mirror of
https://github.com/praetorian-inc/ChromeAlone
synced 2026-06-06 16:34:31 +00:00
Build + Deploy Issue Bugfixes
- Changed .NET projects to target net472 so there's no need for runtime installs. - Updated the build.sh script to handle deploying to targeted AWS regions by specifying the --region flag - Removed hardcoded AMIs from the terrafrom deploy process - Fixed some issues that come up when running the script from ARM architecture machines.
This commit is contained in:
@@ -3,7 +3,7 @@ set -e
|
||||
|
||||
# Parse command line arguments
|
||||
DOMAIN_NAME=""
|
||||
AWS_REGION="us-east-2" # Default region
|
||||
AWS_REGION="us-east-2" # Default region (matches build.sh default)
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case $1 in
|
||||
--domain)
|
||||
@@ -51,9 +51,10 @@ cd "$DEPLOY_DIR"
|
||||
|
||||
# Create SSH key pair if it doesn't exist
|
||||
KEY_NAME="relay-proxy-key"
|
||||
if ! aws ec2 describe-key-pairs --key-names "$KEY_NAME" &> /dev/null; then
|
||||
echo "Creating new SSH key pair..."
|
||||
if ! aws ec2 describe-key-pairs --region "$AWS_REGION" --key-names "$KEY_NAME" &> /dev/null; then
|
||||
echo "Creating new SSH key pair in region $AWS_REGION..."
|
||||
aws ec2 create-key-pair \
|
||||
--region "$AWS_REGION" \
|
||||
--key-name "$KEY_NAME" \
|
||||
--query 'KeyMaterial' \
|
||||
--output text > "${KEY_NAME}.pem"
|
||||
|
||||
+40
-8
@@ -4,6 +4,10 @@ terraform {
|
||||
source = "hashicorp/aws"
|
||||
version = "~> 5.0"
|
||||
}
|
||||
random = {
|
||||
source = "hashicorp/random"
|
||||
version = "~> 3.1"
|
||||
}
|
||||
}
|
||||
required_version = ">= 1.2.0"
|
||||
}
|
||||
@@ -12,9 +16,30 @@ provider "aws" {
|
||||
region = var.aws_region
|
||||
}
|
||||
|
||||
# Random ID for unique resource names
|
||||
resource "random_id" "deployment" {
|
||||
byte_length = 4
|
||||
}
|
||||
|
||||
# Data source to find the latest Amazon Linux 2023 AMI
|
||||
data "aws_ami" "amazon_linux" {
|
||||
most_recent = true
|
||||
owners = ["amazon"]
|
||||
|
||||
filter {
|
||||
name = "name"
|
||||
values = ["al2023-ami-*-x86_64"]
|
||||
}
|
||||
|
||||
filter {
|
||||
name = "virtualization-type"
|
||||
values = ["hvm"]
|
||||
}
|
||||
}
|
||||
|
||||
# Security Group
|
||||
resource "aws_security_group" "relay_sg" {
|
||||
name = "relay-security-group"
|
||||
name = "relay-security-group-${random_id.deployment.hex}"
|
||||
description = "Security group for relay server"
|
||||
|
||||
ingress {
|
||||
@@ -72,7 +97,7 @@ resource "aws_security_group" "relay_sg" {
|
||||
|
||||
# EC2 Instance
|
||||
resource "aws_instance" "relay_server" {
|
||||
ami = var.ami_id
|
||||
ami = var.ami_id != "" ? var.ami_id : data.aws_ami.amazon_linux.id
|
||||
instance_type = var.instance_type
|
||||
|
||||
vpc_security_group_ids = [aws_security_group.relay_sg.id]
|
||||
@@ -80,7 +105,7 @@ resource "aws_instance" "relay_server" {
|
||||
associate_public_ip_address = true
|
||||
|
||||
root_block_device {
|
||||
volume_size = 20
|
||||
volume_size = 30
|
||||
volume_type = "gp3"
|
||||
encrypted = true
|
||||
}
|
||||
@@ -106,22 +131,29 @@ resource "aws_instance" "relay_server" {
|
||||
}
|
||||
}
|
||||
|
||||
# Elastic IP
|
||||
# Elastic IP (only create if not using existing one)
|
||||
resource "aws_eip" "relay_ip" {
|
||||
count = var.existing_eip_allocation_id == "" ? 1 : 0
|
||||
tags = {
|
||||
Name = "relay-eip"
|
||||
}
|
||||
}
|
||||
|
||||
# Data source for existing EIP (if provided)
|
||||
data "aws_eip" "existing" {
|
||||
count = var.existing_eip_allocation_id != "" ? 1 : 0
|
||||
id = var.existing_eip_allocation_id
|
||||
}
|
||||
|
||||
resource "aws_eip_association" "relay_eip_assoc" {
|
||||
instance_id = aws_instance.relay_server.id
|
||||
allocation_id = aws_eip.relay_ip.id
|
||||
allocation_id = var.existing_eip_allocation_id != "" ? data.aws_eip.existing[0].id : aws_eip.relay_ip[0].id
|
||||
}
|
||||
|
||||
# Get the hosted zone ID if domain is provided
|
||||
data "aws_route53_zone" "selected" {
|
||||
count = var.domain_name != "" ? 1 : 0
|
||||
name = regex(".[^.]+.[^.]+$", var.domain_name) # Get parent domain
|
||||
count = var.domain_name != "" ? 1 : 0
|
||||
name = regex(".[^.]+.[^.]+$", var.domain_name) # Get parent domain
|
||||
