#!/usr/bin/env bash # Ok2panel bootstrap: https://get.ok2panel.ru # # curl -fsSL https://get.ok2panel.ru | bash # curl -fsSL https://get.ok2panel.ru | bash -s -- --port 8888 # # Downloads the current release, checks it against the SHA256SUMS file signed # with the Ok2panel release key (the public key is below), then runs the # installer from the release. Arguments are passed to install.sh. # # The whole script is wrapped in main() so that a truncated download (a dropped # connection under `curl | bash`) runs nothing at all. set -euo pipefail main() { local base="${OK2PANEL_MIRROR:-https://get.ok2panel.ru}" local channel="${OK2PANEL_CHANNEL:-latest}" if [[ $EUID -ne 0 ]]; then echo "❌ Run as root: sudo -i, then run the command again" >&2 exit 1 fi if [[ "$(uname -m)" != "x86_64" ]]; then echo "❌ Only x86_64 servers are supported (this one is $(uname -m))" >&2 exit 1 fi local need=() for tool in curl openssl tar sha256sum; do command -v "$tool" >/dev/null 2>&1 || need+=("$tool") done if [[ ${#need[@]} -gt 0 ]]; then echo "==> Installing: ${need[*]}" # Only what is missing, one package at a time: minimal RHEL images ship # coreutils-single, which conflicts with the coreutils package. local pm="" if command -v apt-get >/dev/null 2>&1; then pm="apt" DEBIAN_FRONTEND=noninteractive apt-get update -qq >/dev/null 2>&1 || true elif command -v dnf >/dev/null 2>&1; then pm="dnf" elif command -v yum >/dev/null 2>&1; then pm="yum" fi for tool in "${need[@]}"; do local package="$tool" [[ "$tool" == sha256sum ]] && package="coreutils" case "$pm" in apt) DEBIAN_FRONTEND=noninteractive apt-get install -y -qq "$package" ca-certificates >/dev/null 2>&1 || true ;; dnf|yum) "$pm" install -y -q "$package" >/dev/null 2>&1 || true ;; esac done for tool in "${need[@]}"; do if ! command -v "$tool" >/dev/null 2>&1; then echo "❌ $tool is required and could not be installed" >&2 exit 1 fi done fi local work work="$(mktemp -d /tmp/ok2panel-install.XXXXXX)" trap 'rm -rf "$work"' EXIT cd "$work" cat > release-key.pem <<'KEY' -----BEGIN PUBLIC KEY----- MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEE2I2kZqd9d1jXfE/KtWaBzFiqP/4 0Xw6Ad3YIC3FNVpuJIxbKNX8TQe95pUplfWoI9RSN9sx+zd3Mqgpy2JoxQ== -----END PUBLIC KEY----- KEY echo "==> Downloading the Ok2panel release ($channel)" local dl=(curl -fsSL --proto '=https' --tlsv1.2 --retry 3 --max-time 600) "${dl[@]}" -o SHA256SUMS "$base/releases/$channel/SHA256SUMS" "${dl[@]}" -o SHA256SUMS.sig "$base/releases/$channel/SHA256SUMS.sig" if ! openssl dgst -sha256 -verify release-key.pem -signature SHA256SUMS.sig SHA256SUMS >/dev/null 2>&1; then echo "❌ The release signature is invalid. Nothing was installed." >&2 exit 1 fi local archive archive="$(awk '$2 ~ /^ok2panel-.*-linux-amd64\.tar\.gz$/ {print $2; exit}' SHA256SUMS)" if [[ -z "$archive" ]]; then echo "❌ The release does not list a linux-amd64 archive" >&2 exit 1 fi "${dl[@]}" -o "$archive" "$base/releases/$channel/$archive" if ! grep -E " ${archive//./\\.}\$" SHA256SUMS | sha256sum -c --status -; then echo "❌ The downloaded archive does not match the signed checksum. Nothing was installed." >&2 exit 1 fi echo " ✅ $archive verified (signature and SHA-256)" tar -xzf "$archive" local dir="${archive%.tar.gz}" [[ -f "$dir/install.sh" ]] || { echo "❌ install.sh missing from $archive" >&2; exit 1; } bash "$dir/install.sh" "$@" } main "$@"