cover failed-login push. Both crowdsec variants verified with 'bash -n'
and a --dry-run --unattended pass (exit 0).

https://claude.ai/code/session_017eA2qqq9jfF2tNtpUYL8vK
2026-06-03 12:05:13 +00:00
Claude 7cf82d5d28 Add no-keycloak and CrowdSec script variants; restore originals
Provide three tiers of the install script for both 24.04 and 26.04:

- Originals (ubuntu-post-install-24.04.sh / -26.04.sh): restored to their
  true original state, with Keycloak intact, as a fallback baseline. (This
  reverts the in-place Keycloak removal from the previous commit; the cleanup
  now lives in the -no-keycloak variants instead.)
- -no-keycloak.sh: Keycloak fully removed, Authelia as the SSO/2FA option.
- -crowdsec.sh: builds on -no-keycloak and replaces fail2ban entirely with
  CrowdSec (SSH via auth.log/sshd collection, Caddy via caddy collection + log
  acquisition, firewall bouncer for enforcement, plus geo-blocking and
  community IP-reputation blocklists).

Add SCRIPT-VARIANTS.md documenting the three tiers and how the Authelia /
fail2ban / CrowdSec security layers differ.

All variants pass 'bash -n'.

https://claude.ai/code/session_017eA2qqq9jfF2tNtpUYL8vK
2026-06-03 11:34:43 +00:00
Claude f564b4b6d8 Remove Keycloak; standardize on Authelia for SSO
Keycloak never reliably ran (fiddly reverse-proxy/hostname config) and the
repo has standardized on Authelia for SSO + 2FA. This rips Keycloak out
entirely:

- Delete the install block, whiptail menu entry, uninstall plumbing, and
  EXISTING_SERVICES detection from both 24.04 and 26.04 scripts
- Delete docker-compose-keycloak.yml, fix-keycloak-proxy.sh, and
  KEYCLOAK-SETUP-GUIDE.md
- Remove the Keycloak block from caddy-setup-helper.sh
- Update docs (CADDY-FAIL2BAN-SETUP.md, SECURITY-IMPROVEMENTS.md,
  NEW-SCRIPT-STRUCTURE.md, SCRIPT-FLOW-INTRO.txt) to reference Authelia

Also documents the fail2ban/Authelia overlap: Authelia handles failed-login
regulation (per-account lockout); the Caddy fail2ban jail is complementary
firewall-level IP banning. Neither does geo-blocking — noted CrowdSec / Caddy
GeoIP as the path for that.

https://claude.ai/code/session_017eA2qqq9jfF2tNtpUYL8vK
2026-06-03 03:44:26 +00:00
Outis c54cd9ecc6 Merge pull request #34 from outis1one/claude/zen-dirac-4vV0h
Claude/zen dirac 4v v0h
2026-06-02 14:48:17 -04:00
Claude a8dd0d78dd Install Caddy before Authelia so Caddyfile exists at Authelia setup time
Authelia's installer auto-injects the (authelia) snippet and auth portal
block into the Caddyfile. Moving Caddy first means that injection works
in a single fresh install run without manual follow-up.

https://claude.ai/code/session_01FvqXSZyk3g7rUombwLcprZ
2026-06-02 18:44:15 +00:00
Claude 49f91ac9c0 Fix Authelia authentication_backend config for 4.38+ format
The working authelia-setup repo uses the Authelia 4.38+ password
hashing config format with a nested argon2 block and variant key.
The previous version used the old flat format which is rejected by
Authelia 4.39.20 validation. Fix both 24.04 and 26.04 scripts.

  Before (broken):
    password:
      algorithm: argon2id
      iterations: 3
      ...