private_zone = false
|
||||
}
|
||||
|
||||
@@ -132,5 +164,5 @@ resource "aws_route53_record" "relay" {
|
||||
name = var.domain_name
|
||||
type = "A"
|
||||
ttl = "300"
|
||||
records = [aws_eip.relay_ip.public_ip]
|
||||
records = [var.existing_eip_allocation_id != "" ? data.aws_eip.existing[0].public_ip : aws_eip.relay_ip[0].public_ip]
|
||||
}
|
||||
@@ -1,17 +1,17 @@
|
||||
output "relay_public_ip" {
|
||||
description = "Public IP of the relay server"
|
||||
value = aws_eip.relay_ip.public_ip
|
||||
value = var.existing_eip_allocation_id != "" ? data.aws_eip.existing[0].public_ip : aws_eip.relay_ip[0].public_ip
|
||||
}
|
||||
|
||||
output "relay_websocket_url" {
|
||||
description = "WebSocket URL for agent connections"
|
||||
value = var.domain_name != "" ? "wss://${var.domain_name}:443" : "ws://${aws_eip.relay_ip.public_ip}:8080"
|
||||
value = var.domain_name != "" ? "wss://${var.domain_name}:443" : "ws://${var.existing_eip_allocation_id != "" ? data.aws_eip.existing[0].public_ip : aws_eip.relay_ip[0].public_ip}:8080"
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
output "socks_proxy_address" {
|
||||
description = "SOCKS proxy address"
|
||||
value = "${aws_eip.relay_ip.public_ip}:1080"
|
||||
value = "${var.existing_eip_allocation_id != "" ? data.aws_eip.existing[0].public_ip : aws_eip.relay_ip[0].public_ip}:1080"
|
||||
}
|
||||
|
||||
output "relay_instance_id" {
|
||||
|
||||
+10
-4
@@ -1,7 +1,7 @@
|
||||
variable "aws_region" {
|
||||
description = "AWS region to deploy resources"
|
||||
type = string
|
||||
default = "us-west-2"
|
||||
default = "us-east-2"
|
||||
}
|
||||
|
||||
variable "office_ip_range" {
|
||||
@@ -14,9 +14,9 @@ variable "office_ip_range" {
|
||||
}
|
||||
|
||||
variable "ami_id" {
|
||||
description = "AMI ID for relay server"
|
||||
description = "AMI ID for relay server (leave empty to use latest Amazon Linux 2023)"
|
||||
type = string
|
||||
default = "ami-0e0bf53f6def86294" # Amazon Linux 2023 for us-east-2
|
||||
default = "" # Will be auto-detected using data source
|
||||
}
|
||||
|
||||
variable "instance_type" {
|
||||
@@ -51,6 +51,12 @@ variable "proxy_pass" {
|
||||
variable "domain_name" {
|
||||
description = "Domain name to use for the relay server (e.g., relay.example.com)"
|
||||
type = string
|
||||
default = "" # Optional, deployment will work without a domain
|
||||
default = "" # Optional, deployment will work without a domain
|
||||
}
|
||||
|
||||
variable "existing_eip_allocation_id" {
|
||||
description = "Existing Elastic IP allocation ID to use instead of creating a new one"
|
||||
type = string
|
||||
default = "" # If empty, a new EIP will be created
|
||||
}
|
||||
|
||||
|
||||
@@ -2,11 +2,9 @@
|
||||
<Project Sdk="Microsoft.NET.Sdk">
|
||||
<PropertyGroup>
|
||||
<OutputType>Exe</OutputType>
|
||||
<TargetFramework>net8.0</TargetFramework>
|
||||
<TargetFramework>net472</TargetFramework>
|
||||
<RootNamespace>NativeAppHost</RootNamespace>
|
||||
<AssemblyName>NativeAppHost</AssemblyName>
|
||||
<ImplicitUsings>enable</ImplicitUsings>
|
||||
<Nullable>enable</Nullable>
|
||||
</PropertyGroup>
|
||||
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|AnyCPU'">
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<Project Sdk="Microsoft.NET.Sdk">
|
||||
<PropertyGroup>
|
||||
<TargetFramework>netstandard2.0</TargetFramework>
|
||||
<TargetFramework>net472</TargetFramework>
|
||||
<EnableDefaultCompileItems>false</EnableDefaultCompileItems>
|
||||
|
||||
<!-- Explicitly set the assembly name -->
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<Project Sdk="Microsoft.NET.Sdk">
|
||||
<PropertyGroup>
|
||||
<TargetFramework>netstandard2.0</TargetFramework>
|
||||
<TargetFramework>net472</TargetFramework>
|
||||
<EnableDefaultCompileItems>false</EnableDefaultCompileItems>
|
||||
|
||||
<!-- Explicitly set the assembly name -->
|
||||
|
||||
@@ -19,7 +19,7 @@ First build the docker container: `docker build -t chromealone .`
|
||||
|
||||
## Deployment Instructions
|
||||
|
||||
There are currently two supported deployment modes:
|
||||
There are currently two supported deployment modes. Note that in either case, you should be running `docker` from the base directory of the ChromeAlone git repository.
