install.sh 35 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047
  1. #!/usr/bin/env bash
  2. #
  3. # BamBuddy Native Installation Script
  4. # Supports: Debian/Ubuntu, RHEL/Fedora/CentOS, Arch Linux, macOS
  5. #
  6. # Usage:
  7. # Interactive: curl -fsSL https://raw.githubusercontent.com/maziggy/bambuddy/main/install/install.sh -o install.sh && chmod +x install.sh && ./install.sh
  8. # Unattended: ./install.sh --path /opt/bambuddy --port 8000 --yes
  9. #
  10. # Options:
  11. # --path PATH Installation directory (default: /opt/bambuddy)
  12. # --port PORT Port to listen on (default: 8000)
  13. # --bind ADDRESS Bind address: 0.0.0.0 (network) or 127.0.0.1 (local only)
  14. # --tz TIMEZONE Timezone (default: system timezone or UTC)
  15. # --data-dir PATH Data directory (default: INSTALL_PATH/data)
  16. # --log-dir PATH Log directory (default: INSTALL_PATH/logs)
  17. # --debug Enable debug mode
  18. # --log-level LEVEL Log level: DEBUG, INFO, WARNING, ERROR (default: INFO)
  19. # --branch BRANCH Git branch to install (default: main)
  20. # --no-service Skip systemd service setup (Linux only)
  21. # --set-system-tz Set system timezone to match (for unattended installs)
  22. # --yes, -y Non-interactive mode, accept defaults
  23. # --help, -h Show this help message
  24. #
  25. set -e
  26. # Colors for output
  27. RED='\033[0;31m'
  28. GREEN='\033[0;32m'
  29. YELLOW='\033[1;33m'
  30. BLUE='\033[0;34m'
  31. CYAN='\033[0;36m'
  32. NC='\033[0m' # No Color
  33. BOLD='\033[1m'
  34. # Default values
  35. DEFAULT_INSTALL_PATH="/opt/bambuddy"
  36. DEFAULT_PORT="8000"
  37. DEFAULT_BIND_ADDRESS="0.0.0.0"
  38. DEFAULT_LOG_LEVEL="INFO"
  39. DEFAULT_DEBUG="false"
  40. # Script variables
  41. INSTALL_PATH=""
  42. PORT=""
  43. BIND_ADDRESS=""
  44. TIMEZONE=""
  45. DATA_DIR=""
  46. LOG_DIR=""
  47. DEBUG_MODE=""
  48. LOG_LEVEL=""
  49. SKIP_SERVICE="false"
  50. SET_SYSTEM_TZ=""
  51. NON_INTERACTIVE="false"
  52. OS_TYPE=""
  53. PKG_MANAGER=""
  54. PYTHON_CMD=""
  55. BRANCH=""
  56. SERVICE_USER="bambuddy"
  57. # -----------------------------------------------------------------------------
  58. # Helper Functions
  59. # -----------------------------------------------------------------------------
  60. print_banner() {
  61. echo -e "${CYAN}"
  62. echo "╔════════════════════════════════════════════════════════╗"
  63. echo "║ ║"
  64. echo "║ ____ _ _ _ ║"
  65. echo "║ | __ ) __ _ _ __ ___ | |__ _ _ __| | __| |_ _ ║"
  66. echo "║ | _ \\ / _\` | '_ \` _ \\| '_ \\| | | |/ _\` |/ _\` | | | | ║"
  67. echo "║ | |_) | (_| | | | | | | |_) | |_| | (_| | (_| | |_| | ║"
  68. echo "║ |____/ \\__,_|_| |_| |_|_.__/ \\__,_|\\__,_|\\__,_|\\__, | ║"
  69. echo "║ |___/ ║"
  70. echo "║ ║"
  71. echo "║ Native Installation Script ║"
  72. echo "║ ║"
  73. echo "╚════════════════════════════════════════════════════════╝"
  74. echo -e "${NC}"
  75. }
  76. log_info() {
  77. echo -e "${BLUE}[INFO]${NC} $1"
  78. }
  79. log_success() {
  80. echo -e "${GREEN}[OK]${NC} $1"
  81. }
  82. log_warn() {
  83. echo -e "${YELLOW}[WARN]${NC} $1"
  84. }
  85. log_error() {
  86. echo -e "${RED}[ERROR]${NC} $1"
  87. }
  88. prompt() {
  89. local prompt_text="$1"
  90. local default_value="$2"
  91. local var_name="$3"
  92. if [[ "$NON_INTERACTIVE" == "true" ]]; then
  93. eval "$var_name=\"$default_value\""
  94. return
  95. fi
  96. if [[ -n "$default_value" ]]; then
  97. echo -en "${BOLD}$prompt_text${NC} [${CYAN}$default_value${NC}]: "
  98. else
  99. echo -en "${BOLD}$prompt_text${NC}: "
  100. fi
  101. read -r input
  102. if [[ -z "$input" ]]; then
  103. eval "$var_name=\"$default_value\""
  104. else
  105. eval "$var_name=\"$input\""
  106. fi
  107. }
  108. prompt_yes_no() {
  109. local prompt_text="$1"
  110. local default="$2" # y or n
  111. if [[ "$NON_INTERACTIVE" == "true" ]]; then
  112. [[ "$default" == "y" ]] && return 0 || return 1
  113. fi
  114. local yn_hint="[y/n]"
  115. [[ "$default" == "y" ]] && yn_hint="[Y/n]"
  116. [[ "$default" == "n" ]] && yn_hint="[y/N]"
  117. while true; do
  118. echo -en "${BOLD}$prompt_text${NC} $yn_hint: "
  119. read -r yn
  120. [[ -z "$yn" ]] && yn="$default"
  121. case "$yn" in
  122. [Yy]* ) return 0;;
  123. [Nn]* ) return 1;;
  124. * ) echo "Please answer yes or no.";;
  125. esac
  126. done
  127. }
  128. show_help() {
  129. echo "BamBuddy Native Installation Script"
  130. echo ""
  131. echo "Usage: $0 [OPTIONS]"
