X-Git-Url: https://git.cyclocoop.org/?a=blobdiff_plain;f=vm_hosted;h=4ae72230cdfe9c721e1ce5f00c7dd0969a3978d7;hb=69b12c8b4360bdf14f0844140e88ef40a3d6e16f;hp=847b818592963ac19ecc98baf455961426391903;hpb=7313fbbd10b0321c3e460639137f0e0e9ed9dcad;p=lhc%2Fateliers.git
diff --git a/vm_hosted b/vm_hosted
index 847b818..4ae7223 100755
--- a/vm_hosted
+++ b/vm_hosted
@@ -1,9 +1,13 @@
#!/bin/sh
set -e -f ${DRY_RUN:+-n} -u
-tool=${0%/*}
+tool=$0
+while test -L "$tool"
+ do tool=$(readlink "$tool")
+ done
+tool=${tool%/*}
. "$tool"/lib/rule.sh
. "$tool"/etc/vm.sh
-. "$tool"/lib/mk.sh
+export TRACE=1
rule_help () { # SYNTAX: [--hidden]
local hidden; [ ${1:+set} ] || hidden=set
@@ -23,11 +27,23 @@ rule_help () { # SYNTAX: [--hidden]
EOF
}
-rule_git_config () {
+rule_git_configure () {
(
cd "$tool"
git config --replace branch.master.remote .
git config --replace branch.master.merge refs/remotes/master
+ local tool
+ tool=$(cd "$tool"; cd -)
+ install -m 770 /dev/stdin .git/hooks/post-update <<-EOF
+ #!/bin/sh -efux
+ case \$1 in
+ (refs/remotes/master)
+ cd ..
+ git --git-dir=\$PWD/.git checkout -f -B master remotes/master
+ git --git-dir=\$PWD/.git clean -f -d -x
+ ;;
+ esac
+ EOF
)
}
rule_git_reset () {
@@ -38,14 +54,22 @@ rule_git_reset () {
)
}
+rule_adduser () {
+ local user="$1"; shift
+ getent passwd "$user" >/dev/null ||
+ sudo adduser "$@" "$user"
+ }
rule_apt_get_install () { # SYNTAX: $package
- case $(dpkg -s "$1" | grep '^Status: ') in
- ("Status: install ok installed");;
- (*)
- test ! -x /usr/bin/etckeeper ||
- assert 'sudo etckeeper unclean'
- sudo apt-get "$@";;
- esac
+ sudo \
+ DEBIAN_FRONTEND=noninteractive \
+ DEBIAN_PRIORITY=low \
+ apt-get install --yes "$@"
+ }
+rule_dpkg_reconfigure () { # SYNTAX: $package
+ sudo \
+ DEBIAN_FRONTEND=noninteractive \
+ DEBIAN_PRIORITY=low \
+ dpkg-reconfigure "$@"
}
rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
@@ -54,50 +78,211 @@ rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
. /etc/profile
}
+rule_apache2_configure () { # XXX: cette règle n'est pas testée/mise-à -jour
+ local -; set +f
+ rule apt_get_install \
+ apache2-mpm-itk \
+ libapache2-mod-php5
+ # VOIR: http://serverfault.com/questions/383526/how-do-i-select-which-apache-mpm-to-use/383634#383634
+ # VOIR: http://jkroon.blogs.uls.co.za/it/security/using-php-fpm-and-mod_proxy_fcgi-to-optimize-and-secure-lamp-servers
+ # NOTE: apache2-mpm-itk semble le plus sécurisé,
+ # car on est certain que tout est exécuté avec les uid/gid
+ # assignés au VirtualHost/Directory/Location
+ # néamoins il se peut qu'une combinaison du genre :
+ # apache2-mpm-{worker,event} + mod_proxy_fcgi + apache2-suexec-custom + php-fpm
+ # soit plus performante (threads et pas forks),
+ # cependant l'usage de suexec impose des forks il semble..
