Generate passwords with random_password

openssl rand -base64 | tr -dc | head -c returned fewer characters than asked for, and the unfiltered | cut variants put / and + into passwords that end up in DSNs and sed expressions. Secrets an app decodes as base64 are unchanged. Requires community-scripts/core#61.
This commit is contained in:
MickLesk
2026-10-02 20:01:38 +02:00
parent 6e63fb3e5f
commit 76f17ddf67
94 changed files with 119 additions and 119 deletions
+1 -1
View File
@@ -149,7 +149,7 @@ EOF
msg_info "Updating Dispatcharr Backend"
if ! grep -q "DJANGO_SECRET_KEY" /opt/dispatcharr/.env; then
DJANGO_SECRET=$(openssl rand -base64 48 | tr -dc 'a-zA-Z0-9' | cut -c1-50)
DJANGO_SECRET=$(random_password 50)
echo "DJANGO_SECRET_KEY=$DJANGO_SECRET" >>/opt/dispatcharr/.env
fi
+1 -1
View File
@@ -50,7 +50,7 @@ function update_script() {
[ -d /opt/.data ] && mv /opt/.data /opt/homebox/.data
if ! grep -q "HBOX_AUTH_API_KEY_PEPPER" /opt/homebox/.env; then
AUTH_KEY=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)
AUTH_KEY=$(random_password 32)
echo "HBOX_AUTH_API_KEY_PEPPER=${AUTH_KEY}" >>/opt/homebox/.env
fi
+2 -2
View File
@@ -30,10 +30,10 @@ PG_DB_NAME="adventurelog_db" PG_DB_USER="adventurelog_user" PG_DB_EXTENSIONS="po
fetch_and_deploy_gh_release "adventurelog" "seanmorley15/adventurelog" "tarball"
msg_info "Installing AdventureLog (Patience)"
SECRET_KEY="$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)"
SECRET_KEY="$(random_password 32)"
echo "AdventureLog Secret: $SECRET_KEY" >>~/adventurelog.creds
DJANGO_ADMIN_USER="djangoadmin"
DJANGO_ADMIN_PASS="$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)"
DJANGO_ADMIN_PASS="$(random_password 13)"
cat <<EOF >/opt/adventurelog/backend/server/.env
PGHOST='localhost'
PGDATABASE='${PG_DB_NAME}'
+1 -1
View File
@@ -160,7 +160,7 @@ systemctl enable -q --now redis-server affine-web affine-worker
msg_ok "Created Services"
msg_info "Creating Admin User"
ADMIN_PASS=$(openssl rand -base64 12)
ADMIN_PASS=$(random_password 16)
for i in {1..30}; do
if curl -s http://localhost:3010/info >/dev/null 2>&1; then
break
+2 -2
View File
@@ -37,8 +37,8 @@ msg_ok "Installed PHP/Redis"
msg_info "Installing MySQL Database"
DB_NAME=nextcloud
DB_USER=nextcloud
DB_PASS="$(openssl rand -base64 18 | cut -c1-13)"
ADMIN_PASS="$(openssl rand -base64 18 | cut -c1-13)"
DB_PASS="$(random_password 13)"
ADMIN_PASS="$(random_password 13)"
echo "" >>~/nextcloud.creds
echo -e "MySQL Admin Password: \e[32m$ADMIN_PASS\e[0m" >>~/nextcloud.creds
echo -e "Nextcloud Database Username: \e[32m$DB_USER\e[0m" >>~/nextcloud.creds
+1 -1
View File
@@ -40,7 +40,7 @@ msg_ok "Installed Apache Airflow"
msg_info "Configuring Application"
FERNET_KEY=$(/opt/airflow/.venv/bin/python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())")
SECRET_KEY=$(openssl rand -hex 32)
ADMIN_PASS=$(openssl rand -base64 12 | tr -dc 'a-zA-Z0-9' | cut -c1-12)
ADMIN_PASS=$(random_password 12)
cat <<EOF >/opt/airflow/.env
AIRFLOW_HOME=/opt/airflow
AIRFLOW__DATABASE__SQL_ALCHEMY_CONN=postgresql+psycopg2://${PG_DB_USER}:${PG_DB_PASS}@localhost:5432/${PG_DB_NAME}
+1 -1
View File
@@ -15,7 +15,7 @@ update_os
msg_info "Installing Apache CouchDB"
ERLANG_COOKIE=$(openssl rand -hex 32)
ADMIN_PASS="$(openssl rand -base64 18 | cut -c1-13)"
ADMIN_PASS="$(random_password 13)"
debconf-set-selections <<<"couchdb couchdb/cookie string $ERLANG_COOKIE"
debconf-set-selections <<<"couchdb couchdb/mode select standalone"
debconf-set-selections <<<"couchdb couchdb/bindaddress string 0.0.0.0"
+1 -1
View File
@@ -142,7 +142,7 @@ msg_ok "Setup python server"
msg_info "Creating authentik config"
mkdir -p /etc/authentik
mv /opt/authentik/authentik/lib/default.yml /etc/authentik/config.yml
yq -i ".secret_key = \"$(openssl rand -base64 128 | tr -dc 'a-zA-Z0-9' | head -c64)\"" /etc/authentik/config.yml
yq -i ".secret_key = \"$(random_password 64)\"" /etc/authentik/config.yml
yq -i ".postgresql.password = \"${PG_DB_PASS}\"" /etc/authentik/config.yml
yq -i ".events.context_processors.geoip = \"/opt/authentik-data/geoip/GeoLite2-City.mmdb\"" /etc/authentik/config.yml
yq -i ".events.context_processors.asn = \"/opt/authentik-data/geoip/GeoLite2-ASN.mmdb\"" /etc/authentik/config.yml
+1 -1
View File
@@ -33,7 +33,7 @@ $STD uv venv --clear .venv
$STD source .venv/bin/activate
$STD uv pip install -r requirements.txt
cp babybuddy/settings/production.example.py babybuddy/settings/production.py
SECRET_KEY=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)
SECRET_KEY=$(random_password 32)
ALLOWED_HOSTS=$(hostname -I | tr ' ' ',' | sed 's/,$//')",127.0.0.1,localhost"
sed -i \
-e "s/^SECRET_KEY = \"\"/SECRET_KEY = \"$SECRET_KEY\"/" \
+1 -1
View File
@@ -21,7 +21,7 @@ PG_VERSION="16" setup_postgresql
PHP_APACHE="YES" PHP_VERSION="8.3" setup_php
setup_composer
fetch_and_deploy_gh_release "baikal" "sabre-io/Baikal" "tarball"
PG_DB_NAME="baikal_db" PG_DB_USER="baikal_user" PG_DB_PASS="$(openssl rand -base64 12)" setup_postgresql_db
PG_DB_NAME="baikal_db" PG_DB_USER="baikal_user" PG_DB_PASS="$(random_password 16)" setup_postgresql_db
msg_info "Configuring Baikal"
cd /opt/baikal
+1 -1
View File
@@ -50,7 +50,7 @@ NODE_OPTIONS="--max-old-space-size=4096" $STD npm run build
msg_ok "Built Frontend"
msg_info "Configuring Baserow"
SECRET_KEY=$(openssl rand -base64 64 | tr -dc 'a-zA-Z0-9' | head -c50)
SECRET_KEY=$(random_password 50)
cat <<EOF >/opt/baserow/.env
DATABASE_HOST=localhost
DATABASE_PORT=5432
+1 -1
View File
@@ -28,7 +28,7 @@ fi
msg_info "Setting up Bichon"
mkdir -p /opt/bichon-data
BICHON_ENC_PASSWORD=$(openssl rand -base64 32 | tr -d "=+/" | cut -c1-32)
BICHON_ENC_PASSWORD=$(random_password 32)
cat <<EOF >/opt/bichon/bichon.env
BICHON_ROOT_DIR=/opt/bichon-data
+1 -1
View File
@@ -17,7 +17,7 @@ NODE_VERSION="22" setup_nodejs
