X-Git-Url: https://git.cyclocoop.org/?a=blobdiff_plain;f=vm_hosted;h=4ae72230cdfe9c721e1ce5f00c7dd0969a3978d7;hb=69b12c8b4360bdf14f0844140e88ef40a3d6e16f;hp=f6107016c3afb686403f486dca06122ff8718218;hpb=a7d0fb2448e129747fce8e108ce80e4ce3c17845;p=lhc%2Fateliers.git
diff --git a/vm_hosted b/vm_hosted
index f610701..4ae7223 100755
--- a/vm_hosted
+++ b/vm_hosted
@@ -7,6 +7,7 @@ while test -L "$tool"
tool=${tool%/*}
. "$tool"/lib/rule.sh
. "$tool"/etc/vm.sh
+export TRACE=1
rule_help () { # SYNTAX: [--hidden]
local hidden; [ ${1:+set} ] || hidden=set
@@ -33,8 +34,16 @@ rule_git_configure () {
git config --replace branch.master.merge refs/remotes/master
local tool
tool=$(cd "$tool"; cd -)
- sudo ln -fns "$tool"/vm_hosted /usr/local/sbin/
- sudo ln -fns "$tool"/vm_hosted /usr/local/sbin/vm
+ install -m 770 /dev/stdin .git/hooks/post-update <<-EOF
+ #!/bin/sh -efux
+ case \$1 in
+ (refs/remotes/master)
+ cd ..
+ git --git-dir=\$PWD/.git checkout -f -B master remotes/master
+ git --git-dir=\$PWD/.git clean -f -d -x
+ ;;
+ esac
+ EOF
)
}
rule_git_reset () {
@@ -45,8 +54,22 @@ rule_git_reset () {
)
}
+rule_adduser () {
+ local user="$1"; shift
+ getent passwd "$user" >/dev/null ||
+ sudo adduser "$@" "$user"
+ }
rule_apt_get_install () { # SYNTAX: $package
- sudo apt-get install "$@"
+ sudo \
+ DEBIAN_FRONTEND=noninteractive \
+ DEBIAN_PRIORITY=low \
+ apt-get install --yes "$@"
+ }
+rule_dpkg_reconfigure () { # SYNTAX: $package
+ sudo \
+ DEBIAN_FRONTEND=noninteractive \
+ DEBIAN_PRIORITY=low \
+ dpkg-reconfigure "$@"
}
rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
@@ -55,45 +78,207 @@ rule__chrooted_configure () { # NOTE: est-ce bien utile à un moment ?
. /etc/profile
}
+rule_apache2_configure () { # XXX: cette règle n'est pas testée/mise-à -jour
+ local -; set +f
+ rule apt_get_install \
+ apache2-mpm-itk \
+ libapache2-mod-php5
+ # VOIR: http://serverfault.com/questions/383526/how-do-i-select-which-apache-mpm-to-use/383634#383634
+ # VOIR: http://jkroon.blogs.uls.co.za/it/security/using-php-fpm-and-mod_proxy_fcgi-to-optimize-and-secure-lamp-servers
+ # NOTE: apache2-mpm-itk semble le plus sécurisé,
+ # car on est certain que tout est exécuté avec les uid/gid
+ # assignés au VirtualHost/Directory/Location
+ # néamoins il se peut qu'une combinaison du genre :
+ # apache2-mpm-{worker,event} + mod_proxy_fcgi + apache2-suexec-custom + php-fpm
+ # soit plus performante (threads et pas forks),
+ # cependant l'usage de suexec impose des forks il semble..
