296 lines
8.7 KiB
Bash
296 lines
8.7 KiB
Bash
#!/bin/bash
|
|
set -e
|
|
|
|
# ==============================================================================
|
|
# CENTRAL SERVER AUTOMATED INSTALLATION SCRIPT
|
|
# Installs: Tailscale, NodeJS, MeshCentral, Prometheus, Alertmanager, Grafana
|
|
# ==============================================================================
|
|
|
|
# --- CONFIGURATION VARIABLES ---
|
|
SMTP_EMAIL="no-reply@seekright.com"
|
|
SMTP_PASSWORD="clzfywewriqxlvqv"
|
|
ADMIN_EMAIL="kaushik@seekright.com"
|
|
ROCKETCHAT_WEBHOOK="https://text.seekright.com/hooks/6a05a268a88367bc6e0fe318/aNjZzmLy2wB3R4BR7ZtoLtAZYyfNyfLAoQMszmhfBDveKrB"
|
|
|
|
PROM_VERSION="2.51.2"
|
|
AM_VERSION="0.27.0"
|
|
# -------------------------------
|
|
|
|
if [ "$EUID" -ne 0 ]; then
|
|
echo "❌ Error: Please run this script with sudo."
|
|
exit 1
|
|
fi
|
|
|
|
# Get the actual user who ran sudo, so we don't put MeshCentral in /root
|
|
ACTUAL_USER="${SUDO_USER:-root}"
|
|
ACTUAL_HOME=$(eval echo ~$ACTUAL_USER)
|
|
|
|
echo "======================================"
|
|
echo "🚀 Starting Central Server Setup..."
|
|
echo "======================================"
|
|
|
|
echo "1. System Preparation..."
|
|
apt-get update -yq
|
|
# Disable sleep and hibernate (critical for a server)
|
|
systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target >/dev/null 2>&1
|
|
|
|
echo "======================================"
|
|
echo "2. Installing Tailscale..."
|
|
echo "======================================"
|
|
if ! command -v tailscale &> /dev/null; then
|
|
curl -fsSL https://tailscale.com/install.sh | sh
|
|
fi
|
|
|
|
echo ""
|
|
echo "⚠️ TAILSCALE AUTHENTICATION REQUIRED ⚠️"
|
|
echo "A URL will appear below. Open it in your browser and log in."
|
|
echo "DO NOT PRESS Ctrl+C! The script will automatically continue after you log in."
|
|
echo ""
|
|
tailscale up
|
|
|
|
TAILSCALE_IP=$(tailscale ip -4)
|
|
echo "✅ Tailscale connected! Server IP: $TAILSCALE_IP"
|
|
|
|
echo "======================================"
|
|
echo "3. Installing NodeJS & MeshCentral..."
|
|
echo "======================================"
|
|
if ! command -v node &> /dev/null; then
|
|
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
|
|
apt-get install -yq nodejs
|
|
fi
|
|
|
|
# Install MeshCentral in the user's home directory
|
|
mkdir -p "$ACTUAL_HOME/meshcentral/meshcentral-data"
|
|
cd "$ACTUAL_HOME/meshcentral"
|
|
# Run npm install as the actual user to avoid root permission issues
|
|
sudo -u "$ACTUAL_USER" npm install meshcentral
|
|
|
|
# Create MeshCentral config
|
|
cat > "$ACTUAL_HOME/meshcentral/meshcentral-data/config.json" << EOF
|
|
{
|
|
"settings": {
|
|
"cert": "$TAILSCALE_IP",
|
|
"port": 4430,
|
|
"redirport": 4431
|
|
},
|
|
"domains": {
|
|
"": {
|
|
"title": "My RMM"
|
|
}
|
|
}
|
|
}
|
|
EOF
|
|
chown -R "$ACTUAL_USER:$ACTUAL_USER" "$ACTUAL_HOME/meshcentral"
|
|
|
|
# Create MeshCentral Systemd Service
|
|
cat > /etc/systemd/system/meshcentral.service << EOF
|
|
[Unit]
|
|
Description=MeshCentral RMM Server
|
|
After=network.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=$ACTUAL_USER
|
|
WorkingDirectory=$ACTUAL_HOME/meshcentral
|
|
ExecStart=/usr/bin/node $ACTUAL_HOME/meshcentral/node_modules/meshcentral
|
|
Restart=always
|
|
RestartSec=10
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
systemctl daemon-reload
|
|
systemctl enable --now meshcentral
|
|
|
|
echo "✅ MeshCentral installed and running on port 4430!"
