1
0
Fork 0
mirror of https://github.com/YunoHost-Apps/glitchsoc_ynh.git synced 2024-09-03 19:15:59 +02:00
glitchsoc_ynh/scripts/upgrade

324 lines
13 KiB
Text
Raw Normal View History

#!/bin/bash
#=================================================
# GENERIC START
#=================================================
# IMPORT GENERIC HELPERS
#=================================================
2018-04-06 19:58:23 +02:00
source _common.sh
2019-03-21 02:07:49 +01:00
source ynh_install_ruby
source ynh_add_secure_repos__3
source ynh_systemd_action
source /usr/share/yunohost/helpers
#=================================================
# LOAD SETTINGS
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Loading installation settings..."
app=$YNH_APP_INSTANCE_NAME
2019-03-21 02:07:49 +01:00
domain=$(ynh_app_setting_get $app domain)
path_url=$(ynh_app_setting_get $app path)
admin=$(ynh_app_setting_get $app admin)
is_public=$(ynh_app_setting_get $app is_public)
final_path=$(ynh_app_setting_get $app final_path)
language=$(ynh_app_setting_get $app language)
db_name=$(ynh_app_setting_get $app db_name)
db_pwd=$(ynh_app_setting_get $app db_pwd)
2019-03-23 01:54:06 +01:00
admin_mail=$(ynh_user_get_info $admin 'mail')
2018-06-21 04:48:02 +02:00
port_web=$(ynh_app_setting_get "$app" port_web)
port_stream=$(ynh_app_setting_get "$app" port_stream)
2019-03-23 01:54:06 +01:00
paperclip_secret=$(ynh_app_setting_get "$app" paperclip_secret)
secret_key_base=$(ynh_app_setting_get "$app" secret_key_base)
otp_secret=$(ynh_app_setting_get "$app" otp_secret)
2019-03-23 02:58:59 +01:00
vapid_private_key=$(ynh_app_setting_get "$app" vapid_private_key)
vapid_public_key=$(ynh_app_setting_get "$app" vapid_public_key)
2019-03-23 01:54:06 +01:00
#=================================================
# ENSURE DOWNWARD COMPATIBILITY
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Ensuring downward compatibility..."
# If db_name doesn't exist, create it
2019-03-21 02:07:49 +01:00
if [ -z $db_name ]; then
2019-03-23 03:44:14 +01:00
db_name="${app}_production"
2019-03-21 02:07:49 +01:00
ynh_app_setting_set $app db_name $db_name
fi
# If final_path doesn't exist, create it
2019-03-21 02:07:49 +01:00
if [ -z $final_path ]; then
final_path=/var/www/$app
2019-03-21 02:07:49 +01:00
ynh_app_setting_set $app final_path $final_path
fi
# Check if admin is not null
2017-04-17 02:04:18 +02:00
if [[ "$admin" = "" || "$language" = "" ]]; then
echo "Unable to upgrade, please contact support"
ynh_die
fi
2018-06-21 11:08:52 +02:00
# If db_pwd doesn't exist, create it, need for old install
2018-06-18 15:15:27 +02:00
if [[ -z "$db_pwd" ]]; then
db_pwd=$(ynh_string_random)
ynh_app_setting_set $app db_pwd $db_pwd
ynh_psql_test_if_first_run
sudo --login --user=postgres psql -c"ALTER user $app WITH PASSWORD '$db_pwd'" postgres
2018-06-22 10:30:26 +02:00
ynh_replace_string "DB_PASS=" "DB_PASS=${db_pwd}" "${final_path}/live/.env.production"
2018-06-18 15:15:27 +02:00
fi
2019-03-23 01:54:06 +01:00
# If paperclip_secret doesn't exist, retrieve it or create it
if [[ -z "$paperclip_secret" ]]; then
2019-05-10 21:07:21 +02:00
paperclip_secret=$(grep -oP "PAPERCLIP_SECRET=\K\w+" ${final_path}/live/.env.production)
2019-03-23 02:58:59 +01:00
if [[ -z "$paperclip_secret" ]]; then
paperclip_secret=$(head -n128 /dev/urandom | tail -n +1 | tr -dc -d 'a-z0-9' | head -c128)
fi
2019-03-23 01:54:06 +01:00
ynh_app_setting_set "$app" paperclip_secret "$paperclip_secret"
fi
# If secret_key_base doesn't exist, retrieve it or create it
if [[ -z "$secret_key_base" ]]; then
2019-05-10 21:07:21 +02:00
secret_key_base=$(grep -oP "SECRET_KEY_BASE=\K\w+" ${final_path}/live/.env.production)
2019-03-23 02:58:59 +01:00
if [[ -z "$secret_key_base" ]]; then