  132. echo ""
  133. echo "Options:"
  134. echo " --path PATH Installation directory (default: /opt/bambuddy)"
  135. echo " --port PORT Port to listen on (default: 8000)"
  136. echo " --bind ADDRESS Bind address: 0.0.0.0 (network) or 127.0.0.1 (local only)"
  137. echo " --tz TIMEZONE Timezone (default: system timezone or UTC)"
  138. echo " --data-dir PATH Data directory (default: INSTALL_PATH/data)"
  139. echo " --log-dir PATH Log directory (default: INSTALL_PATH/logs)"
  140. echo " --debug Enable debug mode"
  141. echo " --log-level LEVEL Log level: DEBUG, INFO, WARNING, ERROR (default: INFO)"
  142. echo " --branch BRANCH Git branch to install (default: main)"
  143. echo " --no-service Skip systemd service setup (Linux only)"
  144. echo " --set-system-tz Set system timezone to match (for unattended installs)"
  145. echo " --yes, -y Non-interactive mode, accept defaults"
  146. echo " --help, -h Show this help message"
  147. echo ""
  148. echo "Examples:"
  149. echo " Interactive installation:"
  150. echo " ./install.sh"
  151. echo ""
  152. echo " Unattended installation with custom settings:"
  153. echo " ./install.sh --path /srv/bambuddy --port 3000 --tz America/New_York --yes"
  154. echo ""
  155. echo " Minimal unattended installation:"
  156. echo " ./install.sh -y"
  157. exit 0
  158. }
  159. # -----------------------------------------------------------------------------
  160. # System Detection
  161. # -----------------------------------------------------------------------------
  162. detect_os() {
  163. if [[ "$OSTYPE" == "darwin"* ]]; then
  164. OS_TYPE="macos"
  165. PKG_MANAGER="brew"
  166. return
  167. fi
  168. if [[ -f /etc/os-release ]]; then
  169. . /etc/os-release
  170. case "$ID" in
  171. ubuntu|debian|raspbian|linuxmint|pop)
  172. OS_TYPE="debian"
  173. PKG_MANAGER="apt"
  174. ;;
  175. fedora|rhel|centos|rocky|almalinux|ol)
  176. OS_TYPE="rhel"
  177. if command -v dnf &>/dev/null; then
  178. PKG_MANAGER="dnf"
  179. else
  180. PKG_MANAGER="yum"
  181. fi
  182. ;;
  183. arch|manjaro|endeavouros)
  184. OS_TYPE="arch"
  185. PKG_MANAGER="pacman"
  186. ;;
  187. opensuse*|sles)
  188. OS_TYPE="suse"
  189. PKG_MANAGER="zypper"
  190. ;;
  191. *)
  192. log_error "Unsupported Linux distribution: $ID"
  193. exit 1
  194. ;;
  195. esac
  196. else
  197. log_error "Cannot detect operating system"
  198. exit 1
  199. fi
  200. }
  201. detect_python() {
  202. # Try python3 first, then python
  203. if command -v python3 &>/dev/null; then
  204. PYTHON_CMD="python3"
  205. elif command -v python &>/dev/null; then
  206. local version
  207. version=$(python --version 2>&1 | cut -d' ' -f2 | cut -d'.' -f1)
  208. if [[ "$version" -ge 3 ]]; then
  209. PYTHON_CMD="python"
  210. fi
  211. fi
  212. if [[ -z "$PYTHON_CMD" ]]; then
  213. return 1
  214. fi
  215. # Check version >= 3.10
  216. local version
  217. version=$($PYTHON_CMD -c 'import sys; print(f"{sys.version_info.major}.{sys.version_info.minor}")')
  218. local major minor
  219. major=$(echo "$version" | cut -d'.' -f1)
  220. minor=$(echo "$version" | cut -d'.' -f2)
  221. if [[ "$major" -lt 3 ]] || { [[ "$major" -eq 3 ]] && [[ "$minor" -lt 10 ]]; }; then
  222. log_warn "Python $version found, but 3.10 or newer is required"
  223. return 1
  224. fi
  225. log_success "Found Python $version"
  226. return 0
  227. }
  228. detect_timezone() {
  229. if [[ -n "$TIMEZONE" ]]; then
  230. return 0
  231. fi
  232. # Try to get system timezone (with error handling for set -e)
  233. TIMEZONE=""
  234. if [[ -f /etc/timezone ]]; then
  235. TIMEZONE=$(cat /etc/timezone 2>/dev/null) || true
  236. fi
  237. if [[ -z "$TIMEZONE" ]] && [[ -L /etc/localtime ]]; then
  238. TIMEZONE=$(readlink /etc/localtime 2>/dev/null | sed 's|.*/zoneinfo/||') || true
  239. fi
  240. if [[ -z "$TIMEZONE" ]] && command -v timedatectl &>/dev/null; then
  241. TIMEZONE=$(timedatectl show --property=Timezone --value 2>/dev/null) || true
  242. fi
  243. # Default to UTC if not found (use if/then to avoid set -e issue with &&)
  244. if [[ -z "$TIMEZONE" ]]; then
  245. TIMEZONE="UTC"
  246. fi
  247. return 0
  248. }
  249. # -----------------------------------------------------------------------------
  250. # Package Installation
  251. # -----------------------------------------------------------------------------
  252. install_dependencies() {
  253. log_info "Installing system dependencies..."
