The host's Caddyfile gathers each game's site from /etc/caddy/sites/; Wiz-War's is rendered from deploy/Caddyfile.tmpl and logs to wizwar-access.log, which the rollup and the pulse read. The server's memory cap drops from 700M to 350M (it runs in about 125M), so a runaway cannot starve other games sharing the box. Applied on the live droplet with its logs renamed in place. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jm2auWk6RP71CjaAb4FMoG
59 lines
2.5 KiB
Bash
Executable File
59 lines
2.5 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# One-time host setup. The host may be shared with the other games of
|
|
# Kestrel's Hall; this touches nothing of theirs. Copy it and Caddyfile.tmpl
|
|
# to the host and run ON it as root:
|
|
# bash setup-droplet.sh 'wizwar.kestrelsnest.social, wizwar.<host-ip>.sslip.io'
|
|
# The argument is Wiz-War's Caddy site address line: one name, or several
|
|
# separated by commas. Every name must already resolve to this host.
|
|
set -euo pipefail
|
|
HOST="${1:?usage: setup-droplet.sh <site address line>}"
|
|
|
|
apt-get update -q
|
|
apt-get install -qy curl git rsync
|
|
|
|
# Node 22
|
|
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
|
|
apt-get install -qy nodejs
|
|
|
|
# Caddy (auto-HTTPS)
|
|
apt-get install -qy debian-keyring debian-archive-keyring apt-transport-https
|
|
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \
|
|
| gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
|
|
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \
|
|
| tee /etc/apt/sources.list.d/caddy-stable.list
|
|
apt-get update -q && apt-get install -qy caddy
|
|
|
|
# App user + directories
|
|
id -u wizwar &>/dev/null || useradd -r -m -d /opt/wizwar-home wizwar
|
|
mkdir -p /opt/wizwar /var/lib/wizwar/rooms
|
|
chown -R wizwar:wizwar /opt/wizwar /var/lib/wizwar
|
|
|
|
# Caddy: the host's Caddyfile only gathers each game's site file, so this
|
|
# host can be shared with the other games of Kestrel's Hall. A Caddyfile
|
|
# that is neither Caddy's stock one nor that is a single-site host from
|
|
# before the shared layout: stop rather than overwrite it.
|
|
ROOT_CADDY='# Kestrel'"'"'s Hall: every game on this host brings its own site file.
|
|
import sites/*.caddy'
|
|
mkdir -p /etc/caddy/sites
|
|
if ! grep -q '^import sites/\*.caddy' /etc/caddy/Caddyfile 2>/dev/null; then
|
|
if [ -s /etc/caddy/Caddyfile ] && ! grep -q 'root \* /usr/share/caddy' /etc/caddy/Caddyfile; then
|
|
echo "/etc/caddy/Caddyfile holds another site; move it into /etc/caddy/sites/ first" >&2
|
|
exit 1
|
|
fi
|
|
printf '%s\n' "$ROOT_CADDY" > /etc/caddy/Caddyfile
|
|
fi
|
|
sed "s|__HOST__|$HOST|" "$(dirname "$0")/Caddyfile.tmpl" > /etc/caddy/sites/wizwar.caddy
|
|
caddy validate --config /etc/caddy/Caddyfile
|
|
# Validation as root touches the access logs; Caddy runs as caddy and must own them.
|
|
chown -R caddy:caddy /var/lib/caddy
|
|
systemctl reload-or-restart caddy
|
|
|
|
# Firewall: ssh + web only. The game server binds loopback and is reached
|
|
# through Caddy; nothing else should answer the internet.
|
|
ufw allow OpenSSH
|
|
ufw allow 80/tcp
|
|
ufw allow 443/tcp
|
|
ufw --force enable
|
|
|
|
echo "droplet ready — now run deploy.sh from your machine"
|