renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 8s
ci / lint-actionlint (push) Successful in 7s
ci / lint-shellcheck (push) Successful in 10s
ci / lint-prettier (push) Successful in 14s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 11s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 7s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 8s
ci / lint-actionlint (pull_request) Successful in 4s
ci / lint-shellcheck (pull_request) Successful in 6s
ci / lint-prettier (pull_request) Successful in 14s
ci / lint-ruff (pull_request) Successful in 6s
ci / lint-yaml (pull_request) Successful in 9s
ci / lint-dockerfiles (pull_request) Successful in 5s
ci / validate (pull_request) Successful in 6s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 10s
110 lines
2.4 KiB
Bash
Executable File
110 lines
2.4 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
umask 077
|
|
|
|
TEMPLATE_PATH=/opt/netbird/config.template.yaml
|
|
RENDERED_PATH=/run/netbird/config.yaml
|
|
RELAY_SECRET_PATH=/run/secrets/relay_auth_secret
|
|
ENCRYPTION_KEY_PATH=/run/secrets/datastore_encryption_key
|
|
|
|
is_valid_proxy_subnet() {
|
|
candidate="$1"
|
|
case "$candidate" in
|
|
0.0.0.0/0)
|
|
return 1
|
|
;;
|
|
*/*)
|
|
address="${candidate%%/*}"
|
|
prefix="${candidate#*/}"
|
|
;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
|
|
case "$prefix" in
|
|
0|[1-9]|[1-2][0-9]|3[0-2]) ;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
|
|
old_ifs="$IFS"
|
|
IFS=.
|
|
# shellcheck disable=SC2086
|
|
set -- $address
|
|
IFS="$old_ifs"
|
|
[ "$#" -eq 4 ] || return 1
|
|
|
|
for octet do
|
|
case "$octet" in
|
|
0|[1-9]|[1-9][0-9]|1[0-9][0-9]|2[0-4][0-9]|25[0-5]) ;;
|
|
*)
|
|
return 1
|
|
;;
|
|
esac
|
|
done
|
|
}
|
|
|
|
read_secret() {
|
|
secret_path="$1"
|
|
|
|
if [ ! -r "$secret_path" ]; then
|
|
echo "Required secret is not readable: $secret_path" >&2
|
|
exit 1
|
|
fi
|
|
|
|
secret_value="$(cat "$secret_path")"
|
|
if [ -z "$secret_value" ]; then
|
|
echo "Required secret is empty: $secret_path" >&2
|
|
exit 1
|
|
fi
|
|
|
|
printf '%s' "$secret_value"
|
|
}
|
|
|
|
if [ -z "${NETBIRD_DOMAIN:-}" ]; then
|
|
echo "NETBIRD_DOMAIN must be set" >&2
|
|
exit 1
|
|
fi
|
|
|
|
case "$NETBIRD_DOMAIN" in
|
|
*[!A-Za-z0-9.-]*)
|
|
echo "NETBIRD_DOMAIN contains unsupported characters" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
if [ -z "${NETBIRD_PROXY_SUBNET:-}" ] || [ "$NETBIRD_PROXY_SUBNET" = "auto" ]; then
|
|
echo "NETBIRD_PROXY_SUBNET must be an explicit IPv4 CIDR; run netbird/setup.sh first" >&2
|
|
exit 1
|
|
fi
|
|
if ! is_valid_proxy_subnet "$NETBIRD_PROXY_SUBNET"; then
|
|
echo "NETBIRD_PROXY_SUBNET must be a non-default IPv4 CIDR, for example 172.20.0.0/16" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$#" -ne 2 ] || [ "$1" != "--config" ] || [ "$2" != "$RENDERED_PATH" ]; then
|
|
echo "Expected: --config $RENDERED_PATH" >&2
|
|
exit 1
|
|
fi
|
|
|
|
relay_secret="$(read_secret "$RELAY_SECRET_PATH")"
|
|
encryption_key="$(read_secret "$ENCRYPTION_KEY_PATH")"
|
|
|
|
mkdir -p "$(dirname "$RENDERED_PATH")"
|
|
sed \
|
|
-e "s|__NETBIRD_DOMAIN__|${NETBIRD_DOMAIN}|g" \
|
|
-e "s|__NETBIRD_AUTH_SECRET__|${relay_secret}|g" \
|
|
-e "s|__NETBIRD_ENCRYPTION_KEY__|${encryption_key}|g" \
|
|
-e "s|__NETBIRD_PROXY_SUBNET__|${NETBIRD_PROXY_SUBNET}|g" \
|
|
"$TEMPLATE_PATH" >"$RENDERED_PATH"
|
|
|
|
if grep -q '__NETBIRD_' "$RENDERED_PATH"; then
|
|
echo "Rendered NetBird configuration still contains unresolved placeholders" >&2
|
|
exit 1
|
|
fi
|
|
|
|
exec /go/bin/netbird-server "$@"
|