| 1 | # Ubuntu Lighthouse bootstrap |
| 2 | |
| 3 | Choose the trusted networks that may reach SSH before running the bootstrap: |
| 4 | |
| 5 | ```bash |
| 6 | sudo SSH_ALLOWED_CIDRS='203.0.113.4/32,2001:db8::/64' \ |
| 7 | bash scripts/tencent-lighthouse/bootstrap-ubuntu.sh |
| 8 | ``` |
| 9 | |
| 10 | Replace the example networks with your own. Every IPv4 /8–/32 or IPv6 /16–/128 |
| 11 | CIDR is validated before packages, users, files, or firewall rules change. |
| 12 | The script adds the narrow rules before removing the broad OpenSSH rule. |
| 13 | Keep the Lighthouse console firewall consistent with this policy. |
| 14 | |
| 15 | If a public SSH endpoint is deliberately required, explicitly pass |
| 16 | `SSH_ALLOW_ANY_SOURCE=1` instead. Omitting both settings stops the bootstrap. |
| 17 | The final instructions install the unified CLI, which includes the TUI and |
| 18 | runtime server, using Rust 1.89 or newer. |
| 19 | |
| 20 | ## 简体中文 |
| 21 | |
| 22 | 运行上面的命令前,请把示例网段替换为允许访问 SSH 的可信来源。脚本接受逗号或 |
| 23 | 空格分隔的 IPv4 /8–/32 和 IPv6 /16–/128 CIDR,并在安装软件包、创建用户、修改 |
| 24 | 文件或防火墙规则之前验证整个列表。它先添加受限规则,再删除对所有来源开放的 |
| 25 | OpenSSH 规则。Lighthouse 控制台防火墙也应采用一致的策略。 |
| 26 | |
| 27 | 确实需要公开 SSH 时,必须显式设置 `SSH_ALLOW_ANY_SOURCE=1`。两个设置都未 |
| 28 | 提供时,脚本会停止。最后的安装步骤使用 Rust 1.89 或更新版本,安装包含 TUI 和 |
| 29 | 运行时服务的统一 CLI。 |
| 30 |