mirror of
https://github.com/Retropex/raspiblitz.git
synced 2025-05-12 11:10:48 +02:00

* cln: use default normal feerate to withdraw all * Bugfix: bad subsititution (#3668) Fix for error: /home/admin/config.scripts/bonus.go.sh: line 31: ${goOSversion{}: bad substitution * whiptail one line * fix syntax * lnproxy: fix api access through nginx (#3671) * lnproxy: fix api access through nginx * fix tor config and fit the menu * add to the menu and provision * merge #3682 * cln update to v23.02, backup-plugin update, add poetry (#3684) * cln backup-plugin update, add poetry * fix mkdir error, remove commented code, fmt #3677 * poetry and path fixes * add terminal feedback, format #3676 * detect the full name of the plugin * install pyln-client tqdm with pip * git-verify: add --keyid-format LONG to recognise if the signing key is not the main key * cln update to v23.02 * cln-grpc: add protobuf-compiler dep * rtl update to v0.13.6 and formatting * C-lightningREST update to v0.10.1 * CLN FAQ update (#3666) * improve the detection of existing cln aliases * add the emergencyrecover instructions to CLN FAQ * update help entries * Update Tallycoin to version 1.8.0 (#3693) * add tallycoin update info to CHANGES * Fix typo in README.md (#3699) excepted -> accepted * #3694 add LCD info * #3664 att timeout 30s to ln monitor calls (#3665) * fix setting LND_REST_ENDPOINT (#3689) * btcpay update v1.8.2, postgres database fix (#3697) * btcpay update v1.8.0, postgres database fix * btcpayserver update to v1.8.2 * update lnbits to 0.10.2 and use poetry instead of venv (#3703) * fix apt update Key error for influx repo (#3711) Co-authored-by: Patrick Scheich <patrick.scheich@syscovery.de> * fix missing timeout value for nc cmnd (#3712) Co-authored-by: Patrick Scheich <patrick.scheich@syscovery.de> * #3706 Update CLN v23.02.2 (#3716) * used patched/rolledback 23.02.2 release * check rusty sig * fix typo * fix default lightning setting * #3683 Update LIT to 0.8.6 (#3717) * update LIT to 0.8.6 * activate lnd rpcmiddleware * CHANGES.md * #3667 change all up/download from sftp tp scp (#3718) * #3722 add no hostkeys available detection (#3723) * #1186 FinTS/HBCI interface (#3704) * #1186 FinTS install script first draft * only start app when blitz is ready * improve menu * improve dit lnbits config * preserve edit * improve edit * improve edit * fix insertion * dont use fingerprint * now use main repo * add port * show local ip * fix typo * show port SSL * Update bonus.lndg.sh (#3725) * Update bonus.lndg.sh Changes version to v1.6.0. Fixes update menu bug. Cleans up code a bit (removes tabs and changes to spaces to match raspiblitz formats). * Update bonus.lndg.sh Cleaned up code, added requirements.txt install to updates (needed for this update, may be needed in future). * #3725 update lndg version in CHANGES * #3692 update lnd to v0.16.0-beta (#3732) * update SD CARD base image info * Clenaup CHANGES info * RTL install fix (#3739) * c-lightning-REST update to 0.10.2, fmt * rtl: npm insatll with --legacy-peer-deps * purge c-lightning-REST as