fetch_and_deploy_gh_release "bytestash" "jordan-dalby/ByteStash" "tarball"
msg_info "Installing ByteStash"
JWT_SECRET=$(openssl rand -base64 32 | tr -d '/+=')
JWT_SECRET=$(random_password 42)
cd /opt/bytestash/server
$STD npm install
cd /opt/bytestash/client
+1 -1
View File
@@ -25,7 +25,7 @@ msg_ok "Installed Checkmk"
msg_info "Creating Service"
SITE_NAME="monitoring"
$STD omd create "$SITE_NAME"
MKPASSWORD=$(openssl rand -base64 18 | tr -d '/+=' | cut -c1-16)
MKPASSWORD=$(random_password 16)
echo -e "$MKPASSWORD\n$MKPASSWORD" | su - "$SITE_NAME" -c "cmk-passwd cmkadmin --stdin"
$STD omd start "$SITE_NAME"
+1 -1
View File
@@ -63,7 +63,7 @@ cd /opt/convertx
mkdir -p data
$STD bun install
JWT_SECRET=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c 32)
JWT_SECRET=$(random_password 32)
cat <<EOF >/opt/convertx/.env
JWT_SECRET=$JWT_SECRET
HTTP_ALLOWED=true
+1 -1
View File
@@ -35,7 +35,7 @@ msg_ok "Installed Directus"
msg_info "Configuring Directus"
DIRECTUS_KEY=$(openssl rand -hex 32)
DIRECTUS_SECRET=$(openssl rand -hex 32)
DIRECTUS_ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
DIRECTUS_ADMIN_PASSWORD=$(random_password 16)
cat <<EOF >/opt/directus/.env
HOST="0.0.0.0"
PORT=8055
+2 -2
View File
@@ -33,7 +33,7 @@ NODE_VERSION="24" setup_nodejs
RUBY_VERSION="3.4.4" setup_ruby
msg_info "Configuring PostgreSQL for Discourse"
DISCOURSE_DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
DISCOURSE_DB_PASS=$(random_password 13)
PG_HBA=$(find /etc/postgresql -name pg_hba.conf 2>/dev/null | head -n1)
sed -i 's/^local\s\+all\s\+all\s\+peer$/local all all md5/' "$PG_HBA"
$STD systemctl restart postgresql
@@ -97,7 +97,7 @@ $STD bundle exec rails db:seed
msg_ok "Set Up Database"
msg_info "Creating Admin Account"
ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
ADMIN_PASS=$(random_password 16)
$STD bundle exec rails runner "
user = User.new(email: 'admin@discourse.local', username: 'admin', password: '${ADMIN_PASS}')
user.active = true
+1 -1
View File
@@ -62,7 +62,7 @@ install -d -m 755 \
/data/uploads/{m3us,epgs} \
/data/{m3us,epgs}
chown -R root:root /data
DJANGO_SECRET=$(openssl rand -base64 48 | tr -dc 'a-zA-Z0-9' | cut -c1-50)
DJANGO_SECRET=$(random_password 50)
export DATABASE_URL="postgresql://${PG_DB_USER}:${PG_DB_PASS}@localhost:5432/${PG_DB_NAME}"
export POSTGRES_DB=$PG_DB_NAME
export POSTGRES_USER=$PG_DB_USER
+1 -1
View File
@@ -39,7 +39,7 @@ fi
mv .env.example .env
mkdir data
sed -i -e "s|APP_SECRET=.*|APP_SECRET=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)|" \
sed -i -e "s|APP_SECRET=.*|APP_SECRET=$(random_password 32)|" \
-e "s|DATABASE_URL=.*|DATABASE_URL=\"postgres://$PG_DB_USER:$PG_DB_PASS@localhost:5432/$PG_DB_NAME?schema=public\"|" \
-e "s|FILE_UPLOAD_SIZE_LIMIT=.*|FILE_UPLOAD_SIZE_LIMIT=50mb|" \
-e "s|DRAWIO_URL=.*|DRAWIO_URL=https://embed.diagrams.net|" \
+1 -1
View File
@@ -22,7 +22,7 @@ msg_ok "Installed Dependencies"
setup_mariadb
msg_info "Setting up Database"
ROOT_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ROOT_PASS=$(random_password 13)
$STD mariadb -u root -e "ALTER USER 'root'@'localhost' IDENTIFIED BY '$ROOT_PASS'; flush privileges;"
cat <<EOF >~/dolibarr.creds
Dolibarr DB Credentials
+1 -1
View File
@@ -31,7 +31,7 @@ read -r -p "${TAB3}Type the assembly name of the project: " var_project_name
msg_info "Setting up FTP Server"
useradd ftpuser
FTP_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
FTP_PASS=$(random_password 13)
usermod --password $(echo ${FTP_PASS} | openssl passwd -1 -stdin) ftpuser
mkdir -p /var/www/html
usermod -d /var/www/html ftp
+2 -2
View File
@@ -23,8 +23,8 @@ msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "duplicati" "duplicati/duplicati" "binary" "latest" "/opt/duplicati" "duplicati-*-linux-$(arch_resolve "x64" "arm64")-gui.deb"
msg_info "Configuring duplicati"
DECRYPTKEY=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMINPASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
DECRYPTKEY=$(random_password 13)
ADMINPASS=$(random_password 13)
cat <<EOF >~/duplicati.creds
Admin password = ${ADMINPASS}
Database encryption key = ${DECRYPTKEY}
+1 -1
View File
@@ -40,7 +40,7 @@ rm -f /usr/sbin/policy-rc.d
sed -i 's/127.0.0.1/0.0.0.0/g' /etc/matrix-synapse/homeserver.yaml
sed -i 's/'\''::1'\'', //g' /etc/matrix-synapse/homeserver.yaml
SECRET=$(openssl rand -hex 32)
ADMIN_PASS="$(openssl rand -base64 18 | cut -c1-13)"
ADMIN_PASS="$(random_password 13)"
echo "enable_registration_without_verification: true" >>/etc/matrix-synapse/homeserver.yaml
echo "registration_shared_secret: ${SECRET}" >>/etc/matrix-synapse/homeserver.yaml
+2 -2
View File
@@ -61,8 +61,8 @@ $STD sudo -u frappe bash -c 'export PATH="$HOME/.local/bin:$PATH"; uv tool insta
msg_ok "Installed Frappe Bench"
msg_info "Initializing Frappe Bench"
ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
DB_ROOT_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMIN_PASS=$(random_password 13)
DB_ROOT_PASS=$(random_password 13)
mysql -u root -e "ALTER USER 'root'@'localhost' IDENTIFIED BY '${DB_ROOT_PASS}'; FLUSH PRIVILEGES;"
$STD sudo -u frappe bash -c 'export PATH="$HOME/.local/bin:$PATH"; uv python install 3.14'
$STD sudo -u frappe bash -c 'export PATH="$HOME/.local/bin:$PATH"; cd /opt && bench init --frappe-branch version-16 --python "$(uv python find 3.14)" frappe-bench'
+1 -1
View File
@@ -17,7 +17,7 @@ fetch_and_deploy_gh_release "ezbookkeeping" "mayswind/ezbookkeeping" "prebuild"
create_self_signed_cert
msg_info "Configuring ezBookkeeping"
SECRET_KEY=$(openssl rand -base64 64 | tr -dc 'a-zA-Z0-9' | head -c50)
SECRET_KEY=$(random_password 50)
sed -i "s/enable_gzip = false/enable_gzip = true/" /opt/ezbookkeeping/conf/ezbookkeeping.ini
sed -i "s/protocol = http/protocol = https/" /opt/ezbookkeeping/conf/ezbookkeeping.ini