secret_key_base=$(head -n128 /dev/urandom | tail -n +1 | tr -dc -d 'a-z0-9' | head -c128)
fi
2019-03-23 01:54:06 +01:00
ynh_app_setting_set "$app" secret_key_base "$secret_key_base"
fi
# If otp_secret doesn't exist, retrieve it or create it
if [[ -z "$otp_secret" ]]; then
2019-05-10 21:07:21 +02:00
otp_secret=$(grep -oP "OTP_SECRET=\K\w+" ${final_path}/live/.env.production)
2019-03-23 02:58:59 +01:00
if [[ -z "$otp_secret" ]]; then
otp_secret=$(head -n128 /dev/urandom | tail -n +1 | tr -dc -d 'a-z0-9' | head -c128)
fi
2019-03-23 01:54:06 +01:00
ynh_app_setting_set "$app" otp_secret "$otp_secret"
fi
2019-05-10 21:07:21 +02:00
# If vapid_private_key doesn't exist, retrieve it or create it
if [[ -z "$vapid_private_key" ]]; then
vapid_private_key=$(grep -oP "VAPID_PRIVATE_KEY=\K\w+" ${final_path}/live/.env.production)
vapid_public_key=$(grep -oP "VAPID_PUBLIC_KEY=\K\w+" ${final_path}/live/.env.production)
ynh_app_setting_set "$app" vapid_private_key "$vapid_private_key"
ynh_app_setting_set "$app" vapid_public_key "$vapid_public_key"
fi
#=================================================
# BACKUP BEFORE UPGRADE THEN ACTIVE TRAP
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Backing up the app before upgrading (may take a while)..."
# Backup the current version of the app
ynh_backup_before_upgrade
ynh_clean_setup () {
ynh_clean_check_starting
# restore it if the upgrade fails
ynh_restore_upgradebackup
}
# Exit if an error occurs during the execution of the script
ynh_abort_if_errors
#=================================================
2019-03-21 02:07:49 +01:00
# CHECK THE PATH
#=================================================
2017-04-11 17:03:11 +02:00
2019-03-21 02:07:49 +01:00
# Normalize the URL path syntax
path_url=$(ynh_normalize_url_path $path_url)
2017-05-06 20:34:29 +02:00
#=================================================
# STANDARD UPGRADE STEPS
#=================================================
2019-03-21 02:07:49 +01:00
# STOP MASTODON SERVICES
#=================================================
ynh_print_info "Stopping Mastodon services..."
ynh_systemd_action --action=stop --service_name=${app}-web --line_match="Stopped" --log_path=systemd
ynh_systemd_action --action=stop --service_name=${app}-sidekiq --line_match="Stopped" --log_path=systemd
ynh_systemd_action --action=stop --service_name=${app}-streaming --line_match="Stopped" --log_path=systemd
2019-03-18 04:22:38 +01:00
#=================================================
# DOWNLOAD, CHECK AND UNPACK SOURCE
#=================================================
ynh_print_info "Upgrading source files..."
# Download Mastodon
2018-11-07 05:12:21 +01:00
mv "$final_path/live" "$final_path/live_back"
2019-03-23 00:11:09 +01:00
ynh_setup_source "$final_path/live"
if [ -z $final_path/live_back/public/system ]; then
rsync -a "$final_path/live_back/public/system" "$final_path/live_back/public/."
fi
2018-11-07 05:12:21 +01:00
rsync -a "$final_path/live_back/.env.production" "$final_path/live/."
rm -Rf "$final_path/live_back"
2018-06-21 04:48:02 +02:00
# Clean files which are not needed anymore
2018-06-20 11:54:30 +02:00
ynh_secure_remove $final_path/live/config/initializers/timeout.rb
#=================================================
# NGINX CONFIGURATION
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Upgrading nginx web server configuration..."
2018-09-03 01:02:28 +02:00
ynh_replace_string "__PORT_WEB__" "$port_web" "../conf/nginx.conf"
ynh_replace_string "__PORT_STREAM__" "$port_stream" "../conf/nginx.conf"
ynh_add_nginx_config
2019-03-18 04:22:38 +01:00
#=================================================
# UPGRADE DEPENDENCIES
#=================================================
ynh_print_info "Upgrading dependencies..."
