All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s
- Deleted flow_identity.py and nfstream_flow_worker.py as they are no longer needed. - Removed nfstream_manager.py and its associated logic for managing NFStream workers. - Added tshark_manager.py to manage tshark packet enrichment and matching. - Updated setup_build_server.sh to include default environment variables for tshark. - Implemented packet signature generation and enrichment logic in the new TsharkManager class.
235 lines
6.2 KiB
Bash
Executable File
235 lines
6.2 KiB
Bash
Executable File
#!/bin/bash
|
|
set -e
|
|
|
|
# -----------------------------
|
|
# Variablen anpassen
|
|
# -----------------------------
|
|
REPO_URL="https://gitea.malmert.de/marcus/mitm-webserver.git"
|
|
APP_DIR="/opt/mitm-webserver"
|
|
FRONTEND_DIR="$APP_DIR/frontend"
|
|
BACKEND_DIR="$APP_DIR/backend"
|
|
BACKEND_SERVICE="mitm-backend"
|
|
NGINX_SITE="/etc/nginx/sites-available/mitm-webserver"
|
|
USER_ROOT="root"
|
|
BACKEND_ENV_FILE="$BACKEND_DIR/.env"
|
|
|
|
GITEA_RUNNER_URL="https://gitea.malmert.de//api/v1/repos/marcus/mitm-webserver/actions/runners/register"
|
|
RUNNER_TOKEN="cThC2xmAZWaOAqRRMENuVVTJckxaHiJxVGx2NCQY"
|
|
RUNNER_NAME="mitm-runner"
|
|
|
|
NODE_VERSION="lts/*" # aktuelle LTS Version
|
|
PYTHON_VERSION="3" # aktuelle Python 3 Version
|
|
|
|
# -----------------------------
|
|
# System aktualisieren & Pakete installieren
|
|
# -----------------------------
|
|
echo "==> Update & Upgrade"
|
|
apt update && apt upgrade -y
|
|
DEBIAN_FRONTEND=noninteractive apt install -y git curl build-essential nginx python3 python3-pip python3-venv unzip wget python3-dev \
|
|
libpcap-dev autoconf automake libtool pkg-config libjson-c-dev gettext flex bison libnuma-dev \
|
|
libpcre2-dev libmaxminddb-dev librrd-dev python3-bpfcc bpfcc-tools linux-headers-generic tshark \
|
|
clang llvm libelf-dev libbpf-dev iproute2
|
|
DEBIAN_FRONTEND=noninteractive apt install -y linux-headers-$(uname -r) || DEBIAN_FRONTEND=noninteractive apt install -y linux-headers-generic
|
|
|
|
# -----------------------------
|
|
# Node.js installieren (LTS)
|
|
# -----------------------------
|
|
echo "==> Install Node.js LTS"
|
|
curl -fsSL https://deb.nodesource.com/setup_lts.x | bash -
|
|
apt install -y nodejs
|
|
|
|
# -----------------------------
|
|
# Repository clonen / pull
|
|
# -----------------------------
|
|
echo "==> Setup repository"
|
|
if [ ! -d "$APP_DIR" ]; then
|
|
git clone "$REPO_URL" "$APP_DIR"
|
|
else
|
|
cd "$APP_DIR"
|
|
git reset --hard
|
|
git pull
|
|
fi
|
|
|
|
# -----------------------------
|
|
# Frontend bauen
|
|
# -----------------------------
|
|
echo "==> Build Frontend"
|
|
cd "$FRONTEND_DIR"
|
|
npm install
|
|
npm run build
|
|
|
|
# -----------------------------
|
|
# Backend vorbereiten
|
|
# -----------------------------
|
|
echo "==> Setup Backend"
|
|
cd "$BACKEND_DIR"
|
|
python3 -m venv venv
|
|
source venv/bin/activate
|
|
pip install --upgrade pip
|
|
|
|
cd "$BACKEND_DIR"
|
|
pip install -r requirements.txt
|
|
deactivate
|
|
|
|
# -----------------------------
|
|
# Backend Environment Defaults
|
|
# -----------------------------
|
|
echo "==> Write backend environment defaults"
|
|
cat >"$BACKEND_ENV_FILE" <<EOL
|
|
BACKEND_TSHARK_ENABLED=true
|
|
BACKEND_TSHARK_DISPLAY_FILTER=http or tls or dns
|
|
BACKEND_TSHARK_CACHE_TTL_SECONDS=5.0
|
|
BACKEND_TSHARK_MATCH_WINDOW_MS=1500
|
|
BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS=2.0
|
|
BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS=3.0
|
|
EOL
|
|
|
|
# -----------------------------
|
|
# Systemd Service für Backend
|
|
# -----------------------------
|
|
echo "==> Setup Systemd Service"
|
|
cat >/etc/systemd/system/$BACKEND_SERVICE.service <<EOL
|
|
[Unit]
|
|