sed -i "s/http_port = 8080/http_port = 443/" /opt/ezbookkeeping/conf/ezbookkeeping.ini
+1 -1
View File
@@ -56,7 +56,7 @@ msg_ok "Configured pg_cron"
msg_info "Configuring RabbitMQ"
systemctl enable -q --now rabbitmq-server
until rabbitmqctl status &>/dev/null; do sleep 1; done
RABBITMQ_PASSWORD="$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c24)"
RABBITMQ_PASSWORD="$(random_password 24)"
$STD rabbitmqctl add_user firecrawl "$RABBITMQ_PASSWORD"
$STD rabbitmqctl set_permissions -p / firecrawl ".*" ".*" ".*"
msg_ok "Configured RabbitMQ"
+1 -1
View File
@@ -92,7 +92,7 @@ $STD ldconfig
msg_ok "Compiled ffmpeg"
msg_info "Configuring Fireshare (Patience)"
ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMIN_PASSWORD=$(random_password 13)
SECRET=$(openssl rand -base64 48)
mkdir -p /opt/fireshare-{data,videos,images,processed}
cd /opt/fireshare
+1 -1
View File
@@ -25,7 +25,7 @@ NODE_VERSION="24" setup_nodejs
fetch_and_deploy_gh_release "fluid-calendar" "dotnetfactory/fluid-calendar" "tarball"
msg_info "Configuring fluid-calendar"
NEXTAUTH_SECRET="$(openssl rand -base64 44 | tr -dc 'a-zA-Z0-9' | cut -c1-32)"
NEXTAUTH_SECRET="$(random_password 32)"
echo "NextAuth Secret: $NEXTAUTH_SECRET" >>~/$APPLICATION.creds
cat <<EOF >/opt/fluid-calendar/.env
DATABASE_URL="postgresql://${PG_DB_USER}:${PG_DB_PASS}@localhost:5432/${PG_DB_NAME}"
+1 -1
View File
@@ -26,7 +26,7 @@ NODE_VERSION="24" setup_nodejs
msg_info "Setting up Database"
PG_DB_NAME="ghostfolio" PG_DB_USER="ghostfolio" PG_DB_SCHEMA_PERMS="true" setup_postgresql_db
REDIS_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
REDIS_PASS=$(random_password 13)
ACCESS_TOKEN_SALT=$(openssl rand -base64 32)
JWT_SECRET_KEY=$(openssl rand -base64 32)
cat <<EOF >~/ghostfolio.creds
+2 -2
View File
@@ -16,7 +16,7 @@ update_os
MONGO_VERSION="8.2" setup_mongodb
msg_info "Setup Graylog Data Node"
PASSWORD_SECRET=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
PASSWORD_SECRET=$(random_password 16)
curl -fsSL "https://packages.graylog2.org/repo/packages/graylog-7.0-repository_latest.deb" -o "graylog-7.0-repository_latest.deb"
$STD dpkg -i graylog-7.0-repository_latest.deb
apt_update_safe
@@ -27,7 +27,7 @@ msg_ok "Setup Graylog Data Node"
msg_info "Setup ${APPLICATION}"
$STD apt install graylog-server
ROOT_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
ROOT_PASSWORD=$(random_password 16)
cat <<EOF >~/graylog.creds
${APPLICATION} Credentials
Admin User: admin
+2 -2
View File
@@ -31,10 +31,10 @@ EOF
msg_ok "Installed Dependencies"
PG_VERSION=16 setup_postgresql
PG_DB_NAME="healthchecks_db" PG_DB_USER="hc_user" PG_DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13) setup_postgresql_db
PG_DB_NAME="healthchecks_db" PG_DB_USER="hc_user" PG_DB_PASS=$(random_password 13) setup_postgresql_db
msg_info "Setup Keys (Admin / Secret)"
SECRET_KEY="$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)"
SECRET_KEY="$(random_password 32)"
ADMIN_EMAIL="admin@community-scripts.org"
ADMIN_PASSWORD="$PG_DB_PASS"
cat <<EOF >~/healthchecks.creds
+1 -1
View File
@@ -57,7 +57,7 @@ git config --system --add safe.directory /home/hermes/.hermes/hermes-agent 2>/de
msg_ok "Installed Hermes Agent"
msg_info "Configuring API Server"
API_SERVER_KEY=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)
API_SERVER_KEY=$(random_password 32)
mkdir -p /home/hermes/.hermes
cat <<EOF >/home/hermes/.hermes/.env
API_SERVER_ENABLED=true
+1 -1
View File
@@ -19,7 +19,7 @@ msg_info "Setup hev-socks5-server"
mkdir -p /etc/hev-socks5-server
download_file "https://raw.githubusercontent.com/heiher/hev-socks5-server/refs/heads/main/conf/main.yml" "/etc/hev-socks5-server/main.yml"
sed -i 's/^#auth:/auth:/; s/^# file: conf\/auth.txt/ file: \/root\/hev.creds/' /etc/hev-socks5-server/main.yml
PASSWORD=$(openssl rand -base64 16)
PASSWORD=$(random_password 21)
echo "admin $PASSWORD 0" >/root/hev.creds
msg_ok "Setup hev-socks5-server"
+1 -1
View File
@@ -18,7 +18,7 @@ fetch_and_deploy_gh_release "homebox" "sysadminsmedia/homebox" "prebuild" "lates
msg_info "Configuring Homebox"
chmod +x /opt/homebox/homebox
AUTH_KEY="$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)"
AUTH_KEY="$(random_password 32)"
cat <<EOF >/opt/homebox/.env
# For possible environment variables check here: https://homebox.software/en/configure-homebox
HBOX_MODE=production
+1 -1
View File
@@ -17,7 +17,7 @@ fetch_and_deploy_gh_release "hoodik" "hudikhq/hoodik" "prebuild" "latest" "/opt/
msg_info "Configuring Hoodik"
mkdir -p /opt/hoodik_data
JWT_SECRET=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)
JWT_SECRET=$(random_password 32)
cat <<EOF >/opt/hoodik/.env
DATA_DIR=/opt/hoodik_data
HTTP_PORT=5443
+1 -1
View File
@@ -46,7 +46,7 @@ $STD php asatru calendar:classes
$STD php asatru plants:attributes
$STD php asatru aquashell:config
ADMIN_EMAIL="admin@example.com"
ADMIN_PASS="$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)"
ADMIN_PASS="$(random_password 13)"
ADMIN_HASH=$(php -r "echo password_hash('$ADMIN_PASS', PASSWORD_BCRYPT);")
$STD mariadb -u root -D $MARIADB_DB_NAME -e "INSERT IGNORE INTO UserModel (name, email, password, admin) VALUES ('Admin', '$ADMIN_EMAIL', '$ADMIN_HASH', 1);"
cat <<EOF >~/hortusfox.creds
+1 -1
View File
@@ -97,7 +97,7 @@ setup_alpine() {
msg_ok "Installed PostgreSQL"
msg_info "Setting up Database"
PG_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
PG_PASS=$(random_password 13)
$STD su -s /bin/sh postgres -c "psql -c \"CREATE ROLE ironclaw WITH LOGIN PASSWORD '${PG_PASS}';\""
$STD su -s /bin/sh postgres -c "psql -c \"CREATE DATABASE ironclaw WITH OWNER ironclaw;\""
$STD su -s /bin/sh postgres -c "psql -d ironclaw -c \"CREATE EXTENSION IF NOT EXISTS vector;\""
+1 -1
View File
@@ -83,7 +83,7 @@ if [[ -n "${var_jitsi_admin_user:-}" ]]; then
msg_info "Configuring Secure Domain"
