#!/bin/bash #================================================= # GENERIC START #================================================= # Load common variables and helpers source ./_common.sh # IMPORT GENERIC HELPERS source /usr/share/yunohost/helpers #================================================= # Create install and data subdirs #================================================= ynh_setup_source --dest_dir="$install_dir" xz -d "$install_dir/forgejo.xz" chmod +x "$install_dir/forgejo" mkdir -p "$install_dir/custom/conf" chmod -R o-rwx "$install_dir/custom" chown -R $app:$app "$install_dir/custom" #================================================= # KEYS GENERATION #================================================= secret_key=$($install_dir/forgejo generate secret SECRET_KEY) lfs_jwt_secret=$($install_dir/forgejo generate secret JWT_SECRET) internal_token=$($install_dir/forgejo generate secret INTERNAL_TOKEN) oauth2_jwt_secret=$($install_dir/forgejo generate secret JWT_SECRET) ynh_app_setting_set --app=$app --key=secret_key --value=$secret_key ynh_app_setting_set --app=$app --key=lfs_jwt_secret --value=$lfs_jwt_secret ynh_app_setting_set --app=$app --key=internal_token --value=$internal_token ynh_app_setting_set --app=$app --key=oauth2_jwt_secret --value=$oauth2_jwt_secret #================================================= # ADD A CONFIGURATION #================================================= ynh_script_progression --message="Adding a configuration file..." --weight=1 register_email_confirm=false register_manual_confirm=false disable_registration=true require_signin_view=false enable_notify_mail=true show_registration_button=true mirror_enabled=true mirror_disable_new_pull=false mirror_disable_new_push=false mirror_default_interval="8h" mirror_min_interval="10m" ynh_app_setting_set --app="$app" --key=register_email_confirm --value=$register_email_confirm ynh_app_setting_set --app="$app" --key=register_manual_confirm --value=$register_manual_confirm ynh_app_setting_set --app="$app" --key=disable_registration --value=$disable_registration ynh_app_setting_set --app="$app" --key=require_signin_view --value=$require_signin_view ynh_app_setting_set --app="$app" --key=enable_notify_mail --value=$enable_notify_mail ynh_app_setting_set --app="$app" --key=show_registration_button --value=$show_registration_button ynh_app_setting_set --app="$app" --key=mirror_enabled --value=$mirror_enabled ynh_app_setting_set --app="$app" --key=mirror_disable_new_pull --value=$mirror_disable_new_pull ynh_app_setting_set --app="$app" --key=mirror_disable_new_push --value=$mirror_disable_new_push ynh_app_setting_set --app="$app" --key=mirror_default_interval --value=$mirror_default_interval ynh_app_setting_set --app="$app" --key=mirror_min_interval --value=$mirror_min_interval ssh_port=$(grep -P "Port\s+\d+" /etc/ssh/sshd_config | grep -P -o "\d+") ynh_add_config --template="app.ini" --destination="$install_dir/custom/conf/app.ini" chmod 640 "$install_dir/custom/conf/app.ini" chown $app:$app "$install_dir/custom/conf/app.ini" #================================================= # SETUP SYSTEMD #================================================= ynh_script_progression --message="Upgrading systemd configuration..." --weight=1 ynh_add_systemd_config #================================================= # NGINX CONFIGURATION #================================================= ynh_script_progression --message="Upgrading NGINX web server configuration..." --weight=2 ynh_add_nginx_config #================================================= # GENERIC FINALIZATION #================================================= # SETUP LOGROTATE #================================================= ynh_script_progression --message="Configuring log rotation..." --weight=1 # Use logrotate to manage application logfile(s) ynh_use_logrotate --logfile "/var/log/$app" --nonappend chown -R $app:$app "/var/log/$app" chmod u=rwX,g=rX,o= "/var/log/$app" #================================================= # INTEGRATE SERVICE IN YUNOHOST #================================================= ynh_script_progression --message="Integrating service in YunoHost..." --weight=2 yunohost service add $app --description="Forgejo" --log="/var/log/$app/forgejo.log" #================================================= # START SYSTEMD SERVICE #================================================= ynh_script_progression --message="Starting a systemd service..." --weight=3 # Start a systemd service ynh_systemd_action --service_name=$app --action="start" --log_path="/var/log/$app/forgejo.log" --line_match="Starting new Web server: tcp:127.0.0.1:" #================================================= # SETUP FAIL2BAN #================================================= ynh_script_progression --message="Configuring Fail2Ban..." --weight=1 ynh_add_fail2ban_config --logpath "/var/log/$app/forgejo.log" --failregex ".*Failed authentication attempt for .* from " --max_retry 5 #================================================= # LDAP CONFIGURATION #================================================= ynh_script_progression --message="Adding LDAP configuration..." --weight=1 set_forgejo_login_source enable_login_source_sync # API user creation create_forgejo_api_user # Yunohost user creation synchronize_users #================================================= # END OF SCRIPT #================================================= ynh_script_progression --message="Installation of $app completed" --last