+ # et mod_proxy_fcgi n'apparaît que dans apache 2.4 ;
+ # donc pour l'instant : apache2-mpm-itk
+ sudo rm -rf \
+ /etc/apache2/site.d
+ sudo install -d -m 770 -o www -g www \
+ /etc/apache2 \
+ /etc/apache2/site.d \
+ /etc/apache2/x509.d
+ cat /dev/stdin "$tool"/etc/apache2/apache2.conf <<-EOF |
+ ServerName "$vm_fqdn"
+ EOF
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/apache2.conf
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/envvars \
+ /etc/apache2/envvars
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/httpd.conf \
+ /etc/apache2/httpd.conf
+ #sudo install -m 660 -o root -g root /dev/stdin \
+ # /etc/apache2/suexec/www-data <<-EOF
+ # /home
+ # pub/www/cgi
+ # EOF
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/ports.conf \
+ /etc/apache2/ports.conf
+ sudo a2enmod actions
+ sudo a2enmod headers
+ sudo a2enmod rewrite
+ sudo a2enmod ssl
+ sudo a2enmod userdir
+ local conf
+ sudo a2dissite "*"
+ sudo ln -fns \
+ /etc/apache2 \
+ /home/www/etc/apache2
+ for conf in "$tool"/etc/apache2/site.d/*/VirtualHost.conf
+ do conf=${conf#"$tool"/etc/apache2/site.d/}
+ local site=${conf%/VirtualHost.conf}
+ case $site in
+ (*-tls)
+ local hint="run vm_remote apache2_key_send before"
+ assert "sudo test -f /etc/apache2/site.d/\"$site\"/x509/key.pem" hint
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /etc/apache2 \
+ /etc/apache2/site.d/"$site" \
+ /etc/apache2/x509.d/"$site" \
+ /etc/apache2/x509.d/"$site"/ca \
+ /etc/apache2/x509.d/"$site"/empty \
+ /etc/apache2/x509.d/"$site"/rvk \
+ /etc/apache2/x509.d/"$site"/usr
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/crt.self-signed.pem
+ #sudo install -m 664 -o www-"$site" -g www-"$site" \
+ # "$tool"/var/pub/x509/"$site"/rvk.pem \
+ # /etc/apache2/x509.d/"$site"/rvk.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/ca/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/ca/crt.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.pem \
+ /etc/apache2/x509.d/"$site"/crt.pem
+ ;;
+ esac
+ case $site in
+ (*-tls)
+ cat <<-EOF
+
+
+ AssignUserID www-$site www-$site
+ BrowserMatch "MSIE [2-6]" ssl-unclean-shutdown nokeepalive downgrade-1.0 force-response-1.0
+ BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ SSLCACertificateFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCACertificatePath /etc/apache2/x509.d/$site/usr/
+ #SSLCARevocationFile /etc/apache2/x509.d/$site/rvk.pem
+ SSLCADNRequestFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCADNRequestPath /etc/apache2/x509.d/$site/empty/
+ # NOTE: ne publie pas les certificats dâutilisateur-ice-s acceptés
+ SSLCARevocationPath /etc/apache2/x509.d/$site/rvk/
+ SSLCertificateChainFile /etc/apache2/x509.d/$site/ca/crt.pem
+ SSLCertificateFile /etc/apache2/x509.d/$site/crt.pem
+ SSLCertificateKeyFile /etc/apache2/x509.d/$site/key.pem
+ SSLCipherSuite AES+RSA+SHA256
+ SSLEngine On
+ SSLInsecureRenegotiation Off
+ SSLOptions +StrictRequire +OptRenegotiate +StdEnvVars
+ SSLProtocol -All +TLSv1
+ #SSLRenegBufferSize 262144
+ SSLSessionCacheTimeout 1200
+ SSLStrictSNIVHostCheck On
+ SSLUserName SSL_CLIENT_S_DN_CN
+ SSLVerifyClient None
+ SSLVerifyDepth 1
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+
+ EOF
+ ;;
+ (*)
+ cat <<-EOF
+
+ AssignUserID www-$site www-$site
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+ EOF
+ ;;
+ esac |
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/site.d/"$site"/VirtualHost.conf
+ sudo ln -fns \
+ ../site.d/"$site"/VirtualHost.conf \
+ /etc/apache2/sites-available/"$site"
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /home/www/log/"$site" \
+ /home/www/log/"$site"/apache2
+ sudo ln -fns \
+ /etc/apache2/site.d/"$site" \
+ /home/www/etc/apache2/"$site"
+ test -e /home/www/pub/"$site" ||
+ sudo install -d -m 2770 -o www-"$site" -g www-"$site" \
+ /home/www/pub/"$site"
+ rule adduser www-"$site"
+ --disabled-password \
+ --group \
+ --no-create-home \
+ --home /home/www/pub/"$site" \
+ --shell /bin/false \
+ --system
+ #sudo setfacl -m u:"www-$site":--x \
+ # /home/www/ \
+ # /home/www/pub/ \
+ # /home/www/pub/"$site"/
+ #sudo setfacl -m d:u:"www-$site":rwx \
+ # "$home"/pub/www/"$site"/
+ test ! -r "$tool"/etc/apache2/site.d/"$site"/configure.sh ||
+ . "$tool"/etc/apache2/site.d/"$site"/configure.sh
+ test -e /etc/apache2/sites-enabled/"$site" ||
+ sudo a2ensite "$site"
+ done
+ sudo service apache2 restart
+ }
rule_apt_configure () {
