Files
ubuntu-post-install/SCRIPT-FLOW-INTRO.txt
T
Claude 7cf82d5d28 Add no-keycloak and CrowdSec script variants; restore originals
Provide three tiers of the install script for both 24.04 and 26.04:

- Originals (ubuntu-post-install-24.04.sh / -26.04.sh): restored to their
  true original state, with Keycloak intact, as a fallback baseline. (This
  reverts the in-place Keycloak removal from the previous commit; the cleanup
  now lives in the -no-keycloak variants instead.)
- -no-keycloak.sh: Keycloak fully removed, Authelia as the SSO/2FA option.
- -crowdsec.sh: builds on -no-keycloak and replaces fail2ban entirely with
  CrowdSec (SSH via auth.log/sshd collection, Caddy via caddy collection + log
  acquisition, firewall bouncer for enforcement, plus geo-blocking and
  community IP-reputation blocklists).

Add SCRIPT-VARIANTS.md documenting the three tiers and how the Authelia /
fail2ban / CrowdSec security layers differ.

All variants pass 'bash -n'.

https://claude.ai/code/session_017eA2qqq9jfF2tNtpUYL8vK
2026-06-03 11:34:43 +00:00

60 lines
4.6 KiB
Plaintext

#!/bin/bash
# SCRIPT FLOW EXPLANATION FOR USERS
cat << 'EOF'
╔════════════════════════════════════════════════════════════════╗
║ Ubuntu Post-Install Setup Script ║
╚════════════════════════════════════════════════════════════════╝
This script is divided into TWO main phases:
┌────────────────────────────────────────────────────────────────┐
│ PHASE 1: ESSENTIAL SYSTEM SETUP (Required) │
├────────────────────────────────────────────────────────────────┤
│ These are installed/configured FIRST: │
│ ✓ System updates and essential packages │
│ ✓ OpenSSH server (remote access) │
│ ✓ rsync, curl, wget (core utilities) │
│ ✓ SSH key configuration │
│ ✓ Docker & Docker Compose (container platform) │
│ ✓ Hard drive mounting (storage setup) │
│ │
│ These are REQUIRED for everything else to work. │
└────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────┐
│ PHASE 2: SERVICE SELECTION MENU (Optional) │
├────────────────────────────────────────────────────────────────┤
│ After Phase 1, you'll see a CHECKBOX MENU where you can: │
│ • Select which services to INSTALL │
│ • Select which services to UNINSTALL │
│ • Skip services you don't want │
│ │
│ Services include: │
│ • Self-hosted apps (ActualBudget, Keycloak, Jellyfin, etc.) │
│ • Network services (Samba, VPNs, fail2ban) │
│ • Monitoring tools (Uptime Kuma, Portainer, Watchtower) │
│ • And many more... │
└────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────┐
│ RE-RUNNING THIS SCRIPT │
├────────────────────────────────────────────────────────────────┤
│ You can safely re-run this script on an already configured │
│ server: │
│ • Phase 1 will DETECT existing installations and skip them │
│ • Phase 2 menu will show ALL services (installed and not) │
│ • Select NEW services to add │
│ • Or select UNINSTALL to remove services │
│ │
│ The script is IDEMPOTENT - safe to run multiple times! │
└────────────────────────────────────────────────────────────────┘
Press ENTER to continue with Phase 1 (Essential Setup)...
EOF
read -p ""
# Now continue with the actual script...
EOF