# Only authenticated users may create rooms; guests join via the anonymous domain.
# https://jitsi.github.io/handbook/docs/devops-guide/secure-domain/
var_jitsi_admin_pass="${var_jitsi_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-16)}"
var_jitsi_admin_pass="${var_jitsi_admin_pass:-$(random_password 16)}"
sed -i "0,/authentication = \"jitsi-anonymous\"/s//authentication = \"internal_hashed\"/" \
"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
cat <<EOF >>"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
+1 -1
View File
@@ -66,7 +66,7 @@ EOF
chmod +x /usr/bin/karakeep
export DATA_DIR=/opt/karakeep_data
karakeep_SECRET=$(openssl rand -base64 36 | cut -c1-24)
karakeep_SECRET=$(random_password 24)
mkdir -p /etc/karakeep
cat <<EOF >/etc/karakeep/karakeep.env
SERVER_VERSION="$(sed 's/^v//' ~/.karakeep)"
+1 -1
View File
@@ -19,7 +19,7 @@ msg_info "Configuring LeafWiki"
mkdir -p /opt/leafwiki/data
mkdir -p /etc/leafwiki
JWT_SECRET=$(openssl rand -hex 32)
ADMIN_PASS=$(openssl rand -base64 12 | tr -dc 'a-zA-Z0-9' | head -c12)
ADMIN_PASS=$(random_password 12)
cat <<EOF >/etc/leafwiki/.env
LEAFWIKI_DATA_DIR=/opt/leafwiki/data
LEAFWIKI_HOST=0.0.0.0
+1 -1
View File
@@ -46,7 +46,7 @@ mv "/opt/leantime/config/sample.env" "/opt/leantime/config/.env"
sed -i -e "s|^LEAN_DB_DATABASE.*|LEAN_DB_DATABASE = '$MARIADB_DB_NAME'|" \
-e "s|^LEAN_DB_USER.*|LEAN_DB_USER = '$MARIADB_DB_USER'|" \
-e "s|^LEAN_DB_PASSWORD.*|LEAN_DB_PASSWORD = '$MARIADB_DB_PASS'|" \
-e "s|^LEAN_SESSION_PASSWORD.*|LEAN_SESSION_PASSWORD = '$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)'|" \
-e "s|^LEAN_SESSION_PASSWORD.*|LEAN_SESSION_PASSWORD = '$(random_password 13)'|" \
"/opt/leantime/config/.env"
$STD a2enmod -q proxy_fcgi setenvif rewrite
$STD a2enconf -q "php8.4-fpm"
+3 -3
View File
@@ -45,7 +45,7 @@ PHP_VERSION="8.4" PHP_FPM="YES" PHP_MODULE="cli,snmp,gmp" setup_php
setup_mariadb
setup_composer
PYTHON_VERSION="3.13" setup_uv
MARIADB_DB_NAME="librenms" MARIADB_DB_USER="librenms" MARIADB_DB_PASS="$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)" setup_mariadb_db
MARIADB_DB_NAME="librenms" MARIADB_DB_USER="librenms" MARIADB_DB_PASS="$(random_password 13)" setup_mariadb_db
fetch_and_deploy_gh_release "librenms" "librenms/librenms" "tarball"
msg_info "Configuring LibreNMS"
@@ -114,7 +114,7 @@ mkdir -p /etc/bash_completion.d/
cp /opt/librenms/misc/lnms-completion.bash /etc/bash_completion.d/
cp /opt/librenms/snmpd.conf.example /etc/snmp/snmpd.conf
APP_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
APP_PASSWORD=$(random_password 13)
APP_USER="admin"
cat <<EOF >~/librenms.creds
LibreNMS Credentials
@@ -128,7 +128,7 @@ $STD su - librenms -s /bin/bash -c "cd /opt/librenms && php8.4 artisan key:gener
$STD su - librenms -s /bin/bash -c "cd /opt/librenms && lnms db:seed --force"
$STD su - librenms -s /bin/bash -c "cd /opt/librenms && lnms user:add -p ${APP_PASSWORD} ${APP_USER} --role=admin"
RANDOM_STRING=$(openssl rand -base64 16 | tr -dc 'a-zA-Z0-9')
RANDOM_STRING=$(random_password 20)
sed -i "s/RANDOMSTRINGGOESHERE/$RANDOM_STRING/g" /etc/snmp/snmpd.conf
echo "SNMP Community String: $RANDOM_STRING" >>~/librenms.creds
curl -qso /usr/bin/distro https://raw.githubusercontent.com/librenms/librenms-agent/master/snmp/distro
+1 -1
View File
@@ -42,7 +42,7 @@ touch bookmarks/settings/custom.py
$STD uv sync --no-dev --frozen
$STD uv pip install gunicorn
mkdir -p data/{favicons,previews,assets}
ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
ADMIN_PASS=$(random_password 13)
cat <<EOF >/opt/linkding/.env
LD_SUPERUSER_NAME=admin
LD_SUPERUSER_PASSWORD=${ADMIN_PASS}
+1 -1
View File
@@ -32,7 +32,7 @@ fi
fetch_and_deploy_gh_release "linkwarden" "linkwarden/linkwarden" "tarball"
msg_info "Installing Linkwarden (Patience)"
SECRET_KEY="$(head /dev/urandom | tr -dc A-Za-z0-9 | head -c 32)"
SECRET_KEY="$(random_password 32)"
echo "Linkwarden Secret: $SECRET_KEY" >>"${HOME}/linkwarden.creds"
cd /opt/linkwarden
yarn_ver="4.12.0"
+1 -1
View File
@@ -44,7 +44,7 @@ $STD sh install.sh elixir@latest otp@latest
msg_info "Setup Erlang and Elixir"
ERLANG_VERSION=$(ls /opt/livebook/.elixir-install/installs/otp/ | head -n1)
ELIXIR_VERSION=$(ls /opt/livebook/.elixir-install/installs/elixir/ | head -n1)
LIVEBOOK_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
LIVEBOOK_PASSWORD=$(random_password 16)
export ERLANG_BIN="/opt/livebook/.elixir-install/installs/otp/$ERLANG_VERSION/bin"
export ELIXIR_BIN="/opt/livebook/.elixir-install/installs/elixir/$ELIXIR_VERSION/bin"
+1 -1
View File
@@ -32,7 +32,7 @@ sed -i -e 's|db|localhost|' \
-e 's|5433|3306|' \
-e 's|DB_DIALECT=postgres|DB_DIALECT=mysql|' \
-e "s|sample_install_mmdm|mmdl|" \
-e "s|=PASSWORD|=$(openssl rand -base64 40 | tr -dc 'a-zA-Z0-9' | head -c40)|" \
-e "s|=PASSWORD|=$(random_password 40)|" \
/opt/mmdl/.env
cd /opt/mmdl
export NEXT_TELEMETRY_DISABLED=1
+1 -1
View File
@@ -19,7 +19,7 @@ fetch_and_deploy_gh_release "miniflux" "miniflux/v2" "binary" "latest"
msg_info "Configuring Miniflux"
ADMIN_NAME=admin
ADMIN_PASS="$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)"
ADMIN_PASS="$(random_password 13)"
cat <<EOF >/etc/miniflux.conf
# See https://miniflux.app/docs/configuration.html
DATABASE_URL=user=$PG_DB_USER password=$PG_DB_PASS dbname=$PG_DB_NAME sslmode=disable
+1 -1
View File
@@ -58,7 +58,7 @@ systemctl enable -q --now elasticsearch
msg_ok "Set up Elasticsearch"
