wallarm/setup.sh
Sechpoint Admin 537beed957 fix: make setup.sh download both deployment types under curl|bash
The interactive deployment-type prompt read from stdin, which is the script
pipe (not the terminal) when piped to bash, so it was silently skipped and
only Docker scripts were downloaded. setup.sh is now non-interactive by
default and downloads BOTH deployment types (docker/ + native/) so the native
option is always available; DEPLOYMENT_TYPE=docker|native restricts to one.
Also guard clear and drop the broken overwrite confirmation.
2026-08-01 08:45:29 +01:00

149 lines
5.5 KiB
Bash
Executable file

#!/bin/bash
# ==============================================================================
# Wallarm Deployment Setup Script
# ==============================================================================
# Downloads all necessary Wallarm deployment scripts from the Git repository
# and makes them executable.
#
# By default BOTH deployment types are downloaded, so you can choose later:
# 1. docker - Wallarm filtering node as a Docker container
# 2. native - Wallarm filtering node installed directly on the OS (no Docker)
#
# To download only one type (e.g. for automation or smaller downloads):
# DEPLOYMENT_TYPE=docker curl -fsSL ".../setup.sh" | bash
# DEPLOYMENT_TYPE=native curl -fsSL ".../setup.sh" | bash
#
# Usage: curl -fsSL "https://git.sechpoint.app/customer-engineering/wallarm/raw/branch/main/setup.sh" | bash
# NOTE: This script is non-interactive on purpose - it must work when piped to
# bash (stdin is then the script pipe, not the terminal).
# ==============================================================================
set -euo pipefail
# Color definitions
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
BLUE='\033[1;34m'
CYAN='\033[0;36m'
BOLD='\033[1m'
NC='\033[0m'
# Git repository URL base
GIT_BASE="https://git.sechpoint.app/customer-engineering/wallarm/raw/branch/main/"
# Per-deployment-type scripts
DOCKER_SCRIPTS=(
"wallarm-ct-check.sh"
"wallarm-ct-deploy.sh"
"wallarm-ct-reconfigure.sh"
"wallarm-ct-uninstall.sh"
)
NATIVE_SCRIPTS=(
"wallarm-ct-check.sh"
"wallarm-ct-deploy.sh"
"wallarm-ct-reconfigure.sh"
"wallarm-ct-uninstall.sh"
"wallarm-native.sh"
)
# Detect download command
if command -v curl >/dev/null 2>&1; then
DOWNLOAD_NAME="curl"
elif command -v wget >/dev/null 2>&1; then
DOWNLOAD_NAME="wget"
else
echo -e "${RED}${BOLD}ERROR:${NC} Neither curl nor wget is installed."
echo -e "Please install one of them and run this script again."
exit 1
fi
download_file() {
local url="$1"
local dest="$2"
local description="$3"
echo -e "${YELLOW}Downloading ${description}...${NC}"
if [ "$DOWNLOAD_NAME" = "curl" ]; then
curl -fsSL "$url" -o "$dest"
else
wget -q "$url" -O "$dest"
fi
if [ -s "$dest" ]; then
chmod +x "$dest"
echo -e "${GREEN} Success: ${description} downloaded to ${dest}${NC}"
else
rm -f "$dest"
echo -e "${RED} Failed to download ${description}. Check network connectivity.${NC}"
exit 1
fi
}
download_deployment_type() {
local type="$1"
local scripts
case "$type" in
native) scripts=("${NATIVE_SCRIPTS[@]}") ;;
docker) scripts=("${DOCKER_SCRIPTS[@]}") ;;
*) err "Unknown deployment type: $type"; exit 1 ;;
esac
mkdir -p "$type"
for script in "${scripts[@]}"; do
download_file "${GIT_BASE}${type}/${script}" "${type}/${script}" "$type/$script"
done
}
# Main
clear 2>/dev/null || true
echo -e "${BLUE}${BOLD}"
echo "╔══════════════════════════════════════════════════════════════╗"
echo "║ WALLARM DEPLOYMENT SETUP SCRIPT ║"
echo "║ Downloads all necessary deployment tools ║"
echo "╚══════════════════════════════════════════════════════════════╝${NC}"
echo
# Decide which deployment type(s) to download
DEPLOY_TYPES=()
if [[ "${DEPLOYMENT_TYPE:-}" =~ ^(docker|native)$ ]]; then
DEPLOY_TYPES+=("$DEPLOYMENT_TYPE")
echo -e "${GREEN}Downloading only deployment type: $DEPLOYMENT_TYPE${NC}"
else
DEPLOY_TYPES+=("docker" "native")
echo -e "${CYAN}Downloading BOTH deployment types (docker + native).${NC}"
echo -e "${YELLOW}To download only one type, re-run with: DEPLOYMENT_TYPE=docker or DEPLOYMENT_TYPE=native${NC}"
fi
echo
# Download shared library (required by all deployment scripts)
mkdir -p "common"
download_file "${GIT_BASE}common/wallarm-lib.sh" "common/wallarm-lib.sh" "shared library (common/wallarm-lib.sh)"
# Download the selected deployment type(s)
for type in "${DEPLOY_TYPES[@]}"; do
download_deployment_type "$type"
done
echo
echo -e "${GREEN}${BOLD}Setup complete - all requested scripts downloaded!${NC}"
echo
echo -e "${CYAN}Next steps:${NC}"
echo -e " Docker deployment:"
echo -e " 1. Run the preflight check: ${YELLOW}./docker/wallarm-ct-check.sh${NC}"
echo -e " 2. Deploy a Wallarm node: ${YELLOW}./docker/wallarm-ct-deploy.sh${NC}"
echo -e " 3. Reconfigure existing node: ${YELLOW}./docker/wallarm-ct-reconfigure.sh${NC}"
echo -e " 4. Uninstall a node: ${YELLOW}./docker/wallarm-ct-uninstall.sh${NC}"
echo
echo -e " Native deployment (no Docker):"
echo -e " 1. Run the preflight check: ${YELLOW}./native/wallarm-ct-check.sh${NC}"
echo -e " 2. Deploy a Wallarm node: ${YELLOW}./native/wallarm-ct-deploy.sh${NC}"
echo -e " 3. Unified node manager: ${YELLOW}./native/wallarm-native.sh --preflight${NC} (then --install)"
echo -e " 4. Reconfigure existing node: ${YELLOW}./native/wallarm-ct-reconfigure.sh${NC}"
echo -e " 5. Uninstall a node: ${YELLOW}./native/wallarm-ct-uninstall.sh${NC}"
echo
echo -e "${YELLOW}Note: Some scripts require sudo. Run them with: sudo ./<script>${NC}"
echo -e "${YELLOW}Make sure you have the required information ready (see documentation).${NC}"