  After (correct for 4.38+):
    password:
      algorithm: argon2
      argon2:
        variant: argon2id
        iterations: 3
        ...

https://claude.ai/code/session_01FvqXSZyk3g7rUombwLcprZ
2026-06-02 17:56:39 +00:00
Claude 9e353eb921 Sync 24.04 and 26.04 scripts: rename, Authelia, NetBird SSH
- Rename ubuntu-post-install.sh → ubuntu-post-install-24.04.sh to match 26.04 naming convention
- Add --allow-server-ssh systemd override to 24.04 NetBird install (already in 26.04)
- Add full Authelia install block to 26.04 (matching what was added to 24.04)
  - Whiptail menu, uninstall, detection, default vars, parse flags, install block
- Both scripts now identical in Authelia and NetBird SSH behavior

https://claude.ai/code/session_01FvqXSZyk3g7rUombwLcprZ
2026-06-02 17:52:25 +00:00
Claude db8e83447a Add working Authelia SSO install based on authelia-setup repo
Ports the full working configuration from outis1one/authelia-setup:
- Authelia 4.39.20 on caddy_net with secrets via env var files
- Generates jwt/session/storage secrets with openssl at install time
- Prompts for domain, admin user, SMTP settings, timezone
- Generates argon2id password hash via Docker during install
- Writes configuration.yml, users.yml, docker-compose.yml, .env
- Auto-injects (authelia) snippet + auth portal block into Caddyfile
- Creates caddy_net Docker network if missing
- Adds Authelia to whiptail service menu, uninstall list, and detection
- Adds Authelia snippet as commented example in new Caddyfile template

https://claude.ai/code/session_01FvqXSZyk3g7rUombwLcprZ
2026-06-02 17:43:35 +00:00
Outis eac4f7c4f8 Merge pull request #33 from outis1one/claude/kind-knuth-j1AO6
Claude/kind knuth j1 ao6
2026-06-01 17:56:09 -04:00
Claude d790d09295 Persist --allow-server-ssh in netbird systemd override
Without --allow-server-ssh, NetBird prompts for re-authentication on
every SSH connection. This adds a systemd drop-in override at
/etc/systemd/system/netbird.service.d/ssh-server.conf so the flag
is set automatically on every boot without manual intervention.

https://claude.ai/code/session_017jFG5YuHf2CCGS5HiheoeM
2026-06-01 21:51:34 +00:00
Claude afb5d22d2e Update NetBird SSH for v0.60.0+ breaking change in 26.04 script
NetBird v0.60.0 removed the built-in SSH server ('netbird ssh <peer-name>').
SSH now routes through standard openssh-server via a drop-in config at
/etc/ssh/sshd_config.d/99-netbird.conf on port 22022.

- Ensure openssh-server is installed and enabled when NetBird is selected
- Remove all 'netbird ssh <peer-name>' references
- Update instructions: connect via 'ssh user@<netbird-ip>' using netbird status
- Note the dashboard step: Peers > [peer] > SSH to enable per-peer SSH access
- Applied across install section, SSH summary, and next-steps section

https://claude.ai/code/session_017jFG5YuHf2CCGS5HiheoeM
2026-06-01 21:49:06 +00:00
Outis dab2a8fe25 Merge pull request #32 from outis1one/claude/kind-knuth-j1AO6
Add ubuntu-post-install-26.04.sh for Ubuntu 26.04 LTS (Resolute Raccoon)
2026-06-01 16:45:34 -04:00
Claude 8a276337ab Add ubuntu-post-install-26.04.sh for Ubuntu 26.04 LTS (Resolute Raccoon)
Based on the 24.04 script with the following updates:
- Updated all version references from 24.04 to 26.04
- Fixed Tailscale APT repo from hardcoded 'jammy' to 'resolute' codename
  (was a latent bug even on 24.04; jammy is 22.04)
- All other repos (Docker, Kopia, NodeSource) already use dynamic
  VERSION_CODENAME detection and work as-is on 26.04

https://claude.ai/code/session_017jFG5YuHf2CCGS5HiheoeM
2026-06-01 20:43:24 +00:00
Outis 2ea93aab77 Merge pull request #31 from outis1one/claude/immich-external-library-yZbdk
Claude/immich external library y zbdk
2026-03-20 15:36:03 -04:00
Claude 947d9597e6 Require Node.js >= 20 for Immich CLI; install Node 22 LTS from NodeSource
The Immich CLI uses the File global class which requires Node.js v20+.
The script previously fell back to apt install nodejs which gives v18 on
Ubuntu and fails with "ReferenceError: File is not defined".

