yunohost_demo/demo_lxc_build_init.sh

190 lines
6.6 KiB
Bash
Raw Normal View History

2016-08-13 01:08:44 +02:00
#!/bin/bash
# Installe LXC et les paramètres réseaux avant de procéder au build.
# Récupère le dossier du script
2016-09-18 19:23:54 +02:00
if [ "${0:0:1}" == "/" ]; then script_dir="$(dirname "$0")"; else script_dir="$(echo $PWD/$(dirname "$0" | cut -d '.' -f2) | sed 's@/$@@')"; fi
2016-08-13 01:08:44 +02:00
2016-08-13 19:31:36 +02:00
LOG=$(cat "$script_dir/demo_lxc_build.sh" | grep LOG= | cut -d '=' -f2)
LOG_BUILD_LXC="$script_dir/$LOG"
2016-08-13 01:08:44 +02:00
LXC_NAME1=$(cat "$script_dir/demo_lxc_build.sh" | grep LXC_NAME1= | cut -d '=' -f2)
LXC_NAME2=$(cat "$script_dir/demo_lxc_build.sh" | grep LXC_NAME2= | cut -d '=' -f2)
PLAGE_IP=$(cat "$script_dir/demo_lxc_build.sh" | grep PLAGE_IP= | cut -d '=' -f2)
2016-08-13 19:31:36 +02:00
IP_LXC1=$(cat "$script_dir/demo_lxc_build.sh" | grep IP_LXC1= | cut -d '=' -f2)
IP_LXC2=$(cat "$script_dir/demo_lxc_build.sh" | grep IP_LXC2= | cut -d '=' -f2)
2016-09-08 13:40:03 +02:00
MAIL_ADDR=$(cat "$script_dir/demo_lxc_build.sh" | grep MAIL_ADDR= | cut -d '=' -f2)
2016-08-16 15:36:12 +02:00
2016-09-18 19:23:54 +02:00
# Check user
2018-08-26 13:40:41 +02:00
echo $(whoami) > "$script_dir/setup_user"
2016-08-16 15:36:12 +02:00
read -p "Indiquer le nom de domaine du serveur de demo: " DOMAIN
echo "$DOMAIN" > "$script_dir/domain.ini"
2016-08-13 01:08:44 +02:00
# Créer le dossier de log
sudo mkdir -p $(dirname $LOG_BUILD_LXC)
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Update et install lxc, lxctl et mailutils\e[0m" | tee "$LOG_BUILD_LXC"
2016-08-13 01:08:44 +02:00
sudo apt-get update >> "$LOG_BUILD_LXC" 2>&1
2016-09-08 13:40:03 +02:00
sudo apt-get install -y lxc lxctl mailutils >> "$LOG_BUILD_LXC" 2>&1
2016-08-13 01:08:44 +02:00
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Autoriser l'ip forwarding, pour router vers la machine virtuelle.\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-08-13 01:08:44 +02:00
echo "net.ipv4.ip_forward=1" | sudo tee /etc/sysctl.d/lxc_demo.conf >> "$LOG_BUILD_LXC" 2>&1
sudo sysctl -p /etc/sysctl.d/lxc_demo.conf >> "$LOG_BUILD_LXC" 2>&1
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Ajoute un brige réseau pour la machine virtualisée\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-08-13 01:08:44 +02:00
echo | sudo tee /etc/network/interfaces.d/lxc_demo <<EOF >> "$LOG_BUILD_LXC" 2>&1
auto lxc_demo
iface lxc_demo inet static
address $PLAGE_IP.1/24
bridge_ports none
bridge_fd 0
bridge_maxwait 0
EOF
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Active le bridge réseau\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-08-13 01:08:44 +02:00
sudo ifup lxc_demo --interfaces=/etc/network/interfaces.d/lxc_demo >> "$LOG_BUILD_LXC" 2>&1