msg_info "Configuring Database"
DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
DB_PASS=$(random_password 13)
$STD mariadb -u root -e "CREATE USER 'minthcm'@'localhost' IDENTIFIED BY '${DB_PASS}';"
$STD mariadb -u root -e "GRANT ALL ON *.* TO 'minthcm'@'localhost'; FLUSH PRIVILEGES;"
sed -i "s/^DB_HOST=.*/DB_HOST=localhost/" /var/www/script/.env
+1 -1
View File
@@ -54,7 +54,7 @@ $STD apt install -y \
msg_ok "Installed MySQL"
msg_info "Configure MySQL Server"
ADMIN_PASS="$(openssl rand -base64 18 | cut -c1-13)"
ADMIN_PASS="$(random_password 13)"
$STD mysql -uroot -p"$ADMIN_PASS" -e "ALTER USER 'root'@'localhost' IDENTIFIED WITH $RELEASE_AUTH BY '$ADMIN_PASS'; FLUSH PRIVILEGES;"
echo "" >~/mysql.creds
echo -e "MySQL user: root" >>~/mysql.creds
+1 -1
View File
@@ -117,7 +117,7 @@ msg_ok "Configured NetBox"
msg_info "Setting up Django Admin"
DJANGO_USER=Admin
DJANGO_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
DJANGO_PASS=$(random_password 13)
source /opt/netbox/venv/bin/activate
$STD python3 /opt/netbox/netbox/manage.py shell <<EOF
+2 -2
View File
@@ -26,9 +26,9 @@ NODE_VERSION="22" setup_nodejs
msg_info "Configuring MongoDB"
MONGO_ADMIN_USER="admin"
MONGO_ADMIN_PWD="$(openssl rand -base64 18 | cut -c1-13)"
MONGO_ADMIN_PWD="$(random_password 13)"
NODEBB_USER="nodebb"
NODEBB_PWD="$(openssl rand -base64 18 | cut -c1-13)"
NODEBB_PWD="$(random_password 13)"
MONGO_CONNECTION_STRING="mongodb://${NODEBB_USER}:${NODEBB_PWD}@localhost:27017/nodebb"
NODEBB_SECRET=$(uuidgen)
cat <<EOF >~/nodebb.creds
+1 -1
View File
@@ -26,7 +26,7 @@ JWT_SECRET=$(openssl rand -base64 48)
API_KEY_SECRET=$(openssl rand -hex 32)
STORAGE_ENCRYPTION_KEY=$(openssl rand -hex 32)
STORAGE_ENCRYPTION_KEY_VERSION=v1
INITIAL_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-20)
INITIAL_PASSWORD=$(random_password 20)
PORT=20128
OMNIROUTE_SERVER_HOST=0.0.0.0
EOF
+1 -1
View File
@@ -50,7 +50,7 @@ rm -f "$TMP_KEY_CONTENT"
msg_info "Preconfiguring ONLYOFFICE Debconf Settings"
RMQ_USER=onlyoffice_rmq
RMQ_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
RMQ_PASS=$(random_password 13)
JWT_SECRET=$(openssl rand -hex 16)
$STD rabbitmqctl add_user $RMQ_USER $RMQ_PASS
$STD rabbitmqctl set_permissions -p / $RMQ_USER ".*" ".*" ".*"
+1 -1
View File
@@ -17,7 +17,7 @@ msg_info "Installing OpenObserve"
mkdir -p /opt/openobserve/data
RELEASE=$(get_latest_github_release "openobserve/openobserve")
tar zxf <(curl -fsSL https://downloads.openobserve.ai/releases/openobserve/v$RELEASE/openobserve-v$RELEASE-linux-$(arch_resolve).tar.gz) -C /opt/openobserve
ROOT_PASS="$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c9)Aa1!"
ROOT_PASS="$(random_password 9)Aa1!"
cat <<EOF >/opt/openobserve/data/.env
ZO_ROOT_USER_EMAIL = "admin@example.com"
+1 -1
View File
@@ -22,7 +22,7 @@ msg_ok "Installed Dependencies"
PG_VERSION="17" setup_postgresql
PG_DB_NAME="openproject" PG_DB_USER="openproject" setup_postgresql_db
API_KEY=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
API_KEY=$(random_password 13)
echo "OpenProject API Key: $API_KEY" >>~/openproject.creds
fetch_and_deploy_gh_release "jemalloc" "jemalloc/jemalloc" "tarball"
+1 -1
View File
@@ -41,7 +41,7 @@ if [[ -z "$pango_email" ]]; then
fi
msg_info "Setup Pangolin"
SECRET_KEY=$(openssl rand -base64 48 | tr -dc 'A-Za-z0-9' | head -c 32)
SECRET_KEY=$(random_password 32)
BADGER_VERSION=$(get_latest_github_release "fosrl/badger" "false")
cd /opt/pangolin
mkdir -p /opt/pangolin/config/{traefik,db,letsencrypt,logs}
+1 -1
View File
@@ -54,7 +54,7 @@ rm -rf /opt/paperless/docker
$STD uv sync --all-extras
mkdir -p /opt/paperless_data/{consume,data,media,trash}
mkdir -p /opt/paperless/static
SECRET_KEY="$(head /dev/urandom | tr -dc A-Za-z0-9 | head -c 32)"
SECRET_KEY="$(random_password 32)"
cat <<EOF >~/paperless-ngx.creds
Paperless-ngx Secret Key: $SECRET_KEY
+3 -3
View File
@@ -37,7 +37,7 @@ PG_VERSION="16" setup_postgresql
PG_DB_NAME="plane" PG_DB_USER="plane" setup_postgresql_db
msg_info "Configuring RabbitMQ"
RABBITMQ_PASS=$(openssl rand -base64 24 | tr -dc 'a-zA-Z0-9' | head -c16)
RABBITMQ_PASS=$(random_password 16)
$STD rabbitmqctl add_vhost plane
$STD rabbitmqctl add_user plane "${RABBITMQ_PASS}"
$STD rabbitmqctl set_permissions -p plane plane ".*" ".*" ".*"
@@ -48,8 +48,8 @@ fetch_and_deploy_gh_release "silo_mcli" "pgsty/mc" "prebuild" "latest" "/opt/mcl
msg_info "Configuring Silo"
mkdir -p /opt/minio/data
MINIO_ACCESS_KEY=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
MINIO_SECRET_KEY=$(openssl rand -base64 36 | tr -dc 'a-zA-Z0-9' | head -c32)
MINIO_ACCESS_KEY=$(random_password 16)
MINIO_SECRET_KEY=$(random_password 32)
cat <<EOF >/etc/default/minio
MINIO_ROOT_USER="${MINIO_ACCESS_KEY}"
MINIO_ROOT_PASSWORD="${MINIO_SECRET_KEY}"
+1 -1
View File
@@ -26,7 +26,7 @@ USE_ORIGINAL_FILENAME="true" fetch_and_deploy_gh_release "plant-it" "MDeLuise/pl
fetch_and_deploy_gh_release "plant-it-front" "MDeLuise/plant-it" "prebuild" "0.10.0" "/opt/plant-it/frontend" "client.tar.gz"
msg_info "Configuring Plant-it"
JWT_SECRET=$(openssl rand -base64 24 | tr -d '/+=')
JWT_SECRET=$(random_password 32)
mkdir -p /opt/plant-it-data
cat <<EOF >/opt/plant-it/backend/server.env
MYSQL_HOST=localhost
+1 -1
View File
@@ -55,7 +55,7 @@ sqlite3 /var/lib/powerdns/powerdns.db </opt/poweradmin/sql/pdns/49/schema.sqlite
PA_ADMIN_USERNAME="admin"
PA_ADMIN_EMAIL="admin@example.com"
PA_ADMIN_FULLNAME="Administrator"