Now checks the Node.js major version first. If < 20, offers to install
Node.js 22 LTS from NodeSource before proceeding.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 07:15:51 +00:00
Claude d3d887a548 Fix Immich docker-compose: update DB image, create marker dirs, remove broken healthcheck
- Update database image from deprecated tensorchord/pgvecto-rs:pg14-v0.2.0
  to ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0
- Remove database command block (vectors.so) that blocks VectorChord from
  loading — the new image handles shared_preload_libraries internally
- Remove bogus healthcheck using non-existent googlechecksum function
- Create required subdirectories (thumbs, upload, backups, library, profile,
  encoded-video) with .immich marker files before first start — fixes
  ENOENT crash on encoded-video/.immich
- Update Valkey from 8-bookworm to 9-bookworm
- Fix status output: show UPLOAD_LOCATION instead of unset PHOTOS_DIR
  for external library strategy

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 06:56:48 +00:00
Claude 791c9a3c47 Fix YAML syntax error in Immich docker-compose templates
The healthcheck test value contained "googlechecksum: $$Chksum"
which YAML interprets as a mapping separator (colon-space in an
unquoted scalar). This caused "mapping values are not allowed in
this context" on the command line below it.

Fixed by using >- block scalar for the healthcheck test and
multi-line array format for the postgres command, matching the
official Immich docker-compose format.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 06:27:32 +00:00
Claude b591f44626 Skip already-configured services on rerun, respect whiptail selection
Three issues fixed:

1. SSH/VPN/Remote Desktop rerun detection: When services are already
   configured, ask a single "Reconfigure?" question instead of
   prompting through every individual service again.

2. Whiptail selection respected: When user selects specific services
   in the whiptail menu, skip all unrelated sections (linux-to-sync,
   Caddy Legacy, Kopia, local backup, cloud backup, UFW) instead of
   prompting for each one.

3. Import-photos.sh reminder: Clarify that import-photos.sh should
   be run AFTER the main setup script completes, not during.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 06:16:03 +00:00
Outis bd9773a374 Merge pull request #30 from outis1one/claude/immich-external-library-yZbdk
Add progress feedback to import-photos.sh scan step
2026-02-19 00:25:38 -05:00
Claude 28896fd194 Add progress feedback to import-photos.sh scan step
The find command to count photos can take a long time on large
collections or slow mounts. Added visible output so it doesn't
look like the script hung.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 05:24:32 +00:00
Outis d158b87be2 Merge pull request #29 from outis1one/claude/immich-external-library-yZbdk
Make apt upgrade optional; simplify Immich photo library prompts
2026-02-19 00:09:20 -05:00
Claude 0058af3242 Make apt upgrade optional; simplify Immich photo library prompts
- apt upgrade at end of script now prompts (default: no) instead of
  running unconditionally. This prevents unwanted package upgrades
  when running the script just to install a new service.

- Immich setup: ask "existing photos?" first (default: no) so fresh
  installs only get one path question. Strategy choice and path prompts
  now only appear when relevant to the chosen strategy.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 05:00:18 +00:00
Outis de411fabff Merge pull request #28 from outis1one/claude/immich-external-library-yZbdk
Claude/immich external library y zbdk
2026-02-18 23:30:11 -05:00
Claude 99a6843010 Ask strategy before photo location in Immich setup
The user should decide *what* they want (import vs external library)
before being asked *where* their photos are. The "what" frames the
context for the "where" question.