- mk_reg mod= own= /etc/apt/sources.list <<-EOF
- deb http://ftp.fr.debian.org/debian $vm_lsb_name main contrib non-free
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name main
+ EOF
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list.d/$vm_lsb_name-backports.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name-backports main
EOF
- mk_reg mod= own= /etc/apt/sources.list.d/$vm_lsb_name-backports.list <<-EOF
- #deb http://backports.debian.org/debian-backports $vm_lsb_name-backports main contrib non-free
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
+ deb http://nightly.openerp.com/7.0/nightly/deb/ ./
EOF
- mk_reg mod= own= /etc/apt/preferences <<-EOF
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/preferences <<-EOF
Package: *
Pin: release a=$vm_lsb_name
- Pin-Priority: 170
+ Pin-Priority: 200
Package: *
Pin: release a=$vm_lsb_name-backports
- Pin-Priority: 200
- EOF
- mk_reg mod= own= /etc/apt/sources.list.d/openerp.list <<-EOF
- deb http://nightly.openerp.com/trunk/nightly/deb/ ./
+ Pin-Priority: 170
EOF
- }
-rule_apticron_configure () {
+ sudo apt-get update
rule apt_get_install apticron
- mk_reg mod=644 own=root:root /etc/apticron/apticron.conf <<-EOF
- EMAIL="admin@heureux-cyclage.org"
- # DIFF_ONLY="1"
- # LISTCHANGES_PROFILE="apticron"
- # ALL_FQDNS="1"
- # SYSTEM="foobar.example.com"
- # IPADDRESSNUM="1"
- # IPADDRESSES="192.0.2.1 2001:db8:1:2:3::1"
- # NOTIFY_HOLDS="0"
- # NOTIFY_NEW="0"
- # NOTIFY_NO_UPDATES="0"
- # CUSTOM_SUBJECT=""
- # CUSTOM_NO_UPDATES_SUBJECT=""
- # CUSTOM_FROM="root@ateliers.heureux-cyclage.org"
- EOF
+ m4 \
+ --define=VM_DOMAINNAME=$vm_domainname \
+ <"$tool"/etc/apticron/apticron.conf.m4 |
+ sudo install -m 644 -o root -g root /dev/stdin \
+ /etc/apticron/apticron.conf
}
rule_boot_configure () {
- warn "attention à n'installer GRUB sur AUCUN disque proposé !"
+ #warn "lors de l'installation Debian, surtout n'installer GRUB sur AUCUN disque proposé !"
+ sudo debconf-set-selections <<-EOF
+ grub-pc grub-pc/install_devices multiselect
+ EOF
rule apt_get_install grub-pc
- mk_dir mod=644 own=root:root /boot/grub
+ sudo install -d -m 644 -o root -g root /boot/grub
rule apt_get_install linux-image-$vm_arch
- mk_reg mod=644 own=root:root /etc/default/grub <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /etc/default/grub <<-EOF
GRUB_DEFAULT=0
GRUB_TIMEOUT=5
GRUB_DISTRIBUTOR=\`lsb_release -i -s 2> /dev/null || echo Debian\`
@@ -106,15 +291,22 @@ rule_boot_configure () {
GRUB_DISABLE_RECOVERY="true"
#GRUB_PRELOAD_MODULES="lvm"
EOF
- mk_reg mod=644 own=root:root /boot/grub/device.map <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /boot/grub/device.map <<-EOF
(hd0) /dev/xvda
(hd0) /dev/mapper/domU-$(printf %s $vm_fqdn-disk | sed -e 's/-/--/g')
EOF
sudo update-grub2 # NOTE: prend en compte /boot/grub/device.map
rule initramfs_configure
+ rule apt_get_install molly-guard
+ sudo install -m 644 -o root -g root /dev/stdin /etc/molly-guard/rc <<-EOF
+ ALWAYS_QUERY_HOSTNAME=true
+ # NOTE: une alternative est de dire à sudo de conserver les SSH_*
+ # néamoins demander tout le temps n'est pas trop contraignant
+ # et davantage sécurisant.
+ EOF
}
rule_etckeeper_configure () {
- mk_reg mod=644 own=root:root /etc/etckeeper/etckeeper.conf <<-EOF
+ sudo install -m 644 -o root -g root /dev/stdin /etc/etckeeper/etckeeper.conf <<-EOF
VCS=git
GIT_COMMIT_OPTIONS=""
AVOID_DAILY_AUTOCOMMITS=1
@@ -123,45 +315,39 @@ rule_etckeeper_configure () {
HIGHLEVEL_PACKAGE_MANAGER=apt
LOWLEVEL_PACKAGE_MANAGER=dpkg
EOF
+ sudo install -m 644 -o root -g root \
+ "$tool"/etc/etckeeper/prompt.sh \
+ /etc/etckeeper/prompt.sh
rule apt_get_install etckeeper
}
rule_filesystem_configure () {
- mk_reg mod=644 own=root:root /etc/fstab <<-EOF
- #
- LABEL=${vm_lvm_lv}_boot /boot ext2 defaults 0 0
- proc /proc proc defaults 0 0
- sysfs /sys sysfs defaults 0 0
- tmpfs /tmp tmpfs rw,nosuid,nodev,auto,size=200m,nr_inodes=1000k,mode=1777,noatime,nodiratime 0 0
- /dev/mapper/${vm_lvm_lv}_root_deciphered / ext4 defaults,errors=remount-ro,acl,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_var_deciphered /var ext4 defaults,errors=remount-ro,acl,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_home_deciphered /home ext4 defaults,errors=remount-ro,acl,noatime,usrquota,grpquota 0 0
- /dev/mapper/${vm_lvm_lv}_swap_deciphered swap swap sw 0 0
- EOF
- mk_reg mod=644 own=root:root /etc/crypttab <<-EOF
- #