  254. case "$PKG_MANAGER" in
  255. apt)
  256. sudo apt-get update
  257. sudo apt-get install -y python3 python3-pip python3-venv git curl ffmpeg
  258. ;;
  259. dnf|yum)
  260. sudo $PKG_MANAGER install -y python3 python3-pip git curl ffmpeg
  261. ;;
  262. pacman)
  263. sudo pacman -Sy --noconfirm python python-pip git curl ffmpeg
  264. ;;
  265. zypper)
  266. sudo zypper install -y python3 python3-pip git curl ffmpeg
  267. ;;
  268. brew)
  269. # Check if Homebrew is installed
  270. if ! command -v brew &>/dev/null; then
  271. log_error "Homebrew not found. Please install it first: https://brew.sh"
  272. exit 1
  273. fi
  274. brew install python git curl ffmpeg
  275. ;;
  276. esac
  277. log_success "System dependencies installed"
  278. }
  279. # -----------------------------------------------------------------------------
  280. # Installation Steps
  281. # -----------------------------------------------------------------------------
  282. create_user() {
  283. if [[ "$OS_TYPE" == "macos" ]]; then
  284. return # Skip user creation on macOS
  285. fi
  286. if id "$SERVICE_USER" &>/dev/null; then
  287. log_info "User '$SERVICE_USER' already exists"
  288. return
  289. fi
  290. log_info "Creating service user '$SERVICE_USER'..."
  291. sudo useradd --system --shell /usr/sbin/nologin --home-dir "$INSTALL_PATH" "$SERVICE_USER"
  292. log_success "Service user created"
  293. }
  294. # Ensure a directory exists and is owned by the current user. Used on macOS so
  295. # the install tree stays user-owned (git/venv/npm never touch a root-owned dir).
  296. # Only elevates when the target's parent is root-owned (e.g. /opt); a path under
  297. # $HOME is created without any sudo prompt.
  298. ensure_user_owned_dir() {
  299. local dir="$1"
  300. if [[ -d "$dir" ]] && [[ -w "$dir" ]]; then
  301. return
  302. fi
  303. if mkdir -p "$dir" 2>/dev/null; then
  304. return
  305. fi
  306. log_info "Creating $dir (requires your password)..."
  307. sudo mkdir -p "$dir"
  308. sudo chown "$(id -un):$(id -gn)" "$dir"
  309. }
  310. download_bambuddy() {
  311. log_info "Downloading BamBuddy..."
  312. # Validate branch exists on remote before proceeding
  313. if ! git ls-remote --exit-code --heads https://github.com/maziggy/bambuddy.git "$BRANCH" &>/dev/null; then
  314. log_error "Branch '$BRANCH' not found in the BamBuddy repository."
  315. log_info "Available branches:"
  316. git ls-remote --heads https://github.com/maziggy/bambuddy.git | sed 's|.*refs/heads/| - |'
  317. exit 1
  318. fi
  319. if [[ "$OS_TYPE" == "macos" ]]; then
  320. # macOS has no service user — the whole install runs as the current user.
  321. # Create the target user-owned (elevating only if its parent is root-owned,
  322. # e.g. /opt), then clone/update without sudo so the venv/frontend the user
  323. # builds next aren't fighting a root-owned tree.
  324. ensure_user_owned_dir "$INSTALL_PATH"
  325. if [[ -d "$INSTALL_PATH/.git" ]]; then
  326. log_info "Existing installation found, updating..."
  327. git config --global --add safe.directory "$INSTALL_PATH" 2>/dev/null || true
  328. cd "$INSTALL_PATH"
  329. git fetch origin
  330. git checkout "$BRANCH" 2>/dev/null || git checkout -b "$BRANCH" "origin/$BRANCH"
  331. git reset --hard "origin/$BRANCH"
  332. else
  333. git clone --branch "$BRANCH" https://github.com/maziggy/bambuddy.git "$INSTALL_PATH"
  334. fi
  335. elif [[ -d "$INSTALL_PATH/.git" ]]; then
  336. log_info "Existing installation found, updating..."
  337. # Add safe.directory to avoid "dubious ownership" error when running as root
  338. git config --global --add safe.directory "$INSTALL_PATH" 2>/dev/null || true
  339. cd "$INSTALL_PATH"
  340. git fetch origin
  341. git checkout "$BRANCH" 2>/dev/null || git checkout -b "$BRANCH" "origin/$BRANCH"
  342. git reset --hard "origin/$BRANCH"
  343. # Ensure correct ownership after update
  344. sudo chown -R "$SERVICE_USER:$SERVICE_USER" "$INSTALL_PATH" 2>/dev/null || true
  345. else
  346. # Clone as root so we have write access regardless of the installing user,
  347. # then hand ownership to the service user. Previously we chown'd the empty
  348. # dir to the service user before the clone, which left the install-running
  349. # user (not root, not bambuddy) unable to write .git into it.