PA_ADMIN_PASSWORD=$(openssl rand -base64 16 | tr -d "=+/" | cut -c1-16)
PA_ADMIN_PASSWORD=$(random_password 16)
PA_SESSION_KEY=$(openssl rand -base64 75 | tr -dc 'A-Za-z0-9^@#!(){}[]%_\-+=~' | head -c 50)
PASSWORD_HASH=$(php -r "echo password_hash(\$argv[1], PASSWORD_DEFAULT);" -- "${PA_ADMIN_PASSWORD}" 2>/dev/null)
sqlite3 /var/lib/powerdns/powerdns.db "INSERT INTO users (username, password, fullname, email, description, perm_templ, active, use_ldap) \
+1 -1
View File
@@ -28,7 +28,7 @@ msg_info "Configuring ProjectSend"
cd /opt/projectsend
cp .env.example .env
ADMIN_EMAIL="admin@example.com"
ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMIN_PASSWORD=$(random_password 13)
sed -i \
-e "s|^APP_ENV=.*|APP_ENV=production|" \
-e "s|^APP_DEBUG=.*|APP_DEBUG=false|" \
+1 -1
View File
@@ -56,7 +56,7 @@ fetch_and_deploy_gh_release "pterodactyl-panel" "pterodactyl/panel" "prebuild" "
msg_info "Installing pterodactyl Panel"
cd /opt/pterodactyl-panel
cp .env.example .env
ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMIN_PASS=$(random_password 13)
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD php artisan key:generate --force
$STD php artisan p:environment:setup --no-interaction --author "$ADMIN_EMAIL" --url "http://$LOCAL_IP"
+1 -1
View File
@@ -22,7 +22,7 @@ fetch_and_deploy_gh_release "Radicale" "Kozea/Radicale" "tarball" "latest" "/opt
msg_info "Setting up Radicale"
cd /opt/radicale
RNDPASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
RNDPASS=$(random_password 13)
$STD htpasswd -c -b -5 /opt/radicale/users admin "$RNDPASS"
cat <<EOF >~/radicale.creds
Radicale Credentials
+1 -1
View File
@@ -22,7 +22,7 @@ setup_deb_based() {
msg_info "Installing rclone"
cd /opt/rclone
RCLONE_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
RCLONE_PASSWORD=$(random_password 13)
$STD htpasswd -cb -B /opt/login.pwd admin "$RCLONE_PASSWORD"
cat <<EOF >~/rclone.creds
rclone-Credentials
+1 -1
View File
@@ -19,7 +19,7 @@ chmod +x /opt/rustfs/rustfs
msg_info "Configuring RustFS"
RUSTFS_ACCESS_KEY=$(openssl rand -hex 8)
RUSTFS_SECRET_KEY=$(openssl rand -base64 24 | tr -dc 'a-zA-Z0-9' | head -c 32)
RUSTFS_SECRET_KEY=$(random_password 32)
cat <<EOF >/etc/default/rustfs
RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY}
RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY}
+1 -1
View File
@@ -116,7 +116,7 @@ msg_info "Configuring Safebucket"
useradd --system --no-create-home --shell /usr/sbin/nologin safebucket 2>/dev/null || true
mkdir -p /opt/safebucket/data/{notifications,activity}
TOKEN_SECRET=$(openssl rand -base64 32)
MFA_KEY=$(openssl rand -base64 48 | tr -dc 'a-zA-Z0-9' | cut -c1-32)
MFA_KEY=$(random_password 32)
ADMIN_PASSWORD=$(openssl rand -hex 12)
cat <<EOF >/opt/safebucket/config.yaml
app:
+1 -1
View File
@@ -30,7 +30,7 @@ fetch_and_deploy_gh_release "seanime" "5rahim/seanime" "prebuild" "latest" "/opt
chmod +x /opt/seanime/seanime
msg_info "Configuring Seanime"
SEANIME_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
SEANIME_PASSWORD=$(random_password 13)
mkdir -p /opt/seanime-data
cat <<EOF >/opt/seanime-data/config.toml
[server]
+1 -1
View File
@@ -26,7 +26,7 @@ GO_VERSION="$(grep -m1 '^go ' /opt/seelf/go.mod | awk '{print $2}')" setup_go
msg_info "Setting up seelf. Patience"
cd /opt/seelf
$STD make build
PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
PASS=$(random_password 13)
mkdir -p /opt/seelf/data
{
echo "ADMIN_EMAIL=admin@example.com"
+1 -1
View File
@@ -27,7 +27,7 @@ cd /opt/semaphore
SEM_HASH=$(openssl rand -base64 32)
SEM_ENCRYPTION=$(openssl rand -base64 32)
SEM_KEY=$(openssl rand -base64 32)
SEM_PW=$(openssl rand -base64 12)
SEM_PW=$(random_password 16)
cat <<EOF >/opt/semaphore/config.json
{
"sqlite": {
+1 -1
View File
@@ -18,7 +18,7 @@ fetch_and_deploy_gh_release "silo" "pgsty/silo" "binary"
msg_info "Configuring Silo"
mkdir -p /opt/silo_data
chown silo:silo /opt/silo_data
SILO_ROOT_PASSWORD=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c 32)
SILO_ROOT_PASSWORD=$(random_password 32)
cat <<EOF >/etc/default/silo
MINIO_VOLUMES="/opt/silo_data"
MINIO_OPTS="--console-address :9001"
+1 -1
View File
@@ -36,7 +36,7 @@ sed \
-e "s|^SPARKY_FITNESS_DB_USER=.*|SPARKY_FITNESS_DB_USER=sparky|" \
-e "s|^SPARKY_FITNESS_DB_PASSWORD=.*|SPARKY_FITNESS_DB_PASSWORD=${PG_DB_PASS}|" \
-e "s|^# SPARKY_FITNESS_APP_DB_USER=.*|SPARKY_FITNESS_APP_DB_USER=sparky_app|" \
-e "s|^# SPARKY_FITNESS_APP_DB_PASSWORD=.*|SPARKY_FITNESS_APP_DB_PASSWORD=$(openssl rand -base64 24 | tr -dc 'a-zA-Z0-9' | head -c20)|" \
-e "s|^# SPARKY_FITNESS_APP_DB_PASSWORD=.*|SPARKY_FITNESS_APP_DB_PASSWORD=$(random_password 20)|" \
-e "s|^# SPARKY_FITNESS_SERVER_HOST=.*|SPARKY_FITNESS_SERVER_HOST=localhost|" \
-e "s|^# SPARKY_FITNESS_SERVER_PORT=.*|SPARKY_FITNESS_SERVER_PORT=3010|" \
-e "s|^SPARKY_FITNESS_FRONTEND_URL=.*|SPARKY_FITNESS_FRONTEND_URL=http://${LOCAL_IP}:80|" \
+1 -1
View File
@@ -58,7 +58,7 @@ msg_ok "Setup Splunk Enterprise v${RELEASE}"
msg_info "Creating Splunk admin user"
ADMIN_USER="admin"
ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ADMIN_PASS=$(random_password 13)
cat <<EOF >~/splunk.creds
Splunk-Credentials
Username: $ADMIN_USER
+1 -1
View File
@@ -51,7 +51,7 @@ msg_ok "Ran Database Migrations"
msg_info "Creating Admin User"
cd /opt/sync-in
ADMIN_PASS=$(openssl rand -base64 18)
ADMIN_PASS=$(random_password 24)
$STD npx sync-in-server create-user --role admin --login admin --password "${ADMIN_PASS}"