well with RTL * jam update to v0.1.5 (#3736) * 3733 CLN GRPC > JRPC (#3741) * change exit code * change to cln_jrpc * deactivate the cln_grpc settings * set v1.9.0rc3 version --------- Co-authored-by: openoms <oms@tuta.io> Co-authored-by: Metallicc <72348+metallicc@users.noreply.github.com> Co-authored-by: openoms <43343391+openoms@users.noreply.github.com> Co-authored-by: DJ Booth <djbooth007@gmail.com> Co-authored-by: Yuck Fou <115867254+YuckFouBTC@users.noreply.github.com> Co-authored-by: dni ⚡ <office@dnilabs.com> Co-authored-by: PatrickScheich <50054697+PatrickScheich@users.noreply.github.com> Co-authored-by: Patrick Scheich <patrick.scheich@syscovery.de> Co-authored-by: allyourbankarebelongtous <100060902+allyourbankarebelongtous@users.noreply.github.com>
253 lines
7.6 KiB
Bash
253 lines
7.6 KiB
Bash
#!/bin/bash
|
|
|
|
# https://github.com/lnproxy/lnproxy/commits/main
|
|
LNPROXYVERSION="423723b58cc45daa2fdf6c8b22537d560aca4d7a"
|
|
# https://github.com/lnproxy/lnproxy-webui/commits/main
|
|
WEBUIVERSION=24d291c884a0b60126c1915301f29c893900a155
|
|
|
|
# command info
|
|
if [ $# -eq 0 ] || [ "$1" = "-h" ] || [ "$1" = "-help" ]; then
|
|
echo "config script to install or uninstall the lnproxy server"
|
|
echo "bonus.lnproxy.sh [on|off|menu]"
|
|
echo "installs the version $LNPROXYVERSION by default"
|
|
exit 1
|
|
fi
|
|
|
|
source /mnt/hdd/raspiblitz.conf
|
|
localip=$(hostname -I | awk '{print $1}')
|
|
|
|
# menu
|
|
if [ "$1" = "menu" ]; then
|
|
|
|
if systemctl is-active --quiet lnproxy; then
|
|
# get network info
|
|
torAddress=$(sudo cat /mnt/hdd/tor/lnproxy/hostname 2>/dev/null)
|
|
fingerprint=$(openssl x509 -in /mnt/hdd/app-data/nginx/tls.cert -fingerprint -noout | cut -d"=" -f2)
|
|
|
|
if [ "${runBehindTor}" = "on" ] && [ -n "${torAddress}" ]; then
|
|
# Info with Tor
|
|
sudo /home/admin/config.scripts/blitz.display.sh qr "${torAddress}"
|
|
whiptail --title " lnproxy-webui and API" --msgbox "\
|
|
Open in your local web browser:
|
|
http://${localip}:4748
|
|
https://${localip}:4749 with Fingerprint:
|
|
${fingerprint}\n
|
|
Hidden Service address for Tor Browser (see LCD for QR):
|
|
${torAddress}\n
|
|
To use the API:
|
|
curl -k https://${localip}:4749/api/{invoice}?routing_msat={budget}\n
|
|
The Tor Hidden Service address to share for using the API:
|
|
${torAddress}/api
|
|
" 20 70
|
|
sudo /home/admin/config.scripts/blitz.display.sh hide
|
|
else
|
|
# Info without Tor
|
|
whiptail --title " lnproxy-webui " --msgbox "Open in your local web browser:
|
|
http://${localip}:4748\n
|
|
Activate Tor to access the web interface from outside your local network.
|
|
" 15 57
|
|
fi
|
|
echo "# please wait ..."
|
|
else
|
|
echo "# *** LNPROXY IS NOT INSTALLED ***"
|
|
fi
|
|
exit 0
|
|
fi
|
|
|
|
# install
|
|
if [ "$1" = "1" ] || [ "$1" = "on" ]; then
|
|
|
|
if systemctl is-active --quiet lnproxy; then
|
|
echo "# FAIL - lnproxy already installed"
|
|
sleep 3
|
|
exit 1
|
|
fi
|
|
|
|
echo "*** INSTALL LNPROXY ***"
|
|
# check and install Go
|
|
/home/admin/config.scripts/bonus.go.sh on
|
|
|
|