  350. sudo mkdir -p "$INSTALL_PATH"
  351. sudo git clone --branch "$BRANCH" https://github.com/maziggy/bambuddy.git "$INSTALL_PATH"
  352. sudo chown -R "$SERVICE_USER:$SERVICE_USER" "$INSTALL_PATH" 2>/dev/null || true
  353. fi
  354. log_success "BamBuddy downloaded to $INSTALL_PATH (branch: $BRANCH)"
  355. }
  356. setup_virtualenv() {
  357. log_info "Setting up Python virtual environment..."
  358. cd "$INSTALL_PATH"
  359. if [[ "$OS_TYPE" == "macos" ]]; then
  360. $PYTHON_CMD -m venv venv
  361. "$INSTALL_PATH/venv/bin/pip" install --upgrade pip
  362. "$INSTALL_PATH/venv/bin/pip" install -r requirements.txt
  363. else
  364. # Venv is owned by the service user, so pip must also run as that user —
  365. # otherwise `pip install --upgrade pip` fails trying to rewrite its own
  366. # binary inside the venv it doesn't own.
  367. sudo -u "$SERVICE_USER" $PYTHON_CMD -m venv venv 2>/dev/null || $PYTHON_CMD -m venv venv
  368. sudo -u "$SERVICE_USER" "$INSTALL_PATH/venv/bin/pip" install --upgrade pip
  369. sudo -u "$SERVICE_USER" "$INSTALL_PATH/venv/bin/pip" install -r requirements.txt
  370. fi
  371. log_success "Virtual environment configured"
  372. }
  373. check_node_version() {
  374. # Returns 0 if Node.js 20+ is available, 1 otherwise
  375. if ! command -v node &>/dev/null; then
  376. return 1
  377. fi
  378. local version
  379. version=$(node --version 2>/dev/null | sed 's/^v//')
  380. local major
  381. major=$(echo "$version" | cut -d'.' -f1)
  382. if [[ "$major" -ge 20 ]]; then
  383. log_success "Found Node.js v$version"
  384. return 0
  385. else
  386. log_warn "Found Node.js v$version (need 20+)"
  387. return 1
  388. fi
  389. }
  390. install_nodejs() {
  391. log_info "Installing Node.js 22..."
  392. case "$PKG_MANAGER" in
  393. apt)
  394. # Remove old nodejs if present
  395. sudo apt-get remove -y nodejs npm 2>/dev/null || true
  396. curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
  397. sudo apt-get install -y nodejs
  398. ;;
  399. dnf|yum)
  400. sudo $PKG_MANAGER remove -y nodejs npm 2>/dev/null || true
  401. curl -fsSL https://rpm.nodesource.com/setup_22.x | sudo bash -
  402. sudo $PKG_MANAGER install -y nodejs
  403. ;;
  404. pacman)
  405. sudo pacman -S --noconfirm nodejs npm
  406. ;;
  407. zypper)
  408. sudo zypper install -y nodejs22
  409. ;;
  410. brew)
  411. brew install node@22
  412. brew link --overwrite node@22
  413. ;;
  414. *)
  415. log_error "Please install Node.js 20+ manually: https://nodejs.org/"
  416. exit 1
  417. ;;
  418. esac
  419. # Refresh PATH
  420. hash -r 2>/dev/null || true
  421. }
  422. build_frontend() {
  423. log_info "Building frontend..."
  424. cd "$INSTALL_PATH/frontend"
  425. # Check for Node.js 20+
  426. if ! check_node_version; then
  427. install_nodejs
  428. # Verify installation
  429. if ! check_node_version; then
  430. log_error "Failed to install Node.js 20+. Please install manually."
  431. exit 1
  432. fi
  433. fi
  434. # Frontend tree is owned by the service user, so npm must run as that user —
  435. # otherwise creating node_modules/ and writing build output fails. macOS
  436. # keeps the current-user flow since it has no service user.
  437. if [[ "$OS_TYPE" == "macos" ]]; then
  438. npm ci
  439. npm run build
  440. else
  441. sudo -H -u "$SERVICE_USER" npm ci
  442. sudo -H -u "$SERVICE_USER" npm run build
  443. fi
  444. log_success "Frontend built"
  445. }
  446. create_directories() {
  447. log_info "Creating data directories..."
  448. if [[ "$OS_TYPE" == "macos" ]]; then
  449. # Rootless: DATA_DIR/LOG_DIR default under the user-owned install path.
  450. ensure_user_owned_dir "$DATA_DIR"
  451. ensure_user_owned_dir "$LOG_DIR"
  452. else
  453. sudo mkdir -p "$DATA_DIR" "$LOG_DIR"
  454. sudo chown -R "$SERVICE_USER:$SERVICE_USER" "$DATA_DIR" "$LOG_DIR"
  455. fi
  456. log_success "Directories created"
  457. }
  458. create_env_file() {
  459. log_info "Creating environment configuration..."
