Damien 1217b26ff9 fix(lib): ini_set n'écrase plus app.ini si awk échoue, insertion avant les lignes vides
Deux corrections dans ini_set() suite à la review de #24 :

- Le mv s'exécutait même si awk avait échoué en cours de route (OOM,
  signal, valeur exotique) : $tmp, créé par la redirection avant
  qu'awk ne tourne, pouvait être tronqué ou vide et venait quand même
  écraser le fichier original. mv est maintenant gaté sur le code de
  retour d'awk : en cas d'échec, $tmp est supprimé, une erreur est
  logguée, et la fonction retourne 1 sans toucher au fichier d'origine.

- L'insertion d'une clé juste avant l'en-tête de section suivante
  atterrissait après la ou les lignes vides de fin de section plutôt
  qu'avant, rendant le fichier plus difficile à lire au fil des appels
  répétés. Les lignes vides rencontrées section active/clé pas encore
  trouvée sont désormais bufferisées et réémises juste après la clé
  insérée (ou en fin de fichier si la section n'est jamais refermée),
  sans toucher à l'ordre dans tous les autres cas.
2026-08-01 11:18:48 +02:00
2026-05-12 15:17:34 +02:00

infra-scripts

Public infrastructure deployment scripts designed to be executed directly via curl | bash.

Philosophy

These scripts automate the deployment of personal infrastructure components. They are:

  • Self-contained: No external dependencies beyond standard Debian packages
  • Idempotent-ish: Safe to re-run (where possible)
  • Curl-friendly: Designed for one-liner deployment from a fresh server
  • Multi-OS: Supports Debian and Alpine-based deployments, chosen per-script based on that service's requirements
  • Loopback by default: Services bind to 127.0.0.1; Tailscale handles the reverse proxy and TLS termination
  • Log hygiene: Every long-running service ships with a logrotate config (no unbounded log files)
  • Console auto-login: Proxmox LXCs are configured for root auto-login on tty1 (fast pct enter and Web UI shell access)
  • Keep it simple: One script per service, plain bash, no frameworks — readability over cleverness

Available Scripts

Script Description Usage
proxy/install.sh Reverse proxy with Tailscale + Nginx Proxy Manager curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/proxy/install.sh | bash
netlab/install.sh Network lab with ContainerLab curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/netlab/install.sh | bash
gitea-runner/install.sh Gitea Act Runner on Alpine LXC (Proxmox) bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/gitea-runner/install.sh)"
openbao/install.sh OpenBao secrets manager on Alpine LXC (Proxmox) bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/openbao/install.sh)"
komodo/install.sh Komodo (Docker + MongoDB) on Alpine VM bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/komodo/install.sh)"

Requirements

  • Fresh Debian 12/13 installation (proxy, netlab) or Proxmox VE host (gitea-runner, openbao) or Alpine VM (komodo)
  • User with sudo privileges (do not run as root) — except gitea-runner, openbao, and komodo which run as root
  • Internet access
S
Description
Public infrastructure deployment scripts - curl-friendly automation
Readme
654 KiB
Languages
Shell 100%