Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
Log in as root to a fresh Ubuntu server and run:

```
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -v noble-400 -s bbb.example.com -e info@example.com -w
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -v noble-400 -s bbb.example.com -e info@example.com
```

Substitute your own hostname and email. For the full list of flags and more example command lines:
Expand Down Expand Up @@ -53,7 +53,7 @@ If your server is behind an external firewall (AWS security group, Azure NSG, GC

Amazon EC2 users should also assign an [Elastic IP](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html) so the server's address is stable across reboots.

Even with an external firewall in place, pass `-w` to install UFW on the BigBlueButton host itself — defense in depth.
Even with an external firewall in place, the script installs UFW on the BigBlueButton host itself — defense in depth. The default rules allow SSH only on port 22, so the script stops if sshd listens on another port. Pass `-W` to skip UFW and manage the host firewall yourself.

<details>
<summary>Screenshots: Azure and GCE firewall rules</summary>
Expand Down
55 changes: 36 additions & 19 deletions bbb-install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -24,13 +24,13 @@
# Examples
#
# Install BigBlueButton 4.0.x with a SSL certificate from Let's Encrypt using hostname bbb.example.com
# and email address info@example.com and apply a basic firewall
# and email address info@example.com (a basic firewall is applied by default)
#
# wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -w -v noble-400 -s bbb.example.com -e info@example.com
# wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -v noble-400 -s bbb.example.com -e info@example.com
#
# Install BigBlueButton with SSL + Greenlight
#
# wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -w -v noble-400 -s bbb.example.com -e info@example.com -g
# wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- -v noble-400 -s bbb.example.com -e info@example.com -g
#

usage() {
Expand All @@ -48,7 +48,9 @@ CORE:
-v <version> BigBlueButton version (e.g. 'noble-400')
-s <hostname> Server FQDN (must resolve to this host's public IP)
-e <email> Email for Let's Encrypt certbot
-w Install UFW firewall (recommended)
-W Skip UFW firewall configuration (dangerous)
A firewall is required to secure BBB services.
-w Does nothing (Previously: Install UFW firewall)
-h Print this help

SSL / CERTIFICATES:
Expand Down Expand Up @@ -90,39 +92,39 @@ EXAMPLES:

# Install BigBlueButton 4.0 with firewall + Let's Encrypt SSL
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w
-v noble-400 -s bbb.example.com -e info@example.com

# Same, plus Greenlight v3
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -g
-v noble-400 -s bbb.example.com -e info@example.com -g

# Same, plus Greenlight + Keycloak for external auth
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -g -k
-v noble-400 -s bbb.example.com -e info@example.com -g -k

# With LTI framework (MY_KEY/MY_SECRET must be random and kept private)
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -t MY_KEY:MY_SECRET
-v noble-400 -s bbb.example.com -e info@example.com -t MY_KEY:MY_SECRET

# Install coturn on a dedicated TURN host (note: no -v)
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-c turn.example.com:1234abcd -e info@example.com

# Then point BigBlueButton at that external TURN server
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -c turn.example.com:1234abcd
-v noble-400 -s bbb.example.com -e info@example.com -c turn.example.com:1234abcd

# Private network: manual DNS challenge for Let's Encrypt
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -x
-v noble-400 -s bbb.example.com -e info@example.com -x

# Store recordings on a separate volume
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -m /mnt/bbb
-v noble-400 -s bbb.example.com -e info@example.com -m /mnt/bbb

# Everything at once: BBB + UFW + Greenlight + Keycloak + LTI
wget -qO- https://raw.githubusercontent.com/bigbluebutton/bbb-install/v4.0.x-release/bbb-install.sh | bash -s -- \\
-v noble-400 -s bbb.example.com -e info@example.com -w -g -k -t MY_KEY:MY_SECRET
-v noble-400 -s bbb.example.com -e info@example.com -g -k -t MY_KEY:MY_SECRET

UPGRADING:
Re-run the same command used at install time to upgrade to the latest iteration
Expand Down Expand Up @@ -151,7 +153,7 @@ main() {

need_x64

while builtin getopts "hs:r:c:v:e:p:m:t:xgadwjikb" opt "${@}"; do
while builtin getopts "hs:r:c:v:e:p:m:t:xgadwWjikb" opt "${@}"; do

case $opt in
h)
Expand Down Expand Up @@ -233,11 +235,11 @@ main() {
PROVIDED_CERTIFICATE=true
;;
w)
SSH_PORT=$(grep Port /etc/ssh/ssh_config | grep -v \# | sed 's/[^0-9]*//g')
if [[ -n "$SSH_PORT" && "$SSH_PORT" != "22" ]]; then
err "Detected sshd not listening to standard port 22 -- unable to install default UFW firewall rules."
fi
UFW=true
# Still accepted so existing commands keep working
say "WARNING: -w is deprecated -- the UFW firewall is now installed by default. To opt out, pass -W instead." >&2
;;
W)
SKIP_UFW=true
;;
j)
SKIP_MIN_SERVER_REQUIREMENTS_CHECK=true
Expand Down Expand Up @@ -295,6 +297,9 @@ main() {
check_cpus
check_ipv6

if [ "$SKIP_UFW" != true ]; then
check_ssh_port
fi

if [ "$DISTRO" != "noble" ]; then
err "This version of BigBlueButton requires Ubuntu 24.04"
Expand Down Expand Up @@ -371,7 +376,7 @@ main() {

systemctl restart systemd-journald

if [ -n "$UFW" ]; then
if [ "$SKIP_UFW" != true ]; then
setup_ufw
fi

Expand Down Expand Up @@ -576,6 +581,18 @@ check_cpus() {
fi
}

check_ssh_port() {
# setup_ufw leaves an existing apply-config.sh untouched, so there is nothing to guard
if [ -f /etc/bigbluebutton/bbb-conf/apply-config.sh ]; then return 0; fi

# The default UFW rules allow SSH only on port 22
local ssh_ports
ssh_ports=$(sshd -T 2>/dev/null | awk '$1 == "port" { print $2 }')
if [ -n "$ssh_ports" ] && ! grep -qx 22 <<< "$ssh_ports"; then
err "Detected sshd not listening to standard port 22 -- unable to install default UFW firewall rules. Pass -W to skip the firewall."
fi
}

check_ubuntu(){
RELEASE=$(lsb_release -r | sed 's/^[^0-9]*//g')
if [ "$RELEASE" != "$1" ]; then err "You must run this command on Ubuntu $1 server."; fi
Expand Down
Loading