# create lnproxy user
|
|
sudo adduser --disabled-password --gecos "" lnproxy
|
|
|
|
# create macaroon
|
|
cd /home/bitcoin || exit 1
|
|
sudo -u bitcoin lncli bakemacaroon --save_to lnproxy.macaroon \
|
|
uri:/lnrpc.Lightning/DecodePayReq \
|
|
uri:/lnrpc.Lightning/LookupInvoice \
|
|
uri:/invoicesrpc.Invoices/AddHoldInvoice \
|
|
uri:/invoicesrpc.Invoices/SubscribeSingleInvoice \
|
|
uri:/invoicesrpc.Invoices/CancelInvoice \
|
|
uri:/invoicesrpc.Invoices/SettleInvoice \
|
|
uri:/routerrpc.Router/SendPaymentV2
|
|
sudo mv ./lnproxy.macaroon /home/lnproxy/
|
|
sudo chown lnproxy:lnproxy /home/lnproxy/lnproxy.macaroon
|
|
sudo chmod 600 /home/lnproxy/lnproxy.macaroon
|
|
|
|
# make sure symlink to central app-data directory exists
|
|
sudo rm -rf /home/lnproxy/.lnd # not a symlink.. delete it silently
|
|
# create symlink
|
|
sudo ln -s "/mnt/hdd/app-data/lnd/" "/home/lnproxy/.lnd"
|
|
|
|
# download source code
|
|
cd /home/lnproxy/ || exit 1
|
|
sudo -u lnproxy git clone https://github.com/lnproxy/lnproxy.git /home/lnproxy/lnproxy
|
|
cd /home/lnproxy/lnproxy || exit 1
|
|
sudo -u lnproxy git reset --hard ${LNPROXYVERSION} || exit 1
|
|
|
|
# build
|
|
sudo -u lnproxy /usr/local/go/bin/go get lnproxy
|
|
sudo -u lnproxy /usr/local/go/bin/go build
|
|
|
|
# manual start (in tmux)
|
|
# sudo -u lnproxy /home/lnproxy/lnproxy/lnproxy -lnd-cert /home/lnproxy/.lnd/tls.cert /home/lnproxy/lnproxy.macaroon
|
|
|
|
# create systemd service
|
|
cat <<EOF | sudo tee /etc/systemd/system/lnproxy.service
|
|
[Unit]
|
|
Description=lnproxy
|
|
After=lnd.service
|
|
|
|
[Service]
|
|
User=lnproxy
|
|
Group=lnproxy
|
|
Type=simple
|
|
ExecStart=/home/lnproxy/lnproxy/lnproxy -lnd-cert /home/lnproxy/.lnd/tls.cert /home/lnproxy/lnproxy.macaroon
|
|
Restart=on-failure
|
|
RestartSec=30
|
|
TimeoutSec=120
|
|
|
|
# Hardening measures
|
|
PrivateTmp=true
|
|
ProtectSystem=full
|
|
NoNewPrivileges=true
|
|
PrivateDevices=true
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
|
|
# enable and start service
|
|
sudo systemctl enable lnproxy
|
|
|
|
source <(/home/admin/_cache.sh get state)
|
|
if [ "${state}" == "ready" ]; then
|
|
echo "# OK - the lnproxy.service is enabled, system is on ready so starting service"
|
|
sudo systemctl start lnproxy
|
|
else
|
|
echo "# OK - the lnproxy.service is enabled, to start manually use: sudo systemctl start lnproxy"
|
|
fi
|
|
|
|
# lnproxy-webui
|
|
cd /home/lnproxy/ || exit 1
|
|
sudo -u lnproxy git clone https://github.com/lnproxy/lnproxy-webui
|
|
cd /home/lnproxy/lnproxy-webui || exit 1
|
|
sudo -u lnproxy git reset --hard ${WEBUIVERSION} || exit 1
|
|
|
|
# build
|
|
sudo -u lnproxy /usr/local/go/bin/go get lnproxy-webui
|
|
sudo -u lnproxy /usr/local/go/bin/go build
|
|
|
|
# create systemd service
|
|
cat <<EOF | sudo tee /etc/systemd/system/lnproxy-webui.service
|
|
[Unit]
|
|
Description=lnproxy-webui
|
|
After=lnproxy.service
|
|
|
|
[Service]
|
|
WorkingDirectory=/home/lnproxy/lnproxy-webui
|
|
User=lnproxy
|
|
Group=lnproxy
|
|
Type=simple
|
|
ExecStart=/home/lnproxy/lnproxy-webui/lnproxy-webui