2019-03-22 23:59:16 +01:00
# Install extra_repo debian package backports & yarn
2019-03-21 02:07:49 +01:00
if [ "$(lsb_release --codename --short)" == "jessie" ]; then
2019-03-27 22:24:36 +01:00
ynh_install_extra_repo --repo="deb http://httpredir.debian.org/debian jessie-backports main" --append
2019-03-21 02:07:49 +01:00
fi
2019-03-27 22:24:36 +01:00
ynh_install_extra_repo --repo="deb https://dl.yarnpkg.com/debian/ stable main" --key="https://dl.yarnpkg.com/debian/pubkey.gpg" --append
2019-03-21 02:07:49 +01:00
2019-03-23 00:14:12 +01:00
# Install nodejs
2019-03-18 04:22:38 +01:00
ynh_install_nodejs 8
# TODO: use the same mecanism with other files
2019-03-19 23:11:01 +01:00
ynh_install_app_dependencies $pkg_dependencies
2019-03-18 04:22:38 +01:00
#=================================================
# CREATE DEDICATED USER
#=================================================
ynh_print_info "Making sure dedicated system user exists..."
# Create a dedicated user (if not existing)
ynh_system_user_create $app
#=================================================
# SPECIFIC UPGRADE
2019-03-21 02:58:33 +01:00
#=================================================
2019-03-21 03:43:47 +01:00
# INSTALLING RUBY AND BUNDLER
2019-03-21 02:58:33 +01:00
#=================================================
ynh_install_ruby --ruby_version=2.6.0
2019-03-21 03:43:47 +01:00
/opt/rbenv/versions/2.6.0/bin/gem update --system
2019-03-21 03:52:37 +01:00
#/opt/rbenv/versions/2.6.0/bin/gem install bundler
2019-03-21 02:58:33 +01:00
2019-03-23 01:54:06 +01:00
#=================================================
# MODIFY A CONFIG FILE
#=================================================
cp -f ../conf/.env.production.sample "$final_path/live/.env.production"
ynh_replace_string "__DB_USER__" "$app" "$final_path/live/.env.production"
ynh_replace_string "__DB_NAME__" "$db_name" "$final_path/live/.env.production"
ynh_replace_string "__DB_PWD__" "$db_pwd" "$final_path/live/.env.production"
ynh_replace_string "__DOMAIN__" "$domain" "$final_path/live/.env.production"
ynh_replace_string "__SMTP_FROM_ADDRESS__" "$admin_mail" "${final_path}/live/.env.production"
language="$(echo $language | head -c 2)"
ynh_replace_string "__LANGUAGE__" "$language" "$final_path/live/.env.production"
ynh_replace_string "PAPERCLIP_SECRET=" "PAPERCLIP_SECRET=$paperclip_secret" "${final_path}/live/.env.production"
ynh_replace_string "__SECRET_KEY_BASE__" "$secret_key_base" "$final_path/live/.env.production"
ynh_replace_string "__OTP_SECRET__" "$otp_secret" "$final_path/live/.env.production"
2019-05-10 21:07:21 +02:00
ynh_replace_string "__VAPID_PRIVATE_KEY__" "$vapid_private_key" "$final_path/live/.env.production"
ynh_replace_string "__VAPID_PUBLIC_KEY__" "$vapid_public_key" "$final_path/live/.env.production"
2019-03-21 02:07:49 +01:00
#=================================================
# UPGRADE MASTODON
#=================================================
ynh_print_info "Upgrading Mastodon..."
