sh/bash/rescue-hetzner.sh

177 lines
3.6 KiB
Bash
Raw Normal View History

2024-11-11 17:06:27 +00:00
rescue_wipe_0_init_hetzner_8_8() {
2024-11-11 16:01:19 +00:00
local device
local devices=(
2024-11-12 08:35:29 +00:00
"/dev/sda"
"/dev/sdb"
2024-11-11 16:01:19 +00:00
)
local members
local number
local passphrase
# read passphrase
2024-11-12 08:28:08 +00:00
passphrase="$(read_passphrase)"
2024-11-11 16:01:19 +00:00
#
lsblk
2024-11-12 08:35:29 +00:00
echo -n "WIPE" "${devices[@]}" "/?\\ OR CANCEL /!\\"
2024-11-12 09:27:50 +00:00
read -r
2024-11-11 16:01:19 +00:00
#
number=0
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
((number++))
2024-11-11 16:14:04 +00:00
echo
echo "#${number}: ${device}"
2024-11-11 16:01:19 +00:00
#
2024-11-12 18:45:47 +00:00
parted --script "${device}" \
mktable gpt \
unit "mib" \
mkpart "crypt-${number}" 33282 7630885 \
mkpart "boot-${number}" 514 33282 \
mkpart "esp-${number}" 2 514 \
set 3 esp on \
mkpart "bios-${number}" 1 2 \
2024-11-11 16:14:04 +00:00
set 4 bios_grub on
2024-11-11 16:01:19 +00:00
done
#
number=0
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
((number++))
2024-11-11 16:14:04 +00:00
echo
echo "#${number}: ${device}4"
2024-11-11 16:01:19 +00:00
# wipe bios
dd \
2024-11-12 08:35:29 +00:00
if="/dev/zero" of="${device}4"
2024-11-11 16:01:19 +00:00
done
#
number=0
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
((number++))
2024-11-11 16:14:04 +00:00
echo
echo "#${number}: ${device}3"
2024-11-11 16:01:19 +00:00
# format esp
dd \
2024-11-12 08:35:29 +00:00
if="/dev/zero" of="${device}3" bs="1M"
2024-11-12 19:03:47 +00:00
fs_make_fat "${device}3" "esp-${number}" "0000000${number}"
2024-11-11 16:01:19 +00:00
# mount esp
mkdir --parents "/media/esp/${number}"
mount "${device}3" "/media/esp/${number}"
done
#
number=0
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
((number++))
2024-11-11 16:14:04 +00:00
echo
echo "#${number}: ${device}2"
2024-11-11 16:01:19 +00:00
# wipe boot
2024-11-12 08:35:29 +00:00
dd status="progress" \
if="/dev/zero" of="${device}2" bs="1G" count=1
2024-11-11 16:01:19 +00:00
done
#
members=()
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
members+=("${device}2")
done
mdadm \
2024-11-12 08:35:29 +00:00
--create "/dev/md/boot" \
2024-11-11 16:14:04 +00:00
--level 0 \
--metadata 1 \
2024-11-12 08:35:29 +00:00
--name "md:boot" \
2024-11-11 16:14:04 +00:00
--raid-devices ${#devices[@]} \
2024-11-12 08:35:29 +00:00
--uuid "00000000:00000000:00000000:00000002" \
2024-11-11 16:14:04 +00:00
"${members[@]}"
2024-11-11 16:01:19 +00:00
#
mkfs.btrfs --force \
2024-11-12 08:35:29 +00:00
--checksum "sha256" \
--label "boot" \
--uuid "00000000-0000-0000-0000-00000000000b" \
"/dev/md/boot"
2024-11-11 16:01:19 +00:00
# mount boot
2024-11-12 08:35:29 +00:00
mkdir --parents "/media/boot"
2024-11-11 16:01:19 +00:00
mount \
2024-11-12 08:35:29 +00:00
--options "autodefrag,compress-force=zstd" \
"/dev/md/boot" "/media/boot"
2024-11-11 16:01:19 +00:00
#
number=0
