X-Git-Url: https://git.cyclocoop.org/?a=blobdiff_plain;ds=sidebyside;f=vm_hosted;h=b9275fa05a2ba53560d5a983e115236c5d785294;hb=7c02698fa11a13fd332c2e95986339241aaa79a6;hp=db7247a4ac14aac573bdf700d6a8cd0de3689fc7;hpb=fdea46138aab165fff4ba27888c354c87190de9a;p=lhc%2Fateliers.git
diff --git a/vm_hosted b/vm_hosted
index db7247a..b9275fa 100755
--- a/vm_hosted
+++ b/vm_hosted
@@ -1,248 +1,348 @@
#!/bin/sh
set -e -f ${DRY_RUN:+-n} -u
-tool=${0%/*}
-. "$tool"/lib/functions.sh
+tool=$0
+while test -L "$tool"
+ do tool=$(readlink "$tool")
+ done
+tool=${tool%/*}
+. "$tool"/lib/rule.sh
. "$tool"/etc/vm.sh
+export TRACE=1
+cd /
-rule_help () {
+rule_help () { # SYNTAX: [--hidden]
+ local hidden; [ ${1:+set} ] || hidden=set
cat >&2 <<-EOF
- DESCRIPTION: ce script regroupe des fonctions utilitaires
- pour gérer la VM _depuis_ la VM hébergée ;
- il sert à la fois d'outil et de documentation.
- Voir \`$tool/vm_host' pour les utilitaires côté machine hôte.
+ DESCRIPTION:
+ ce script regroupe des règles pour administrer la VM ($vm_fqdn)
+ _depuis_ la VM hébergée ($vm_fqdn) ;
+ il sert à la fois d'outil (aisément bidouillable)
+ et de documentation (préçise).
+ Voir \`$tool/vm_host' pour les règles côté machine hôte ($vm_host).
SYNTAX: $0 \$RULE \${RULE}_SYNTAX
RULES:
- $(sed -ne 's/^rule_\([^_][^ ]*\) () {\( *#.*\|\)/\t\1\2/p' "$tool"/vm.sh "$0")
+ $(sed -ne "s/^rule_\(${hidden:+[^_]}[^ ]*\) () {\( *#.*\|\)/ \1\2/p" "$tool"/etc/vm.sh "$0")
ENVIRONMENT:
TRACE # affiche les commandes avant leur exécution
- $(sed -ne 's/^readonly \([^ ][^ =]*\).*}\( *#.*\|\)$/\t$\1\2/p' "$tool"/vm.sh "$0")
+ $(sed -ne 's/^readonly \([^ ][^ =]*\).*}\( *#.*\|\)$/\t$\1\2/p' "$tool"/etc/vm.sh "$0")
EOF
}
+rule_git_configure () {
+ (
+ cd "$tool"
+ git config --replace branch.master.remote .
+ git config --replace branch.master.merge refs/remotes/master
+ local tool
+ tool=$(cd "$tool"; cd -)
+ install -m 770 /dev/stdin .git/hooks/post-update <<-EOF
+ #!/bin/sh -efux
+ case \$1 in
+ (refs/remotes/master)
+ cd ..
+ git --git-dir=\$PWD/.git checkout -f -B master remotes/master
+ git --git-dir=\$PWD/.git clean -f -d -x
+ ;;
+ esac
+ EOF
+ )
+ }
rule_git_reset () {
(
cd "$tool"
- git checkout -f -B master origin
+ git checkout -f -B master remotes/master
git clean -f -d -x
)
}
-rule_chrooted () {
+rule_adduser () {
+ local user="$1"; shift
+ getent passwd "$user" >/dev/null ||
+ sudo adduser "$@" "$user"
+ }
+rule_apt_get_install () { # SYNTAX: $package
+ sudo DEBIAN_FRONTEND=noninteractive apt-get install --yes "$@"
+ }
+rule_dpkg_reconfigure () { # SYNTAX: $package
+ sudo DEBIAN_FRONTEND=noninteractive dpkg-reconfigure "$@"
+ }
+
+rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
export LANG=C
export LC_CTYPE=C
. /etc/profile
}
-rule__etckeeper_init () {
- mk_reg mod=644 own=root:root /etc/etckeeper/etckeeper.conf <<-EOF
- VCS=git
- GIT_COMMIT_OPTIONS=""
- AVOID_DAILY_AUTOCOMMITS=1
- #AVOID_SPECIAL_FILE_WARNING=1
- #AVOID_COMMIT_BEFORE_INSTALL=1
- HIGHLEVEL_PACKAGE_MANAGER=apt
- LOWLEVEL_PACKAGE_MANAGER=dpkg
- EOF
+rule_apache2_configure () { # XXX: cette règle n'est pas testée/mise-à -jour
+ local -; set +f
+ rule apt_get_install \
+ apache2-mpm-itk \
+ libapache2-mod-php5
+ # VOIR: http://serverfault.com/questions/383526/how-do-i-select-which-apache-mpm-to-use/383634#383634
+ # VOIR: http://jkroon.blogs.uls.co.za/it/security/using-php-fpm-and-mod_proxy_fcgi-to-optimize-and-secure-lamp-servers
+ # NOTE: apache2-mpm-itk semble le plus sécurisé,
+ # car on est certain que tout est exécuté avec les uid/gid
+ # assignés au VirtualHost/Directory/Location
+ # néamoins il se peut qu'une combinaison du genre :
+ # apache2-mpm-{worker,event} + mod_proxy_fcgi + apache2-suexec-custom + php-fpm
+ # soit plus performante (threads et pas forks),
+ # cependant l'usage de suexec impose des forks il semble..
