Files
Omarchy-Stream/install.sh
Levi Woodard 16e2465cf5 Self-healing headless, working JARVIS install fixes, public-safe docs
This bundles every fix we made debugging the first real install plus a
comprehensive troubleshooting reference. Working tree is now PII-safe for
public distribution: hostname-based default mode is driven by a HEADLESS_HOSTS
env var instead of a hardcoded literal; docs use placeholders for hostnames
and LAN IPs.

Self-healing headless management
- bin/sunshine-prestart.sh (new): runs as systemd ExecStartPre. Resolves the
  Hyprland instance signature from XDG_RUNTIME_DIR/hypr when systemd-user env
  didn't propagate it. Reduces to exactly one headless output by keeping the
  lowest-numbered HEADLESS-N and removing the rest. Rewrites the managed
  sunshine.conf's output_name line to match the surviving name — Hyprland's
  HEADLESS-N counter is monotonic and ignores the optional name argument to
  'output create headless', so without active sync output_name drifts off
  HEADLESS-1 after the first restart cycle.
- bin/sunshine-stream-do.sh: dropped the hardcoded MON=HEADLESS-1. Now
  discovers whatever HEADLESS-* exists via jq. Resize and workspace migration
  target the actual output.
- bin/sunshine-stream-undo.sh: reads the headless name from a state file the
  do-script wrote, with discovery fallback. Stops removing the output between
  sessions — the create/destroy race caused fatal startup encoder errors on
  the next Sunshine restart.
- files/headless-prestart.conf, files/sunshine.service: ExecStartPre now
  points at the new prestart script.
- lib/headless.sh: install_headless_hooks now installs all three scripts.
  New install_headless_prestart_dropin resolves the actual systemd unit name
  (sunshine.service vs app-dev.lizardbyte.app.Sunshine.service) and lands the
  drop-in under <unit>.service.d/.

Firewall detection
- lib/firewall.sh: _ufw_active now uses 'systemctl is-active ufw.service'
  instead of 'ufw status'. The latter requires root to read /etc/ufw state,
  so the unprivileged probe returned false and we silently skipped opening
  Sunshine's ports on hosts where ufw was actively dropping packets.

Service unit fallbacks
- lib/service.sh: ensure_sunshine_unit_present looks for sunshine.service in
  every systemd-user path first; falls back to the reverse-DNS AUR-source
  unit name; last resort drops a repo-provided fallback unit. systemctl
  reset-failed before each restart so a previous start-limit-hit doesn't
  immediately reject the new attempt.

Preflight
- lib/preflight.sh: new preflight_headless step that, only when STREAM_MODE
  is headless, surfaces missing hyprctl / jq / Hyprland reachability before
  install proceeds.

Public-safe defaults
- install.sh: streaming-mode default is now driven by HEADLESS_HOSTS env var
  (comma-separated, case-insensitive). Unset by default — every host gets
  mirror mode unless its hostname is listed or --headless is passed
  explicitly. Past versions hardcoded a specific hostname.
- README.md: replaced JARVIS-specific examples with HEADLESS_HOSTS prose.

Docs
- docs/TROUBLESHOOTING.md (new): comprehensive failure-mode reference. Every
  issue hit during the first end-to-end install, in order, with symptom →
  cause → fix → permanent prevention. Plus a "Custom keybinding to escape
  Moonlight" section and an outstanding-followups punch list (1Password
  black-rectangle workarounds, hypridle inhibit during stream, busiest-
  workspace auto-switch, jarvis.lan DNS, 1Password SSH agent timeouts).
2026-05-18 16:52:41 -06:00

