From 2f2a366661eba900373ff55fcbc69814c219c6f9 Mon Sep 17 00:00:00 2001 From: "push-app-to-main[bot]" <203845782+push-app-to-main[bot]@users.noreply.github.com> Date: Sat, 15 Aug 2026 06:12:45 +0000 Subject: [PATCH] Add securo (ct) --- ct/headers/securo | 6 ++ ct/securo.sh | 78 ++++++++++++++++++ install/securo-install.sh | 166 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 250 insertions(+) create mode 100644 ct/headers/securo create mode 100644 ct/securo.sh create mode 100644 install/securo-install.sh diff --git a/ct/headers/securo b/ct/headers/securo new file mode 100644 index 000000000..21ee88be5 --- /dev/null +++ b/ct/headers/securo @@ -0,0 +1,6 @@ + _____ + / ___/___ _______ ___________ + \__ \/ _ \/ ___/ / / / ___/ __ \ + ___/ / __/ /__/ /_/ / / / /_/ / +/____/\___/\___/\__,_/_/ \____/ + diff --git a/ct/securo.sh b/ct/securo.sh new file mode 100644 index 000000000..5ed7f2974 --- /dev/null +++ b/ct/securo.sh @@ -0,0 +1,78 @@ +#!/usr/bin/env bash +# Engine comes from community-scripts/core; this repo only ships the scripts. +# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core), +# so a fork or branch of core can be tested without editing this file. +_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func" +source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func") +# Copyright (c) 2021-2026 community-scripts ORG +# Author: MickLesk (CanbiZ) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/securo-finance/securo + +APP="Securo" +var_tags="${var_tags:-finance;self-hosted}" +var_cpu="${var_cpu:-2}" +var_ram="${var_ram:-4096}" +var_disk="${var_disk:-12}" +var_os="${var_os:-debian}" +var_version="${var_version:-13}" +#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified +var_unprivileged="${var_unprivileged:-1}" + +header_info "$APP" +variables +color +catch_errors + +function update_script() { + header_info + check_container_storage + check_container_resources + + if [[ ! -d /opt/securo ]]; then + msg_error "No ${APP} Installation Found!" + exit + fi + + if check_for_gh_release "securo" "securo-finance/securo"; then + msg_info "Stopping Services" + systemctl stop securo securo-worker securo-beat + msg_ok "Stopped Services" + + CLEAN_INSTALL=1 fetch_and_deploy_gh_release "securo" "securo-finance/securo" "tarball" + + msg_info "Updating Backend" + cd /opt/securo/backend + ln -sf /opt/securo_data/.env /opt/securo/backend/.env + $STD uv venv --python 3.12 /opt/securo/backend/.venv + $STD uv pip install --python /opt/securo/backend/.venv -e . + set -a + source /opt/securo_data/.env + set +a + $STD /opt/securo/backend/.venv/bin/alembic upgrade head + msg_ok "Updated Backend" + + msg_info "Rebuilding Frontend" + cd /opt/securo/frontend + export NODE_OPTIONS="--max-old-space-size=4096" + $STD npm install + $STD npm run build + msg_ok "Rebuilt Frontend" + + msg_info "Starting Services" + systemctl start securo securo-worker securo-beat + systemctl reload nginx + msg_ok "Started Services" + msg_ok "Updated successfully!" + fi + exit +} + +start +build_container +description + +msg_ok "Completed Successfully!\n" +echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}" +echo -e "${INFO}${YW}Access it using the following URL:${CL}" +echo -e "${GATEWAY}${BGN}https://${IP}${CL}" diff --git a/install/securo-install.sh b/install/securo-install.sh new file mode 100644 index 000000000..ed9554466 --- /dev/null +++ b/install/securo-install.sh @@ -0,0 +1,166 @@ +#!