-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathfresh_setup.sh
More file actions
executable file
·182 lines (151 loc) · 5.21 KB
/
Copy pathfresh_setup.sh
File metadata and controls
executable file
·182 lines (151 loc) · 5.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
#!/usr/bin/env bash
set -euo pipefail
# this is a script for seting up the website from a fresh install
# NOTE: it should be downloaded directly onto the machine to be set-up with:
# - wget https://raw.githubusercontent.com/CSSS/csss-site-config/refs/heads/master/fresh_setup.sh
# TODO:
# - look into `apt install unattended-upgrades`
# - look into activating fail2ban for ssh protection (I doubt we'll need this unless we get too much random traffic)
# make sure user is root
user=$(whoami)
if [ $user != 'root' ]; then
echo "this script must be run as the superuser."
exit 1
fi
echo "hi sysadmin!"
echo "this script will install (almost) everything needed to run the csss website"
echo "(make sure you are running on a Debian 13 Linux machine as the superuser!)"
echo "(P)roceed, (c)ancel?"
read choice
# if choice isn't (P)roceed, just cancel
if [ "$choice" != "P" ]; then
echo "OK, cancelling."
exit 0
fi
MAIN_NGINX_CONFIG=/etc/nginx/conf.d
# Configure 1GB swapfile
echo "----"
echo "configure swapfile..."
fallocate -l 1G /swapfile
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
sysctl vm.swappiness=10
echo 'vm.swappiness=10' | sudo tee /etc/sysctl.d/99-swappiness.conf
echo "----"
echo "install apt source prerequisites..."
apt update
apt install -y ca-certificates curl gnupg
source /etc/os-release
echo "----"
echo "configure apt sources..."
install -d -m 0755 /usr/share/postgresql-common/pgdg
curl --fail --silent --show-error \
-o /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc \
https://www.postgresql.org/media/keys/ACCC4CF8.asc
cat >/etc/apt/sources.list.d/pgdg.sources <<EOF
Types: deb
URIs: https://apt.postgresql.org/pub/repos/apt
Suites: ${VERSION_CODENAME}-pgdg
Architectures: $(dpkg --print-architecture)
Components: main
Signed-By: /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc
EOF
echo "Adding nginx"
curl --fail --silent --show-error https://nginx.org/keys/nginx_signing.key | gpg --dearmor |
sudo tee /usr/share/keyrings/nginx-archive-keyring.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/nginx-archive-keyring.gpg] \
https://nginx.org/packages/debian ${VERSION_CODENAME} nginx" |
sudo tee /etc/apt/sources.list.d/nginx.list
echo -e "Package: *\nPin: origin nginx.org\nPin: release o=nginx\nPin-Priority: 900\n" |
sudo tee /etc/apt/preferences.d/99nginx
echo "----"
echo "update and upgrade apt..."
apt update && apt upgrade -y
echo "----"
echo "install packages..."
apt install \
git \
software-properties-common \
python3 \
python3-venv \
libaugeas0 \
nginx \
postgresql-18 \
rsync -y
echo "----"
echo "install uv..."
curl -LsSf https://astral.sh/uv/install.sh |
env UV_UNMANAGED_INSTALL=/usr/local/bin sh
# install certbot
python3 -m venv /opt/certbot
/opt/certbot/bin/pip install --upgrade pip
/opt/certbot/bin/pip install certbot certbot-nginx
ln -s /opt/certbot/bin/certbot /usr/bin/certbot
echo "----"
echo "add user csss_site..."
useradd csss-site -m # -m: has home /home/csss-site
usermod -L csss-site # -L: cannot login
chsh -s /usr/bin/bash csss-site # make user csss-site use the bash shell
cd /home/csss-site
echo "----"
echo "clone repository csss-site-config..."
sudo -u csss-site git clone https://github.com/CSSS/csss-site-config --recurse-submodules
cd csss-site-config
echo "----"
echo "configure sudo..."
cp ./sudoers.conf /etc/sudoers.d/csss-site
echo "----"
echo "configure nginx..."
# www-data and /var/www stuff
usermod -aG www-data csss-site
mkdir /var/www/logs
mkdir /var/www/logs/csss-site-backend
mkdir /var/www/logs/csss-site-docs
chown -R www-data:www-data /var/www
chmod -R ug=rwx,o=rx /var/www
# shared media files
groupadd csss-media
usermod -aG csss-media csss-site # Server will upload media
usermod -aG csss-media nginx # Nginx will read media
mkdir -p /srv/csss/media
chown -R csss-site:csss-media /srv/csss/media
chmod 2750 /srv/csss/media
# nginx config files
rsync -a --exclude='/snippets/' ./nginx/ "$MAIN_NGINX_CONFIG/"
rsync -a nginx/snippets/ /etc/nginx/snippets/
# remove default configuration to prevent funky certbot behaviour
rm /etc/nginx/sites-enabled/default
echo "You'll need to fill out the certbot configuration manually."
echo "Use csss-sysadmin@sfu.ca for contact email."
certbot --nginx
nginx -t
echo "----"
echo "starting nginx..."
systemctl enable nginx && systemctl start nginx
echo "----"
echo "configure postgres..."
# NOTE: the installation of postgresql-18 creates the postgres user, which has special privileges
sudo -u postgres createuser --no-password --login csss-site
sudo -u postgres createdb --no-password --owner=csss-site main
echo "----"
echo "install uv-managed Python 3.13, and backend dependencies..."
sudo -u csss-site -H env \
/usr/local/bin/uv sync \
--project /home/csss-site/csss-site-config/backend \
--locked \
--python 3.13 \
--managed-python
echo "----"
echo "configure csss-site service..."
cp ./csss-site.service /etc/systemd/system/csss-site.service
systemctl enable csss-site
echo "----"
echo "deploy static sites"
rsync -a errors/ /var/www/html/errors/
mkdir -p /var/www/html/main # Main site
mkdir -p /var/www/html/docs # Documentation site
mkdir -p /var/www/html/events # Event sites
mkdir -p /var/www/html/errors # Error pages
./deploy.sh