diff --git a/ct/defguard.sh b/ct/defguard.sh new file mode 100644 index 000000000..1fc574fa6 --- /dev/null +++ b/ct/defguard.sh @@ -0,0 +1,54 @@ +#!/usr/bin/env bash +_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main" +_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func" +source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func") +# Copyright (c) 2021-2026 community-scripts ORG +# Author: MickLesk (CanbiZ) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/DefGuard/defguard + +APP="Defguard" +var_tags="${var_tags:-vpn;wireguard;sso}" +var_cpu="${var_cpu:-2}" +var_ram="${var_ram:-2048}" +var_disk="${var_disk:-8}" +var_os="${var_os:-debian}" +var_version="${var_version:-13}" +var_arm64="${var_arm64:-yes}" +var_unprivileged="${var_unprivileged:-1}" + +header_info "$APP" +variables +color +catch_errors + +function update_script() { + header_info + check_container_storage + check_container_resources + + if [[ ! -f /etc/defguard/core.conf ]]; then + msg_error "No ${APP} Installation Found!" + exit + fi + + msg_info "Updating Defguard" + $STD apt update + $STD apt install -y defguard defguard-proxy + msg_ok "Updated Defguard" + + msg_info "Restarting Services" + systemctl restart defguard defguard-proxy + msg_ok "Restarted Services" + msg_ok "Updated successfully!" + exit +} + +start +build_container +description + +msg_ok "Completed Successfully!\n" +echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}" +echo -e "${INFO}${YW}Access it using the following URL:${CL}" +echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}" diff --git a/ct/headers/defguard b/ct/headers/defguard new file mode 100644 index 000000000..66f3a1ed0 --- /dev/null +++ b/ct/headers/defguard @@ -0,0 +1,6 @@ + ____ ____ __ + / __ \___ / __/___ ___ ______ __________/ / + / / / / _ \/ /_/ __ `/ / / / __ `/ ___/ __ / + / /_/ / __/ __/ /_/ / /_/ / /_/ / / / /_/ / +/_____/\___/_/ \__, /\__,_/\__,_/_/ \__,_/ + /____/ diff --git a/install/defguard-install.sh b/install/defguard-install.sh new file mode 100644 index 000000000..81918003b --- /dev/null +++ b/install/defguard-install.sh @@ -0,0 +1,78 @@ +#!/usr/bin/env bash + +# Copyright (c) 2021-2026 community-scripts ORG +# Author: MickLesk (CanbiZ) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/DefGuard/defguard + +source /dev/stdin <<<"$FUNCTIONS_FILE_PATH" +color +verb_ip6 +catch_errors +setting_up_container +network_check +update_os + +PG_VERSION="17" setup_postgresql +PG_DB_NAME="defguard" PG_DB_USER="defguard" setup_postgresql_db + +setup_deb822_repo \ + "defguard" \ + "https://apt.defguard.net/defguard.asc" \ + "https://apt.defguard.net" \ + "$(get_os_info codename)" \ + "release-2.0" + +msg_info "Installing Defguard" +$STD apt install -y defguard +msg_ok "Installed Defguard" + +msg_info "Configuring Defguard" +DEFGUARD_ADMIN_PASSWORD=$(openssl rand -base64 18) +cat </etc/defguard/core.conf +DEFGUARD_DB_HOST=localhost +DEFGUARD_DB_PORT=5432 +DEFGUARD_DB_NAME=defguard +DEFGUARD_DB_USER=defguard +DEFGUARD_DB_PASSWORD=${PG_DB_PASS} + +DEFGUARD_URL=http://${LOCAL_IP}:8000 +DEFGUARD_HTTP_PORT=8000 +DEFGUARD_GRPC_PORT=50055 + +DEFGUARD_DEFAULT_ADMIN_PASSWORD=${DEFGUARD_ADMIN_PASSWORD} +DEFGUARD_COOKIE_INSECURE=true +DEFGUARD_LOG_LEVEL=info +EOF +chown root:defguard /etc/defguard/core.conf +chmod 640 /etc/defguard/core.conf +systemctl restart defguard +msg_ok "Configured Defguard" + +msg_info "Installing Defguard Edge" +$STD apt install -y defguard-proxy +mkdir -p /etc/defguard/certs +cat </etc/defguard/proxy.toml +# Defguard Edge (proxy) configuration +# Apply changes with: systemctl restart defguard-proxy + +# Port the API/enrollment HTTP server listens on +http_port = 8080 +# Port the HTTPS server listens on (used after Core provisions TLS) +https_port = 8443 +# Port the gRPC server listens on. Core connects here to adopt and manage the Edge. +grpc_port = 50051 +# Directory where adoption-provisioned mTLS certificates are stored +cert_dir = "/etc/defguard/certs" + +log_level = "info" +rate_limit_per_second = 0 +rate_limit_burst = 0 +EOF +chown -R defguard:defguard /etc/defguard/certs /etc/defguard/proxy.toml +systemctl enable -q --now defguard-proxy +msg_ok "Installed Defguard Edge" + +motd_ssh +customize +cleanup_lxc