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 04:24:12 +00:00
Claude 5c37d23788 Clean up post-setup instructions: one step for import path
The import-photos.sh script creates the admin account via API, so
"Open browser and create admin account" is no longer needed for the
import path. Post-setup is now just:

  Import path (Strategy 1 + existing photos):
    "Run ~/docker/immich/import-photos.sh" — one step, no browser

  External library path (Strategy 2):
    Still requires web UI for library creation (3 steps)

  No existing photos:
    Still requires web UI for storage template (2 steps)

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 04:14:37 +00:00
Claude 89c484e0f2 Fully automate Immich import: account creation, API key, and upload
The import-photos.sh helper script now handles the entire setup flow
without requiring any manual web UI interaction:

1. Checks if Immich is initialized via /api/server/config
2. If uninitialized: creates admin account via /api/auth/admin-sign-up
   (prompts for email, password, name)
3. If already initialized: prompts for existing credentials
4. Logs in via /api/auth/login to get bearer token
5. Creates API key via /api/api-keys automatically
6. Configures storage template via /api/system-config (PUT)
7. Installs immich-cli (checks immich → npx → npm → offers apt install)
8. Runs recursive upload with EXIF date preservation

Also accepts an API key as argument to skip account setup for re-runs.

Fixes:
- Removed -f flag from curl calls that suppressed error details
- Fixed $? check after login (now uses if ! command pattern)
- Variable naming collision (INSTALL_NODE → INSTALL_NODE_YN)
- Post-setup instructions now just say "run the import script"
  instead of listing manual steps

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 04:10:17 +00:00
Outis 4f9348e86a Merge pull request #27 from outis1one/claude/immich-external-library-yZbdk
Rework Immich setup UX with strategy-based photo library flow
2026-02-18 23:07:00 -05:00
Claude ee145dc736 Add automated import-photos.sh helper script for existing photos
When Strategy 1 (unified library) is chosen with existing photos, the
setup now generates an import-photos.sh script that automates the entire
import process:

- Verifies Immich is running (API health check)
- Prompts for API key with validation
- Configures the storage template via API automatically (uses python3
  for JSON manipulation, falls back to manual instructions)
- Installs immich-cli via npx if Node.js available, offers to install
  Node.js if not
- Runs the upload with --recursive from the baked-in source path
- Shows photo count and progress

Also:
- Ask where existing photos currently live (separate from library path)
- Use that path for both the external library mount (Strategy 2) and
  the import script source (Strategy 1)
- Post-setup instructions reduced to 3 steps: create account, get API
  key, run import script
- .env comments reference the import script instead of raw CLI commands

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 03:23:15 +00:00
Claude 430a30ca18 Rework Immich setup UX with strategy-based photo library flow
Replace the confusing two-prompt (upload/external) configuration with a
cohesive strategy-based flow:

- One question for photo library path instead of two separate prompts
- Ask if user has existing photos, then present two clear strategies:
  [1] Import everything into Immich (unified library, recommended)
  [2] Keep existing photos in place (external library, read-only)
- Generate strategy-specific docker-compose.yml (no unused external
  mount when not needed)
- Strategy-specific .env files with relevant instructions only
- Fix nesting issue: external library uploads now go to sibling dir
  instead of subfolder (prevents duplicate scan)
- Unified post-setup instructions that match chosen strategy

