X-Git-Url: https://git.cyclocoop.org/?a=blobdiff_plain;ds=sidebyside;f=vm_hosted;h=34c28f59e9bc38848729635f63f77ed817e065d6;hb=f59993b7864851b163d10764edc5b9d1d798b411;hp=0f900aa91d0176c107fe079b0b2b06e50c6021c6;hpb=ced74ab27db05f2203dc1c3d80ee6b0cf1dbc5d4;p=lhc%2Fateliers.git
diff --git a/vm_hosted b/vm_hosted
index 0f900aa..34c28f5 100755
--- a/vm_hosted
+++ b/vm_hosted
@@ -1,6 +1,10 @@
#!/bin/sh
set -e -f ${DRY_RUN:+-n} -u
-tool=${0%/*}
+tool=$0
+while test -L "$tool"
+ do tool=$(readlink "$tool")
+ done
+tool=${tool%/*}
. "$tool"/lib/rule.sh
. "$tool"/etc/vm.sh
@@ -22,11 +26,15 @@ rule_help () { # SYNTAX: [--hidden]
EOF
}
-rule_git_config () {
+rule_git_configure () {
(
cd "$tool"
git config --replace branch.master.remote .
git config --replace branch.master.merge refs/remotes/master
+ local tool
+ tool=$(cd "$tool"; cd -)
+ sudo ln -fns "$tool"/vm_hosted /usr/local/sbin/
+ sudo ln -fns "$tool"/vm_hosted /usr/local/sbin/vm
)
}
rule_git_reset () {
@@ -38,13 +46,7 @@ rule_git_reset () {
}
rule_apt_get_install () { # SYNTAX: $package
- case $(dpkg -s "$1" | grep '^Status: ') in
- ("Status: install ok installed");;
- (*)
- test ! -x /usr/bin/etckeeper ||
- assert 'sudo etckeeper unclean'
- sudo apt-get "$@";;
- esac
+ sudo apt-get install "$@"
}
rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
@@ -53,14 +55,189 @@ rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
. /etc/profile
}
+rule_apache2_configure () {
+ local -; set +f
+ rule apt_get_install \
+ apache2-mpm-itk \
+ libapache2-mod-php5
+ # VOIR: http://serverfault.com/questions/383526/how-do-i-select-which-apache-mpm-to-use/383634#383634
+ # VOIR: http://jkroon.blogs.uls.co.za/it/security/using-php-fpm-and-mod_proxy_fcgi-to-optimize-and-secure-lamp-servers
+ # NOTE: apache2-mpm-itk semble le plus sécurisé,
+ # car on est certain que tout est exécuté avec les uid/gid
+ # assignés au VirtualHost/Directory/Location
+ # néamoins il se peut qu'une combinaison du genre :
+ # apache2-mpm-{worker,event} + mod_proxy_fcgi + apache2-suexec-custom + php-fpm
+ # soit plus performante (threads et pas forks),
+ # cependant l'usage de suexec impose des forks il semble..
