Refactor: Extract shared helpers to lib/, improve error handling, add tests - #1
Merged
Merged
Conversation
….04)
Root causes of "it doesn't work":
- generate_password used `tr … | head -c N` under pipefail (SIGPIPE, exit
141) and killed LEMP right after MySQL installed
- MySQL hardening ran with `2>/dev/null || true`, then wrote /root/.my.cnf
with a password that was never applied; root also kept auth_socket
- no `set -E`, so the ERR trap never fired inside functions
- every module prompted on stdin and ignored flags (hung non-interactive)
- redis maxmemory sed used `\|` with `|` delimiter and never matched
- php_tune overwrote opcache.ini, dropping its zend_extension line
- nginx default site / RHEL stock server{} shadowed the PulseDeploy site
- fail2ban jails referenced missing logs/backends and crashed the service
- RHEL base step installed+enabled firewalld before ports were opened
- docker cleanup cron ran `prune --volumes` (data loss); Compose v1 via pip
- revert.sh called dnf on Debian and apt on RHEL, aborting mid-run
Changes:
- scripts/lib/common.sh + web.sh: shared logging, validation, retry, apt
lock handling, package/service helpers, idempotent conf_set, PHP layout,
nginx/apache activation with `-t` validation and rollback, HTTP->PHP
health check
- new services/mysql.sh: distro packages only, real password auth, checks
before saving credentials, DB/user creation with validated identifiers
- bootstrap.sh: strict flag parsing (--flag=value, unknown flags error),
input validation before any change, PID-file lock, preflight checks,
guarded --disable-root-ssh, hostname/timezone handling, tee logging
- firewall never resets rules and always allows every SSH port first
- swap/redis/docker/certbot/php_tune rewritten to be idempotent and to
verify that the service actually works before reporting success
- revert.sh rewritten OS-aware; keeps data unless --purge-data
- config templates: client_max_body_size, try_files guard, dotfile blocks
- tests/run.sh (75 unit tests) and CI jobs for lint/tests/structure
Tested on Ubuntu 24.04: LEMP, LAMP, Node (NodeSource stubbed), Redis,
swap, PHP tuning, fail2ban, SSH hardening, hostname/timezone, wizard via
PTY, re-run idempotency and revert. Debian, RHEL-family and Amazon Linux
paths follow the same design but are not yet run on real machines.
Claude-Session: https://claude.ai/code/session_01WF2SiSxEVxKmDEdmffxPbT
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Major refactoring to improve code organization, maintainability, and reliability. Extracts common functions into reusable library modules, strengthens error handling with better traps and logging, adds comprehensive unit tests, and updates all services/stacks to use the new modular structure.
Type of change
Changes made
Core refactoring:
scripts/lib/common.sh— centralized logging, validation, package management, and utility functions (retry, password generation, IP detection, swap sizing, etc.)scripts/lib/web.sh— web-stack helpers for PHP layout detection, package installation, and Nginx/Apache configurationscripts/services/mysql.sh— extracted MySQL/MariaDB installation and configuration logictests/run.sh— unit tests for helper functions (conf_set, valid_port, pkg_available, etc.)bootstrap.sh improvements:
set -euo pipefailtoset -Eeuo pipefail(ERR trap fires in functions)PULSE_OPEN_PORTS,PULSE_REDIS_CONN, tracking flags for wizard statedeclare -gAtodeclare -A(global is implicit at top level)revert.sh improvements:
--no-confirmflag for automation (skip typed-YES prompts)--purge-dataflag to optionally delete databases/Redis/Docker data--listflag to show detected components without making changesDOarray toTARGETfor clarityService modules updated:
firewall.sh— Added support for firewalld (dnf systems), port validation, configurable extra ports viaOPEN_PORTSdocker.sh— Improved repo setup, better error handling, daemon.json managementredis.sh— Added connection type validation, improved readiness checksphp_tune.sh— Refactored to detect PHP version from filesystem, improved pool calculationscertbot.sh— Simplified to use distribution packages only (no snap), better plugin detectionswap.sh— Improved size parsing, better swap detectionStack modules updated:
lemp.sh,lamp.sh,node.sh— Now source web.sh and mysql.sh helpers, removed duplicate codeOS modules updated:
ubuntu.sh,debian.sh,centos_rocky.sh,amazon_linux.sh— Now source common.sh, use retry wrapper for package operations, consistent error handlingConfiguration files:
CI/CD:
.github/workflows/ci.ymlto lint both bootstrap.sh and revert.shTesting
tests/run.shcovering:conf_set— config file manipulation (replace, comment, append)valid_port— port number validationpkg_available/pkg_installed— package detectiongenerate_password— password generationswap_suggest_size— swap sizing logicbackup_file— file backup logicChecklist
shellcheck -xpasses on all modified.shfileshttps://claude.ai/code/session_01WF2SiSxEVxKmDEdmffxPbT