Files

186 lines
6.2 KiB
Markdown

# Docker-Install
A polished one-command Docker installer for fresh Ubuntu/Debian servers.
It installs:
- Docker Engine
- Docker CLI
- containerd
- Docker Buildx plugin
- Docker Compose plugin
It can also optionally add a chosen Linux user to the `docker` group so Docker commands can be run without `sudo` after the user logs out/in. If requested, it can install Portainer CE as a local Docker container too.
## One-command install
Install Docker only:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash
```
Install Docker and add the current SSH/login user to the docker group:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --current-user
```
Install Docker and add a specific user to the docker group:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --user obin
```
Install Docker, add the current SSH/login user, and install Portainer CE:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --current-user --portainer
```
Install Docker and Portainer CE only:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --portainer
```
Non-interactive install without adding a docker user:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --yes
```
## Local usage
```bash
git clone https://gitea.wheelytho.com/Wheelz/Docker-Install.git
cd Docker-Install
chmod +x install-docker.sh
./install-docker.sh --current-user
```
The old `Docker-Install.sh` filename still exists as a compatibility wrapper.
## Wheelz user + Termix SSH key
Create/update the `wheelz` Linux user, prompt for a password, install the Termix public SSH key, and add the user to the sudo/wheel admin group when present:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash
```
If you are not already root and the host has sudo:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | sudo bash
```
Skip sudo/admin group membership:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/create-wheelz-user-termix-key.sh | bash -s -- --no-sudo
```
## PatchMon enrollment
Enroll a Linux host into PatchMon. By default this uses the canonical PatchMon FQDN `https://patchmon.wheelz.lab` and the `direct-host` enrollment type. The wrapper installs/updates the Wheelz Caddy local root CA first so the agent can keep `skip_ssl_verify: false`.
Recommended interactive one-liner. It prompts for the PatchMon auto-enrollment token key and secret:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/patchmon-enroll.sh | sudo bash
```
Non-interactive direct-host enrollment:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/patchmon-enroll.sh | sudo bash -s -- --token-key '<key>' --token-secret '<secret>' --type direct-host -y
```
Proxmox LXC enrollment:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/patchmon-enroll.sh | sudo bash -s -- --token-key '<key>' --token-secret '<secret>' --type proxmox-lxc -y
```
Useful options:
```text
--server URL PatchMon base URL. Default: https://patchmon.wheelz.lab
--type TYPE direct-host or proxmox-lxc. Default: direct-host
--friendly-name NAME Friendly name to report to PatchMon
--force Ask PatchMon's generated installer to force/reinstall when supported
--no-caddy-ca Do not install the Wheelz/Caddy internal CA before enrollment
--print-script Download and print the generated PatchMon script instead of running it
-y, --yes Non-interactive mode
```
Token note: keep the token secret out of Git. Store it in a password manager or a local `.env` and paste/use it at enrollment time only.
## Options
```text
--user USER Add USER to the docker group after install.
--current-user Add the invoking SSH/login user to the docker group.
--no-docker-user Do not add anyone to the docker group.
--portainer Install or start Portainer CE after Docker install.
--portainer-port PORT Host port for Portainer HTTPS UI. Default: 9443.
--portainer-edge-port PORT Host port for Portainer Edge agent tunnel. Default: 8000.
--portainer-image IMAGE Portainer image to run. Default: portainer/portainer-ce:lts.
-y, --yes Non-interactive defaults. Skips docker group unless --user/--current-user is supplied.
-h, --help Show help.
```
## After adding a user to the docker group
Group membership does not apply to already-open shells. Log out and back in, or run:
```bash
newgrp docker
```
Then verify Docker works without sudo:
```bash
docker run --rm hello-world
```
## Portainer
When `--portainer` is supplied, the installer creates a persistent Docker volume named `portainer_data` and starts Portainer CE with:
- HTTPS UI: `https://<server-ip>:9443`
- Edge agent tunnel: `<server-ip>:8000`
- Container name: `portainer`
- Restart policy: `always`
Portainer uses a self-signed certificate by default, so the browser warning is expected on first visit.
Custom Portainer UI port example:
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-docker.sh | bash -s -- --current-user --portainer --portainer-port 9444
```
## Supported systems
- Ubuntu
- Debian
The installer uses Docker's official apt repository for the detected OS and codename.
## Trust Wheelz Caddy local HTTPS CA
Use this on Linux hosts that need to trust internal `*.wheelz.lab` HTTPS services such as PatchMon. It installs the public Caddy local root CA and verifies the certificate SHA256.
```bash
curl -fsSL https://gitea.wheelytho.com/Wheelz/Docker-Install/raw/branch/main/install-caddy-local-ca.sh | sudo bash
```
Certificate SHA256:
```text
d4b15cd45c797fd329df47b634d0fc7e9f858e9506ed572c64d00332ea5cf388
```