+ # et mod_proxy_fcgi n'apparaît que dans apache 2.4 ;
+ # donc pour l'instant : apache2-mpm-itk
+ rule www_configure
+ cat /dev/stdin "$tool"/etc/apache2/apache2.conf <<-EOF |
+ ServerName "$vm_fqdn"
+ EOF
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/apache2.conf
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/envvars \
+ /etc/apache2/envvars
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/httpd.conf \
+ /etc/apache2/httpd.conf
+ #sudo install -m 660 -o root -g root /dev/stdin \
+ # /etc/apache2/suexec/www-data <<-EOF
+ # /home
+ # pub/www/cgi
+ # EOF
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/ports.conf \
+ /etc/apache2/ports.conf
+ sudo a2enmod actions
+ sudo a2enmod headers
+ sudo a2enmod rewrite
+ sudo a2enmod ssl
+ sudo a2enmod userdir
+ local conf
+ sudo a2dissite "*"
+ sudo ln -fns \
+ /etc/apache2 \
+ /home/www/etc/apache2
+ for conf in "$tool"/etc/apache2/site.d/*/VirtualHost.conf
+ do conf=${conf#"$tool"/etc/apache2/site.d/}
+ local port site
+ IFS=. read -r port site <<-EOF
+ ${conf%\/VirtualHost\.conf}
+ EOF
+ assert 'test "${site:+set}"'
+ assert 'test "${port:+set}"'
+ local site_user="$user.$port.$site"
+ local site_dir="$user.$port.$site"
+ case $port in
+ (443)
+ local hint="run vm_remote apache2_key_send before"
+ assert "sudo test -f /etc/apache2/site.d/\"$site_dir\"/x509/key.pem" hint
+ sudo install -d -m 770 -o "$user" -g "$user" \
+ /etc/apache2 \
+ /etc/apache2/site.d/"$site_dir" \
+ /etc/apache2/site.d/"$site_dir"/x509 \
+ /etc/apache2/site.d/"$site_dir"/x509/ca \
+ /etc/apache2/site.d/"$site_dir"/x509/empty \
+ /etc/apache2/site.d/"$site_dir"/x509/rvk \
+ /etc/apache2/site.d/"$site_dir"/x509/usr
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.self-signed.pem \
+ /etc/apache2/site.d/"$site_dir"/x509/crt.self-signed.pem
+ #sudo install -m 664 -o "$user" -g "$user" \
+ # "$tool"/var/pub/x509/"$site"/rvk.pem \
+ # /etc/apache2/site.d/"$site_dir"/x509/rvk.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/ca/crt.self-signed.pem \
+ /etc/apache2/site.d/"$site_dir"/x509/ca/crt.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.pem \
+ /etc/apache2/site.d/"$site_dir"/x509/crt.pem
+ ;;
+ esac
+ case $port in
+ (80)
+ cat <<-EOF
+
+ AssignUserID $site_user $site_user
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site_dir/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site_dir
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site_dir/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ ServerName $site
+ LogLevel Warn
+ $(cat "$tool"/etc/apache2/site.d/"$site_dir"/VirtualHost.conf)
+
+ EOF
+ ;;
+ (443)
+ cat <<-EOF
+
+
+ AssignUserID $site_user $site_user
+ BrowserMatch "MSIE [2-6]" ssl-unclean-shutdown nokeepalive downgrade-1.0 force-response-1.0
+ BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site_dir/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site_dir
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site_dir/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ ServerName $site
+ SSLCACertificateFile /etc/apache2/site.d/$site_dir/x509/crt.self-signed.pem
+ SSLCACertificatePath /etc/apache2/site.d/$site_dir/x509/usr/
+ #SSLCARevocationFile /etc/apache2/site.d/$site_dir/x509/rvk.pem
+ SSLCADNRequestFile /etc/apache2/site.d/$site_dir/x509/crt.self-signed.pem
+ SSLCADNRequestPath /etc/apache2/site.d/$site_dir/x509/empty/