https://claude.ai/code/session_01NAtxAkC5t6YVb3gcP1VcX8
2026-02-19 02:37:02 +00:00
outis1one 104ce83ac0 Merge pull request #26 from outis1one/claude/fix-docker-ownership-UIder
Improve fix-keycloak-proxy.sh to handle existing .env files
2026-01-12 23:36:59 -05:00
Claude 3620a3adf0 Improve fix-keycloak-proxy.sh to handle existing .env files
- Check for existing .env file instead of extracting from docker-compose
- Replace KC_PROXY with KC_PROXY_HEADERS in .env
- Add KC_PROXY_HEADERS if missing
- Remove KC_PROXY from docker-compose.yml if present
- Show current configuration before restart
- Handles both migration scenarios:
  1. Old config with KC_PROXY in .env
  2. Existing .env without proxy settings
2026-01-13 04:34:46 +00:00
outis1one f2fb658a1a Merge pull request #25 from outis1one/claude/fix-docker-ownership-UIder
Claude/fix docker ownership u ider
2026-01-12 23:30:40 -05:00
Claude b4cb82c0d7 Make fix-keycloak-proxy.sh executable 2026-01-13 03:40:18 +00:00
Claude 736c53b1db Update Keycloak to use v2 proxy headers (KC_PROXY_HEADERS)
- Replace deprecated KC_PROXY=edge with KC_PROXY_HEADERS=xforwarded
- Fixes 'Hostname v1 options [proxy] are still in use' warning
- Convert docker-compose-keycloak.yml to use .env file
- Remove hardcoded passwords from docker-compose.yml
- Add comprehensive .env template in comments
- Update deployment instructions and production checklist
- Resolves CORS and secure context warnings
- All credentials now in .env with proper security
2026-01-13 03:39:08 +00:00
Claude 6098bbc209 Add Keycloak proxy configuration fix script
- Fixes deprecated KC_PROXY warning
- Updates to KC_PROXY_HEADERS=xforwarded (v2)
- Migrates credentials to .env file
- Preserves existing passwords
- Automatic backup and restart
- Resolves 'Hostname v1 options [proxy] are still in use' warning
2026-01-13 03:36:54 +00:00
outis1one 75a07a2a9b Merge pull request #24 from outis1one/claude/fix-docker-ownership-UIder
Fix Docker ownership, Keycloak security, and .env file management
2026-01-12 19:53:50 -05:00
Claude ccb145103f Fix Docker ownership, Keycloak security, and .env file management
This comprehensive update addresses multiple security and usability issues:

## Docker Directory Ownership
- Added ensure_docker_dir_ownership() helper function
- Applied to ALL 25+ services (Immich, Keycloak, ActualBudget, Jellyfin,
  Emby, ARM, FileBrowser, MagicMirror, Lyrion, Mealie, Minecraft, Frigate,
  ntfy, Uptime Kuma, wg-easy, Traccar, Portainer, MeshCentral, FindMyDevice,
  Frigate-Notify, Watchtower, Kopia, Caddy)
- Fixed disaster recovery path (line 309) to set ownership
- Docker folders now owned by sudo user, not root
- Users can run docker commands without sudo

## Keycloak Security Improvements
- Implemented password validation with retry loop
- Password requirements: 12+ chars, alphanumeric only (no special chars)
- Auto-generate secure passwords by pressing ENTER
- Moved all credentials to .env file (no passwords in docker-compose.yml)
- Added production vs development mode selection
- Production mode uses 'start' command with hostname configuration
- Development mode uses 'start-dev' for testing only
- Proper KC_HOSTNAME configuration for public deployments
- Interactive prompts with clear security warnings

## Environment Variable Management
- ActualBudget now uses .env file for configuration
- Keycloak uses .env for admin and database passwords
- Consistent .env pattern across services
- Passwords no longer visible in docker-compose files
- Easier credential management and rotation

## Helper Functions
- ensure_docker_dir_ownership(): Fix ownership recursively
- generate_password(): Generate secure alphanumeric passwords
- validate_password(): Validate Keycloak-compatible passwords

## Documentation
- Added SECURITY-IMPROVEMENTS.md with comprehensive guide
- Password requirements and best practices
- Keycloak setup guide for ActualBudget on Pikapods
- Migration guide for existing services
- Troubleshooting section
- Verification checklist

## Integration Status
- Caddy2 reverse proxy: Already integrated via configure_caddy_for_service()
- fail2ban monitoring: Already configured with labels on all services
- HTTPS and security headers: Already implemented
- JSON logging for fail2ban: Already configured

All services now follow consistent patterns for ownership, credentials,
and security configuration. Script tested with bash -n for syntax errors.
2026-01-13 00:44:23 +00:00
outis1one bc1523db8e Merge pull request #23 from outis1one/claude/fix-magic-mirror-setup-LWG3r
Claude/fix magic mirror setup lwg3r
2026-01-12 13:41:45 -05:00
Claude 7cdd9345b5 Implement global drive detection - detect once, use everywhere
MAJOR IMPROVEMENT: Drive detection now happens ONCE at startup and
is reused by all services, instead of each service detecting separately.