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Mise en place de la connexion ssh vers l'invité.\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-08-13 01:08:44 +02:00
if [ -e $HOME/.ssh/$LXC_NAME1 ]; then
rm -f $HOME/.ssh/$LXC_NAME1 $HOME/.ssh/$LXC_NAME1.pub
2016-08-13 19:31:36 +02:00
ssh-keygen -f $HOME/.ssh/known_hosts -R $IP_LXC1
ssh-keygen -f $HOME/.ssh/known_hosts -R $IP_LXC2
2016-08-13 01:08:44 +02:00
fi
2018-08-26 13:40:41 +02:00
ssh-keygen -t rsa -f $HOME/.ssh/$LXC_NAME1 -P '' >> "$LOG_BUILD_LXC" 2>&1
2016-08-13 01:08:44 +02:00
echo | tee -a $HOME/.ssh/config <<EOF >> "$LOG_BUILD_LXC" 2>&1
# ssh $LXC_NAME1
Host $LXC_NAME1
2016-08-13 19:31:36 +02:00
Hostname $IP_LXC1
User ssh_demo
IdentityFile $HOME/.ssh/$LXC_NAME1
2016-08-13 01:08:44 +02:00
Host $LXC_NAME2
2016-08-13 19:31:36 +02:00
Hostname $IP_LXC2
2016-08-13 01:08:44 +02:00
User ssh_demo
IdentityFile $HOME/.ssh/$LXC_NAME1
2016-08-13 19:31:36 +02:00
# End ssh $LXC_NAME1
2016-08-13 01:08:44 +02:00
EOF
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Mise en place du reverse proxy et du load balancing\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-08-16 15:36:12 +02:00
echo | sudo tee /etc/nginx/conf.d/$DOMAIN.conf <<EOF >> "$LOG_BUILD_LXC" 2>&1
2016-10-05 15:41:39 +02:00
#upstream $DOMAIN {
# server $IP_LXC1:443 ;
# server $IP_LXC2:443 ;
#}
2016-08-16 15:36:12 +02:00
2016-08-16 01:45:21 +02:00
server {
listen 80;
listen [::]:80;
server_name $DOMAIN;
2016-09-08 13:40:03 +02:00
location '/.well-known/acme-challenge' {
default_type "text/plain";
root /tmp/letsencrypt-auto;
}
2016-09-07 23:31:11 +02:00
2016-08-16 01:45:21 +02:00
access_log /var/log/nginx/$DOMAIN-access.log;
error_log /var/log/nginx/$DOMAIN-error.log;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name $DOMAIN;
2016-10-05 15:41:39 +02:00
# ssl_certificate /etc/letsencrypt/live/$DOMAIN/fullchain.pem;
# ssl_certificate_key /etc/letsencrypt/live/$DOMAIN/privkey.pem;
2016-09-08 13:40:03 +02:00
ssl_session_timeout 5m;
ssl_session_cache shared:SSL:50m;
ssl_prefer_server_ciphers on;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers ALL:!aNULL:!eNULL:!LOW:!EXP:!RC4:!3DES:+HIGH:+MEDIUM;
add_header Strict-Transport-Security "max-age=31536000;";
2016-08-16 01:45:21 +02:00
location / {
2016-08-16 15:36:12 +02:00
proxy_pass https://$DOMAIN;
2016-08-16 01:45:21 +02:00
proxy_redirect off;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host \$server_name;
}
access_log /var/log/nginx/$DOMAIN-access.log;
error_log /var/log/nginx/$DOMAIN-error.log;
}
EOF
sudo service nginx reload
2016-08-13 01:08:44 +02:00
2016-12-17 19:31:44 +01:00
echo -e "\e[1m> Installation de let's encrypt et création du certificat SSL.\e[0m" | tee -a "$LOG_BUILD_LXC"
2016-09-08 13:40:03 +02:00
cd ~
# Télécharge let's encrypt
git clone https://github.com/letsencrypt/letsencrypt
cd letsencrypt/
# Installe les dépendances de let's encrypt
2016-09-18 19:23:54 +02:00
sudo ./letsencrypt-auto --help