|
|
|
|
echo "======================================"
|
|
echo "4. Installing Prometheus..."
|
|
echo "======================================"
|
|
cd /tmp
|
|
wget -q https://github.com/prometheus/prometheus/releases/download/v${PROM_VERSION}/prometheus-${PROM_VERSION}.linux-amd64.tar.gz
|
|
tar -xf prometheus-${PROM_VERSION}.linux-amd64.tar.gz
|
|
mv prometheus-${PROM_VERSION}.linux-amd64/prometheus /usr/local/bin/
|
|
mv prometheus-${PROM_VERSION}.linux-amd64/promtool /usr/local/bin/
|
|
mkdir -p /etc/prometheus /var/lib/prometheus
|
|
|
|
# Prometheus config
|
|
cat > /etc/prometheus/prometheus.yml << 'EOF'
|
|
global:
|
|
scrape_interval: 15s
|
|
evaluation_interval: 15s
|
|
|
|
alerting:
|
|
alertmanagers:
|
|
- static_configs:
|
|
- targets: ['localhost:9093']
|
|
|
|
rule_files:
|
|
- "/etc/prometheus/rules.yml"
|
|
|
|
scrape_configs:
|
|
- job_name: 'prometheus'
|
|
static_configs:
|
|
- targets: ['localhost:9090']
|
|
EOF
|
|
|
|
# Alert Rules
|
|
cat > /etc/prometheus/rules.yml << 'EOF'
|
|
groups:
|
|
- name: server_alerts
|
|
rules:
|
|
- alert: ServerDown
|
|
expr: up == 0
|
|
for: 1m
|
|
labels:
|
|
severity: critical
|
|
annotations:
|
|
summary: "Server {{ $labels.instance }} is DOWN"
|
|
description: "{{ $labels.instance }} has been unreachable for over 1 minute."
|
|
|
|
- alert: HighCPU
|
|
expr: 100 - (avg by(instance)(rate(node_cpu_seconds_total{mode="idle"}[5m])) * 100) > 85
|
|
for: 5m
|
|
labels:
|
|
severity: warning
|
|
annotations:
|
|
summary: "High CPU on {{ $labels.instance }}"
|
|
|
|
- alert: HighRAM
|
|
expr: (1 - (node_memory_MemAvailable_bytes / node_memory_MemTotal_bytes)) * 100 > 90
|
|
for: 5m
|
|
labels:
|
|
severity: warning
|
|
annotations:
|
|
summary: "High RAM on {{ $labels.instance }}"
|
|
|
|
- alert: LowDisk
|
|
expr: (node_filesystem_avail_bytes{mountpoint="/"} / node_filesystem_size_bytes{mountpoint="/"}) * 100 < 15
|
|
for: 5m
|
|
labels:
|
|
severity: warning
|
|
annotations:
|
|
summary: "Low disk on {{ $labels.instance }}"
|
|
EOF
|
|
|
|
# Prometheus Systemd Service
|
|
cat > /etc/systemd/system/prometheus.service << 'EOF'
|
|
[Unit]
|
|
Description=Prometheus Monitoring
|
|
After=network.target
|
|
|
|
[Service]
|
|
User=root
|
|
ExecStart=/usr/local/bin/prometheus \
|
|
--config.file=/etc/prometheus/prometheus.yml \
|
|
--storage.tsdb.path=/var/lib/prometheus \
|
|
--storage.tsdb.retention.time=30d \
|
|
--storage.tsdb.retention.size=15GB \
|
|
--web.listen-address=0.0.0.0:9090 \
|
|
--web.enable-lifecycle
|
|
Restart=always
|
|
RestartSec=5
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
systemctl daemon-reload
|
|
systemctl enable --now prometheus
|
|
echo "✅ Prometheus installed and running on port 9090!"
|
|
|
|
echo "======================================"
|
|
echo "5. Installing Alertmanager..."