1. **New detect_drives() Function:**
   - Runs once before service selection menu
   - Scans ~/drives directory for all mounted drives
   - Shows drive name, path, size, used space, available space
   - Sets global variables for all services to use

2. **Global Variables Set:**
   - PRIMARY_DRIVE: name of first drive (e.g., "storage1")
   - PRIMARY_DRIVE_PATH: full path to first drive
   - DRIVES_DETECTED: true/false
   - DRIVES_DIR: base drives directory
   - AVAILABLE_DRIVES_COUNT: number of drives

3. **Display Example:**
   ```
   ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
     DETECTED DRIVES
   ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

     ✓ storage1
       Path: /home/user/drives/storage1
       Size: 2.0T (Used: 800G, Available: 1.2T)

     ✓ backup
       Path: /home/user/drives/backup
       Size: 4.0T (Used: 1.5T, Available: 2.5T)

     Using 'storage1' as primary drive for default paths
   ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
   ```

4. **Updated Services to Use Global Detection:**
   - Immich: photos/immich-uploads
   - AudioBookshelf: audiobooks
   - Emby: media
   - Jellyfin: media
   - ARM: ripped
   - FileBrowser: (root browse)
   - LMS: music

5. **Benefits:**
   - Detect drives only once (faster)
   - Consistent paths across all services
   - Shows actual drive information (size, usage)
   - Falls back to $HOME if no ~/drives exists
   - All services use PRIMARY_DRIVE_PATH variable

This fixes user complaint:
"There is no ~/drives.... it should detect which drives are already
 in ~/drives and offer to use one of those"
2026-01-12 18:05:49 +00:00
Claude de4bbf4711 Apply reconfigure fix to ActualBudget
- Added check_service_exists() to ActualBudget
- Now shows Skip/Reconfigure/Restart options
- Prevents accidental overwrite of existing configurations

Progress: 6/24 services complete (Immich, AudioBookshelf, Emby, ARM, FileBrowser, ActualBudget)
2026-01-12 17:54:08 +00:00
Claude 53f0101f9b Apply reconfigure fix to ARM and FileBrowser services
- Added check_service_exists() to ARM (Automatic Ripping Machine)
- Added check_service_exists() to FileBrowser
- Both now show Skip/Reconfigure/Restart options
- Prevents accidental overwrite of existing configurations

Progress: 5/24 services complete (Immich, AudioBookshelf, Emby, ARM, FileBrowser)
2026-01-12 17:52:47 +00:00
Claude 4a7dd2e654 Add helper function and apply reconfigure fix to key services
1. **Created check_service_exists() Helper Function:**
   - Reusable function to check if service exists
   - Shows options: Skip / Reconfigure / Restart
   - Handles backup automatically on reconfigure
   - Returns boolean flag to control installation flow
   - Reduces code duplication across services

2. **Applied Reconfigure Fix to Services:**
   - Immich (with drive detection)
   - AudioBookshelf
   - Emby

3. **How It Works:**
   ```bash
   check_service_exists "ServiceName" "$SERVICE_DIR" RECONFIGURE_FLAG
   if [ "$RECONFIGURE_FLAG" = "true" ]; then
       # Only run configuration if true
   fi
   ```

4. **Benefits:**
   - Consistent behavior across all services
   - Automatic backup before any changes
   - Safe default (Skip) protects existing configs
   - Easy to apply to remaining services

Next: Apply to remaining 20+ services (ActualBudget, Mealie, Jellyfin, etc.)
2026-01-12 17:46:43 +00:00
Claude bbaec6b86d Fix critical reconfigure bug - detect existing installations and skip reinstall
CRITICAL FIX: Script was reinstalling and reconfiguring services from scratch
when they were already installed, potentially breaking existing configurations.