  460. local env_file="$INSTALL_PATH/.env"
  461. # Note: Only include settings recognized by the app's pydantic Settings class
  462. # Other settings (PORT, BIND_ADDRESS, DATA_DIR, LOG_DIR, TZ) are set in systemd service
  463. cat > /tmp/bambuddy.env << EOF
  464. # BamBuddy Configuration
  465. # Generated by install.sh on $(date)
  466. # Debug mode (true = verbose logging)
  467. DEBUG=$DEBUG_MODE
  468. # Log level (only used when DEBUG=false)
  469. # Options: DEBUG, INFO, WARNING, ERROR
  470. LOG_LEVEL=$LOG_LEVEL
  471. # Enable file logging
  472. LOG_TO_FILE=true
  473. EOF
  474. if [[ "$OS_TYPE" == "macos" ]]; then
  475. # Rootless: install path is user-owned, so write it directly.
  476. mv /tmp/bambuddy.env "$env_file"
  477. chmod 600 "$env_file"
  478. else
  479. sudo mv /tmp/bambuddy.env "$env_file"
  480. sudo chown "$SERVICE_USER:$SERVICE_USER" "$env_file"
  481. sudo chmod 600 "$env_file"
  482. fi
  483. log_success "Environment file created at $env_file"
  484. }
  485. create_systemd_service() {
  486. if [[ "$OS_TYPE" == "macos" ]] || [[ "$SKIP_SERVICE" == "true" ]]; then
  487. return
  488. fi
  489. log_info "Creating systemd service..."
  490. # ProtectHome=true hides /home/* from the service, which breaks ExecStart
  491. # when INSTALL_PATH lives under /home (issue #1685). Loosen to read-only in
  492. # that case so the venv binary is still resolvable; ReadWritePaths below
  493. # re-grants writes for the install/data/log dirs.
  494. local protect_home="true"
  495. if [[ "$INSTALL_PATH" == /home/* ]]; then
  496. protect_home="read-only"
  497. fi
  498. # This function overwrites /etc/systemd/system/bambuddy.service outright. Any
  499. # ReadWritePaths the operator added by hand — a NAS share for Scheduled
  500. # Backups, typically — used to disappear with it, and the next backup failed
  501. # with EROFS ("Read-only file system"), which reads like a permission problem
  502. # and is not one (issue #2544). Back the old unit up and carry those paths
  503. # forward.
  504. local existing_unit="/etc/systemd/system/bambuddy.service"
  505. local extra_rw=""
  506. if [[ -f "$existing_unit" ]]; then
  507. local backup_unit="${existing_unit}.bak-$(date +%Y%m%d-%H%M%S)"
  508. sudo cp "$existing_unit" "$backup_unit"
  509. log_info "Existing service backed up to $backup_unit"
  510. local prev_rw
  511. prev_rw=$(sudo grep -hE '^ReadWritePaths=' "$existing_unit" 2>/dev/null | sed 's/^ReadWritePaths=//' || true)
  512. local p
  513. for p in $prev_rw; do
  514. case "$p" in
  515. "$DATA_DIR" | "$LOG_DIR" | "$INSTALL_PATH") continue ;;
  516. esac
  517. extra_rw+=" $p"
  518. done
  519. if [[ -n "$extra_rw" ]]; then
  520. log_info "Keeping custom writable paths from the previous service:$extra_rw"
  521. fi
  522. fi
  523. cat > /tmp/bambuddy.service << EOF
  524. [Unit]
  525. Description=BamBuddy - Bambu Lab Print Management
  526. Documentation=https://github.com/maziggy/bambuddy
  527. After=network.target
  528. [Service]
  529. Type=simple
  530. User=$SERVICE_USER
  531. Group=$SERVICE_USER
  532. WorkingDirectory=$INSTALL_PATH
  533. # App settings from .env file
  534. EnvironmentFile=$INSTALL_PATH/.env
  535. # Service settings (not in .env to avoid pydantic validation errors)
  536. Environment="DATA_DIR=$DATA_DIR"
  537. Environment="LOG_DIR=$LOG_DIR"
  538. Environment="TZ=$TIMEZONE"
  539. # --loop asyncio required: uvloop can truncate VP FTP uploads (#1896)
  540. # --timeout-graceful-shutdown required: uvicorn otherwise waits forever for
  541. # in-flight requests, and an MJPEG camera stream never completes — one open
  542. # camera tile hangs the stop until systemd SIGKILLs, skipping the WAL
  543. # checkpoint and the MQTT / virtual-printer teardown.
  544. ExecStart=$INSTALL_PATH/venv/bin/uvicorn backend.app.main:app --host $BIND_ADDRESS --port $PORT --loop asyncio --timeout-graceful-shutdown 5
  545. Restart=on-failure
  546. RestartSec=5
  547. # Backstop only — uvicorn bounds its own wait at 5s and teardown takes ~1-2s.
