#!/usr/bin/env bash # One-time droplet setup. Run ON the droplet as root: # bash setup-droplet.sh wizwar..sslip.io set -euo pipefail HOST="${1:?usage: setup-droplet.sh }" apt-get update -q apt-get install -qy curl git rsync # Node 22 curl -fsSL https://deb.nodesource.com/setup_22.x | bash - apt-get install -qy nodejs # Caddy (auto-HTTPS) apt-get install -qy debian-keyring debian-archive-keyring apt-transport-https curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \ | gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \ | tee /etc/apt/sources.list.d/caddy-stable.list apt-get update -q && apt-get install -qy caddy # App user + directories id -u wizwar &>/dev/null || useradd -r -m -d /opt/wizwar-home wizwar mkdir -p /opt/wizwar /var/lib/wizwar/rooms chown -R wizwar:wizwar /opt/wizwar /var/lib/wizwar # Caddy vhost: auto-TLS, security headers, proxy to the game. printf '%s\n\nheader {\n\tStrict-Transport-Security "max-age=31536000"\n\tX-Content-Type-Options "nosniff"\n\tX-Frame-Options "DENY"\n\tReferrer-Policy "no-referrer"\n}\nreverse_proxy localhost:8787\n' "$HOST" > /etc/caddy/Caddyfile systemctl reload caddy # Firewall: ssh + web only. The game server binds loopback and is reached # through Caddy; nothing else should answer the internet. ufw allow OpenSSH ufw allow 80/tcp ufw allow 443/tcp ufw --force enable echo "droplet ready — now run deploy.sh from your machine"