feat: serve the home vision system on LAN and Tailscale with architecture documentation

This commit is contained in:
Codex
2026-10-03 16:21:00 +08:00
parent 528007ea43
commit 0674f260a4
5 changed files with 78 additions and 12 deletions
+4 -3
View File
@@ -1,7 +1,7 @@
#!/usr/bin/env bash
set -euo pipefail
# Run from a committed, published release checkout on an x86_64 Ubuntu host.
# VISION_BIND is the host's Tailscale IPv4; defaults to loopback.
# VISION_BIND is a comma-separated list of explicit private/Tailscale IPv4s.
# MEDIA_ARCHIVE optionally points to an already downloaded pinned release archive.
[[ $(id -u) == 0 ]] || { echo 'Run as root'; exit 1; }
[[ $(uname -m) == x86_64 ]] || { echo 'This installer targets x86_64'; exit 1; }
@@ -10,8 +10,9 @@ release_dir=$(cd -- "$(dirname -- "$0")/.." && pwd)
bind_address=${VISION_BIND:-127.0.0.1}
python3 - "$bind_address" <<'PY'
import ipaddress,sys
ip=ipaddress.ip_address(sys.argv[1])
assert ip.version==4 and (ip.is_loopback or ip in ipaddress.ip_network('100.64.0.0/10')), 'Use a Tailscale or loopback address'
for value in sys.argv[1].split(','):
ip=ipaddress.ip_address(value.strip())
assert ip.version==4 and not ip.is_unspecified and not ip.is_multicast and (ip.is_private or ip in ipaddress.ip_network('100.64.0.0/10')), 'Use explicit private or Tailscale addresses'
PY
getent passwd zhaovision >/dev/null || useradd --system --home-dir /var/lib/zhaovision --shell /usr/sbin/nologin zhaovision
install -d -o zhaovision -g zhaovision -m 700 /var/lib/zhaovision /var/lib/zhaovision/recordings