1. **Detect Existing Installations:**
   - Check for existing docker-compose.yml before configuration
   - Show options: Skip / Reconfigure / Restart only
   - Default to Skip to preserve existing configs

2. **Skip/Reconfigure/Restart Options:**
   - Option 1: Skip (keep existing configuration)
   - Option 2: Reconfigure (backup existing, then reconfigure)
   - Option 3: Restart containers only (no reconfiguration)

3. **Automatic Backup on Reconfigure:**
   - Creates timestamped backup before any changes
   - Backup location: ~/docker/backups/YYYYMMDD-HHMMSS-servicename/
   - Full service directory backed up

4. **Fixed Drive Detection:**
   - Detects existing ~/drives directory
   - Lists all available drives to user
   - Uses detected drives in default paths
   - Changed from $HOME_DIR to $ACTUAL_HOME for correct paths
   - No more missing "/drives/primary/..." paths

5. **Drive Path Examples:**
   - Detects: ~/drives/storage1, ~/drives/backup, ~/drives/media
   - Shows: "Detected drives: storage1, backup, media"
   - Default becomes: ~/drives/storage1/photos/immich-uploads

Applied to: Immich (template for other services)

This fixes user issues:
- "I selected keep the items that were already installed, then it lead
  me to reinstall configure from scratch all those services"
- "It did not detect if the service was already in the Caddyfile"
- "it might have messed up what I already had"
- "There is no ~/drives...."
- "it should detect which drives are already in ~/drives and offer to
  use one of those"
2026-01-12 17:41:29 +00:00
outis1one d925137fe6 Merge pull request #22 from outis1one/claude/fix-magic-mirror-setup-LWG3r
Add automatic Caddy configuration for services during installation
2026-01-12 12:17:02 -05:00
Claude 671a59bf12 Add automatic Caddy configuration for services during installation
Implemented automatic Caddy reverse proxy configuration that runs
BEFORE each service is started, with backup, reload, and formatting.

1. **New configure_caddy_for_service() Function:**
   - Detects if Caddy is installed (skips if not)
   - Prompts user if they want to configure reverse proxy
   - Asks for domain/subdomain (e.g., photos.example.com)
   - Backs up Caddyfile with timestamp
   - Checks for existing configuration and offers to overwrite
   - Adds service block with security headers and fail2ban logging
   - Reloads Caddy configuration
   - Formats Caddyfile with `caddy fmt --overwrite`
   - Final reload after formatting
   - Shows final access URL (https://...)

2. **Configuration Sequence:**
   - Service docker-compose.yml created
   - Service .env configured
   - Caddy configuration added (if Caddy installed)
   - Caddy reloaded and formatted
   - Service containers started
   - All happens before `docker compose up -d`

3. **Integrated into Services:**
   - Immich (photos.example.com)
   - AudioBookshelf (audiobooks.example.com)
   - Emby (emby.example.com)
   - ActualBudget (budget.example.com)
   - Mealie (recipes.example.com)
   - Jellyfin (jellyfin.example.com)
   - Uptime Kuma (uptime.example.com)

4. **Caddy Configuration Includes:**
   - Automatic HTTPS via Let's Encrypt
   - Security headers (HSTS, X-Content-Type-Options, etc.)
   - JSON logging for fail2ban
   - Proper reverse_proxy to localhost:PORT

5. **Backup & Safety:**
   - Caddyfile backed up to: Caddyfile.backup.YYYYMMDD-HHMMSS
   - Existing configs detected and user can choose to overwrite
   - Reload errors show backup file path for restoration

6. **Commands Used:**
   - `docker exec caddy caddy reload --config /etc/caddy/Caddyfile`
   - `docker exec caddy caddy fmt --overwrite /etc/caddy/Caddyfile`