228 lines
7.1 KiB
Bash
Executable File

#!/usr/bin/env bash
# omarchy-moonlight installer
# Sets up Sunshine (host) + Moonlight (client) on Omarchy/Hyprland/Wayland.
# Idempotent: re-run safely. Same script works on NVIDIA and AMD machines.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# shellcheck source=lib/common.sh
source "$SCRIPT_DIR/lib/common.sh"
# shellcheck source=lib/detect.sh
source "$SCRIPT_DIR/lib/detect.sh"
# shellcheck source=lib/preflight.sh
source "$SCRIPT_DIR/lib/preflight.sh"
# shellcheck source=lib/packages.sh
source "$SCRIPT_DIR/lib/packages.sh"
# shellcheck source=lib/permissions.sh
source "$SCRIPT_DIR/lib/permissions.sh"
# shellcheck source=lib/config.sh
source "$SCRIPT_DIR/lib/config.sh"
# shellcheck source=lib/firewall.sh
source "$SCRIPT_DIR/lib/firewall.sh"
# shellcheck source=lib/service.sh
source "$SCRIPT_DIR/lib/service.sh"
# shellcheck source=lib/verify.sh
source "$SCRIPT_DIR/lib/verify.sh"
# shellcheck source=lib/headless.sh
source "$SCRIPT_DIR/lib/headless.sh"
# shellcheck source=lib/certs.sh
source "$SCRIPT_DIR/lib/certs.sh"
usage() {
cat <<EOF
Usage: $(basename "$0") [options]
Installs Sunshine + Moonlight on an Omarchy machine.
Options:
--no-autostart Don't enable user service or lingering (manual start only)
--no-firewall Skip firewall configuration
--no-moonlight Don't install moonlight-qt (host-only setup)
--no-sunshine Don't install sunshine (client-only setup)
--no-config Don't write a tuned sunshine.conf
--from-source Build Sunshine from source (equivalent to SUNSHINE_PKG=sunshine)
--headless Force headless streaming mode (wlr capture of HEADLESS-1)
--mirror Force mirror mode (KMS capture of the real display)
--no-certs Skip the 1Password-backed cert step (use Sunshine's self-signed)
--force-certs Re-mint the host cert even if the current one is valid
--doctor Run only the post-install verification checks
-h, --help Show this help
Environment overrides:
SUNSHINE_PKG AUR package to use for Sunshine (default: sunshine-bin)
Set to 'sunshine' to build from source instead.
OP_VAULT 1Password vault that holds the root CA (default: Private)
OP_CA_ITEM Item title in that vault (default: Omarchy-Stream Root CA)
HEADLESS_HOSTS Comma-separated hostnames that default to headless mode.
Unset by default; anything not listed defaults to mirror.
Override per-invocation with --headless or --mirror.
EOF
}
AUTOSTART=1
FIREWALL=1
INSTALL_SUNSHINE=1
INSTALL_MOONLIGHT=1
WRITE_CONFIG=1
DOCTOR_ONLY=0
MODE_OVERRIDE=""
INSTALL_CERTS=1
while [[ $# -gt 0 ]]; do
case "$1" in
--no-autostart) AUTOSTART=0 ;;
--no-firewall) FIREWALL=0 ;;
--no-moonlight) INSTALL_MOONLIGHT=0 ;;
--no-sunshine) INSTALL_SUNSHINE=0 ;;
--no-config) WRITE_CONFIG=0 ;;
--no-certs) INSTALL_CERTS=0 ;;
--force-certs) export FORCE_CERTS=1 ;;
--from-source) export SUNSHINE_PKG=sunshine ;;
--headless) MODE_OVERRIDE="headless" ;;
--mirror) MODE_OVERRIDE="mirror" ;;
--doctor) DOCTOR_ONLY=1 ;;
-h|--help) usage; exit 0 ;;
*) err "Unknown option: $1"; usage; exit 2 ;;
esac
shift
done
# Pick streaming mode: explicit flag wins; otherwise hostnames listed in the
# HEADLESS_HOSTS env var (comma-separated, case-insensitive) default to headless
# mode, anything else defaults to mirror. Override per-invocation with
# --headless / --mirror.
#
# Example (in your shell rc or one-off):
# HEADLESS_HOSTS=mybox,otherbox ./install.sh
compute_stream_mode() {
