setup icloudphotodownloader

This commit is contained in:
tomasr committed 2026-08-14 12:15:38 +02:00
1 parent 69ad5b3d13
commit f2e3f30173
5 files changed
+257 -3

No files matched your search

+6
View File
@@ -24,7 +24,13 @@ METUBE_PASS=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
NTFY_URL=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx # dont forget the https://
NTFY_TOKEN=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
NTFY_TOPIC=xxxxxxxxxxxxxxxxxxxxxxxxxx
DOCKER_COMPOSE_DIR=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
GITEA_ROOT_URL=xxxxxxxxxxxxxxxxxxx # dont forget https://
ICLOUD_EMAIL=xxxxxxxxxxxxxxxxxxxxxxxxxxxx
ICLOUD_PASSWORD=xxxxxxxxxxxxxxxxxxxxxxxxxx
+111 -3
View File
@@ -50,10 +50,12 @@ apt install -y \
unzip \
hledger-web \
vim \
acl
acl \
python3 \
python3-venv
# base setup
echo 'export SYSTEMD_PAGER=cat' >> ~/.bashr
echo 'export SYSTEMD_PAGER=cat' >> ~/.bashrc
source /home/tomasr/.bashrc
################################################################################
@@ -125,6 +127,89 @@ fi
cd "/home/$USERNAME/$REPO_DIR"
chown -R "$USERNAME:$USERNAME" "/home/$USERNAME/"
chmod +x \
"/home/$USERNAME/$REPO_DIR/scripts/icloud-auth.sh" \
"/home/$USERNAME/$REPO_DIR/scripts/backup-icloud.sh"
chown "$USERNAME:$USERNAME" \
"/home/$USERNAME/$REPO_DIR/scripts/icloud-auth.sh" \
"/home/$USERNAME/$REPO_DIR/scripts/backup-icloud.sh"
################################################################################
# Environment
################################################################################
step "Initializing environment"
if [ ! -f "/home/$USERNAME/$REPO_DIR/.env" ]; then
cp "/home/$USERNAME/$REPO_DIR/.env.example" \
"/home/$USERNAME/$REPO_DIR/.env"
chown "$USERNAME:$USERNAME" \
"/home/$USERNAME/$REPO_DIR/.env"
chmod 600 \
"/home/$USERNAME/$REPO_DIR/.env"
cat <<EOF
==============================================================================
Environment file created
==============================================================================
Edit:
/home/$USERNAME/$REPO_DIR/.env
Make sure the following values are filled in:
ICLOUD_EMAIL
ICLOUD_PASSWORD
The iCloud backup cannot authenticate until these are configured.
After filling them in, run:
sudo -u $USERNAME /home/$USERNAME/$REPO_DIR/scripts/icloud-auth.sh
This will perform the interactive iCloud authentication and ask for
your 2FA code if required.
==============================================================================
EOF
fi
################################################################################
# icloudpd
################################################################################
step "Installing icloudpd"
sudo -u "$USERNAME" python3 -m venv \
"/home/$USERNAME/.venvs/icloudpd"
sudo -u "$USERNAME" \
"/home/$USERNAME/.venvs/icloudpd/bin/pip" \
install --upgrade pip
sudo -u "$USERNAME" \
"/home/$USERNAME/.venvs/icloudpd/bin/pip" \
install icloudpd
################################################################################
# icloudpd authentication
################################################################################
step "Preparing icloudpd authentication"
mkdir -p "/home/$USERNAME/.icloudpd"
chown "$USERNAME:$USERNAME" \
"/home/$USERNAME/.icloudpd"
chmod 700 \
"/home/$USERNAME/.icloudpd"
################################################################################
# Security
################################################################################
@@ -187,7 +272,8 @@ rclone config
cp systemd/kdrive-rclone.service \
/etc/systemd/system/
cp systemd/icloud-backup.service \
/etc/systemd/system/
systemctl daemon-reload
systemctl enable --now kdrive-rclone
@@ -254,6 +340,28 @@ step "Initializing freshrss-fav-archiver"