|
||||
|
||||
### Deployment from scratch via AWS
|
||||
|
||||
|
||||
@@ -6,16 +6,18 @@ DOMAIN_NAME=""
|
||||
APP_NAME="com.chrome.alone"
|
||||
OUTPUT_NAME="sideloader.ps1"
|
||||
TFVARS_FILE=""
|
||||
AWS_REGION="us-east-2" # Default region
|
||||
|
||||
# Function to display usage information
|
||||
show_usage() {
|
||||
echo "Usage: $0 [--domain=example.com] [--appname=com.chrome.alone] [--output=sideloader.ps1] [--tfvars=path/to/terraform.tfvars]"
|
||||
echo "Usage: $0 [--domain=example.com] [--appname=com.chrome.alone] [--output=sideloader.ps1] [--tfvars=path/to/terraform.tfvars] [--region=us-east-2]"
|
||||
echo ""
|
||||
echo "Arguments:"
|
||||
echo " --domain=DOMAIN Domain name for the relay server (required unless --tfvars is provided)"
|
||||
echo " --appname=NAME Custom app name (optional, default: com.chrome.alone)"
|
||||
echo " --output=NAME Output file name (optional, default: sideloader.ps1)"
|
||||
echo " --tfvars=PATH Path to existing terraform.tfvars file (skips terraform deployment)"
|
||||
echo " --region=REGION AWS region for deployment (optional, default: us-east-2)"
|
||||
echo ""
|
||||
}
|
||||
|
||||
@@ -38,6 +40,10 @@ while [[ $# -gt 0 ]]; do
|
||||
TFVARS_FILE="${1#*=}"
|
||||
shift
|
||||
;;
|
||||
--region=*)
|
||||
AWS_REGION="${1#*=}"
|
||||
shift
|
||||
;;
|
||||
--help|-h)
|
||||
show_usage
|
||||
exit 0
|
||||
@@ -69,6 +75,7 @@ if [ -n "$TFVARS_FILE" ]; then
|
||||
else
|
||||
echo "Domain Name: $DOMAIN_NAME"
|
||||
fi
|
||||
echo "AWS Region: $AWS_REGION"
|
||||
echo "App Name: ${APP_NAME:-Using default com.chrome.alone}"
|
||||
echo "Output Name: ${OUTPUT_NAME:-Using default sideloader.ps1}"
|
||||
|
||||
@@ -124,7 +131,7 @@ if [ -n "$TFVARS_FILE" ]; then
|
||||
else
|
||||
echo "Step 1: Running .deploy-relay.sh from BATTLEPLAN/ directory"
|
||||
cd "$PROJECT_ROOT/BATTLEPLAN"
|
||||
bash ./deploy-relay.sh --domain "$DOMAIN_NAME"
|
||||
bash ./deploy-relay.sh --domain "$DOMAIN_NAME" --region "$AWS_REGION"
|
||||
fi
|
||||
|
||||
# Extract domain_name and relay_token from terraform.tfvars
|
||||
@@ -186,8 +193,8 @@ cp -r ./HOTWHEELS/extension/ ./output/extension/
|
||||
cp ./PAINTBUCKET/ContentScriptInject/*.js ./output/extension/
|
||||
|
||||
# Step 4b: Build the WASM files
|
||||
GOOS=js GOARCH=wasm go build -trimpath -ldflags "-s -w" -o ./output/extension/wasm/main.wasm ./HOTWHEELS/wasm/content-script/
|
||||
GOOS=js GOARCH=wasm go build -trimpath -ldflags "-s -w -X main.EXTENSION_NAME=$APP_NAME" -o output/extension/wasm/background.wasm ./HOTWHEELS/wasm/background-script/
|
||||
GOOS=js GOARCH=wasm go build -buildvcs=false -trimpath -ldflags "-s -w" -o ./output/extension/wasm/main.wasm ./HOTWHEELS/wasm/content-script/
|
||||
GOOS=js GOARCH=wasm go build -buildvcs=false -trimpath -ldflags "-s -w -X main.EXTENSION_NAME=$APP_NAME" -o output/extension/wasm/background.wasm ./HOTWHEELS/wasm/background-script/
|
||||
|
||||
# Step 4c: build the native messaging host
|
||||
dotnet build -c Release -r win-x64 -o output/extension/ ./DOORKNOB/ExtensionSideloader/dotnet/NativeAppHost/NativeAppHost.csproj
|
||||
|
||||
Reference in New Issue
Block a user