if [[ -n "$MODE_OVERRIDE" ]]; then
STREAM_MODE="$MODE_OVERRIDE"
return 0
fi
local host_lc="${HOSTNAME_SHORT,,}"
local IFS=','
for h in ${HEADLESS_HOSTS:-}; do
if [[ "$host_lc" == "${h,,}" ]]; then
STREAM_MODE="headless"
return 0
fi
done
STREAM_MODE="mirror"
}
main() {
require_not_root
require_arch
require_yay
step "Detecting system"
detect_all
compute_stream_mode
export STREAM_MODE
info "Host: $HOSTNAME_SHORT GPU: $GPU_VENDOR Session: $SESSION_TYPE"
info "Mode: $STREAM_MODE"
if [[ $DOCTOR_ONLY -eq 1 ]]; then
verify_install
exit $(( VERIFY_FAILURES > 0 ? 1 : 0 ))
fi
step "Preflight checks"
preflight_all
if [[ $INSTALL_SUNSHINE -eq 1 ]]; then
step "Installing Sunshine and GPU encoder support"
install_sunshine
install_gpu_encoder_packages
step "Configuring permissions for KMS capture and virtual input"
ensure_input_group
ensure_uinput_udev_rule
set_sunshine_capabilities
if [[ "$STREAM_MODE" == "headless" ]]; then
step "Installing headless prep-cmd hooks"
install_headless_hooks
fi
# NOTE: the headless prestart drop-in needs the sunshine unit to already
# exist; install it after service-unit detection in enable_sunshine_service.
if [[ $WRITE_CONFIG -eq 1 ]]; then
step "Writing tuned sunshine.conf"
write_sunshine_config "$STREAM_MODE"
else
info "Skipping sunshine.conf (--no-config)"
fi
if [[ $INSTALL_CERTS -eq 1 ]]; then
step "Installing CA-signed Sunshine cert from 1Password"
if fetch_and_install_certs; then
CERTS_REPLACED=1
else
warn "Cert install failed — falling back to Sunshine's self-signed cert."
warn "Run scripts/cert-bootstrap.sh to create the CA item, then re-run install.sh."
fi
else
info "Skipping cert step (--no-certs)"
fi
if [[ $FIREWALL -eq 1 ]]; then
step "Configuring firewall for Sunshine ports"
open_sunshine_ports
else
info "Skipping firewall (--no-firewall)"
fi
if [[ $AUTOSTART -eq 1 ]]; then
step "Enabling Sunshine user service"
enable_sunshine_service
else
info "Skipping autostart (--no-autostart). Start manually with: systemctl --user start sunshine"
fi
else
info "Skipping Sunshine install (--no-sunshine)"
fi
if [[ $INSTALL_MOONLIGHT -eq 1 ]]; then
step "Installing Moonlight client"
install_moonlight
else
info "Skipping Moonlight install (--no-moonlight)"
fi
if [[ $INSTALL_SUNSHINE -eq 1 ]]; then
verify_install
fi
step "Done"
print_next_steps
}
print_next_steps() {
local ip
ip="$(ip -4 -o addr show scope global | awk '{print $4}' | cut -d/ -f1 | head -n1)"
cat <<EOF
${BOLD}Next steps:${RESET}
1. ${BOLD}Re-login${RESET} (or run ${DIM}newgrp input${RESET}) if you weren't already in the 'input' group.
This is required for Sunshine to access /dev/uinput.
2. Open Sunshine's web UI to set credentials and pair clients:
${BOLD}https://localhost:47990${RESET}
(Self-signed cert — accept the browser warning.)
3. On a Moonlight client (this machine, the Framework, or your Mac):
- Add this host by IP: ${BOLD}${ip:-<your-lan-ip>}${RESET}
- Enter the 4-digit PIN that Sunshine's UI shows during pairing.
4. To check status: ${DIM}systemctl --user status sunshine${RESET}
To view logs: ${DIM}journalctl --user -u sunshine -f${RESET}
To uninstall: ${DIM}$SCRIPT_DIR/uninstall.sh${RESET}
EOF
}
main "$@"