This addresses user request:
"new/reconfigured services are add to the Caddyfile as part of the
install/reconfigure before they are attempt to be brought up, as a
part of the install/reconfigure of the service? (With backup of
Caddyfile and docker exec -w /etc/caddy caddy caddy reload &&
docker exec -w /etc/caddy caddy caddy fmt --overwrite after each
addition to Caddyfile?)"
2026-01-12 17:08:11 +00:00
outis1one cea7b57be6 Merge pull request #21 from outis1one/claude/fix-magic-mirror-setup-LWG3r
Claude/fix magic mirror setup lwg3r
2026-01-12 10:11:43 -05:00
Claude 52a9617ffe Add uninstall functionality and improve existing server detection
Added comprehensive uninstall functionality to whiptail menu:

1. **Install/Uninstall Menu Choice:**
   - Added action menu: Install new services, Uninstall existing, or Cancel
   - Automatically detects existing services in ~/docker/

2. **Smart Service Detection:**
   - Scans for existing Docker services and marks them in the install menu
   - Install menu shows [*] for already-installed services
   - Helps users identify what's already running on their server

3. **Uninstall Functionality:**
   - Uninstall menu only shows services that are currently installed
   - All services selected by default for quick removal
   - Automatic backup before uninstall to ~/docker/backups/
   - Stops containers, removes directories, backs up data
   - Special handling for system packages (fail2ban)

4. **Improved Re-run Support:**
   - Script detects existing installations on startup
   - Can rerun on configured servers to add new services
   - Uninstall option allows cleanup of unwanted services
   - Backups ensure data safety during removals

Services Supported:
- All 24 Docker services (Immich, Keycloak, Caddy, etc.)
- System packages (fail2ban)
- Backups created with timestamp: YYYYMMDD-HHMMSS-servicename

Usage Examples:
- Fresh install: Select services to install
- Add services: Rerun script, existing services auto-selected
- Remove services: Choose "Uninstall", select what to remove
- Cleanup: All data backed up automatically

This addresses user request for:
- Ability to reinstall on current server
- Option to remove services from whiptail menu
- Better handling of existing installations
2026-01-12 14:36:34 +00:00
Claude 5c9850e2a6 Add documentation for planned script restructuring
Added planning documents for future script reorganization:

NEW-SCRIPT-STRUCTURE.md:
- Outlines two-phase structure (Essential Setup vs Service Selection)
- Documents plan to move optional services to whiptail menu
- Plans for uninstall functionality
- Re-run detection improvements

SCRIPT-FLOW-INTRO.txt:
- Proposed intro text for users
- Explains Phase 1 (required) and Phase 2 (optional)
- Documents re-running behavior

These are planning documents for future enhancements.
Current commit only implements the duplicate prompt fix.
2026-01-12 14:09:32 +00:00
Claude 974b07f51e Fix duplicate prompts after whiptail menu selection
Applied WHIPTAIL_USED flag check to all 25 service prompts that appear
after the whiptail menu to prevent services from being prompted
individually when they weren't selected in the checkbox menu.

This fixes the issue where services like AudioBookshelf were being
prompted even when not selected in whiptail.

Services fixed:
- AudioBookshelf, Emby, ARM, FileBrowser, Magic Mirror
- ActualBudget, Keycloak, Caddy, fail2ban
- Lyrion Music Server, Mealie, Minecraft, Jellyfin, Frigate
- ddclient, ntfy, Uptime Kuma, wg-easy
- Traccar, Portainer, MeshCentral Server
- FindMyDevice, Frigate-Notify, Watchtower

Pattern applied:
  if [ "$WHIPTAIL_USED" != true ] && [ -z "$INSTALL_SERVICE" ]; then
      # Show prompt
  fi

This ensures prompts only appear when whiptail was not used OR
the service variable is not yet set.
2026-01-12 14:08:41 +00:00
outis1one f05f77c6f0 Merge pull request #20 from outis1one/claude/fix-magic-mirror-setup-LWG3r
Claude/fix magic mirror setup lwg3r
2026-01-11 23:42:51 -05:00