+ # et mod_proxy_fcgi n'apparaît que dans apache 2.4 ;
+ # donc pour l'instant : apache2-mpm-itk
+ sudo rm -rf \
+ /etc/apache2/site.d
+ sudo install -d -m 770 -o www -g www \
+ /etc/apache2 \
+ /etc/apache2/site.d \
+ /etc/apache2/x509.d
+ cat /dev/stdin "$tool"/etc/apache2/apache2.conf <<-EOF |
+ ServerName "$vm_fqdn"
+ EOF
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/apache2.conf
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/envvars \
+ /etc/apache2/envvars
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/httpd.conf \
+ /etc/apache2/httpd.conf
+ #sudo install -m 660 -o root -g root /dev/stdin \
+ # /etc/apache2/suexec/www-data <<-EOF
+ # /home
+ # pub/www/cgi
+ # EOF
+ sudo install -m 660 -o root -g root \
+ "$tool"/etc/apache2/ports.conf \
+ /etc/apache2/ports.conf
+ sudo a2enmod actions
+ sudo a2enmod headers
+ sudo a2enmod rewrite
+ sudo a2enmod ssl
+ sudo a2enmod userdir
+ local conf
+ sudo a2dissite "*"
+ sudo ln -fns \
+ /etc/apache2 \
+ /home/www/etc/apache2
+ for conf in "$tool"/etc/apache2/site.d/*/VirtualHost.conf
+ do conf=${conf#"$tool"/etc/apache2/site.d/}
+ local site=${conf%/VirtualHost.conf}
+ case $site in
+ (*-tls)
+ local hint="run vm_remote apache2_key_send before"
+ assert "sudo test -f /etc/apache2/site.d/\"$site\"/x509/key.pem" hint
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /etc/apache2 \
+ /etc/apache2/site.d/"$site" \
+ /etc/apache2/x509.d/"$site" \
+ /etc/apache2/x509.d/"$site"/ca \
+ /etc/apache2/x509.d/"$site"/empty \
+ /etc/apache2/x509.d/"$site"/rvk \
+ /etc/apache2/x509.d/"$site"/usr
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/crt.self-signed.pem
+ #sudo install -m 664 -o www-"$site" -g www-"$site" \
+ # "$tool"/var/pub/x509/"$site"/rvk.pem \
+ # /etc/apache2/x509.d/"$site"/rvk.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/ca/crt.self-signed.pem \
+ /etc/apache2/x509.d/"$site"/ca/crt.pem
+ sudo install -m 664 -o www -g www \
+ "$tool"/var/pub/x509/"$site"/crt.pem \
+ /etc/apache2/x509.d/"$site"/crt.pem
+ ;;
+ esac
+ case $site in
+ (*-tls)
+ cat <<-EOF
+
+
+ AssignUserID www-$site www-$site
+ BrowserMatch "MSIE [2-6]" ssl-unclean-shutdown nokeepalive downgrade-1.0 force-response-1.0
+ BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ SSLCACertificateFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCACertificatePath /etc/apache2/x509.d/$site/usr/
+ #SSLCARevocationFile /etc/apache2/x509.d/$site/rvk.pem
+ SSLCADNRequestFile /etc/apache2/x509.d/$site/crt.self-signed.pem
+ SSLCADNRequestPath /etc/apache2/x509.d/$site/empty/
+ # NOTE: ne publie pas les certificats dâutilisateur-ice-s acceptés
+ SSLCARevocationPath /etc/apache2/x509.d/$site/rvk/
+ SSLCertificateChainFile /etc/apache2/x509.d/$site/ca/crt.pem
+ SSLCertificateFile /etc/apache2/x509.d/$site/crt.pem
+ SSLCertificateKeyFile /etc/apache2/x509.d/$site/key.pem
+ SSLCipherSuite AES+RSA+SHA256
+ SSLEngine On
+ SSLInsecureRenegotiation Off
+ SSLOptions +StrictRequire +OptRenegotiate +StdEnvVars
+ SSLProtocol -All +TLSv1
+ #SSLRenegBufferSize 262144
+ SSLSessionCacheTimeout 1200
+ SSLStrictSNIVHostCheck On
+ SSLUserName SSL_CLIENT_S_DN_CN
+ SSLVerifyClient None
+ SSLVerifyDepth 1
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+
+ EOF
+ ;;
+ (*)
+ cat <<-EOF
+
+ AssignUserID www-$site www-$site
+ CustomLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/access/%Y-%m-%d.log 86400 60" Combined
