home · contact · privacy
Add zettels to dump site.
[config] / buster / setup_scripts / setup_dumpsite.sh
1 #!/bin/sh
2 set -e
3 set -x
4
5 if [ "$#" -ne 3 ]; then
6     echo 'Need domain name and mail and old server.'
7     false
8 fi
9 domain="$1"
10 mail="$2"
11 old_server="$3"
12
13 # Install configs, set up firewall.
14 config_tree_prefix="${HOME}/config/buster"
15 ./install_for_target.sh web dumpsite
16 ./copy_dirtree.sh "${config_tree_prefix}/etc_files" "" web dumpsite
17 nft -f /etc/nftables.conf
18
19 # Set up letsencrypt certificate. TODO: Is it auto-renewed?
20 ln -sf /etc/nginx/sites-available/default /etc/nginx/sites-enabled/default
21 certbot --nginx --agree-tos --redirect --no-eff-email -m "${mail}" -d "${domain}"
22 rm /etc/nginx/sites-enabled/default
23
24 # Set up dump dirs.
25 mkdir /var/www-dump
26 chown plom:plom /var/www-dump
27 dump_dir=dump
28 geheim_dir=geheim
29 su -lc "mkdir ${dump_dir} ${geheim_dir}" plom
30 su -lc "ln -s /home/plom/${dump_dir} /var/www-dump/${dump_dir}" plom
31 su -lc "ln -s /home/plom/${geheim_dir} /var/www-dump/${geheim_dir}" plom
32 password_geheim=$(pwgen -1)
33 echo "foo:{PLAIN}${password_geheim}" > /var/www-dump/password_geheim
34 echo "geheim password is: ${password_geheim}"
35
36 # Set up zettel and redo.
37 wget http://news.dieweltistgarnichtso.net/bin/archives/redo-sh.tar.gz
38 tar -moxzf redo-sh.tar.gz -C /usr/local
39 cp "${config_tree_prefix}/setup_scripts/prepare_to_meet_server.sh" /home/plom/
40 chown plom:plom /home/plom/prepare_to_meet_server.sh
41 su -lc "./prepare_to_meet_server.sh ${old_server}" plom
42 su -lc "cd /var/repos && git clone --mirror ${old_server}:zettel.git" plom
43 cp "${config_tree_prefix}/other_files/zettel_hook_post-receive" /home/plom/zettel.git/hooks/
44 su -lc "git clone ~/zettel.git" plom
45 rm /home/plom/prepare_to_meet_server.sh
46
47 # Prepare NGINX.
48 sed -i "s/REPLACE_fqdn_ECALPER/${domain}/g" /etc/nginx/sites-available/dumpsite.nginx
49 ln -s /etc/nginx/sites-available/dumpsite.nginx /etc/nginx/sites-enabled/dumpsite.nginx
50
51 service nginx restart