bootstrap.sh
#!/bin/bash
# ==============================================================================
# Mr. Walia's Home Server Bootstrap Script (v2.0 - Pro Edition)
# Hardware: Gateway Laptop | i5 10th Gen | 16GB RAM | 256GB SSD
# Purpose: DevOps Sandbox & Cloud Architect Lab
# ==============================================================================
# Ensure script is run as root
if [ "$EUID" -ne 0 ]; then
echo "β Please run as root (sudo ./bootstrap.sh)"
exit 1
fi
echo "π Starting Master Server Provisioning for Mr. Walia..."
sleep 2
# ---------------------------------------------------------
# 1. SYSTEM UPDATES & AUTO-UPDATES
# ---------------------------------------------------------
echo "--> Updating system packages..."
apt-get update -y && apt-get upgrade -y
apt-get install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
# ---------------------------------------------------------
# 2. CORE UTILITIES & ALIASES
# ---------------------------------------------------------
echo "--> Installing core prerequisites..."
apt-get install -y curl wget git vim nano unzip tar jq build-essential apt-transport-https ca-certificates software-properties-common net-tools
apt-get install -y htop ncdu btop glances
echo "--> Adding Quality of Life Aliases..."
cat << 'EOF' >> /etc/bash.bashrc
alias ll='ls -la'
alias k='kubectl'
alias d='docker'
alias dc='docker compose'
EOF
# ---------------------------------------------------------
# 3. PERFORMANCE: SWAP MEMORY (4GB)
# ---------------------------------------------------------
echo "--> Checking swap space..."
if [ ! -f /swapfile ]; then
echo "--> Creating 4GB swap file to protect RAM..."
fallocate -l 4G /swapfile
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
echo '/swapfile none swap sw 0 0' | tee -a /etc/fstab
sysctl vm.swappiness=10
echo 'vm.swappiness=10' | tee -a /etc/sysctl.conf
else
echo "--> Swapfile already exists. Skipping."
fi
# ---------------------------------------------------------
# 4. DEVELOPER ENVIRONMENT
# ---------------------------------------------------------
echo "--> Installing developer languages..."
apt-get install -y python3 python3-pip python3-venv openjdk-17-jdk golang
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
npm install -g pm2 yarn
# ---------------------------------------------------------
# 5. WEB STACK: NGINX & SSL
# ---------------------------------------------------------
echo "--> Installing Nginx & Certbot..."
apt-get install -y nginx certbot python3-certbot-nginx
systemctl enable nginx
systemctl start nginx
# ---------------------------------------------------------
# 6. DOCKER ENGINE
# ---------------------------------------------------------
echo "--> Installing Docker Engine..."
if ! command -v docker &> /dev/null; then
curl -fsSL https://get.docker.com -o get-docker.sh
sh get-docker.sh
rm get-docker.sh
fi
echo "--> Enabling Docker on Boot..."
systemctl enable docker
systemctl start docker
# Fix: Safely add user to docker group if run via sudo
if [ -n "$SUDO_USER" ]; then
usermod -aG docker $SUDO_USER
fi
# ---------------------------------------------------------
# 7. KUBERNETES (k3s)
# ---------------------------------------------------------
echo "--> Installing k3s (Lightweight Kubernetes)..."
if ! command -v k3s &> /dev/null; then
curl -sfL https://get.k3s.io | sh -
fi
echo "--> Configuring Kubernetes access for standard user..."
# Make the config readable and export it so you don't need sudo for kubectl
chmod 644 /etc/rancher/k3s/k3s.yaml
echo "export KUBECONFIG=/etc/rancher/k3s/k3s.yaml" >> /etc/profile
# ---------------------------------------------------------
# 8. MONITORING (Netdata)
# ---------------------------------------------------------
echo "--> Installing Netdata Dashboard..."
bash <(curl -Ss https://my-netdata.io/kickstart.sh) --non-interactive
# ---------------------------------------------------------
# 9. SECURITY & HARDENING
# ---------------------------------------------------------
echo "--> Configuring UFW (Firewall) & Fail2Ban..."
