更新 setup-relay.sh

This commit is contained in:
i
2026-03-18 21:01:15 +08:00
parent 551962389c
commit 2f442b2a24
+56 -11
View File
@@ -479,32 +479,77 @@ volumes:
done # end per-relay loop
# ═════════════════════════════════════════════════════════════════════════════
# STEP 4 – Main server snippet
# STEP 4 – Main server config.yaml snippet
# ═════════════════════════════════════════════════════════════════════════════
header "Step 4 · Main Server Configuration Snippet"
header "Step 4 · Main Server config.yaml Snippet"
echo "Add the following relay entries to your main NetBird server's"
echo "management.json (or equivalent config), replacing any existing ones:"
echo "Reference: Set Up External Relay Servers — NetBird Docs"
echo " https://docs.netbird.io/selfhosted/splitting-self-hosted-deployment/set-up-external-relay-servers"
echo ""
echo -e "${BOLD}Relay URLs:${RESET}"
for i in "${!RELAY_DOMAINS[@]}"; do
echo " rels://${RELAY_DOMAINS[$i]}:${RELAY_LISTEN_PORTS[$i]}"
done
echo "On your main server:"
echo " cd ~/netbird # or wherever your deployment lives"
echo " nano config.yaml"
echo ""
echo -e "${BOLD}STUN URLs:${RESET}"
echo "Remove 'authSecret' from the 'server' section (disables embedded relay),"
echo "and add/replace the 'relays' and 'stuns' sections as shown below."
echo "(The presence of 'relays' also disables the embedded STUN server,"
echo " so 'stuns' is required.)"
echo ""
# ── Build stuns block ─────────────────────────────────────────────────────────
_STUNS_YAML=""
_STUNS_YAML_PLACEHOLDER=""
for i in "${!RELAY_DOMAINS[@]}"; do
if [[ "${RELAY_ENABLE_STUN[$i]}" == "true" ]] && [[ -n "${RELAY_STUN_PORTS_LIST[$i]}" ]]; then
IFS=',' read -ra _SP <<< "${RELAY_STUN_PORTS_LIST[$i]}"
for _P in "${_SP[@]}"; do
_P="${_P// /}"
echo " stun:${RELAY_DOMAINS[$i]}:${_P}"
_STUNS_YAML+=" - uri: \"stun:${RELAY_DOMAINS[$i]}:${_P}\""$'\n'
_STUNS_YAML+=" proto: \"udp\""$'\n'
_STUNS_YAML_PLACEHOLDER+=" - uri: \"stun:<relay-$((i+1))-domain>:${_P}\""$'\n'
_STUNS_YAML_PLACEHOLDER+=" proto: \"udp\""$'\n'
done
fi
done
# ── Build relays.addresses block ──────────────────────────────────────────────
_RELAY_ADDRS_YAML=""
_RELAY_ADDRS_YAML_PLACEHOLDER=""
for i in "${!RELAY_DOMAINS[@]}"; do
_RELAY_ADDRS_YAML+=" - \"rels://${RELAY_DOMAINS[$i]}:${RELAY_LISTEN_PORTS[$i]}\""$'\n'
_RELAY_ADDRS_YAML_PLACEHOLDER+=" - \"rels://<relay-$((i+1))-domain>:${RELAY_LISTEN_PORTS[$i]}\""$'\n'
done
# ── Print the snippet ─────────────────────────────────────────────────────────
echo -e "${BOLD}┌─ config.yaml (relevant section) ───────────────────────────────────┐${RESET}"
cat <<YAML
server:
# listenAddress / exposedAddress / metricsPort / etc. — keep as-is
# Remove or comment out the embedded relay secret:
# authSecret: ...
# Remove or comment out embedded STUN ports:
# stunPorts:
# - 3478
# External STUN servers (your relay servers)
stuns:
${_STUNS_YAML_PLACEHOLDER}
# External relay servers
relays:
addresses:
${_RELAY_ADDRS_YAML_PLACEHOLDER} secret: "<your-shared-secret>"
credentialsTTL: "24h"
# auth: ... (keep your existing auth config below)
YAML
echo -e "${BOLD}└────────────────────────────────────────────────────────────────────┘${RESET}"
echo ""
echo -e "${BOLD}Shared secret:${RESET} ${AUTH_SECRET}"
warn "The 'secret' under relays MUST match NB_AUTH_SECRET on all relay servers."
warn "Mismatched secrets cause relay connections to fail silently."
echo ""
# ═════════════════════════════════════════════════════════════════════════════
# STEP 5 – Next steps
# ═════════════════════════════════════════════════════════════════════════════