cat <<EOF >~/sync-in.creds
Sync-in Credentials
+2 -2
View File
@@ -23,7 +23,7 @@ setup_deb_based() {
fetch_and_deploy_gh_release "tinyauth" "steveiliop56/tinyauth" "singlefile" "latest" "/opt/tinyauth" "tinyauth-$(arch_resolve)"
msg_info "Setting up Tinyauth"
PASS=$(openssl rand -base64 8 | tr -dc 'a-zA-Z0-9' | head -c 8)
PASS=$(random_password 8)
USER=$(htpasswd -Bbn "tinyauth" "${PASS}")
cat <<EOF >/opt/tinyauth/credentials.txt
Tinyauth Credentials
@@ -67,7 +67,7 @@ setup_alpine() {
fetch_and_deploy_gh_release "tinyauth" "tinyauthapp/tinyauth" "singlefile" "latest" "/opt/tinyauth" "tinyauth-$(arch_resolve)"
msg_info "Configuring Tinyauth"
PASS=$(openssl rand -base64 8 | tr -dc 'a-zA-Z0-9' | head -c 8)
PASS=$(random_password 8)
USER=$(htpasswd -Bbn "tinyauth" "${PASS}")
cat <<EOF >/opt/tinyauth/credentials.txt
+1 -1
View File
@@ -55,7 +55,7 @@ msg_ok "Set up TREK Workspace"
msg_info "Configuring TREK"
ENCRYPTION_KEY=$(openssl rand -hex 32)
ADMIN_EMAIL="admin@trek.local"
ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'A-Za-z0-9' | head -c 16)
ADMIN_PASSWORD=$(random_password 16)
cat <<EOF >/opt/trek/server/.env
NODE_ENV=production
HOST=0.0.0.0
+2 -2
View File
@@ -98,8 +98,8 @@ if [[ -f /opt/tubearchivist/backend/requirements.plugins.txt ]]; then
mkdir -p /opt/yt_plugins/bgutil
$STD uv pip install --python /opt/tubearchivist/.venv/bin/python --target /opt/yt_plugins/bgutil -r /opt/tubearchivist/backend/requirements.plugins.txt
fi
TA_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ES_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
TA_PASSWORD=$(random_password 13)
ES_PASSWORD=$(random_password 13)
mkdir -p /opt/tubearchivist/{cache,media}
ln -sf /opt/tubearchivist/cache /cache
ln -sf /opt/tubearchivist/media /youtube
+2 -2
View File
@@ -40,7 +40,7 @@ msg_ok "Umbraco templates installed and project created"
msg_info "Configuring database connection and unattended setup"
cd /var/www/html/$var_project_name
UMBRACO_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
UMBRACO_PASS=$(random_password 13)
jq --arg umbracopass "$UMBRACO_PASS" '. + {
"ConnectionStrings": {
"umbracoDbDSN": "Data Source=|DataDirectory|/Umbraco.sqlite.db;Cache=Shared;Foreign Keys=True;Pooling=True",
@@ -141,7 +141,7 @@ msg_ok "Umbraco published successfully to /var/www/html/$var_project_name-publis
msg_info "Setting up FTP Server"
useradd ftpuser
FTP_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
FTP_PASS=$(random_password 13)
usermod --password $(echo ${FTP_PASS} | openssl passwd -1 -stdin) ftpuser
mkdir -p /var/www/html
usermod -d /var/www/html ftp
+2 -2
View File
@@ -19,7 +19,7 @@ setup_deb_based() {
$STD apt install -y valkey openssl
sed -i 's/^bind .*/bind 0.0.0.0/' /etc/valkey/valkey.conf
PASS="$(openssl rand -base64 48 | tr -dc 'a-zA-Z0-9' | head -c32)"
PASS="$(random_password 32)"
echo "requirepass $PASS" >>/etc/valkey/valkey.conf
echo "$PASS" >~/valkey.creds
chmod 600 ~/valkey.creds
@@ -80,7 +80,7 @@ setup_alpine() {
$STD apk add valkey valkey-openrc valkey-cli
sed -i 's/^bind .*/bind 0.0.0.0/' /etc/valkey/valkey.conf
PASS="$(head -c 100 /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c32)"
PASS="$(random_password 32)"
echo "requirepass $PASS" >>/etc/valkey/valkey.conf
echo "$PASS" >~/valkey.creds
chmod 600 ~/valkey.creds
+2 -2
View File
@@ -24,8 +24,8 @@ fi
msg_info "Configuring VersityGW"
mkdir -p /opt/versitygw-data
ACCESS_KEY=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-20)
SECRET_KEY=$(openssl rand -base64 36 | tr -dc 'a-zA-Z0-9' | cut -c1-40)
ACCESS_KEY=$(random_password 20)
SECRET_KEY=$(random_password 40)
cat <<EOF >/etc/versitygw.d/gateway.conf
VGW_BACKEND=posix
+1 -1
View File
@@ -29,7 +29,7 @@ fetch_and_deploy_gh_release "wallabag" "wallabag/wallabag" "prebuild" "latest" "
msg_info "Configuring Wallabag"
cd /opt/wallabag
SECRET_KEY="$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | cut -c1-32)"
SECRET_KEY="$(random_password 32)"
cat <<EOF >/opt/wallabag/app/config/parameters.yml
parameters:
database_driver: pdo_mysql
+2 -2
View File
@@ -26,9 +26,9 @@ PG_VERSION="17" setup_postgresql
msg_info "Setup PostgreSQL"
DB_NAME="warranty_db"
DB_USER="warranty_user"
DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
DB_PASS=$(random_password 13)
DB_ADMIN_USER="warracker_admin"
DB_ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
DB_ADMIN_PASS=$(random_password 13)
$STD sudo -u postgres psql -c "CREATE USER $DB_USER WITH PASSWORD '$DB_PASS';"
$STD sudo -u postgres psql -c "CREATE USER $DB_ADMIN_USER WITH PASSWORD '$DB_ADMIN_PASS' SUPERUSER;"
$STD sudo -u postgres psql -c "CREATE DATABASE $DB_NAME OWNER $DB_ADMIN_USER;"
+1 -1
View File
@@ -26,7 +26,7 @@ msg_ok "Installed Wealthfolio"
msg_info "Configuring Wealthfolio"
mkdir -p /opt/wealthfolio_data
SECRET_KEY=$(openssl rand -base64 32)
WF_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-16)
WF_PASSWORD=$(random_password 16)
WF_PASSWORD_HASH=$(echo -n "$WF_PASSWORD" | argon2 "$(openssl rand -base64 16)" -id -e)
cat <<EOF >/opt/wealthfolio/.env
WF_LISTEN_ADDR=0.0.0.0:8080
+1 -1
View File
@@ -50,7 +50,7 @@ msg_info "Automating Webtrees Setup"
cd /opt/webtrees
mkdir -p /opt/webtrees/data
chown -R www-data:www-data /opt/webtrees/data
WT_ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c15)
WT_ADMIN_PASS=$(random_password 15)
$STD sudo -u www-data php /opt/webtrees/index.php config-ini \
