bootstrap.sh

#!/bin/bash

# ==============================================================================
# Mr. Walia's Home Server Bootstrap Script (v2.0 - Pro Edition)
# Hardware: Gateway Laptop | i5 10th Gen | 16GB RAM | 256GB SSD
# Purpose: DevOps Sandbox & Cloud Architect Lab
# ==============================================================================

# Ensure script is run as root
if [ "$EUID" -ne 0 ]; then
  echo "❌ Please run as root (sudo ./bootstrap.sh)"
  exit 1
fi

echo "πŸš€ Starting Master Server Provisioning for Mr. Walia..."
sleep 2

# ---------------------------------------------------------
# 1. SYSTEM UPDATES & AUTO-UPDATES
# ---------------------------------------------------------
echo "--> Updating system packages..."
apt-get update -y && apt-get upgrade -y
apt-get install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

# ---------------------------------------------------------
# 2. CORE UTILITIES & ALIASES
# ---------------------------------------------------------
echo "--> Installing core prerequisites..."
apt-get install -y curl wget git vim nano unzip tar jq build-essential apt-transport-https ca-certificates software-properties-common net-tools
apt-get install -y htop ncdu btop glances

echo "--> Adding Quality of Life Aliases..."
cat << 'EOF' >> /etc/bash.bashrc
alias ll='ls -la'
alias k='kubectl'
alias d='docker'
alias dc='docker compose'
EOF

# ---------------------------------------------------------
# 3. PERFORMANCE: SWAP MEMORY (4GB)
# ---------------------------------------------------------
echo "--> Checking swap space..."
if [ ! -f /swapfile ]; then
    echo "--> Creating 4GB swap file to protect RAM..."
    fallocate -l 4G /swapfile
    chmod 600 /swapfile
    mkswap /swapfile
    swapon /swapfile
    echo '/swapfile none swap sw 0 0' | tee -a /etc/fstab
    sysctl vm.swappiness=10
    echo 'vm.swappiness=10' | tee -a /etc/sysctl.conf
else
    echo "--> Swapfile already exists. Skipping."
fi

# ---------------------------------------------------------
# 4. DEVELOPER ENVIRONMENT
# ---------------------------------------------------------
echo "--> Installing developer languages..."
apt-get install -y python3 python3-pip python3-venv openjdk-17-jdk golang
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
npm install -g pm2 yarn

# ---------------------------------------------------------
# 5. WEB STACK: NGINX & SSL
# ---------------------------------------------------------
echo "--> Installing Nginx & Certbot..."
apt-get install -y nginx certbot python3-certbot-nginx
systemctl enable nginx
systemctl start nginx

# ---------------------------------------------------------
# 6. DOCKER ENGINE
# ---------------------------------------------------------
echo "--> Installing Docker Engine..."
if ! command -v docker &> /dev/null; then
    curl -fsSL https://get.docker.com -o get-docker.sh
    sh get-docker.sh
    rm get-docker.sh
fi

echo "--> Enabling Docker on Boot..."
systemctl enable docker
systemctl start docker

# Fix: Safely add user to docker group if run via sudo
if [ -n "$SUDO_USER" ]; then
    usermod -aG docker $SUDO_USER
fi

# ---------------------------------------------------------
# 7. KUBERNETES (k3s)
# ---------------------------------------------------------
echo "--> Installing k3s (Lightweight Kubernetes)..."
if ! command -v k3s &> /dev/null; then
    curl -sfL https://get.k3s.io | sh -
fi

echo "--> Configuring Kubernetes access for standard user..."
# Make the config readable and export it so you don't need sudo for kubectl
chmod 644 /etc/rancher/k3s/k3s.yaml
echo "export KUBECONFIG=/etc/rancher/k3s/k3s.yaml" >> /etc/profile

# ---------------------------------------------------------
# 8. MONITORING (Netdata)
# ---------------------------------------------------------
echo "--> Installing Netdata Dashboard..."
bash <(curl -Ss https://my-netdata.io/kickstart.sh) --non-interactive

# ---------------------------------------------------------
# 9. SECURITY & HARDENING
# ---------------------------------------------------------
echo "--> Configuring UFW (Firewall) & Fail2Ban..."
apt-get install -y ufw fail2ban psad

ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw allow http
ufw allow https
ufw allow 8000  # Portainer edge
ufw allow 9443  # Portainer GUI
ufw allow 19999 # Netdata GUI
ufw --force enable

systemctl enable fail2ban
systemctl start fail2ban

# ---------------------------------------------------------
# 10. HARDWARE: LAPTOP LID SWITCH
# ---------------------------------------------------------
echo "--> Configuring lid switch to ignore (prevent sleep)..."
sed -i 's/#HandleLidSwitch=suspend/HandleLidSwitch=ignore/g' /etc/systemd/logind.conf
sed -i 's/HandleLidSwitch=suspend/HandleLidSwitch=ignore/g' /etc/systemd/logind.conf
systemctl restart systemd-logind

# ---------------------------------------------------------
# 11. FOUNDATIONAL CONTAINERS
# ---------------------------------------------------------
echo "--> Spinning up Portainer & Watchtower..."
docker volume create portainer_data

# Portainer
docker run -d -p 8000:8000 -p 9443:9443 --name portainer --restart=always -v /var/run/docker.sock:/var/run/docker.sock -v portainer_data:/data portainer/portainer-ce:latest || true

# Watchtower (Upgraded for auto-cleanup and 5-min intervals)
docker run -d --name watchtower --restart=always -v /var/run/docker.sock:/var/run/docker.sock containrrr/watchtower --cleanup --interval 300 || true

# ---------------------------------------------------------
# 12. AUTOMATED BACKUPS
# ---------------------------------------------------------
echo "--> Setting up automated daily backups..."
mkdir -p /opt/backups
cat << 'EOF' > /usr/local/bin/backup.sh
#!/bin/bash
# Backs up the /etc directory and user home directories
tar -czf /opt/backups/system_backup_$(date +%F).tar.gz /etc /home
# Deletes backups older than 7 days to save space
find /opt/backups -type f -name "*.tar.gz" -mtime +7 -exec rm {} \;
EOF
chmod +x /usr/local/bin/backup.sh
(crontab -l 2>/dev/null; echo "0 2 * * * /usr/local/bin/backup.sh") | crontab -

# ---------------------------------------------------------
# 13. FINAL CLEANUP
# ---------------------------------------------------------
echo "--> Running final system cleanup..."
apt-get autoremove -y
apt-get autoclean -y

# ---------------------------------------------------------
# 14. AESTHETICS: THE BANNER
# ---------------------------------------------------------
echo "--> Setting up Mr. Walia's Custom Login Banner..."
rm -f /etc/motd
cat << 'EOF' > /etc/update-motd.d/99-walia-banner
#!/bin/bash
GREEN='\033[0;32m'
CYAN='\033[0;36m'
NC='\033[0m'

echo -e "${CYAN}"
cat << 'BANNER'
 _   _      _ _          __  __          __        __     _ _       
| | | | ___| | | ___    |  \/  |_ __     \ \      / /__ _| (_) __ _ 
| |_| |/ _ \ | |/ _ \   | |\/| | '__|_____\ \ /\ / / _ \ | | |/ _` |
|  _  |  __/ | | (_) |  | |  | | | |_____|\ V  V / (_| | | | | (_| |
|_| |_|\___|_|_|\___/   |_|  |_|_|         \_/\_/ \__,_|_|_|_|\__,_|
BANNER
echo -e "${NC}"
echo -e "${GREEN}πŸš€ Welcome to the Cloud Sandbox, Mr. Walia.${NC}"
echo "Hardware: Gateway | i5 10th Gen | 16GB RAM | 256GB SSD"
echo "----------------------------------------------------------------"
echo "🌐 Portainer UI:  https://$(hostname -I | awk '{print $1}'):9443"
echo "πŸ“Š Netdata UI:    http://$(hostname -I | awk '{print $1}'):19999"
echo "☸️  Kubernetes:    k3s is active (try: 'k get nodes')"
echo "🐳 Docker:        Active (try: 'd ps')"
echo "----------------------------------------------------------------"
EOF
chmod +x /etc/update-motd.d/99-walia-banner

echo "================================================================="
echo "βœ… Server Provisioning Complete!"
echo "Please REBOOT your server to apply all group and memory changes."
echo "================================================================="