scripts/setup/ is now what the new installer is being built in — machine-setup/ for the box, officer-setup.sh for the platform on top — and everything being replaced moved to scripts/setup-old/. It still works and is still what to run. Three things the move broke, and what each needed: starship.toml is not an old-setup artifact. os-user-shell.ts reads it at RUNTIME to seed a member's ~/.config/starship.toml when their Linux account is provisioned, and line 125 reads it inside a try whose catch returns "could not read the shell templates" — so account provisioning would have failed outright, not degraded. Moved back to scripts/setup/, which is where it belongs anyway (one file, both audiences) and which leaves the code correct with no edit. package.json's `setup` script pointed at a path that no longer exists. It now points at officer-setup.sh, where the installer is going, rather than at setup-old/ which is temporary. officer-setup.sh was created empty. An empty script exits 0, so `bun setup` would have reported success while doing nothing — worse than the broken path it replaced. It now explains that it is not written yet and exits 1, naming the setup-old script to run meanwhile. Also brought .tmux.conf and ufw-docker-rules.conf in beside machine-setup.sh, which reads both from SCRIPT_DIR and had been silently skipping them since the script was vendored. ssh-keys.zip deliberately stays out: it is key material, and *.zip is ignored. Comments in os-user-claude.ts, app-store/preflight.ts and two docs still name the old scripts/setup/setup.sh path. Left alone on purpose — repointing them at setup-old/ only to repoint them again when officer-setup.sh lands is churn. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
34 lines
905 B
Plaintext
34 lines
905 B
Plaintext
# UFW Docker compatibility rules
|
|
# Append these to /etc/ufw/after.rules (after the existing COMMIT)
|
|
# Blocks all external access to Docker-published ports except:
|
|
# - Trusted IPs (add your own)
|
|
# - Explicitly allowed public ports (80, 443)
|
|
# - Docker internal and loopback traffic
|
|
|
|
*filter
|
|
:DOCKER-USER - [0:0]
|
|
|
|
# Allow established/related
|
|
-A DOCKER-USER -m conntrack --ctstate ESTABLISHED,RELATED -j RETURN
|
|
|
|
# Allow loopback
|
|
-A DOCKER-USER -i lo -j RETURN
|
|
|
|
# Allow Docker internal networks
|
|
-A DOCKER-USER -s 172.16.0.0/12 -j RETURN
|
|
|
|
# Allow trusted external sources (add more lines as needed)
|
|
# -A DOCKER-USER -s <TRUSTED_IP> -j RETURN
|
|
|
|
# Allow public ports
|
|
-A DOCKER-USER -i eth0 -p tcp --dport 80 -j RETURN
|
|
-A DOCKER-USER -i eth0 -p tcp --dport 443 -j RETURN
|
|
|
|
# Drop everything else from external
|
|
-A DOCKER-USER -i eth0 -j DROP
|
|
|
|
# Return for non-external traffic
|
|
-A DOCKER-USER -j RETURN
|
|
|
|
COMMIT
|