--dbhost=127.0.0.1 \
--dbport=3306 \
+1 -1
View File
@@ -25,7 +25,7 @@ fetch_and_deploy_gh_release "yourls" "YOURLS/YOURLS" "tarball"
msg_info "Configuring YOURLS"
COOKIEKEY=$(openssl rand -hex 24)
YOURLS_PASS=$(openssl rand -base64 12 | tr -dc 'a-zA-Z0-9' | cut -c1-16)
YOURLS_PASS=$(random_password 16)
cat <<EOF >/opt/yourls/user/config.php
<?php
define( 'YOURLS_DB_USER', '${MARIADB_DB_USER}' );
+1 -1
View File
@@ -23,7 +23,7 @@ fetch_and_deploy_gh_release "yt-dlp" "yt-dlp/yt-dlp" "singlefile" "latest" "/usr
msg_info "Setting up YT-DLP-WEBUI"
mkdir -p /opt/yt-dlp-webui
mkdir /downloads
RPC_PASSWORD=$(openssl rand -base64 16)
RPC_PASSWORD=$(random_password 21)
cat <<EOF >~/yt-dlp-webui.creds
yt-dlp-webui-Credentials
Username: admin
+1 -1
View File
@@ -18,7 +18,7 @@ NODE_VERSION="24" NODE_MODULE="pnpm" setup_nodejs
PG_VERSION="17" setup_postgresql
PG_DB_NAME="ziplinedb" PG_DB_USER="zipline" setup_postgresql_db
fetch_and_deploy_gh_release "zipline" "diced/zipline" "tarball"
SECRET_KEY="$(openssl rand -base64 42 | tr -dc 'a-zA-Z0-9')"
SECRET_KEY="$(random_password 56)"
echo "Zipline Secret Key: ${SECRET_KEY}" >>~/zipline.creds
msg_info "Installing Zipline (Patience)"
+3 -3
View File
@@ -22,9 +22,9 @@ PG_VERSION="17" setup_postgresql
msg_info "Installing Postgresql"
DB_NAME="zitadel"
DB_USER="zitadel"
DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
DB_PASS=$(random_password 13)
DB_ADMIN_USER="root"
DB_ADMIN_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)
DB_ADMIN_PASS=$(random_password 13)
systemctl start postgresql
$STD sudo -u postgres psql -c "CREATE USER $DB_USER WITH PASSWORD '$DB_PASS';"
$STD sudo -u postgres psql -c "CREATE USER $DB_ADMIN_USER WITH PASSWORD '$DB_ADMIN_PASS' SUPERUSER;"
@@ -44,7 +44,7 @@ fetch_and_deploy_gh_release "zitadel" "zitadel/zitadel" "prebuild" "latest" "/us
msg_info "Setting up Zitadel Environments"
mkdir -p /opt/zitadel
echo "/opt/zitadel/config.yaml" >"/opt/zitadel/.config"
head -c 32 < <(openssl rand -base64 48 | tr -dc 'a-zA-Z0-9') >"/opt/zitadel/.masterkey"
random_password 32 >"/opt/zitadel/.masterkey"
cat <<EOF >~/zitadel.creds
Config location: $(cat "/opt/zitadel/.config")
Masterkey: $(cat "/opt/zitadel/.masterkey")
+1 -1
View File
@@ -22,7 +22,7 @@ fetch_and_deploy_gh_release "zot" "project-zot/zot" "singlefile" "latest" "/usr/
msg_info "Configuring Zot Registry"
mkdir -p /etc/zot
curl -fsSL https://raw.githubusercontent.com/project-zot/zot/refs/heads/main/examples/config-ui.json -o /etc/zot/config.json
ZOTPASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13)
ZOTPASSWORD=$(random_password 13)
$STD htpasswd -b -B -c /etc/zot/htpasswd admin "$ZOTPASSWORD"
cat <<EOF >~/zot.creds
Zot-Credentials
+1 -1
View File
@@ -96,7 +96,7 @@ TEMPLATE=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "All Templat
# Setup script environment
NAME=$(echo "$TEMPLATE" | grep -oE '^[^-]+-[^-]+')
PASS="$(openssl rand -base64 8)"
PASS="$(random_password 16)"
# Get valid Container ID
CTID=$(pvesh get /cluster/nextid)
+2 -2
View File
@@ -86,8 +86,8 @@ function install() {
# Generate secrets and config values
local ENCRYPTION_KEY JWT_SECRET PROJ_DIR BUILDS_DIR
ENCRYPTION_KEY=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c32)
JWT_SECRET=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c32)
ENCRYPTION_KEY=$(random_password 32)
JWT_SECRET=$(random_password 32)
PROJ_DIR="/etc/arcane/projects"
BUILDS_DIR="/etc/arcane/builds"
+1 -1
View File
@@ -89,7 +89,7 @@ function install() {
fetch_and_deploy_gh_release "cronmaster" "fccview/cronmaster" "prebuild" "latest" "$INSTALL_PATH" "cronmaster_*_prebuild.tar.gz"
local AUTH_PASS
AUTH_PASS="$(openssl rand -base64 18 | cut -c1-13)"
AUTH_PASS="$(random_password 13)"
msg_info "Creating configuration"
cat <<EOF >"$CONFIG_PATH"
+2 -2
View File
@@ -137,7 +137,7 @@ function install() {
echo ""
else
# Generate new password
DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
DB_PASS=$(random_password 16)
# Check if user exists, create if not
if sudo -u postgres psql -tAc "SELECT 1 FROM pg_roles WHERE rolname='${DB_USER}'" 2>/dev/null | grep -q 1; then
@@ -187,7 +187,7 @@ function install() {
# Generate JWT Secret
local JWT_SECRET
JWT_SECRET=$(openssl rand -base64 32 | tr -dc 'a-zA-Z0-9' | head -c32)
JWT_SECRET=$(random_password 32)
# Force fresh download by removing version cache
rm -f "$HOME/.jellystat"
+4 -4
View File
@@ -189,10 +189,10 @@ function install() {
msg_info "Configuring environment"
curl -fsSL "https://raw.githubusercontent.com/moghtech/komodo/main/compose/compose.env" -o "$COMPOSE_ENV"
DB_PASSWORD=$(openssl rand -base64 16 | tr -d '/+=')
ADMIN_PASSWORD=$(openssl rand -base64 8 | tr -d '/+=')
WEBHOOK_SECRET=$(openssl rand -base64 24 | tr -d '/+=')
JWT_SECRET=$(openssl rand -base64 24 | tr -d '/+=')
DB_PASSWORD=$(random_password 21)
ADMIN_PASSWORD=$(random_password 16)
WEBHOOK_SECRET=$(random_password 32)
JWT_SECRET=$(random_password 32)
sed -i "s/^KOMODO_DATABASE_USERNAME=.*/KOMODO_DATABASE_USERNAME=komodo_admin/" "$COMPOSE_ENV"
sed -i "s/^KOMODO_DATABASE_PASSWORD=.*/KOMODO_DATABASE_PASSWORD=${DB_PASSWORD}/" "$COMPOSE_ENV"
+1 -1
View File
@@ -224,7 +224,7 @@ TEMPLATE="${TURNKEY_TEMPLATES[$selected]}"
turnkey="${selected%-*}"
# Generate random password
PASS="$(openssl rand -base64 8)"
PASS="$(random_password 16)"
# Prompt for Container ID
NEXT_ID=$(pvesh get /cluster/nextid 2>/dev/null || echo 100)