+ #CustomLog "/dev/null" Combined
+ DocumentRoot /home/www/pub/$site
+ ErrorLog "|/usr/sbin/rotatelogs /home/www/log/$site/apache2/error/%Y-%m-%d.log 86400 60"
+ #ErrorLog "/dev/null"
+ LogLevel Warn
+ $(cat "$tool"/etc/apache2/site.d/"$site"/VirtualHost.conf)
+
+ EOF
+ ;;
+ esac |
+ sudo install -m 660 -o root -g root /dev/stdin \
+ /etc/apache2/site.d/"$site"/VirtualHost.conf
+ sudo ln -fns \
+ ../site.d/"$site"/VirtualHost.conf \
+ /etc/apache2/sites-available/"$site"
+ sudo install -d -m 770 -o www-"$site" -g www-"$site" \
+ /home/www/log/"$site" \
+ /home/www/log/"$site"/apache2
+ sudo ln -fns \
+ /etc/apache2/site.d/"$site" \
+ /home/www/etc/apache2/"$site"
+ test -e /home/www/pub/"$site" ||
+ sudo install -d -m 2770 -o www-"$site" -g www-"$site" \
+ /home/www/pub/"$site"
+ rule adduser www-"$site"
+ --disabled-password \
+ --group \
+ --no-create-home \
+ --home /home/www/pub/"$site" \
+ --shell /bin/false \
+ --system
+ #sudo setfacl -m u:"www-$site":--x \
+ # /home/www/ \
+ # /home/www/pub/ \
+ # /home/www/pub/"$site"/
+ #sudo setfacl -m d:u:"www-$site":rwx \
+ # "$home"/pub/www/"$site"/
+ test ! -r "$tool"/etc/apache2/site.d/"$site"/configure.sh ||
+ . "$tool"/etc/apache2/site.d/"$site"/configure.sh
+ test -e /etc/apache2/sites-enabled/"$site" ||
+ sudo a2ensite "$site"
+ done
+ sudo service apache2 restart
+ }
rule_apt_configure () {
- sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list <<-EOF
- deb http://ftp.fr.debian.org/debian $vm_lsb_name main contrib non-free
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name main
EOF
- sudo install -m 660 -o root -g root /dev/stdin /etc/apt/$vm_lsb_name-backports.list <<-EOF
- #deb http://backports.debian.org/debian-backports $vm_lsb_name-backports main contrib non-free
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list.d/$vm_lsb_name-backports.list <<-EOF
+ deb http://ftp.rezopole.net/debian $vm_lsb_name-backports main
EOF
- sudo install -m 660 -o root -g root /dev/stdin /etc/apt/preferences <<-EOF
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
+ deb http://nightly.openerp.com/7.0/nightly/deb/ ./
+ EOF
+ sudo install -m 664 -o root -g root /dev/stdin /etc/apt/preferences <<-EOF
Package: *
Pin: release a=$vm_lsb_name
- Pin-Priority: 170
+ Pin-Priority: 200
Package: *
Pin: release a=$vm_lsb_name-backports
- Pin-Priority: 200
- EOF
- sudo install -m 660 -o root -g root /dev/stdin /etc/apt/sources.list.d/openerp.list <<-EOF
- deb http://nightly.openerp.com/trunk/nightly/deb/ ./
+ Pin-Priority: 170
EOF
sudo apt-get update
rule apt_get_install apticron
- sudo install -m 644 -o root -g root /dev/stdin /etc/apticron/apticron.conf <<-EOF
- EMAIL="admin@$vm_domainname"
- # DIFF_ONLY="1"
- # LISTCHANGES_PROFILE="apticron"
- # ALL_FQDNS="1"
- # SYSTEM="foobar.example.com"
- # IPADDRESSNUM="1"
- # IPADDRESSES="192.0.2.1 2001:db8:1:2:3::1"
- # NOTIFY_HOLDS="0"
- # NOTIFY_NEW="0"
- # NOTIFY_NO_UPDATES="0"
- # CUSTOM_SUBJECT=""
- # CUSTOM_NO_UPDATES_SUBJECT=""
- # CUSTOM_FROM="root@$vm_fqdn"
- EOF
+ m4 \
+ --define=VM_DOMAINNAME=$vm_domainname \
+ <"$tool"/etc/apticron/apticron.conf.m4 |
+ sudo install -m 644 -o root -g root /dev/stdin \
+ /etc/apticron/apticron.conf
}
rule_boot_configure () {
- warn "lors de l'installation Debian, surtout n'installer GRUB sur AUCUN disque proposé !"