2019-03-21 02:07:49 +01:00
chown -R "$app": "$final_path"
2019-03-21 02:07:49 +01:00
pushd "$final_path/live"
2019-03-21 02:31:06 +01:00
ynh_use_nodejs
2019-03-21 02:07:49 +01:00
if [ "$(lsb_release --codename --short)" == "jessie" ]; then
2019-03-21 02:31:06 +01:00
sudo -u "$app" env PATH=$PATH /opt/rbenv/versions/2.6.0/bin/bundle install --deployment --without development test
2019-03-21 02:07:49 +01:00
else
2019-03-21 02:31:06 +01:00
sudo -u "$app" env PATH=$PATH /opt/rbenv/versions/2.6.0/bin/bundle install --deployment --force --without development test
2019-03-21 02:07:49 +01:00
fi
2019-03-21 02:31:06 +01:00
sudo -u "$app" env PATH=$PATH yarn install --pure-lockfile
sudo -u "$app" env PATH=$PATH RAILS_ENV=production /opt/rbenv/versions/2.6.0/bin/bundle exec rails assets:clean
sudo -u "$app" env PATH=$PATH RAILS_ENV=production /opt/rbenv/versions/2.6.0/bin/bundle exec rails assets:precompile
sudo -u "$app" env PATH=$PATH RAILS_ENV=production /opt/rbenv/versions/2.6.0/bin/bundle exec rails db:migrate
popd
2019-03-23 02:58:59 +01:00
# If vapid_private_key doesn't exist, retrieve it or create it
if [[ -z "$vapid_private_key" ]]; then
sudo -u "$app" env PATH=$PATH RAILS_ENV=production /opt/rbenv/versions/2.6.0/bin/bundle exec rake mastodon:webpush:generate_vapid_key > key.txt
vapid_private_key=$(grep -oP "VAPID_PRIVATE_KEY=\K\w+" "$final_path/live/key.txt")
vapid_public_key=$(grep -oP "VAPID_PUBLIC_KEY=\K\w+" "$final_path/live/key.txt")
ynh_app_setting_set "$app" vapid_private_key "$vapid_private_key"
ynh_app_setting_set "$app" vapid_public_key "$vapid_public_key"
ynh_secure_remove "$final_path/live/key.txt"
2019-05-10 21:07:21 +02:00
ynh_replace_string "__VAPID_PRIVATE_KEY__" "$vapid_private_key" "${final_path}/live/.env.production"
ynh_replace_string "__VAPID_PUBLIC_KEY__" "$vapid_public_key" "${final_path}/live/.env.production"
2019-03-23 02:58:59 +01:00
fi
2019-03-21 02:07:49 +01:00
# Recalculate and store the checksum of the file for the next upgrade.
ynh_store_file_checksum "${final_path}/live/.env.production"
2019-03-21 02:07:49 +01:00
#=================================================
# SETUP CRON JOB FOR REMOVING CACHE
#=================================================
2019-03-23 01:54:06 +01:00
ynh_print_info "Setuping a cron job for removing cache..."
2019-03-21 02:07:49 +01:00
ynh_replace_string "__FINAL_PATH__" "$final_path" ../conf/cron
ynh_replace_string "__USER__" "$app" ../conf/cron
sudo cp -f ../conf/cron /etc/cron.d/$app
#=================================================
2018-06-21 04:48:02 +02:00
# SETUP SYSTEMD
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Upgrading systemd configuration..."
2018-06-21 04:48:02 +02:00
# Create a dedicated systemd config
ynh_replace_string "__PORT_WEB__" "$port_web" "../conf/mastodon-web.service"
ynh_replace_string "__PORT_STREAM__" "$port_stream" "../conf/mastodon-streaming.service"
ynh_replace_string "__NODEJS_PATH__" "$nodejs_path" "../conf/mastodon-streaming.service"
2018-06-21 04:48:02 +02:00
ynh_add_systemd_config "$app-web" "mastodon-web.service"
ynh_add_systemd_config "$app-sidekiq" "mastodon-sidekiq.service"
ynh_add_systemd_config "$app-streaming" "mastodon-streaming.service"
#=================================================
# START MASTODON SERVICES
#=================================================
ynh_print_info "Starting Mastodon services..."
2017-05-06 23:44:21 +02:00
ynh_systemd_action --action=start --service_name=${app}-web --line_match="Listening on tcp" --log_path=systemd
ynh_systemd_action --action=start --service_name=${app}-sidekiq --line_match="Starting processing" --log_path=systemd
ynh_systemd_action --action=start --service_name=${app}-streaming --line_match="Worker 1 now listening" --log_path=systemd
#=================================================
2019-03-18 04:22:38 +01:00
# GENERIC FINALIZATION
#=================================================
# SECURE FILES AND DIRECTORIES
#=================================================
2019-03-18 04:22:38 +01:00
# Set permissions on app files
2019-03-21 02:07:49 +01:00
chown -R $app: $final_path
#=================================================
# SETUP SSOWAT
#=================================================
2019-03-18 04:22:38 +01:00
ynh_print_info "Upgrading SSOwat configuration..."
2017-04-20 16:35:44 +02:00
2019-03-21 02:07:49 +01:00
# Make app public if necessary
if [ $is_public -eq 1 ]
then
# unprotected_uris allows SSO credentials to be passed anyway
ynh_app_setting_set $app unprotected_uris "/"
fi
2019-03-18 04:22:38 +01:00
#=================================================
# RELOAD NGINX
#=================================================
ynh_print_info "Reloading nginx web server..."
systemctl reload nginx
#=================================================
# END OF SCRIPT
#=================================================
ynh_print_info "Upgrade of $app completed"