Description=MITM Backend
|
|
After=network.target
|
|
|
|
[Service]
|
|
User=$USER_ROOT
|
|
WorkingDirectory=$BACKEND_DIR
|
|
EnvironmentFile=-$BACKEND_DIR/.env
|
|
ExecStart=$BACKEND_DIR/venv/bin/uvicorn src.main:app --host 127.0.0.1 --port 8000
|
|
Restart=always
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOL
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable $BACKEND_SERVICE
|
|
systemctl restart $BACKEND_SERVICE
|
|
|
|
# -----------------------------
|
|
# Nginx Setup
|
|
# -----------------------------
|
|
echo "==> Configure Nginx"
|
|
cat >$NGINX_SITE <<EOL
|
|
server {
|
|
listen 80;
|
|
|
|
server_name _;
|
|
|
|
# Frontend
|
|
root $FRONTEND_DIR/dist;
|
|
index index.html;
|
|
|
|
location / {
|
|
try_files \$uri /index.html;
|
|
}
|
|
|
|
# Backend API
|
|
location /api/ {
|
|
proxy_pass http://127.0.0.1:8000/api/;
|
|
proxy_set_header Host \$host;
|
|
proxy_set_header X-Real-IP \$remote_addr;
|
|
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto \$scheme;
|
|
|
|
# Websocket support if needed
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade \$http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
}
|
|
}
|
|
EOL
|
|
|
|
ln -sf $NGINX_SITE /etc/nginx/sites-enabled/
|
|
|
|
DEFAULT_SITE="/etc/nginx/sites-enabled/default"
|
|
if [ -L "$DEFAULT_SITE" ] || [ -f "$DEFAULT_SITE" ]; then
|
|
echo "==> Entferne Nginx Default-Site"
|
|
sudo rm -f "$DEFAULT_SITE"
|
|
fi
|
|
nginx -t
|
|
systemctl restart nginx
|
|
|
|
# -----------------------------
|
|
# Gitea Act Runner installieren
|
|
# -----------------------------
|
|
echo "==> Install Gitea Act Runner"
|
|
RUNNER_DIR="/opt/gitea-act-runner"
|
|
mkdir -p "$RUNNER_DIR"
|
|
cd "$RUNNER_DIR"
|
|
|
|
# Binary herunterladen
|
|
GITEA_RUNNER_BIN="act_runner-0.2.13-linux-amd64"
|
|
wget -O $GITEA_RUNNER_BIN "https://gitea.com/gitea/act_runner/releases/download/v0.2.13/act_runner-0.2.13-linux-amd64"
|
|
chmod +x $GITEA_RUNNER_BIN
|
|
mv $GITEA_RUNNER_BIN act_runner
|
|
|
|
# Runner registrieren
|
|
./act_runner register --instance "https://gitea.malmert.de/" --token "$RUNNER_TOKEN" --name "$RUNNER_NAME" --labels "self-hosted:host" --no-interactive
|
|
|
|
# Systemd-Service einrichten
|
|
cat >/etc/systemd/system/gitea-act-runner.service <<EOL
|
|
[Unit]
|
|
Description=Gitea Actions Runner (act_runner)
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
ExecStartPre=/bin/sleep 10
|
|
ExecStart=$RUNNER_DIR/act_runner daemon
|
|
WorkingDirectory=$RUNNER_DIR
|
|
Restart=always
|
|
User=root
|
|
# Du kannst auch einen dedizierten "act_runner"-User erstellen, falls du nicht als root laufen willst.
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOL
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable gitea-act-runner
|
|
systemctl start gitea-act-runner
|
|
|
|
echo "==> Gitea Act Runner installiert & gestartet"
|
|
|
|
# -----------------------------
|
|
# Gitea Runner Job Script
|
|
# -----------------------------
|
|
echo "==> Setup auto-build script"
|
|
BUILD_SCRIPT="$RUNNER_DIR/build.sh"
|
|
cat >$BUILD_SCRIPT <<'EOL'
|
|
#!/bin/bash
|
|
set -e
|
|
|
|
APP_DIR="/opt/mitm-webserver"
|
|
FRONTEND_DIR="$APP_DIR/frontend"
|
|
BACKEND_DIR="$APP_DIR/backend"
|
|
BACKEND_SERVICE="mitm-backend"
|
|
|
|
cd $APP_DIR
|
|
git reset --hard
|
|
git pull
|
|
|
|
# Build Frontend
|
|
cd $FRONTEND_DIR
|
|
npm install
|
|
npm run build
|
|
|
|
# Backend Dependencies
|
|
cd $BACKEND_DIR
|
|
source venv/bin/activate
|
|
pip install -r requirements.txt
|
|
deactivate
|
|
|
|
# Restart backend
|
|
systemctl restart $BACKEND_SERVICE
|
|
EOL
|
|
|
|
chmod +x $BUILD_SCRIPT
|
|
|
|
echo "==> Setup complete! Gitea Runner will automatically build on push."
|
|
echo "Frontend: http://<server_ip>/"
|
|
echo "Backend API: http://<server_ip>/api/"
|