  548. TimeoutStopSec=30
  549. StandardOutput=journal
  550. StandardError=journal
  551. # Allow binding to privileged ports (322, 990, 2024-2026) for Virtual Printer proxy mode
  552. AmbientCapabilities=CAP_NET_BIND_SERVICE
  553. # Security hardening
  554. NoNewPrivileges=true
  555. PrivateTmp=true
  556. ProtectSystem=strict
  557. ProtectHome=$protect_home
  558. # ProtectSystem=strict makes EVERY path outside the ones below read-only for this
  559. # service — including a NAS share you mounted yourself and can write to from your
  560. # own shell. If you point Scheduled Backups at such a directory, add it here, or
  561. # better in a drop-in that survives a reinstall (#2544):
  562. #
  563. # sudo systemctl edit bambuddy
  564. # [Service]
  565. # ReadWritePaths=/mnt/your-nas-share
  566. #
  567. ReadWritePaths=$DATA_DIR $LOG_DIR $INSTALL_PATH$extra_rw
  568. [Install]
  569. WantedBy=multi-user.target
  570. EOF
  571. sudo mv /tmp/bambuddy.service /etc/systemd/system/bambuddy.service
  572. sudo systemctl daemon-reload
  573. log_success "Systemd service created"
  574. if prompt_yes_no "Enable BamBuddy to start on boot?" "y"; then
  575. sudo systemctl enable bambuddy
  576. log_success "Service enabled"
  577. fi
  578. if prompt_yes_no "Start BamBuddy now?" "y"; then
  579. sudo systemctl start bambuddy
  580. sleep 2
  581. if sudo systemctl is-active --quiet bambuddy; then
  582. log_success "BamBuddy is running"
  583. else
  584. log_warn "Service may have failed to start. Check: sudo journalctl -u bambuddy -f"
  585. fi
  586. fi
  587. }
  588. create_launchd_service() {
  589. if [[ "$OS_TYPE" != "macos" ]] || [[ "$SKIP_SERVICE" == "true" ]]; then
  590. return
  591. fi
  592. log_info "Creating launchd service..."
  593. local plist_path="$HOME/Library/LaunchAgents/com.bambuddy.app.plist"
  594. cat > "$plist_path" << EOF
  595. <?xml version="1.0" encoding="UTF-8"?>
  596. <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
  597. <plist version="1.0">
  598. <dict>
  599. <key>Label</key>
  600. <string>com.bambuddy.app</string>
  601. <key>ProgramArguments</key>
  602. <array>
  603. <string>$INSTALL_PATH/venv/bin/uvicorn</string>
  604. <string>backend.app.main:app</string>
  605. <string>--host</string>
  606. <string>$BIND_ADDRESS</string>
  607. <string>--port</string>
  608. <string>$PORT</string>
  609. <!-- the loop asyncio flag below is required: uvloop can truncate VP FTP uploads, #1896 -->
  610. <string>--loop</string>
  611. <string>asyncio</string>
  612. <!-- required: uvicorn otherwise waits forever for in-flight requests, and an
  613. MJPEG camera stream never completes — one open camera tile hangs the stop
  614. until launchd SIGKILLs, skipping the WAL checkpoint and MQTT teardown -->
  615. <string>--timeout-graceful-shutdown</string>
  616. <string>5</string>
  617. </array>
  618. <key>WorkingDirectory</key>
  619. <string>$INSTALL_PATH</string>
  620. <key>EnvironmentVariables</key>
  621. <dict>
  622. <key>DEBUG</key>
  623. <string>$DEBUG_MODE</string>
  624. <key>LOG_LEVEL</key>
  625. <string>$LOG_LEVEL</string>
  626. <key>DATA_DIR</key>
  627. <string>$DATA_DIR</string>
  628. <key>LOG_DIR</key>
  629. <string>$LOG_DIR</string>
  630. <key>TZ</key>
  631. <string>$TIMEZONE</string>
  632. </dict>
  633. <key>RunAtLoad</key>
  634. <true/>
  635. <key>KeepAlive</key>
  636. <true/>
  637. <key>StandardOutPath</key>
  638. <string>$LOG_DIR/bambuddy.log</string>
  639. <key>StandardErrorPath</key>
  640. <string>$LOG_DIR/bambuddy.error.log</string>
  641. </dict>
  642. </plist>
  643. EOF
  644. log_success "Launchd plist created at $plist_path"
  645. if prompt_yes_no "Load BamBuddy service now?" "y"; then
  646. launchctl load "$plist_path"
  647. sleep 2
  648. if launchctl list | grep -q "com.bambuddy.app"; then
  649. log_success "BamBuddy is running"
  650. else
  651. log_warn "Service may have failed to start. Check: cat $LOG_DIR/bambuddy.error.log"
  652. fi
  653. fi
  654. }
  655. # -----------------------------------------------------------------------------
  656. # Main Installation Flow
  657. # -----------------------------------------------------------------------------
  658. parse_args() {
  659. while [[ $# -gt 0 ]]; do
  660. case "$1" in
  661. --path)
  662. INSTALL_PATH="$2"
  663. shift 2
  664. ;;
  665. --port)
  666. PORT="$2"
  667. shift 2
  668. ;;
  669. --bind)
  670. BIND_ADDRESS="$2"
  671. shift 2
  672. ;;
  673. --tz)
  674. TIMEZONE="$2"
  675. shift 2
  676. ;;
  677. --data-dir)
