forked from heavy-duty/box
The tool underneath was already generic: a thin, honest wrapper over Incus. What was Claude-specific was welded on — one image, one profile, one cloud-init file, one hardcoded 'sudo -u claude'. The weld is now a template. The mechanic: 'box new' stamps the template's identity onto the instance (user.box=1, user.box.template, user.box.user); shell/exec/ tmux read the user back off the instance, and 'incus copy' carries user.* keys (audit B2), so a clone knows what it is without consulting the template. Templates are box.env (parsed against a strict allowlist, never sourced — no key for a network exists, on purpose) plus a verbatim cloud-init. Every template launches with the shared box-net profile: the isolated NIC and root disk, nothing template-controlled — resources land per-instance from box.env, overridable via BOX_CPU/ BOX_MEMORY/BOX_DISK (which is also how the drill shrinks boxes on a small host now that profile edits can't). The three open calls, taken as recommended: clean cut at 0.4.0 (no claudebox shim; the installer retires the old symlink); default template = claude (muscle memory survives); repo stays heavy-duty/ claudebox, binary is box. Compat is the tag, not the name: resolve_box and list honor the legacy user.claudebox=1 forever, and the legacy tag maps to the claude user — a pre-rename box lists, shells, clones, unchanged. Deliberate divergence from #17's table: the host-stack resource names (claudenet, claude-isolate, nft tables, claudebox-firewall.*) are NOT renamed — they are host-internal, invisible to users, and renaming them breaks every provisioned host for zero user-visible gain. claude-dev is no longer created; setup-host creates box-net, teardown removes both. Closes #17
58 lines
2.4 KiB
Bash
Executable file
58 lines
2.4 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Reverse everything host/setup-host.sh created: all claudebox instances, the
|
|
# claudenet network + ACL, the claude-dev profile, and the firewall rules.
|
|
# Usage: ./host/teardown-host.sh [--purge-incus]
|
|
# --purge-incus also apt-purge Incus itself (skipped if non-claudebox
|
|
# instances still exist on this host)
|
|
set -euo pipefail
|
|
|
|
purge=false
|
|
[ "${1:-}" = "--purge-incus" ] && purge=true
|
|
|
|
echo "This removes ALL claudebox instances (uncommitted work in them is lost),"
|
|
echo "the claudenet network/ACL/profile, and the claudebox firewall rules."
|
|
$purge && echo "Incus itself will also be uninstalled (--purge-incus)."
|
|
read -rp "Continue? [y/N] " a
|
|
case "$a" in y|Y) ;; *) echo "aborted"; exit 1 ;; esac
|
|
|
|
# Instances
|
|
for i in $(incus list "user.claudebox=1" -f csv -c n || true); do
|
|
echo "deleting instance $i"
|
|
incus delete -f "$i"
|
|
done
|
|
|
|
incus profile delete box-net 2>/dev/null || true
|
|
incus profile delete claude-dev 2>/dev/null || true # legacy, pre-rename
|
|
incus network delete claudenet 2>/dev/null || true
|
|
incus network acl delete claude-isolate 2>/dev/null || true
|
|
|
|
# Boot-persistence unit
|
|
sudo systemctl disable --now claudebox-firewall.service 2>/dev/null || true
|
|
sudo rm -f /etc/systemd/system/claudebox-firewall.service /usr/local/sbin/claudebox-firewall
|
|
sudo systemctl daemon-reload
|
|
|
|
# Firewall crumbs — UFW rules mentioning claudenet (numbers shift after each
|
|
# delete, so re-scan and remove the first match until none remain)
|
|
if command -v ufw >/dev/null && sudo ufw status 2>/dev/null | grep -q "Status: active"; then
|
|
while sudo ufw status numbered | grep -q "on claudenet"; do
|
|
n="$(sudo ufw status numbered | grep -m1 "on claudenet" | sed -E 's/^\[ *([0-9]+)\].*/\1/')"
|
|
sudo ufw --force delete "$n"
|
|
done
|
|
fi
|
|
sudo nft delete table inet claudebox 2>/dev/null || true
|
|
if command -v docker >/dev/null; then
|
|
sudo iptables -D DOCKER-USER -i claudenet -j ACCEPT 2>/dev/null || true
|
|
sudo iptables -D DOCKER-USER -o claudenet -j ACCEPT 2>/dev/null || true
|
|
fi
|
|
|
|
if $purge; then
|
|
remaining="$(incus list -f csv 2>/dev/null | wc -l)"
|
|
if [ "$remaining" -gt 0 ]; then
|
|
echo "NOTE: $remaining non-claudebox instance(s) remain on this host — leaving Incus installed."
|
|
else
|
|
sudo apt-get purge -y incus
|
|
sudo apt-get autoremove -y
|
|
fi
|
|
fi
|
|
|
|
echo "Teardown complete. (Your ~/.local/bin/claudebox symlink and ~/.local/share/claudebox remain — remove by hand if wanted.)"
|