mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-03 07:29:36 +00:00
* Scripts: close every msg_info block with msg_ok Past-tense msg_info calls that should have been msg_ok, notices that opened a block before a prompt, and blocks without a closing msg_ok. These already left a stale spinner; with core's block stack they would resume it after every later msg_ok. * Generate passwords with random_password openssl rand -base64 | tr -dc | head -c returned fewer characters than asked for, and the unfiltered | cut variants put / and + into passwords that end up in DSNs and sed expressions. Secrets an app decodes as base64 are unchanged. Requires community-scripts/core#61. * Keep data directories through CLEAN_INSTALL instead of copying them create_backup copied uploads, storage and similar directories twice per update and needed their size again in free space. CLEAN_INSTALL_KEEP moves them aside instead. Only directories the upstream release does not ship, in scripts that restored right after the fetch. Requires community-scripts/core#61. * Drop the 300s uv timeout overrides setup_uv exports UV_HTTP_TIMEOUT=600 now; the scripts' 300 only lowered it. Requires community-scripts/core#61.
111 lines
3.1 KiB
Bash
111 lines
3.1 KiB
Bash
#!/usr/bin/env bash
|
|
|
|
# Copyright (c) 2021-2026 community-scripts ORG
|
|
# Author: pshankinclarke (lazarillo)
|
|
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
|
# Source: https://valkey.io/
|
|
|
|
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
|
color
|
|
verb_ip6
|
|
catch_errors
|
|
setting_up_container
|
|
network_check
|
|
update_os
|
|
|
|
setup_deb_based() {
|
|
msg_info "Installing Valkey"
|
|
apt_update_safe
|
|
$STD apt install -y valkey openssl
|
|
sed -i 's/^bind .*/bind 0.0.0.0/' /etc/valkey/valkey.conf
|
|
|
|
PASS="$(random_password 32)"
|
|
echo "requirepass $PASS" >>/etc/valkey/valkey.conf
|
|
echo "$PASS" >~/valkey.creds
|
|
chmod 600 ~/valkey.creds
|
|
|
|
MEMTOTAL_MB=$(free -m | grep ^Mem: | awk '{print $2}')
|
|
# reserve 25% of a node type's maxmemory value for system use
|
|
MAXMEMORY_MB=$((MEMTOTAL_MB * 75 / 100))
|
|
|
|
echo "" >>/etc/valkey/valkey.conf
|
|
echo "# Memory-optimized settings for small-scale deployments" >>/etc/valkey/valkey.conf
|
|
echo "maxmemory ${MAXMEMORY_MB}mb" >>/etc/valkey/valkey.conf
|
|
echo "maxmemory-policy allkeys-lru" >>/etc/valkey/valkey.conf
|
|
echo "maxmemory-samples 10" >>/etc/valkey/valkey.conf
|
|
msg_ok "Installed Valkey"
|
|
|
|
echo
|
|
read -r -p "${TAB3}Enable TLS for Valkey (Sentinel mode does not supported)? [y/N]: " prompt
|
|
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
|
|
read -r -p "${TAB3}Use TLS-only mode (disable TCP port 6379)? [y/N]: " tls_only
|
|
msg_info "Configuring TLS for Valkey..."
|
|
|
|
create_self_signed_cert "Valkey"
|
|
TLS_DIR="/etc/ssl/valkey"
|
|
TLS_CERT="$TLS_DIR/valkey.crt"
|
|
TLS_KEY="$TLS_DIR/valkey.key"
|
|
chown valkey:valkey "$TLS_CERT" "$TLS_KEY"
|
|
|
|
if [[ ${tls_only,,} =~ ^(y|yes)$ ]]; then
|
|
cat <<EOF >/etc/valkey/valkey.conf
|
|
|
|
# TLS configuration generated by Proxmox VE Valkey helper-script
|
|
port 0
|
|
tls-port 6379
|
|
tls-cert-file $TLS_DIR/valkey.crt
|
|
tls-key-file $TLS_DIR/valkey.key
|
|
tls-auth-clients no
|
|
EOF
|
|
msg_ok "Enabled TLS-only mode on port 6379"
|
|
else
|
|
cat <<EOF >/etc/valkey/valkey.conf
|
|
|
|
# TLS configuration generated by Proxmox VE Valkey helper-script
|
|
tls-port 6380
|
|
tls-cert-file $TLS_DIR/valkey.crt
|
|
tls-key-file $TLS_DIR/valkey.key
|
|
tls-auth-clients no
|
|
EOF
|
|
msg_ok "Enabled TLS on port 6380 and TCP on 6379"
|
|
fi
|
|
fi
|
|
|
|
systemctl enable -q --now valkey-server
|
|
systemctl restart valkey-server
|
|
}
|
|
|
|
setup_alpine() {
|
|
msg_info "Installing Valkey"
|
|
$STD apk add valkey valkey-openrc valkey-cli
|
|
sed -i 's/^bind .*/bind 0.0.0.0/' /etc/valkey/valkey.conf
|
|
|
|
PASS="$(random_password 32)"
|
|
echo "requirepass $PASS" >>/etc/valkey/valkey.conf
|
|
echo "$PASS" >~/valkey.creds
|
|
chmod 600 ~/valkey.creds
|
|
|
|
MEMTOTAL_MB=$(free -m | grep ^Mem: | awk '{print $2}')
|
|
MAXMEMORY_MB=$((MEMTOTAL_MB * 75 / 100))
|
|
|
|
cat <<EOF >/etc/valkey/valkey.conf
|
|
# Memory-optimized settings for small-scale deployments
|
|
maxmemory ${MAXMEMORY_MB}mb
|
|
maxmemory-policy allkeys-lru
|
|
maxmemory-samples 10
|
|
EOF
|
|
msg_ok "Installed Valkey"
|
|
|
|
# Note: Alpine's valkey package is compiled without TLS support
|
|
# For TLS, use the Debian-based valkey script instead
|
|
|
|
$STD rc-update add valkey default
|
|
$STD rc-service valkey start
|
|
}
|
|
|
|
run_os_setup
|
|
|
|
motd_ssh
|
|
customize
|
|
cleanup_lxc
|