feat(distribution): production install/update/backup scripts + public-repo sync (#106)

Builds the customer-facing distribution: a curated distribution/ directory
containing only what an end customer needs (production docker-compose.yml
with no build: sections, install.sh/update.sh/uninstall.sh/healthcheck.sh/
backup.sh/restore.sh, a customer-facing CHANGELOG.md, and README/LICENSE/
NOTICE/THIRD_PARTY_LICENSES) — pushed as the initial content of the new
public alleyviper/argus repo.

install.sh: detects OS, validates Docker/Compose, fetches all deployment
files, generates a secure DB password, creates the required Docker
network, pulls images, starts the stack, waits for health, and rotates
the default admin/admin credentials via the auth API — printing the
generated password once at the end.

update.sh/healthcheck.sh/backup.sh/restore.sh/uninstall.sh formalize what
was previously ad-hoc README snippets into real, safe-by-default scripts
(uninstall.sh keeps data unless --remove-data is explicitly passed and
confirmed; restore.sh requires typed confirmation and documents that it
targets a fresh install, not a live merge).

Added a sync-distribution job to release.yml: after a successful release,
mirrors distribution/ into the public repo and creates a matching
(customer-facing, commit-log-free) release marker there. Needs a one-time
setup step — a fine-grained PAT scoped to alleyviper/argus added as the
ARGUS_PUBLIC_REPO_TOKEN secret — the job cleanly no-ops until that's added.

Not yet done: GHCR package visibility (argus-secure-api/-ui/-nginx) is
still private, which blocks a genuine end-to-end curl-install test from a
clean, unauthenticated environment — deferred at the user's request until
they flip it manually (GitHub does not expose this via API).
This commit is contained in:
alleyviper
2026-07-19 18:06:02 +01:00
committed by GitHub
commit 44f662afc0
14 changed files with 1213 additions and 0 deletions
Executable
+59
View File
@@ -0,0 +1,59 @@
#!/usr/bin/env bash
#
# ARGUS uninstaller — stops and removes ARGUS containers.
#
# By default this KEEPS your data (database, certificates, uploaded config) —
# it only stops and removes containers, so a plain re-install (install.sh)
# picks up right where you left off.
#
# cd ~/argus && ./uninstall.sh # containers only, data kept
# ./uninstall.sh --remove-data # also destroys all data (asks to confirm)
# ./uninstall.sh --remove-data --yes # non-interactive, for scripted use
#
set -euo pipefail
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
REMOVE_DATA=false
ASSUME_YES=false
for arg in "$@"; do
case "$arg" in
--remove-data) REMOVE_DATA=true ;;
--yes|-y) ASSUME_YES=true ;;
*) echo "Unknown option: $arg" >&2; exit 1 ;;
esac
done
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
info() { printf ' %s\n' "$1"; }
ok() { printf ' \033[32m✓\033[0m %s\n' "$1"; }
warn() { printf ' \033[33m!\033[0m %s\n' "$1"; }
fail() { printf ' \033[31m✗\033[0m %s\n' "$1" >&2; exit 1; }
bold "ARGUS Uninstaller"
echo
[ -f "$INSTALL_DIR/docker-compose.yml" ] || fail "No ARGUS installation found at $INSTALL_DIR (set ARGUS_INSTALL_DIR if you installed elsewhere)."
cd "$INSTALL_DIR"
if [ "$REMOVE_DATA" = "true" ] && [ "$ASSUME_YES" != "true" ]; then
warn "This will permanently delete your ARGUS database, certificates, and all"
warn "uploaded configuration. This cannot be undone."
printf " Type YES to confirm: "
read -r CONFIRM
[ "$CONFIRM" = "YES" ] || fail "Aborted — data was not touched."
fi
if [ "$REMOVE_DATA" = "true" ]; then
bold "Stopping ARGUS and removing all data..."
docker compose down -v
ok "Containers and data volumes removed"
else
bold "Stopping ARGUS (data preserved)..."
docker compose down
ok "Containers removed — database and certificates are untouched"
info "Re-run install.sh (or 'docker compose up -d' here) to bring ARGUS back with the same data."
fi
echo
info "Configuration files remain at ${INSTALL_DIR} — remove that directory yourself if you want a completely clean slate."