mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-07-28 16:52:55 +02:00
Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time (#16100)
This commit is contained in:
@@ -13,8 +13,6 @@ setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
setup_go
|
||||
|
||||
var_cf_api_token="default"
|
||||
read -rp "${TAB3}Enter the Cloudflare API token: " var_cf_api_token
|
||||
|
||||
@@ -53,23 +51,50 @@ while true; do
|
||||
done
|
||||
msg_ok "Configured Application"
|
||||
|
||||
setup_go
|
||||
fetch_and_deploy_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns" "tarball"
|
||||
|
||||
msg_info "Building ${APPLICATION}"
|
||||
cd /opt/cloudflare-ddns
|
||||
export CGO_ENABLED=0 GOOS=linux
|
||||
$STD go build -trimpath -ldflags="-s -w" -o /usr/local/bin/ddns ./cmd/ddns
|
||||
msg_ok "Built ${APPLICATION}"
|
||||
|
||||
# The binary is statically linked (CGO_ENABLED=0), so Go is only a build-time
|
||||
# dependency. Removing it keeps the container small; update_script reinstalls it
|
||||
# via setup_go when a rebuild is needed.
|
||||
msg_info "Removing Build Dependencies"
|
||||
rm -rf /usr/local/go /usr/local/bin/go /usr/local/bin/gofmt /root/go /root/.cache/go-build /opt/cloudflare-ddns
|
||||
msg_ok "Removed Build Dependencies"
|
||||
|
||||
msg_info "Setting up service"
|
||||
mkdir -p /root/go
|
||||
useradd --system --no-create-home --shell /usr/sbin/nologin cloudflare-ddns 2>/dev/null || true
|
||||
cat <<EOF >/etc/cloudflare-ddns.env
|
||||
CLOUDFLARE_API_TOKEN=${var_cf_api_token}
|
||||
DOMAINS=${var_cf_domains}
|
||||
PROXIED=${var_cf_proxied}
|
||||
IP6_PROVIDER=${var_cf_ip6_provider}
|
||||
EOF
|
||||
chown root:root /etc/cloudflare-ddns.env
|
||||
chmod 600 /etc/cloudflare-ddns.env
|
||||
cat <<EOF >/etc/systemd/system/cloudflare-ddns.service
|
||||
[Unit]
|
||||
Description=Cloudflare DDNS Service (Go run)
|
||||
After=network.target
|
||||
Description=Cloudflare DDNS Service
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Environment="CLOUDFLARE_API_TOKEN=${var_cf_api_token}"
|
||||
Environment="DOMAINS=${var_cf_domains}"
|
||||
Environment="PROXIED=${var_cf_proxied}"
|
||||
Environment="IP6_PROVIDER=${var_cf_ip6_provider}"
|
||||
Environment="GOPATH=/root/go"
|
||||
Environment="GOCACHE=/tmp/go-build"
|
||||
ExecStart=/usr/local/bin/go run github.com/favonia/cloudflare-ddns/cmd/ddns@latest
|
||||
Type=simple
|
||||
User=cloudflare-ddns
|
||||
Group=cloudflare-ddns
|
||||
EnvironmentFile=/etc/cloudflare-ddns.env
|
||||
ExecStart=/usr/local/bin/ddns
|
||||
Restart=always
|
||||
RestartSec=300
|
||||
NoNewPrivileges=true
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
PrivateTmp=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
||||
Reference in New Issue
Block a user