/usr/bin/env bash + +# Copyright (c) 2021-2026 community-scripts ORG +# Author: MickLesk (CanbiZ) +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/securo-finance/securo + +source /dev/stdin <<<"$FUNCTIONS_FILE_PATH" +color +verb_ip6 +catch_errors +setting_up_container +network_check +update_os + +msg_info "Installing Dependencies" +$STD apt install -y \ + nginx \ + redis-server \ + build-essential +systemctl enable -q --now redis-server +msg_ok "Installed Dependencies" + +PG_VERSION="16" PG_MODULES="pgvector" setup_postgresql +PG_DB_NAME="securo" PG_DB_USER="securo" PG_DB_EXTENSIONS="vector" setup_postgresql_db +NODE_VERSION="22" setup_nodejs +UV_PYTHON="3.12" setup_uv + +fetch_and_deploy_gh_release "securo" "securo-finance/securo" "tarball" + +msg_info "Setting up Backend" +cd /opt/securo/backend +$STD uv venv --python 3.12 /opt/securo/backend/.venv +$STD uv pip install --python /opt/securo/backend/.venv -e . +msg_ok "Set up Backend" + +msg_info "Configuring Securo" +mkdir -p /opt/securo_data +SECRET_KEY=$(openssl rand -hex 32) +cat </opt/securo_data/.env +DATABASE_URL=postgresql+asyncpg://securo:${PG_DB_PASS}@127.0.0.1:5432/securo +REDIS_URL=redis://127.0.0.1:6379/0 +SECRET_KEY=${SECRET_KEY} +DEBUG=false +FRONTEND_URL=https://${LOCAL_IP} +EOF +ln -sf /opt/securo_data/.env /opt/securo/backend/.env +set -a +source /opt/securo_data/.env +set +a +$STD /opt/securo/backend/.venv/bin/alembic upgrade head +msg_ok "Configured Securo" + +msg_info "Building Frontend (Patience)" +cd /opt/securo/frontend +export NODE_OPTIONS="--max-old-space-size=4096" +$STD npm install +$STD npm run build +msg_ok "Built Frontend" + +msg_info "Generating Self-Signed Certificate" +create_self_signed_cert "securo" +msg_ok "Generated Self-Signed Certificate" + +msg_info "Creating Services" +cat </etc/systemd/system/securo.service +[Unit] +Description=Securo Backend (FastAPI) +After=network-online.target postgresql.service redis-server.service +Wants=network-online.target + +[Service] +Type=simple +User=root +WorkingDirectory=/opt/securo/backend +EnvironmentFile=/opt/securo_data/.env +ExecStart=/opt/securo/backend/.venv/bin/uvicorn app.main:app --host 127.0.0.1 --port 8000 +Restart=always +RestartSec=5 + +[Install] +WantedBy=multi-user.target +EOF + +cat </etc/systemd/system/securo-worker.service +[Unit] +Description=Securo Celery Worker +After=network-online.target postgresql.service redis-server.service +Wants=network-online.target + +[Service] +Type=simple +User=root +WorkingDirectory=/opt/securo/backend +EnvironmentFile=/opt/securo_data/.env +ExecStart=/opt/securo/backend/.venv/bin/celery -A app.worker worker --loglevel=info --concurrency=2 +Restart=always +RestartSec=5 + +[Install] +WantedBy=multi-user.target +EOF + +cat </etc/systemd/system/securo-beat.service +[Unit] +Description=Securo Celery Beat +After=network-online.target postgresql.service redis-server.service +Wants=network-online.target + +[Service] +Type=simple +User=root +WorkingDirectory=/opt/securo/backend +EnvironmentFile=/opt/securo_data/.env +ExecStart=/opt/securo/backend/.venv/bin/celery -A app.worker beat --loglevel=info +Restart=always +RestartSec=5 + +[Install] +WantedBy=multi-user.target +EOF +systemctl enable -q --now securo securo-worker securo-beat +msg_ok "Created Services" + +msg_info "Configuring Nginx" +cat <<'EOF' >/etc/nginx/sites-available/securo.conf +server { + listen 80 default_server; + server_name _; + return 301 https://$host$request_uri; +} + +server { + listen 443 ssl default_server; + http2 on; + server_name _; + + ssl_certificate /etc/ssl/securo/securo.crt; + ssl_certificate_key /etc/ssl/securo/securo.key; + + client_max_body_size 25m; + + root /opt/securo/frontend/dist; + index index.html; + + location /api/ { + proxy_pass http://127.0.0.1:8000; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + location / { + try_files $uri $uri/ /index.html; + } +} +EOF +ln -sf /etc/nginx/sites-available/securo.conf /etc/nginx/sites-enabled/securo.conf +rm -f /etc/nginx/sites-enabled/default +systemctl restart nginx +msg_ok "Configured Nginx" + +motd_ssh +customize +cleanup_lxc