#!/bin/bash
# ============ CONFIGURATION ============
TIMEZONE="US/Eastern" # Change to your timezone (e.g., US/Pacific, Europe/London)
PDNS_DB_PASSWORD="CHANGE_ME_strong_password"
export DEBIAN_FRONTEND=noninteractive
# Pre-seed timezone so tzdata doesn't prompt
echo "$TIMEZONE" > /etc/timezone
ln -sf /usr/share/zoneinfo/"$TIMEZONE" /etc/localtime
# ============ PACKAGE INSTALLATION ============
apt update
# For Ubuntu 24.04 / Trisquel 12 (PHP 8.3):
apt install -y resolvconf apt-utils wireguard wireguard-tools iproute2 curl iputils-ping dialog libapache2-mod-php apache2 mariadb-server pdns-server pdns-backend-mysql php-imagick php8.3-common php8.3-gd php8.3-imap php8.3-mysql php8.3-curl php8.3-zip php8.3-xml php8.3-mbstring php8.3-bz2 php8.3-intl php8.3-gmp php8.3-redis php-pear wget php8.3-fpm certbot python3-certbot-apache dnsutils
# For Ubuntu 26.04 / Trisquel 13 (PHP 8.5):
# apt install -y resolvconf apt-utils wireguard wireguard-tools iproute2 curl iputils-ping dialog libapache2-mod-php apache2 mariadb-server pdns-server pdns-backend-mysql php-imagick php8.5-common php8.5-gd php8.5-imap php8.5-mysql php8.5-curl php8.5-zip php8.5-xml php8.5-mbstring php8.5-bz2 php8.5-intl php8.5-gmp php8.5-redis php-pear wget php8.5-fpm certbot python3-certbot-apache dnsutils
# ============ DNS (CRITICAL - MUST COME BEFORE WIREGUARD) ============
# Disable systemd-resolved (frees port 53 for PowerDNS)
systemctl disable --now systemd-resolved 2>/dev/null
# Write a static /etc/resolv.conf with public DNS
rm -f /etc/resolv.conf
cat > /etc/resolv.conf << 'EOF'
nameserver 1.1.1.1
nameserver 8.8.8.8
options edns0
EOF
chmod 644 /etc/resolv.conf
# Verify DNS works
ping -c 1 google.com
# ============ POWERDNS SETUP ============
# Create database, user, and load schema
mysql -u root -e "CREATE DATABASE IF NOT EXISTS powerdns; CREATE USER IF NOT EXISTS 'powerdns'@'localhost' IDENTIFIED BY '${PDNS_DB_PASSWORD}'; GRANT ALL ON powerdns.* TO 'powerdns'@'localhost'; FLUSH PRIVILEGES;"
mysql -u powerdns -p"${PDNS_DB_PASSWORD}" powerdns < /usr/share/pdns-backend-mysql/schema/schema.mysql.sql
# Configure PowerDNS to use the MySQL backend
cat > /etc/powerdns/pdns.d/pdns.local.gmysql.conf << 'EOF'
launch=gmysql
gmysql-host=localhost
gmysql-user=powerdns
gmysql-password=${PDNS_DB_PASSWORD}
gmysql-dbname=powerdns
EOF
# Start PowerDNS
systemctl start pdns
systemctl enable pdns
# ============ WIREGUARD CLIENT SETUP ============
# Copy your WireGuard client configuration to the mail server
# (from /tmp/wg-client0.conf on your VPS if you followed the ThinkPenguin guide)
nano /etc/wireguard/wg-client0.conf
# Remove DNS= line (wg-quick would call resolvconf which fails without systemd-resolved)
sed -i '/^DNS[[:space:]]*=/d' /etc/wireguard/wg-client0.conf
# Make it so only root can read the WireGuard configuration
chmod 600 /etc/wireguard/ -R
# Disable broken wait-online services (neither applies to this system)
systemctl disable systemd-networkd-wait-online 2>/dev/null
# Use a sleep as a safety net for DHCP/LAN readiness
mkdir -p /etc/systemd/system/wg-quick@wg-client0.service.d/
cat > /etc/systemd/system/wg-quick@wg-client0.service.d/override.conf << 'EOF'
[Service]
ExecStartPre=/bin/sleep 10
Restart=on-failure
RestartSec=10
[Unit]
StartLimitIntervalSec=0
StartLimitBurst=0
EOF
systemctl daemon-reload
# Start WireGuard client
systemctl start wg-quick@wg-client0.service
# Enable WireGuard client to start on every boot
systemctl enable wg-quick@wg-client0.service
# ============ VERIFICATION ============
# Your dedicated public IP via the WireGuard VPS
curl ifconfig.me
# Test public accessibility
# Open a browser and visit:
# http://public_ip_of_VPS_wireguard_server_static_address_you_were_assigned