+ # et mod_proxy_fcgi n'apparaît que dans apache 2.4 ;
+ # donc pour l'instant : apache2-mpm-itk
+ sudo rm -rf \
+ /etc/apache2/site.d
+ sudo install -d -m 770 -o www -g www \
+ /etc/apache2 \
+ /etc/apache2/site.d \
+ /etc/apache2/x509.d
+ cat /dev/stdin "$tool"/etc/apache2/apache2.conf <<-EOF |
+ ServerName "$vm_fqdn"
+ EOF
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/apache2.conf
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/envvars \
+ /etc/apache2/envvars
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/httpd.conf \
+ /etc/apache2/httpd.conf
+ #sudo install -m 660 -o root -g root /dev/stdin \
+ # /etc/apache2/suexec/www-data <<-EOF
+ # /home
+ # pub/www/cgi
+ # EOF
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/ports.conf \
+ /etc/apache2/ports.conf
+ sudo a2enmod actions
+ sudo a2enmod headers
+ sudo a2enmod rewrite
+ sudo a2enmod ssl
+ sudo a2enmod userdir
+ local conf
+ sudo a2dissite "*"
+ sudo ln -fns \
+ /etc/apache2 \
+ /home/www/etc/apache2
+ for conf in "$tool"/etc/apache2/site.d/*/VirtualHost.conf
+ do conf=${conf#"$tool"/etc/apache2/site.d/}
+ local site=${conf%/VirtualHost.conf}
+ case $site in
+ (*-tls)
+ local hint="run vm_remote apache2_key_send before"
+ assert "sudo test -f /etc/apache2/site.d/\"$site\"/x509/key.pem" hint
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /etc/apache2 \
+ /etc/apache2/site.d/"$site" \
+ /etc/apache2/x509.d/"$site" \
+ /etc/apache2/x509.d/"$site"/ca \
+ /etc/apache2/x509.d/"$site"/empty \
+ /etc/apache2/x509.d/"$site"/rvk \
+ /etc/apache2/x509.d/"$site"/usr
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/crt.self-signed.pem
+ #sudo install -m 664 -o www-"$site" -g www-"$site" \
+ # "$tool"/var/pub/x509/"$site"/rvk.pem \
+ # /etc/apache2/x509.d/"$site"/rvk.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/ca/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/ca/crt.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.pem \
+ /etc/apache2/x509.d/"$site"/crt.pem
+ ;;
+ esac
+ case $site in
+ (*-tls)
+ cat <<-EOF
+
+
+ AssignUserID www-$site www-$site
+ BrowserMatch "MSIE [2-6]" ssl-unclean-shutdown nokeepalive downgrade-1.0 force-response-1.0
+ BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ SSLCACertificateFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCACertificatePath /etc/apache2/x509.d/$site/usr/
+ #SSLCARevocationFile /etc/apache2/x509.d/$site/rvk.pem
+ SSLCADNRequestFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCADNRequestPath /etc/apache2/x509.d/$site/empty/
+ # NOTE: ne publie pas les certificats dâutilisateur-ice-s acceptés
+ SSLCARevocationPath /etc/apache2/x509.d/$site/rvk/
+ SSLCertificateChainFile /etc/apache2/x509.d/$site/ca/crt.pem
+ SSLCertificateFile /etc/apache2/x509.d/$site/crt.pem
+ SSLCertificateKeyFile /etc/apache2/x509.d/$site/key.pem
+ SSLCipherSuite AES+RSA+SHA256
+ SSLEngine On
+ SSLInsecureRenegotiation Off
+ SSLOptions +StrictRequire +OptRenegotiate +StdEnvVars
+ SSLProtocol -All +TLSv1
+ #SSLRenegBufferSize 262144
+ SSLSessionCacheTimeout 1200
+ SSLStrictSNIVHostCheck On
+ SSLUserName SSL_CLIENT_S_DN_CN
+ SSLVerifyClient None
+ SSLVerifyDepth 1
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+
+ EOF
+ ;;
+ (*)
+ cat <<-EOF
+
+ AssignUserID www-$site www-$site
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+ EOF
+ ;;
+ esac |
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/site.d/"$site"/VirtualHost.conf
+ sudo ln -fns \
+ ../site.d/"$site"/VirtualHost.conf \
+ /etc/apache2/sites-available/"$site"
