X-Git-Url: https://plomlompom.com/repos/?p=config;a=blobdiff_plain;f=buster%2Fsetup_scripts%2Fsetup_website.sh;h=5c8d00ce30cf7f2843ae27970cb376591f43a67e;hp=a9909fb98dd7e55a902892c98c8b7b88a99e12a4;hb=792e3fed828682fec088f47f29e8fadf453cc723;hpb=17489120d557d9af614693ff6ee60a904ede4629 diff --git a/buster/setup_scripts/setup_website.sh b/buster/setup_scripts/setup_website.sh index a9909fb..5c8d00c 100755 --- a/buster/setup_scripts/setup_website.sh +++ b/buster/setup_scripts/setup_website.sh @@ -1,18 +1,18 @@ #!/bin/sh set -e -set -x -# Heavily inspired by -if [ "$#" -ne 2 ]; then - echo 'Need domain name and mail as argument.' +if [ "$#" -ne 4 ]; then + echo 'Need domain name and mail and old server IP and key ID as argument.' false fi domain="$1" mail="$2" +old_server="$3" +gpg_key="$4" # Install configs, set up firewall. config_tree_prefix="${HOME}/config/buster" -./install_for_target.sh web +./install_for_target.sh web website ./copy_dirtree.sh "${config_tree_prefix}/etc_files" "" web website nft -f /etc/nftables.conf @@ -31,6 +31,60 @@ chown plom:plom /var/repos # Prepare NGINX and GitWeb config. sed -i "s/REPLACE_fqdn_ECALPER/${domain}/g" /etc/gitweb.conf sed -i "s/REPLACE_fqdn_ECALPER/${domain}/g" /etc/nginx/sites-available/website.nginx -ln -s /etc/nginx/sites-available/static.nginx /etc/nginx/sites-enabled/website.nginx +ln -s /etc/nginx/sites-available/website.nginx /etc/nginx/sites-enabled/website.nginx + +# Set up website. TODO: use non-/var/www dir for better separation to dump site +rm -rf /var/www +mkdir /var/www +chown plom:plom /var/www +cp "${config_tree_prefix}/setup_scripts/prepare_to_meet_server.sh" /home/plom/ +chown plom:plom /home/plom/prepare_to_meet_server.sh +su -lc "./prepare_to_meet_server.sh ${old_server}" plom +read -p'Hit Enter when you are done.' ignore +su -lc "cd /var/repos && git clone --mirror ${old_server}:repos/website" plom +cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive +su -lc 'cd /var/www && git clone /var/repos/website.git .' plom +rm /home/plom/prepare_to_meet_server.sh + +# Add encryption key. +keyservers='sks-keyservers.net/ keys.gnupg.net' +set +e +while true; do + do_break=0 + for keyserver in $(echo "${keyservers}"); do + su plom -c "gpg --no-tty --keyserver $keyserver --recv-key ${gpg_key}" + if [ $? -eq "0" ]; then + do_break=1 + break + fi + echo "Attempt with keyserver ${keyserver} unsuccessful, trying other." + done + if [ "${do_break}" -eq "1" ]; then + break + fi +done +set -e + +# Set up plomlombot. +irclogs_dir=/var/www/html/irclogs +irclogs_pw_dir=/var/www/irclogs_pw +mkdir -p "${irclogs_dir}" +chown -R plom:plom "${irclogs_dir}" +mkdir -p "${irclogs_pw_dir}" +chown -R plom:plom "${irclogs_pw_dir}" +su -lc "cd /var/repos && git clone --mirror https://plomlompom.com/repos/clone/plomlombot-irc" plom +su -lc "touch /var/repos/plomlombot-irc.git/git-daemon-export-ok" plom +cp "${config_tree_prefix}/other_files/plomlombot_hook_post-receive" /var/repos/plomlombot-irc.git/hooks/post-receive +su -lc "git clone /var/repos/plomlombot-irc.git" plom +cp "${config_tree_prefix}/other_files/plomlombot_daemon.sh" /home/plom/ +chown plom:plom /home/plom/plomlombot_daemon.sh +echo 'bot: plomlombog plomlombog #plomlomtest irc.freenode.net foo bar' >> /home/plom/.plomlombot +chown plom:plom /home/plom/.plomlombot +systemctl enable plomlombot.service +service plomlombot start + +# TODO: +# - commit git-daemon-export-ok directly into the public repos; rename +# /home/plom/public_repos to /home/plom/repos service nginx restart