systemctl enable --now freshrss-fav-archiver.timer
################################################################################
# iCloud backup
################################################################################
step "Configuring iCloud backup"
systemctl enable icloud-backup.service
echo
echo "iCloud backup service has been installed."
echo
echo "Before starting it, configure .env and authenticate iCloud:"
echo
echo " vim /home/$USERNAME/$REPO_DIR/.env"
echo " sudo -u $USERNAME $REPO_DIR/scripts/icloud-auth.sh"
echo
echo "Then start the service with:"
echo
echo " systemctl enable --now icloud-backup.service"
echo
################################################################################
# Done
################################################################################
+79
View File
@@ -0,0 +1,79 @@
#!/usr/bin/env bash
set -euo pipefail
REPO_DIR="/home/tomasr/vps-config"
ENV_FILE="$REPO_DIR/.env"
ICLOUDPD="/home/tomasr/.venvs/icloudpd/bin/icloudpd"
COOKIE_DIR="/home/tomasr/.icloudpd"
BACKUP_DIR="/mnt/kdrive/Photo/IPhone/icloudpd-backup"
# Load environment
if [[ ! -f "$ENV_FILE" ]]; then
echo "ERROR: $ENV_FILE does not exist."
exit 1
fi
# shellcheck disable=SC1090
source "$ENV_FILE"
if [[ -z "${ICLOUD_EMAIL:-}" ]]; then
echo "ERROR: ICLOUD_EMAIL is not configured."
exit 1
fi
if [[ -z "${ICLOUD_PASSWORD:-}" ]]; then
echo "ERROR: ICLOUD_PASSWORD is not configured."
exit 1
fi
if [[ -z "${NTFY_URL:-}" ]]; then
echo "ERROR: NTFY_URL is not configured."
exit 1
fi
if [[ -z "${NTFY_TOPIC:-}" ]]; then
echo "ERROR: NTFY_TOPIC is not configured."
exit 1
fi
if [[ -z "${NTFY_TOKEN:-}" ]]; then
echo "ERROR: NTFY_TOKEN is not configured."
exit 1
fi
mkdir -p "$BACKUP_DIR"
# Check whether the existing iCloud authentication is still valid.
if ! "$ICLOUDPD" \
--auth-only \
--username "$ICLOUD_EMAIL" \
--password "$ICLOUD_PASSWORD" \
--cookie-directory "$COOKIE_DIR" \
--dry-run
then
echo "ERROR: iCloud authentication has expired or is not available."
curl \
--fail \
--silent \
--show-error \
-H "Authorization: Bearer $NTFY_TOKEN" \
-H "Title: iCloud authentication required" \
-H "Priority: high" \
-d "icloudpd on the VPS is no longer authenticated. Run: sudo -u tomasr /home/tomasr/vps-config/scripts/icloud-auth.sh" \
"$NTFY_URL/$NTFY_TOPIC"
exit 1
fi
echo "iCloud authentication is valid."
echo "Starting iCloud backup."
exec "$ICLOUDPD" \
--directory "$BACKUP_DIR" \
--username "$ICLOUD_EMAIL" \
--password "$ICLOUD_PASSWORD" \
--cookie-directory "$COOKIE_DIR" \
--watch-with-interval 36000 \
--no-progress-bar
+41
View File
@@ -0,0 +1,41 @@
#!/usr/bin/env bash
set -euo pipefail
REPO_DIR="/home/tomasr/vps-config"
ENV_FILE="$REPO_DIR/.env"
ICLOUDPD="/home/tomasr/.venvs/icloudpd/bin/icloudpd"
COOKIE_DIR="/home/tomasr/.icloudpd"
if [[ ! -f "$ENV_FILE" ]]; then
echo "ERROR: $ENV_FILE does not exist."
exit 1
fi
# shellcheck disable=SC1090
source "$ENV_FILE"
if [[ -z "${ICLOUD_EMAIL:-}" ]]; then
echo "ERROR: ICLOUD_EMAIL is not configured."
exit 1
fi
if [[ -z "${ICLOUD_PASSWORD:-}" ]]; then
echo "ERROR: ICLOUD_PASSWORD is not configured."
exit 1
fi
mkdir -p "$COOKIE_DIR"
chmod 700 "$COOKIE_DIR"
echo "Authenticating icloudpd as $ICLOUD_EMAIL"
echo
"$ICLOUDPD" \
--auth-only \
--username "$ICLOUD_EMAIL" \
--password "$ICLOUD_PASSWORD" \
--cookie-directory "$COOKIE_DIR"
echo
echo "iCloud authentication completed."
+20
View File
@@ -0,0 +1,20 @@
[Unit]
Description=iCloud Photo Backup
After=network-online.target kdrive-rclone.service
Wants=network-online.target
Requires=kdrive-rclone.service
[Service]
Type=simple
User=tomasr
Group=tomasr
WorkingDirectory=/home/tomasr/vps-config
ExecStart=/home/tomasr/vps-config/scripts/backup-icloud.sh
Restart=on-failure
RestartSec=5min
[Install]
WantedBy=multi-user.target