#!/usr/bin/env bash # Prepare local Compose configuration without replacing existing credentials. set -euo pipefail cd "$(dirname "${BASH_SOURCE[0]}")" umask 077 if [ ! -f .env ]; then cp .env.example .env fi if grep -q '^NETBIRD_PROXY_SUBNET=auto$' .env; then subnet="$(docker network inspect proxy --format '{{range .IPAM.Config}}{{println .Subnet}}{{end}}' | awk '/^[0-9]+\./ { print; exit }')" if [ -z "$subnet" ]; then echo "No IPv4 subnet found on the Docker proxy network. Set NETBIRD_PROXY_SUBNET in .env." >&2 exit 1 fi # The detected value must be safe to substitute into the env file. if [[ ! "$subnet" =~ ^[0-9.]+/[0-9]+$ ]]; then echo "Unexpected Docker network subnet: $subnet" >&2 exit 1 fi sed -i "s|^NETBIRD_PROXY_SUBNET=auto$|NETBIRD_PROXY_SUBNET=$subnet|" .env fi mkdir -p secrets chmod 700 secrets for name in relay-auth-secret datastore-encryption-key; do path="secrets/$name" if [ -e "$path" ]; then if [ ! -s "$path" ]; then echo "Existing secret is empty: $path. Restore it before continuing." >&2 exit 1 fi else openssl rand -base64 32 >"$path" fi chmod 600 "$path" done printf '%s\n' 'Local files are ready. Review .env, then run docker compose config --quiet.'