  678. DATA_DIR="$2"
  679. shift 2
  680. ;;
  681. --log-dir)
  682. LOG_DIR="$2"
  683. shift 2
  684. ;;
  685. --debug)
  686. DEBUG_MODE="true"
  687. shift
  688. ;;
  689. --log-level)
  690. LOG_LEVEL="$2"
  691. shift 2
  692. ;;
  693. --branch)
  694. BRANCH="$2"
  695. shift 2
  696. ;;
  697. --no-service)
  698. SKIP_SERVICE="true"
  699. shift
  700. ;;
  701. --set-system-tz)
  702. SET_SYSTEM_TZ="true"
  703. shift
  704. ;;
  705. --yes|-y)
  706. NON_INTERACTIVE="true"
  707. shift
  708. ;;
  709. --help|-h)
  710. show_help
  711. ;;
  712. *)
  713. log_error "Unknown option: $1"
  714. show_help
  715. ;;
  716. esac
  717. done
  718. }
  719. gather_config() {
  720. echo ""
  721. echo -e "${BOLD}Installation Configuration${NC}"
  722. echo -e "${CYAN}─────────────────────────────────────────${NC}"
  723. echo ""
  724. # Installation path
  725. [[ -z "$INSTALL_PATH" ]] && prompt "Installation directory" "$DEFAULT_INSTALL_PATH" INSTALL_PATH
  726. # Branch
  727. [[ -z "$BRANCH" ]] && prompt "Git branch" "main" BRANCH
  728. # Port
  729. [[ -z "$PORT" ]] && prompt "Port to listen on" "$DEFAULT_PORT" PORT
  730. # Bind address
  731. if [[ -z "$BIND_ADDRESS" ]]; then
  732. echo ""
  733. echo "Network access:"
  734. echo " 0.0.0.0 - Accessible from other devices on your network (recommended)"
  735. echo " 127.0.0.1 - Only accessible from this machine"
  736. prompt "Bind address" "$DEFAULT_BIND_ADDRESS" BIND_ADDRESS
  737. fi
  738. # Timezone
  739. detect_timezone
  740. prompt "Timezone" "$TIMEZONE" TIMEZONE
  741. # Offer to set system timezone if different from current (skip if already set via --set-system-tz)
  742. if [[ -z "$SET_SYSTEM_TZ" ]]; then
  743. local current_tz
  744. current_tz=$(timedatectl show --property=Timezone --value 2>/dev/null) || true
  745. if [[ -n "$TIMEZONE" ]] && [[ "$TIMEZONE" != "$current_tz" ]]; then
  746. # Default to "n" so unattended installs don't change system TZ unless --set-system-tz is used
  747. if prompt_yes_no "Set system timezone to $TIMEZONE?" "n"; then
  748. SET_SYSTEM_TZ="true"
  749. else
  750. SET_SYSTEM_TZ="false"
  751. fi
  752. else
  753. SET_SYSTEM_TZ="false"
  754. fi
  755. fi
  756. # Data directory
  757. [[ -z "$DATA_DIR" ]] && DATA_DIR="$INSTALL_PATH/data"
  758. prompt "Data directory" "$DATA_DIR" DATA_DIR
  759. # Log directory
  760. [[ -z "$LOG_DIR" ]] && LOG_DIR="$INSTALL_PATH/logs"
  761. prompt "Log directory" "$LOG_DIR" LOG_DIR
  762. # Debug mode
  763. if [[ -z "$DEBUG_MODE" ]]; then
  764. if prompt_yes_no "Enable debug mode?" "n"; then
  765. DEBUG_MODE="true"
  766. else
  767. DEBUG_MODE="false"
  768. fi
  769. fi
  770. # Log level
  771. if [[ -z "$LOG_LEVEL" ]]; then
  772. echo ""
  773. echo "Log levels: DEBUG, INFO, WARNING, ERROR"
  774. prompt "Log level" "$DEFAULT_LOG_LEVEL" LOG_LEVEL
  775. fi
  776. # Confirm
  777. echo ""
  778. echo -e "${BOLD}Installation Summary${NC}"
  779. echo -e "${CYAN}─────────────────────────────────────────${NC}"
  780. echo -e " Install path: ${GREEN}$INSTALL_PATH${NC}"
  781. if [[ "$BRANCH" != "main" ]]; then
  782. echo -e " Branch: ${YELLOW}$BRANCH${NC} (beta)"
  783. else
  784. echo -e " Branch: ${GREEN}$BRANCH${NC}"
  785. fi
  786. echo -e " Port: ${GREEN}$PORT${NC}"
  787. echo -e " Bind address: ${GREEN}$BIND_ADDRESS${NC}"
  788. echo -e " Timezone: ${GREEN}$TIMEZONE${NC}"
  789. echo -e " Data dir: ${GREEN}$DATA_DIR${NC}"
  790. echo -e " Log dir: ${GREEN}$LOG_DIR${NC}"
  791. echo -e " Debug mode: ${GREEN}$DEBUG_MODE${NC}"
  792. echo -e " Log level: ${GREEN}$LOG_LEVEL${NC}"
  793. echo ""
  794. if ! prompt_yes_no "Proceed with installation?" "y"; then
  795. echo "Installation cancelled."
  796. exit 0
  797. fi
  798. }
  799. main() {
  800. parse_args "$@"
  801. print_banner
  802. # Check if running via pipe (curl | bash) - interactive mode won't work
  803. if [[ ! -t 0 ]] && [[ "$NON_INTERACTIVE" != "true" ]]; then
  804. log_error "Interactive mode requires a terminal."
  805. log_info "When using 'curl | bash', you must use non-interactive mode:"
  806. echo ""
  807. echo " curl -fsSL URL | bash -s -- --yes"
  808. echo ""
  809. log_info "Or download and run directly:"
  810. echo ""
  811. echo " curl -fsSL URL -o install.sh && chmod +x install.sh && ./install.sh"
  812. echo ""
  813. exit 1
  814. fi
  815. # Check for root (we need sudo for some operations)
  816. if [[ "$EUID" -eq 0 ]] && [[ "$OS_TYPE" != "macos" ]]; then
  817. log_warn "Running as root. Consider using a regular user with sudo privileges."