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
((number++))
2024-11-11 16:14:04 +00:00
echo
echo "#${number}: ${device}1"
2024-11-11 16:01:19 +00:00
# wipe crypt head
2024-11-12 08:35:29 +00:00
dd status="progress" \
if="/dev/zero" of="${device}1" bs="1G" count=1
2024-11-11 16:01:19 +00:00
done
#
members=()
2024-11-11 16:14:04 +00:00
for device in "${devices[@]}"; do
2024-11-11 16:01:19 +00:00
members+=("${device}1")
done
mdadm \
2024-11-12 08:35:29 +00:00
--create "/dev/md/crypt" \
2024-11-11 16:14:04 +00:00
--level 0 \
--metadata 1 \
2024-11-12 08:35:29 +00:00
--name "md:crypt" \
2024-11-11 16:14:04 +00:00
--raid-devices ${#devices[@]} \
2024-11-12 08:35:29 +00:00
--uuid "00000000:00000000:00000000:00000001" \
2024-11-11 16:14:04 +00:00
"${members[@]}"
2024-11-11 16:01:19 +00:00
# encrypt
2024-11-11 16:14:04 +00:00
echo "${passphrase}" |
cryptsetup \
--verbose \
--batch-mode \
2024-11-12 08:35:29 +00:00
--type "luks2" \
--pbkdf "argon2id" \
--cipher "aes-xts-plain64" \
2024-11-11 16:14:04 +00:00
--iter-time 8192 \
--key-size 512 \
2024-11-12 08:35:29 +00:00
--hash "sha512" \
2024-11-11 16:14:04 +00:00
--use-random \
luksFormat \
2024-11-12 08:35:29 +00:00
"/dev/md/crypt"
2024-11-11 16:01:19 +00:00
# open
2024-11-11 16:14:04 +00:00
echo "${passphrase}" |
2024-11-12 08:35:29 +00:00
cryptsetup luksOpen "/dev/md/crypt" "crypt"
2024-11-12 08:28:08 +00:00
# passphrase
unset passphrase
2023-12-28 11:00:25 +00:00
}
2024-11-11 17:06:27 +00:00
rescue_wipe_2_make_hetzner_8_8() {
2024-11-11 16:01:19 +00:00
local passphrase
# close
2024-11-12 08:35:29 +00:00
cryptsetup luksClose "crypt"
2024-11-11 16:01:19 +00:00
# read passphrase
2024-11-12 08:28:08 +00:00
passphrase="$(read_passphrase)"
2024-11-11 16:01:19 +00:00
# encrypt
2024-11-11 16:14:04 +00:00
echo "${passphrase}" |
cryptsetup \
--verbose \
--batch-mode \
2024-11-12 08:35:29 +00:00
--type "luks2" \
--pbkdf "argon2id" \
--cipher "aes-xts-plain64" \
2024-11-11 16:14:04 +00:00
--iter-time 8192 \
--key-size 512 \
2024-11-12 08:35:29 +00:00
--hash "sha512" \
2024-11-11 16:14:04 +00:00
--use-random \
luksFormat \
2024-11-12 08:35:29 +00:00
"/dev/md/crypt"
2024-11-11 16:01:19 +00:00
# open
2024-11-11 16:14:04 +00:00
echo "${passphrase}" |
2024-11-12 08:35:29 +00:00
cryptsetup luksOpen "/dev/md/crypt" "crypt"
2024-11-12 08:28:08 +00:00
# passphrase
unset passphrase
2024-11-11 16:01:19 +00:00
# format crypt
mkfs.btrfs --force \
2024-11-12 08:35:29 +00:00
--checksum "sha256" \
--label "crypt" \
--uuid "00000000-0000-0000-0000-00000000000c" \
"/dev/mapper/crypt"
2024-11-11 16:01:19 +00:00
# mount crypt
2024-11-12 08:35:29 +00:00
mkdir --parents "/media/crypt"
2024-11-11 16:01:19 +00:00
mount \
2024-11-12 08:35:29 +00:00
--options "autodefrag,compress-force=zstd" \
"/dev/mapper/crypt" "/media/crypt"
2024-11-11 16:01:19 +00:00
# make swap file
btrfs filesystem mkswapfile \
2024-11-12 08:35:29 +00:00
--size "64g" \
--uuid "00000000-0000-0000-0000-000000000005" \
"/media/crypt/swap"
2023-12-28 12:00:10 +00:00
}