Add encrypted bare-metal recovery workflow

This commit is contained in:
Mikei386
2026-08-23 15:48:41 +02:00
parent e5dffbc2ba
commit 3d528f2716
9 changed files with 416 additions and 7 deletions
+4 -1
View File
@@ -67,7 +67,7 @@ install_base_packages() {
apt-get update
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
ca-certificates curl git gnupg jq openssl wireguard-tools iptables \
iproute2 pciutils rsync unattended-upgrades ethtool
iproute2 pciutils rsync unattended-upgrades ethtool age
}
setup_stable_network_name() {
@@ -287,6 +287,9 @@ install_stack_files() {
install -d -m 0755 "$STACK_DIR" "$MODEL_DIR" "$XTTS_CACHE_DIR" "$STATE_DIR/backups"
rsync -a --delete --exclude .git --exclude '*.local.*' \
--exclude config/install.env "$ROOT_DIR/" "$STACK_DIR/"
if git -C "$ROOT_DIR" rev-parse HEAD >/dev/null 2>&1; then
git -C "$ROOT_DIR" rev-parse HEAD >"$STACK_DIR/.mike-ai-source-commit"
fi
install -d -m 0700 "$SECRETS_DIR"
[[ -s $SECRETS_DIR/router-api-key ]] || openssl rand -base64 48 >$SECRETS_DIR/router-api-key
[[ -s $SECRETS_DIR/controller-token ]] || openssl rand -base64 48 >$SECRETS_DIR/controller-token