+ # NOTE: ne publie pas les certificats dâutilisateur-ice-s acceptés
+ SSLCARevocationPath /etc/apache2/site.d/$site_dir/x509/rvk/
+ SSLCertificateChainFile /etc/apache2/site.d/$site_dir/x509/ca/crt.pem
+ SSLCertificateFile /etc/apache2/site.d/$site_dir/x509/crt.pem
+ SSLCertificateKeyFile /etc/apache2/site.d/$site_dir/x509/key.pem
+ SSLCipherSuite AES+RSA+SHA256
+ SSLEngine On
+ SSLInsecureRenegotiation Off
+ SSLOptions +StrictRequire +OptRenegotiate +StdEnvVars
+ SSLProtocol -All +TLSv1
+ #SSLRenegBufferSize 262144
+ SSLSessionCacheTimeout 1200
+ SSLStrictSNIVHostCheck On
+ SSLUserName SSL_CLIENT_S_DN_CN
+ SSLVerifyClient None
+ SSLVerifyDepth 1
+ $(cat "$tool"/etc/apache2/site.d/"$site_dir"/VirtualHost.conf)
+
+
+ EOF
+ ;;
+ esac |
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/site.d/"$site_dir"/VirtualHost.conf
+ sudo ln -fns \
+ ../site.d/"$site_dir"/VirtualHost.conf \
+ /etc/apache2/sites-available/"$site_dir"
+ sudo install -d -m 770 -o "$user" -g "$user" \
+ /home/www/log/"$site_dir" \
+ /home/www/log/"$site_dir"/apache2
+ sudo ln -fns \
+ /etc/apache2/site.d/"$site_dir" \
+ /home/www/etc/apache2/"$site_dir"
+ test -e /home/www/pub/"$site_dir" ||
+ sudo install -d -m 770 -o "$user" -g "$user" \
+ /home/www/pub/"$site_dir"
+ getent passwd "$site_user" >/dev/null ||
+ sudo adduser \
+ --disabled-password \
+ --group \
+ --no-create-home \
+ --home /home/www/pub/"$site_dir" \
+ --shell /bin/false \
+ --system \
+ "$site_user"
+ sudo setfacl -m u:"$site_user":--x \
+ /home/www/ \
+ /home/www/pub/ \
+ /home/www/pub/"$site_dir"/
+ sudo setfacl -m d:u:"$site_user":rwx \
+ "$home"/pub/www/"$site_dir"/
+ test ! -r "$tool"/etc/apache2/site.d/"$site_dir"/configure.sh ||
+ . "$tool"/etc/apache2/site.d/"$site_dir"/configure.sh
+ test -e /etc/apache2/sites-enabled/"$site_dir" ||
+ sudo a2ensite "$site_dir"
+ done
+ sudo service apache2 restart
+ }
rule_apt_configure () {
- sudo install -m 660 -u root -g root /dev/stdin /etc/apt/sources.list <<-EOF
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list <<-EOF
deb http://ftp.fr.debian.org/debian $vm_lsb_name main contrib non-free
EOF
- sudo install -m 660 -u root -g root /dev/stdin /etc/apt/$vm_lsb_name-backports.list <<-EOF
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/$vm_lsb_name-backports.list <<-EOF
#deb http://backports.debian.org/debian-backports $vm_lsb_name-backports main contrib non-free
EOF
- sudo install -m 660 -u root -g root /dev/stdin /etc/apt/preferences <<-EOF
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/preferences <<-EOF
Package: *
Pin: release a=$vm_lsb_name
Pin-Priority: 170
@@ -69,13 +246,12 @@ rule_apt_configure () {
Pin: release a=$vm_lsb_name-backports
Pin-Priority: 200
EOF
- sudo install -m 660 -u root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
deb http://nightly.openerp.com/trunk/nightly/deb/ ./
EOF
- }
-rule_apticron_configure () {
+ sudo apt-get update
rule apt_get_install apticron
- sudo install -m 644 -u root -g root /dev/stdin /etc/apticron/apticron.conf <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /etc/apticron/apticron.conf <<-EOF
EMAIL="admin@$vm_domainname"
# DIFF_ONLY="1"
# LISTCHANGES_PROFILE="apticron"
@@ -92,11 +268,11 @@ rule_apticron_configure () {
EOF
}
rule_boot_configure () {
- warn "attention à n'installer GRUB sur AUCUN disque proposé !"