2016-09-08 13:40:03 +02:00
sudo mkdir /etc/letsencrypt
# Créer le fichier de config
echo | sudo tee /etc/letsencrypt/conf.ini <<EOF >> "$LOG_BUILD_LXC" 2>&1
#################################
# Let's encrypt configuration #
#################################
# Taille de la clef
rsa-key-size = 4096
# Email de notification / contact si necessaire dans le futur
email = $MAIL_ADDR
# Utiliser l'interface texte
text = True
# Accepter les Conditions d'Utilisation du service
agree-tos = True
# Utiliser la methode d'authentification webroot
# avec le contenu dans /tmp/letsencrypt-auto
authenticator = webroot
webroot-path = /tmp/letsencrypt-auto
# (Serveur de test uniquement : si vous l'utilisez,
# votre certificat ne sera pas vraiment valide)
# server = https://acme-staging.api.letsencrypt.org/directory
EOF
mkdir -p /tmp/letsencrypt-auto
# Créer le certificat
2016-09-18 19:23:54 +02:00
sudo ./letsencrypt-auto certonly --config /etc/letsencrypt/conf.ini -d $DOMAIN
2016-09-08 13:40:03 +02:00
# Route l'upstream sur le port 443. Le port 80 servait uniquement à let's encrypt
2016-10-05 15:41:39 +02:00
# sudo sed -i "s/server $IP_LXC1:80 ;/server $IP_LXC1:443 ;/" /etc/nginx/conf.d/$DOMAIN.conf
2016-09-18 19:23:54 +02:00
# Décommente les lignes du certificat
2016-10-05 15:41:39 +02:00
# sudo sed -i "s/#\tssl_certificate/\tssl_certificate/g" /etc/nginx/conf.d/$DOMAIN.conf
# Supprime les commentaires dans la conf nginx
2016-11-06 14:44:47 +01:00
2016-10-05 15:41:39 +02:00
sudo sed -i "s/^#//g" /etc/nginx/conf.d/$DOMAIN.conf
2016-09-18 19:23:54 +02:00
sudo service nginx reload
2016-09-08 13:40:03 +02:00
# Mise en place du cron de renouvellement.
wget https://raw.githubusercontent.com/YunoHost-Apps/letsencrypt_ynh/master/sources/certificateRenewer
sed -i "s/DOMAIN_NAME/$DOMAIN/" certificateRenewer
sed -i "s/ADMIN_EMAIL/$MAIL_ADDR/" certificateRenewer
2018-08-26 13:40:41 +02:00
# And add a script to renew
echo "#!/bin/bash
2019-06-22 10:11:15 +02:00
sudo sed -i 's@rewrite ^ https://$server_name$request_uri? permanent;@#rewrite ^ https:$//$server_name$request_uri? permanent;@' /etc/nginx/conf.d/$DOMAIN.conf
2018-08-26 13:40:41 +02:00
sudo service nginx reload
sudo /etc/cron.weekly/certificateRenewer
2019-06-22 10:11:15 +02:00
sudo sed -i 's@#rewrite ^ https://$server_name$request_uri? permanent;@rewrite ^ https:$//$server_name$request_uri? permanent;@' /etc/nginx/conf.d/$DOMAIN.conf
2018-08-26 13:40:41 +02:00
sudo service nginx reload" | tee /etc/cron.weekly/Certificate_Renewer
2016-09-08 13:40:03 +02:00
2016-12-17 19:31:44 +01:00
echo -e "\e[1mLe serveur est prêt à déployer les conteneurs de demo.\e[0m"
echo -e "\e[1mExécutez le script demo_lxc_build.sh pour créer les conteneurs et mettre en place la demo.\e[0m"
2018-08-26 13:40:41 +02:00
2016-08-13 01:08:44 +02:00
# Déploie les conteneurs de demo
2016-08-13 19:31:36 +02:00
# "$script_dir/demo_lxc_build.sh"