home · contact · privacy
Add GPG encryption of old plomlombot logs.
authorChristian Heller <c.heller@plomlompom.de>
Wed, 25 Mar 2020 22:47:47 +0000 (23:47 +0100)
committerChristian Heller <c.heller@plomlompom.de>
Wed, 25 Mar 2020 22:47:47 +0000 (23:47 +0100)
buster/apt-mark/website
buster/setup_scripts/setup_website.sh

index a30957551278041b6639f81491a9ac64d894ecff..c046f502b5c7f08a1f5fb48d207cdcf097b8d8e7 100644 (file)
@@ -2,5 +2,7 @@
 gitweb
 fcgiwrap
 # for plomlombot
 gitweb
 fcgiwrap
 # for plomlombot
+gnupg
+dirmngr
 python3-venv
 screen
 python3-venv
 screen
index 6288a27427ac416f16f065f1b5e4e8447b77afbc..2eabead2c8a83ea8a0bcb02bebe7c02ad8510a3e 100755 (executable)
@@ -3,13 +3,14 @@ set -e
 set -x
 # Heavily inspired by <https://docs-develop.pleroma.social/backend/installation/debian_based_en/>
 
 set -x
 # Heavily inspired by <https://docs-develop.pleroma.social/backend/installation/debian_based_en/>
 
-if [ "$#" -ne 3 ]; then
-    echo 'Need domain name and mail and old server IP as argument.'
+if [ "$#" -ne 4 ]; then
+    echo 'Need domain name and mail and old server IP and key ID as argument.'
     false
 fi
 domain="$1"
 mail="$2"
 old_server="$3"
     false
 fi
 domain="$1"
 mail="$2"
 old_server="$3"
+gpg_key="$4"
 
 # Install configs, set up firewall.
 config_tree_prefix="${HOME}/config/buster"
 
 # Install configs, set up firewall.
 config_tree_prefix="${HOME}/config/buster"
@@ -46,6 +47,25 @@ su -lc "cd /var/repos && git clone --mirror ${old_server}:repos/website" plom
 cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive
 su -lc 'cd /var/www && git clone /var/repos/website.git .' plom
 
 cp "${config_tree_prefix}/other_files/website_hook_post-receive" /var/repos/website.git/hooks/post-receive
 su -lc 'cd /var/www && git clone /var/repos/website.git .' plom
 
+# Add encryption key.
+keyservers='sks-keyservers.net/ keys.gnupg.net'
+set +e
+while true; do
+    do_break=0
+    for keyserver in $(echo "${keyservers}"); do
+        su plom -c "gpg --no-tty --keyserver $keyserver --recv-key ${gpg_key}"
+        if [ $? -eq "0" ]; then
+            do_break=1
+            break
+        fi
+        echo "Attempt with keyserver ${keyserver} unsuccessful, trying other."
+    done
+    if [ "${do_break}" -eq "1" ]; then
+        break
+    fi
+done
+set -e
+
 # Set up plomlombot.
 irclogs_dir=/var/www/html/irclogs
 irclogs_pw_dir=/var/www/irclogs_pw
 # Set up plomlombot.
 irclogs_dir=/var/www/html/irclogs
 irclogs_pw_dir=/var/www/irclogs_pw