+ #warn "lors de l'installation Debian, surtout n'installer GRUB sur AUCUN disque proposé !"
+ sudo debconf-set-selections <<-EOF
+ grub-pc grub-pc/install_devices multiselect
+ EOF
rule apt_get_install grub-pc
sudo install -d -m 644 -o root -g root /boot/grub
rule apt_get_install linux-image-$vm_arch
@@ -112,87 +297,13 @@ rule_boot_configure () {
EOF
sudo update-grub2 # NOTE: prend en compte /boot/grub/device.map
rule initramfs_configure
- }
-rule_dovecot_configure () {
- rule apt_get_install dovecot-imapd dovecot-managesieved dovecot-sieve
- local hint="run vm_remote dovecot_key_send before"
- assert "test -f /etc/dovecot/$vm_domainname/imap/x509/key.pem" hint
- sudo install -m 400 -o root -g root \
- "$tool"/var/pub/x509/service/imap/crt+crl.self-signed.pem \
- /etc/dovecot/$vm_domainname/imap/x509/crt+crl.self-signed.pem
- sudo install -d -m 770 -o root -g adm \
- /etc/skel/etc/mail \
- /etc/skel/etc/sieve
- sudo install -d -m 1777 -o root -g root \
- /var/lib/dovecot-control \
- /var/lib/dovecot-index
- sudo install -m 664 -o root -g root /dev/stdin /etc/dovecot/local.conf <<-EOF
- auth_ssl_username_from_cert = yes
- listen = *
- log_timestamp = "%Y-%m-%d %H:%M:%S "
- mail_debug = yes
- mail_location = maildir:~/var/mail:INDEX=/var/lib/dovecot-index/%u:CONTROL=/var/lib/dovecot-control/%u
- # NOTE: INDEX et CONTROL sont sur une partition sans quota comme le demande la doc
- # VOIR: http://wiki2.dovecot.org/Quota/FS
- mail_plugins = \$mail_plugins quota
- mail_privileged_group = mail
- passdb {
- args = /home/%u/etc/dovecot/passwd
- driver = passwd-file
- }
- plugin {
- quota = fs:user
- recipient_delimiter = +
- sieve = ~/etc/mail/filter.sieve
- sieve_dir = ~/etc/mail/sieve
- sieve_global_dir = /var/lib/dovecot/sieve/global/
- sieve_max_script_size = 1M
- sieve_quota_max_scripts = 0
- sieve_quota_max_storage = 10M
- sieve_user_log = ~/var/log/mail/sieve.log
- }
- protocol imap {
- mail_plugins = \$mail_plugins imap_quota
- }
- protocol lda {
- auth_socket_path = /var/run/dovecot/auth-master
- hostname = $vm_domainname
- info_log_path =
- log_path =
- mail_plugins = \$mail_plugins sieve
- postmaster_address = contact+dovecot+lda@$vm_domainname
- syslog_facility = mail
- }
- protocols = imap sieve
- service auth {
- user = root
- unix_listener /var/spool/postfix/private/auth {
- mode = 0660
- user = postfix
- group = postfix
- }
- }
- ssl_ca =
- LABEL=${vm_lvm_lv}_boot /boot ext2 defaults 0 0
- proc /proc proc defaults 0 0
- sysfs /sys sysfs defaults 0 0
- tmpfs /tmp tmpfs rw,nosuid,nodev,auto,size=200m,nr_inodes=1000k,mode=1777,noatime,nodiratime 0 0
- /dev/mapper/${vm_lvm_lv}_root_deciphered / ext4 defaults,errors=remount-ro,acl,barrier=1,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_var_deciphered /var ext4 defaults,errors=remount-ro,acl,barrier=1,noatime 0 1
- /dev/mapper/${vm_lvm_lv}_home_deciphered /home ext4 defaults,errors=remount-ro,acl,barrier=1,noatime,usrquota,grpquota 0 0
- # NOTE: barrier=1 réduit drastiquement les performances d'écriture, mais garantit la cohérence du système de fichiers.
- /dev/mapper/${vm_lvm_lv}_swap_deciphered swap swap sw 0 0
- EOF
- sudo install -m 644 -o root -g root /dev/stdin /etc/crypttab <<-EOF
- #