  818. fi
  819. # Detect system
  820. log_info "Detecting system..."
  821. detect_os
  822. log_success "Detected: $OS_TYPE (package manager: $PKG_MANAGER)"
  823. # macOS must run rootless. Homebrew hard-refuses to run as root, and a venv
  824. # / node_modules created by root can't be managed by the launchd agent (which
  825. # runs as the user). Bail early with an actionable message instead of dying
  826. # halfway through on "brew: running as root is not supported".
  827. if [[ "$OS_TYPE" == "macos" ]]; then
  828. if [[ "$EUID" -eq 0 ]]; then
  829. log_error "Don't run the macOS installer with sudo."
  830. log_info "Homebrew, the Python venv, and the launchd agent must all be created as your"
  831. log_info "normal user. Re-run without sudo (the script elevates only when it truly needs to):"
  832. echo ""
  833. echo " ./install.sh"
  834. echo ""
  835. exit 1
  836. fi
  837. # /opt requires sudo to create and would leave a root-owned tree; default
  838. # macOS installs to a user-owned location so the whole flow stays rootless.
  839. if [[ "$DEFAULT_INSTALL_PATH" == "/opt/bambuddy" ]]; then
  840. DEFAULT_INSTALL_PATH="$HOME/bambuddy"
  841. fi
  842. fi
  843. # Check/install Python
  844. if ! detect_python; then
  845. log_info "Python 3.10+ not found, will install..."
  846. fi
  847. # Gather configuration
  848. gather_config
  849. # Install steps
  850. echo ""
  851. echo -e "${BOLD}Starting Installation${NC}"
  852. echo -e "${CYAN}─────────────────────────────────────────${NC}"
  853. echo ""
  854. install_dependencies
  855. detect_python || { log_error "Failed to install Python"; exit 1; }
  856. # Set system timezone if requested
  857. if [[ "$SET_SYSTEM_TZ" == "true" ]]; then
  858. log_info "Setting system timezone to $TIMEZONE..."
  859. if [[ "$OS_TYPE" == "macos" ]]; then
  860. sudo systemsetup -settimezone "$TIMEZONE" 2>/dev/null || true
  861. else
  862. sudo timedatectl set-timezone "$TIMEZONE" 2>/dev/null || true
  863. fi
  864. log_success "System timezone set to $TIMEZONE"
  865. fi
  866. if [[ "$OS_TYPE" != "macos" ]]; then
  867. create_user
  868. else
  869. SERVICE_USER="$USER"
  870. fi
  871. download_bambuddy
  872. setup_virtualenv
  873. build_frontend
  874. create_directories
  875. create_env_file
  876. if [[ "$OS_TYPE" == "macos" ]]; then
  877. create_launchd_service
  878. else
  879. create_systemd_service
  880. fi
  881. # Done!
  882. echo ""
  883. echo -e "${GREEN}╔══════════════════════════════════════════════════════════════╗${NC}"
  884. echo -e "${GREEN}║ ║${NC}"
  885. echo -e "${GREEN}║ Installation Complete! ║${NC}"
  886. echo -e "${GREEN}║ ║${NC}"
  887. echo -e "${GREEN}╚══════════════════════════════════════════════════════════════╝${NC}"
  888. echo ""
  889. # Show appropriate URL based on bind address
  890. if [[ "$BIND_ADDRESS" == "0.0.0.0" ]]; then
  891. local ip_addr
  892. ip_addr=$(hostname -I 2>/dev/null | awk '{print $1}') || ip_addr="<your-ip>"
  893. echo -e " ${BOLD}Access BamBuddy:${NC} ${CYAN}http://localhost:$PORT${NC}"
  894. echo -e " ${CYAN}http://$ip_addr:$PORT${NC} (from other devices)"
  895. else
  896. echo -e " ${BOLD}Access BamBuddy:${NC} ${CYAN}http://localhost:$PORT${NC}"
  897. fi
  898. echo ""
  899. if [[ "$OS_TYPE" == "macos" ]]; then
  900. echo -e " ${BOLD}Manage service:${NC}"
  901. echo -e " Start: launchctl load ~/Library/LaunchAgents/com.bambuddy.app.plist"
  902. echo -e " Stop: launchctl unload ~/Library/LaunchAgents/com.bambuddy.app.plist"
  903. echo -e " Logs: tail -f $LOG_DIR/bambuddy.log"
  904. else
  905. echo -e " ${BOLD}Manage service:${NC}"
  906. echo -e " Status: sudo systemctl status bambuddy"
  907. echo -e " Start: sudo systemctl start bambuddy"
  908. echo -e " Stop: sudo systemctl stop bambuddy"
  909. echo -e " Logs: sudo journalctl -u bambuddy -f"
  910. fi
  911. echo ""
  912. echo -e " ${BOLD}Update BamBuddy:${NC}"
  913. echo -e " cd $INSTALL_PATH && git pull && source venv/bin/activate"
  914. echo -e " pip install -r requirements.txt && cd frontend && npm ci && npm run build"
  915. if [[ "$OS_TYPE" != "macos" ]]; then
  916. echo -e " sudo systemctl restart bambuddy"
  917. fi
  918. echo ""
  919. echo -e " ${BOLD}Documentation:${NC} ${CYAN}https://wiki.bambuddy.cool${NC}"
  920. echo ""
  921. }
  922. main "$@"