home · contact · privacy
Add GPG encryption of old plomlombot logs.
[config] / buster / setup_scripts / setup_website.sh
index 035d852fc90fdbb41379825800212cc6a76b5a0e..2eabead2c8a83ea8a0bcb02bebe7c02ad8510a3e 100755 (executable)
@@ -3,13 +3,14 @@ set -e
 set -x
 # Heavily inspired by <https://docs-develop.pleroma.social/backend/installation/debian_based_en/>
 
-if [ "$#" -ne 3 ]; then
-    echo 'Need domain name and mail and old server IP as argument.'
+if [ "$#" -ne 4 ]; then
+    echo 'Need domain name and mail and old server IP and key ID as argument.'
     false
 fi
 domain="$1"
 mail="$2"
 old_server="$3"
+gpg_key="$4"
 
 # Install configs, set up firewall.
 config_tree_prefix="${HOME}/config/buster"
@@ -46,11 +47,32 @@ su -lc "cd /var/repos && git clone --mirror ${old_server}:repos/website" plom
 cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive
 su -lc 'cd /var/www && git clone /var/repos/website.git .' plom
 
+# Add encryption key.
+keyservers='sks-keyservers.net/ keys.gnupg.net'
+set +e
+while true; do
+    do_break=0
+    for keyserver in $(echo "${keyservers}"); do
+        su plom -c "gpg --no-tty --keyserver $keyserver --recv-key ${gpg_key}"
+        if [ $? -eq "0" ]; then
+            do_break=1
+            break
+        fi
+        echo "Attempt with keyserver ${keyserver} unsuccessful, trying other."
+    done
+    if [ "${do_break}" -eq "1" ]; then
+        break
+    fi
+done
+set -e
+
 # Set up plomlombot.
-mkdir /var/www/html/irclogs
-chown plom:plom /var/www/html/irclogs
-mkdir /var/www/irclogs_pw
-chown plom:plom /var/www/irclogs_pw
+irclogs_dir=/var/www/html/irclogs
+irclogs_pw_dir=/var/www/irclogs_pw
+mkdir -p "${irclogs_dir}"
+chown -R plom:plom "${irclogs_dir}"
+mkdir -p "${irclogs_pw_dir}"
+chown -R plom:plom "${irclogs_pw_dir}"
 su -lc "cd /var/repos && git clone --mirror https://plomlompom.com/repos/clone/plomlombot-irc" plom
 su -lc "touch /var/repos/plomlombot-irc.git/git-daemon-export-ok" plom
 cp "${config_tree_prefix}/other_files/plomlombot_hook_post-receive" /var/repos/plomlombot-irc.git/hooks/post-receive