#!/usr/bin/env bash # One-time host setup. The host may be shared with the other games of # Kestrel's Hall; this touches nothing of theirs. Copy it and Caddyfile.tmpl # to the host and run ON it as root: # bash setup-droplet.sh 'wizwar.kestrelsnest.social, wizwar..sslip.io' # The argument is Wiz-War's Caddy site address line: one name, or several # separated by commas. Every name must already resolve to this host. set -euo pipefail HOST="${1:?usage: setup-droplet.sh }" apt-get update -q apt-get install -qy curl git rsync # Node 22 curl -fsSL https://deb.nodesource.com/setup_22.x | bash - apt-get install -qy nodejs # Caddy (auto-HTTPS) apt-get install -qy debian-keyring debian-archive-keyring apt-transport-https curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \ | gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \ | tee /etc/apt/sources.list.d/caddy-stable.list apt-get update -q && apt-get install -qy caddy # App user + directories id -u wizwar &>/dev/null || useradd -r -m -d /opt/wizwar-home wizwar mkdir -p /opt/wizwar /var/lib/wizwar/rooms chown -R wizwar:wizwar /opt/wizwar /var/lib/wizwar # Caddy: the host's Caddyfile only gathers each game's site file, so this # host can be shared with the other games of Kestrel's Hall. A Caddyfile # that is neither Caddy's stock one nor that is a single-site host from # before the shared layout: stop rather than overwrite it. ROOT_CADDY='# Kestrel'"'"'s Hall: every game on this host brings its own site file. import sites/*.caddy' mkdir -p /etc/caddy/sites if ! grep -q '^import sites/\*.caddy' /etc/caddy/Caddyfile 2>/dev/null; then if [ -s /etc/caddy/Caddyfile ] && ! grep -q 'root \* /usr/share/caddy' /etc/caddy/Caddyfile; then echo "/etc/caddy/Caddyfile holds another site; move it into /etc/caddy/sites/ first" >&2 exit 1 fi printf '%s\n' "$ROOT_CADDY" > /etc/caddy/Caddyfile fi sed "s|__HOST__|$HOST|" "$(dirname "$0")/Caddyfile.tmpl" > /etc/caddy/sites/wizwar.caddy caddy validate --config /etc/caddy/Caddyfile # Validation as root touches the access logs; Caddy runs as caddy and must own them. chown -R caddy:caddy /var/lib/caddy systemctl reload-or-restart caddy # Firewall: ssh + web only. The game server binds loopback and is reached # through Caddy; nothing else should answer the internet. ufw allow OpenSSH ufw allow 80/tcp ufw allow 443/tcp ufw --force enable echo "droplet ready — now run deploy.sh from your machine"