|
|
echo "======================================"
|
|
cd /tmp
|
|
wget -q https://github.com/prometheus/alertmanager/releases/download/v${AM_VERSION}/alertmanager-${AM_VERSION}.linux-amd64.tar.gz
|
|
tar -xf alertmanager-${AM_VERSION}.linux-amd64.tar.gz
|
|
mv alertmanager-${AM_VERSION}.linux-amd64/alertmanager /usr/local/bin/
|
|
mv alertmanager-${AM_VERSION}.linux-amd64/amtool /usr/local/bin/
|
|
mkdir -p /etc/alertmanager /var/lib/alertmanager
|
|
|
|
# Alertmanager config (Injecting variables)
|
|
cat > /etc/alertmanager/alertmanager.yml << EOF
|
|
global:
|
|
resolve_timeout: 5m
|
|
smtp_smarthost: "smtp.gmail.com:587"
|
|
smtp_from: "${SMTP_EMAIL}"
|
|
smtp_auth_username: "${SMTP_EMAIL}"
|
|
smtp_auth_password: "${SMTP_PASSWORD}"
|
|
|
|
route:
|
|
receiver: "fallback-do-nothing"
|
|
group_wait: 10s
|
|
group_interval: 1m
|
|
repeat_interval: 1m
|
|
routes:
|
|
- receiver: "rocket-chat-alerts"
|
|
continue: true
|
|
- receiver: "email-alerts"
|
|
continue: true
|
|
|
|
receivers:
|
|
- name: "fallback-do-nothing"
|
|
|
|
- name: "rocket-chat-alerts"
|
|
webhook_configs:
|
|
- url: "${ROCKETCHAT_WEBHOOK}"
|
|
send_resolved: true
|
|
|
|
- name: "email-alerts"
|
|
email_configs:
|
|
- to: "${ADMIN_EMAIL}"
|
|
send_resolved: true
|
|
EOF
|
|
|
|
# Alertmanager Systemd Service
|
|
cat > /etc/systemd/system/alertmanager.service << 'EOF'
|
|
[Unit]
|
|
Description=Alertmanager
|
|
After=network.target
|
|
|
|
[Service]
|
|
User=root
|
|
ExecStart=/usr/local/bin/alertmanager \
|
|
--config.file=/etc/alertmanager/alertmanager.yml \
|
|
--storage.path=/var/lib/alertmanager
|
|
Restart=always
|
|
RestartSec=5
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
systemctl daemon-reload
|
|
systemctl enable --now alertmanager
|
|
echo "✅ Alertmanager installed and running on port 9093!"
|
|
|
|
echo "======================================"
|
|
echo "6. Installing Grafana..."
|
|
echo "======================================"
|
|
if ! command -v grafana-server &> /dev/null; then
|
|
apt-get install -y apt-transport-https software-properties-common wget
|
|
mkdir -p /etc/apt/keyrings/
|
|
wget -q -O - https://apt.grafana.com/gpg.key | gpg --dearmor | sudo tee /etc/apt/keyrings/grafana.gpg > /dev/null
|
|
echo "deb [signed-by=/etc/apt/keyrings/grafana.gpg] https://apt.grafana.com stable main" | tee /etc/apt/sources.list.d/grafana.list
|
|
apt-get update -yq
|
|
apt-get install -yq grafana
|
|
fi
|
|
systemctl enable --now grafana-server
|
|
echo "✅ Grafana installed and running on port 3000!"
|
|
|
|
echo "======================================"
|
|
echo "🔍 Verifying All Services..."
|
|
echo "======================================"
|
|
sleep 3
|
|
echo "Service Status:"
|
|
systemctl is-active tailscaled meshcentral prometheus alertmanager grafana-server | sed 's/^/ - /'
|
|
|
|
echo "======================================"
|
|
echo "🎉 Central Server Installation Complete!"
|
|
echo "======================================"
|
|
echo "Access your services:"
|
|
echo "• MeshCentral: https://$TAILSCALE_IP:4430"
|
|
echo "• Grafana: http://$TAILSCALE_IP:3000 (login: admin/admin)"
|
|
echo "• Prometheus: http://$TAILSCALE_IP:9090"
|
|
echo "• Alerts: http://$TAILSCALE_IP:9093"
|
|
echo "======================================"
|