+ warn "lors de l'installation Debian, surtout n'installer GRUB sur AUCUN disque proposé !"
rule apt_get_install grub-pc
- sudo install -d -m 644 -u root -g root /boot/grub
+ sudo install -d -m 644 -o root -g root /boot/grub
rule apt_get_install linux-image-$vm_arch
- sudo install -m 644 -u root -g root /dev/stdin /etc/default/grub <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /etc/default/grub <<-EOF
GRUB_DEFAULT=0
GRUB_TIMEOUT=5
GRUB_DISTRIBUTOR=\`lsb_release -i -s 2> /dev/null || echo Debian\`
@@ -105,15 +281,96 @@ rule_boot_configure () {
GRUB_DISABLE_RECOVERY="true"
#GRUB_PRELOAD_MODULES="lvm"
EOF
- sudo install -m 644 -u root -g root /dev/stdin /boot/grub/device.map <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /boot/grub/device.map <<-EOF
(hd0) /dev/xvda
(hd0) /dev/mapper/domU-$(printf %s $vm_fqdn-disk | sed -e 's/-/--/g')
EOF
sudo update-grub2 # NOTE: prend en compte /boot/grub/device.map
rule initramfs_configure
}
+rule_dovecot_configure () {
+ rule apt_get_install dovecot-imapd dovecot-managesieved dovecot-sieve
+ local hint="run vm_remote dovecot_key_send before"
+ assert "test -f /etc/dovecot/$vm_domainname/imap/x509/key.pem" hint
+ sudo install -m 400 -o root -g root \
+ "$tool"/var/pub/x509/service/imap/crt+crl.self-signed.pem \
+ /etc/dovecot/$vm_domainname/imap/x509/crt+crl.self-signed.pem
+ sudo install -d -m 770 -o root -g adm \
+ /etc/skel/etc/mail \
+ /etc/skel/etc/sieve
+ sudo install -d -m 1777 -o root -g root \
+ /var/lib/dovecot-control \
+ /var/lib/dovecot-index
+ sudo install -m 664 -o root -g root /dev/stdin /etc/dovecot/local.conf <<-EOF
+ auth_ssl_username_from_cert = yes
+ listen = *
+ log_timestamp = "%Y-%m-%d %H:%M:%S "
+ mail_debug = yes
+ mail_location = maildir:~/var/mail:INDEX=/var/lib/dovecot-index/%u:CONTROL=/var/lib/dovecot-control/%u
+ # NOTE: INDEX et CONTROL sont sur une partition sans quota comme le demande la doc
+ # VOIR: http://wiki2.dovecot.org/Quota/FS
+ mail_plugins = \$mail_plugins quota
+ mail_privileged_group = mail
+ passdb {
+ args = /home/%u/etc/dovecot/passwd
+ driver = passwd-file
+ }
+ plugin {
+ quota = fs:user
+ recipient_delimiter = +
+ sieve = ~/etc/mail/filter.sieve
+ sieve_dir = ~/etc/mail/sieve
+ sieve_global_dir = /var/lib/dovecot/sieve/global/
+ sieve_max_script_size = 1M
+ sieve_quota_max_scripts = 0
+ sieve_quota_max_storage = 10M
+ sieve_user_log = ~/var/log/mail/sieve.log
+ }
+ protocol imap {
+ mail_plugins = \$mail_plugins imap_quota
+ }
+ protocol lda {
+ auth_socket_path = /var/run/dovecot/auth-master
+ hostname = $vm_domainname
+ info_log_path =
+ log_path =
+ mail_plugins = \$mail_plugins sieve
+ postmaster_address = contact+dovecot+lda@$vm_domainname
+ syslog_facility = mail
+ }
+ protocols = imap sieve
+ service auth {
+ user = root
+ unix_listener /var/spool/postfix/private/auth {
+ mode = 0660
+ user = postfix
+ group = postfix
+ }
+ }
+ ssl_ca =
LABEL=${vm_lvm_lv}_boot /boot ext2 defaults 0 0
proc /proc proc defaults 0 0
@@ -137,31 +397,31 @@ rule_filesystem_configure () {
# NOTE: barrier=1 réduit drastiquement les performances d'écriture, mais garantit la cohérence du système de fichiers.
/dev/mapper/${vm_lvm_lv}_swap_deciphered swap swap sw 0 0
EOF
- sudo install -m 644 -u root -g root /dev/stdin /etc/crypttab <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /etc/crypttab <<-EOF
#