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /home/www/log/"$site" \
+ /home/www/log/"$site"/apache2
+ sudo ln -fns \
+ /etc/apache2/site.d/"$site" \
+ /home/www/etc/apache2/"$site"
+ test -e /home/www/pub/"$site" ||
+ sudo install -d -m 2770 -o www-"$site" -g www-"$site" \
+ /home/www/pub/"$site"
+ rule adduser www-"$site"
+ --disabled-password \
+ --group \
+ --no-create-home \
+ --home /home/www/pub/"$site" \
+ --shell /bin/false \
+ --system
+ #sudo setfacl -m u:"www-$site":--x \
+ # /home/www/ \
+ # /home/www/pub/ \
+ # /home/www/pub/"$site"/
+ #sudo setfacl -m d:u:"www-$site":rwx \
+ # "$home"/pub/www/"$site"/
+ test ! -r "$tool"/etc/apache2/site.d/"$site"/configure.sh ||
+ . "$tool"/etc/apache2/site.d/"$site"/configure.sh
+ test -e /etc/apache2/sites-enabled/"$site" ||
+ sudo a2ensite "$site"
+ done
+ sudo service apache2 restart
}
-rule__locale_init () {
- mk_reg mod=644 own=root:root /etc/locale.gen <<-EOF
- fr_FR.UTF-8 UTF-8
+rule_apt_configure () {
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name main
EOF
- sudo update-locale
- }
-rule__network_init () {
- mk_reg mod= own= /etc/hostname <<-EOF
- $vm
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list.d/$vm_lsb_name-backports.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name-backports main
EOF
- grep -q " $vm\$" /etc/hosts ||
- mk_reg mod= own= --append /etc/hosts <<-EOF
- 127.0.0.1 $vm_fqdn $vm
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
+ deb http://nightly.openerp.com/7.0/nightly/deb/ ./
EOF
- mk_reg mod= own= /etc/network/interfaces <<-EOF
- auto lo
- iface lo inet loopback
-
- auto eth0=grenode
- iface grenode inet static
- address $vm_ipv4
- gateway $vm_ipv4 # NOTE: proxy_arp sur la passerelle permet d'utiliser la même adresse
- network $vm_ipv4
- broadcast $vm_ipv4
- netmask 255.255.255.255
- mtu 1300 # TODO: voir si c'est nécessaire à Lyon
- post-up ip address add $vm_ipv4/32 dev \$IFACE
- pre-down ip address delete $vm_ipv4/32 dev \$IFACE
- EOF
- }
-rule__apt_init () {
- mk_reg mod= own= /etc/apt/sources.list <<-EOF
- deb http://ftp.fr.debian.org/debian $vm_lsb_name main contrib non-free
- EOF
- mk_reg mod= own= /etc/apt/sources.list.d/$vm_lsb_name-backports.list <<-EOF
- deb http://backports.debian.org/debian-backports $vm_lsb_name-backports main contrib non-free
- EOF
- mk_reg mod= own= /etc/apt/preferences <<-EOF
+ sudo install -m 660 -o root -g root /dev/stdin /etc/apt/preferences <<-EOF
Package: *
Pin: release a=$vm_lsb_name
- Pin-Priority: 170
+ Pin-Priority: 200
Package: *
Pin: release a=$vm_lsb_name-backports
- Pin-Priority: 200
+ Pin-Priority: 170
EOF
- mk_reg mod= own= /etc/apt/sources.list.d/openerp.list <<-EOF
- deb http://nightly.openerp.com/trunk/nightly/deb/ ./
- EOF
- }
-rule__filesystem_init () {
- mk_reg mod=644 own=root:root /etc/fstab <<-EOF
- #
- LABEL=${vm_lvm_lv}_boot /boot ext2 defaults 0 0
- proc /proc proc defaults 0 0
- sysfs /sys sysfs defaults 0 0
- tmpfs /tmp tmpfs rw,nosuid,nodev,auto,size=200m,nr_inodes=1000k,mode=1777,noatime,nodiratime 0 0
- /dev/mapper/${vm_lvm_lv}_root_deciphered / ext4 defaults,errors=remount-ro,acl,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_var_deciphered /var ext4 defaults,errors=remount-ro,acl,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_home_deciphered /home ext4 defaults,errors=remount-ro,acl,noatime,usrquota,grpquota 0 0
- /dev/mapper/${vm_lvm_lv}_swap_deciphered swap swap sw 0 0
- EOF
- mk_reg mod=644 own=root:root /etc/crypttab <<-EOF
- #