|
|
Restart=on-failure
|
|
RestartSec=30
|
|
TimeoutSec=120
|
|
|
|
# Hardening measures
|
|
PrivateTmp=true
|
|
ProtectSystem=full
|
|
NoNewPrivileges=true
|
|
PrivateDevices=true
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
|
|
# enable and start service
|
|
sudo systemctl enable lnproxy-webui
|
|
|
|
source <(/home/admin/_cache.sh get state)
|
|
if [ "${state}" == "ready" ]; then
|
|
echo "# OK - the lnproxy-webui.service is enabled, system is on ready so starting service"
|
|
sudo systemctl start lnproxy-webui
|
|
else
|
|
echo "# OK - the lnproxy-webui.service is enabled, to start manually use: sudo systemctl start lnproxy-webui"
|
|
fi
|
|
|
|
##################
|
|
# NGINX
|
|
##################
|
|
# setup nginx symlinks
|
|
if ! [ -f /etc/nginx/sites-available/lnproxy_ssl.conf ]; then
|
|
sudo cp -f /home/admin/assets/nginx/sites-available/lnproxy_ssl.conf /etc/nginx/sites-available/lnproxy_ssl.conf
|
|
fi
|
|
if ! [ -f /etc/nginx/sites-available/lnproxy_tor.conf ]; then
|
|
sudo cp /home/admin/assets/nginx/sites-available/lnproxy_tor.conf /etc/nginx/sites-available/lnproxy_tor.conf
|
|
fi
|
|
if ! [ -f /etc/nginx/sites-available/lnproxy_tor_ssl.conf ]; then
|
|
sudo cp /home/admin/assets/nginx/sites-available/lnproxy_tor_ssl.conf /etc/nginx/sites-available/lnproxy_tor_ssl.conf
|
|
fi
|
|
sudo ln -sf /etc/nginx/sites-available/lnproxy_ssl.conf /etc/nginx/sites-enabled/
|
|
sudo ln -sf /etc/nginx/sites-available/lnproxy_tor.conf /etc/nginx/sites-enabled/
|
|
sudo ln -sf /etc/nginx/sites-available/lnproxy_tor_ssl.conf /etc/nginx/sites-enabled/
|
|
sudo nginx -t
|
|
sudo systemctl reload nginx
|
|
|
|
sudo ufw allow 4748 comment lnproxy-webui-HTTP
|
|
sudo ufw allow 4749 comment lnproxy-HTTPS
|
|
|
|
/home/admin/config.scripts/tor.onion-service.sh lnproxy 80 4750 443 4751
|
|
|
|
# setting value in raspi blitz config
|
|
/home/admin/config.scripts/blitz.conf.sh set lnproxy "on"
|
|
|
|
echo "# API:"
|
|
echo "curl http://127.0.0.1:4747/{your_invoice}?routing_msat={routing_budget}"
|
|
echo "curl -k https://${localip}:4749/api/{your_invoice}?routing_msat={routing_budget}"
|
|
echo "# WebUI:"
|
|
echo "http://${localip}:4748"
|
|
echo "https://${localip}:4749"
|
|
echo "# More info at:"
|
|
echo "https://github.com/lnproxy/lnproxy"
|
|
|
|
exit 0
|
|
fi
|
|
|
|
# switch off
|
|
if [ "$1" = "0" ] || [ "$1" = "off" ]; then
|
|
echo "*** REMOVING LNPROXY***"
|
|
# remove user and home directory
|
|
sudo userdel -rf lnproxy
|
|
|
|
# remove systemd services
|
|
sudo systemctl disable --now lnproxy
|
|
sudo rm -f /etc/systemd/system/lnproxy.service
|
|
sudo systemctl disable --now lnproxy-webui
|
|
sudo rm -f /etc/systemd/system/lnproxy-webui.service
|
|
|
|
# remove Tor service
|
|
/home/admin/config.scripts/tor.onion-service.sh off lnproxy
|
|
|
|
# close ports on firewall
|
|
sudo ufw delete allow 4748
|
|
sudo ufw delete allow 4749
|
|
|
|
# setting value in raspi blitz config
|
|
/home/admin/config.scripts/blitz.conf.sh set lnproxy "off"
|
|
|
|
echo "# OK, lnproxy is removed."
|
|
|
|
exit 0
|
|
fi
|