apt-get install -y ufw fail2ban psad
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw allow http
ufw allow https
ufw allow 8000 # Portainer edge
ufw allow 9443 # Portainer GUI
ufw allow 19999 # Netdata GUI
ufw --force enable
systemctl enable fail2ban
systemctl start fail2ban
# ---------------------------------------------------------
# 10. HARDWARE: LAPTOP LID SWITCH
# ---------------------------------------------------------
echo "--> Configuring lid switch to ignore (prevent sleep)..."
sed -i 's/#HandleLidSwitch=suspend/HandleLidSwitch=ignore/g' /etc/systemd/logind.conf
sed -i 's/HandleLidSwitch=suspend/HandleLidSwitch=ignore/g' /etc/systemd/logind.conf
systemctl restart systemd-logind
# ---------------------------------------------------------
# 11. FOUNDATIONAL CONTAINERS
# ---------------------------------------------------------
echo "--> Spinning up Portainer & Watchtower..."
docker volume create portainer_data
# Portainer
docker run -d -p 8000:8000 -p 9443:9443 --name portainer --restart=always -v /var/run/docker.sock:/var/run/docker.sock -v portainer_data:/data portainer/portainer-ce:latest || true
# Watchtower (Upgraded for auto-cleanup and 5-min intervals)
docker run -d --name watchtower --restart=always -v /var/run/docker.sock:/var/run/docker.sock containrrr/watchtower --cleanup --interval 300 || true
# ---------------------------------------------------------
# 12. AUTOMATED BACKUPS
# ---------------------------------------------------------
echo "--> Setting up automated daily backups..."
mkdir -p /opt/backups
cat << 'EOF' > /usr/local/bin/backup.sh
#!/bin/bash
# Backs up the /etc directory and user home directories
tar -czf /opt/backups/system_backup_$(date +%F).tar.gz /etc /home
# Deletes backups older than 7 days to save space
find /opt/backups -type f -name "*.tar.gz" -mtime +7 -exec rm {} \;
EOF
chmod +x /usr/local/bin/backup.sh
(crontab -l 2>/dev/null; echo "0 2 * * * /usr/local/bin/backup.sh") | crontab -
# ---------------------------------------------------------
# 13. FINAL CLEANUP
# ---------------------------------------------------------
echo "--> Running final system cleanup..."
apt-get autoremove -y
apt-get autoclean -y
# ---------------------------------------------------------
# 14. AESTHETICS: THE BANNER
# ---------------------------------------------------------
echo "--> Setting up Mr. Walia's Custom Login Banner..."
rm -f /etc/motd
cat << 'EOF' > /etc/update-motd.d/99-walia-banner
#!/bin/bash
GREEN='\033[0;32m'
CYAN='\033[0;36m'
NC='\033[0m'
echo -e "${CYAN}"
cat << 'BANNER'
_ _ _ _ __ __ __ __ _ _
| | | | ___| | | ___ | \/ |_ __ \ \ / /__ _| (_) __ _
| |_| |/ _ \ | |/ _ \ | |\/| | '__|_____\ \ /\ / / _ \ | | |/ _` |
| _ | __/ | | (_) | | | | | | |_____|\ V V / (_| | | | | (_| |
|_| |_|\___|_|_|\___/ |_| |_|_| \_/\_/ \__,_|_|_|_|\__,_|
BANNER
echo -e "${NC}"
echo -e "${GREEN}π Welcome to the Cloud Sandbox, Mr. Walia.${NC}"
echo "Hardware: Gateway | i5 10th Gen | 16GB RAM | 256GB SSD"
echo "----------------------------------------------------------------"
echo "π Portainer UI: https://$(hostname -I | awk '{print $1}'):9443"
echo "π Netdata UI: http://$(hostname -I | awk '{print $1}'):19999"
echo "βΈοΈ Kubernetes: k3s is active (try: 'k get nodes')"
echo "π³ Docker: Active (try: 'd ps')"
echo "----------------------------------------------------------------"
EOF
chmod +x /etc/update-motd.d/99-walia-banner
echo "================================================================="
echo "β
Server Provisioning Complete!"
echo "Please REBOOT your server to apply all group and memory changes."
echo "================================================================="