|
|
|
@@ -2,6 +2,11 @@
|
|
|
|
|
|
|
|
|
|
cd /scripts
|
|
|
|
|
DEBUG_MODE=${DEBUG_MODE:-false}
|
|
|
|
|
VERSION=1.1.0
|
|
|
|
|
|
|
|
|
|
# Set installed version number
|
|
|
|
|
echo '{}' | jq --arg VERSION "$VERSION" '.VERSION = $VERSION' > /var/tmp/shared/output/version.json
|
|
|
|
|
############################
|
|
|
|
|
|
|
|
|
|
#DOCKER_REGISTRY_URL=${DOCKER_REGISTRY_URL:-registry.format.hu}
|
|
|
|
|
DOCKER_REGISTRY_URL=${DOCKER_REGISTRY_URL:-safebox}
|
|
|
|
@@ -91,14 +96,280 @@ debug() {
|
|
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
## Start prevously deployed firewall rules depend on framework scheduler startup at first time
|
|
|
|
|
add_json_target(){
|
|
|
|
|
|
|
|
|
|
if [ -d /etc/user/config/services ]; then
|
|
|
|
|
cd /etc/user/config/services
|
|
|
|
|
for FIREWALL in $(ls firewall*.json); do
|
|
|
|
|
$service_exec $FIREWALL start &
|
|
|
|
|
done
|
|
|
|
|
fi
|
|
|
|
|
local TASK_NAME=$1
|
|
|
|
|
|
|
|
|
|
if [ -n "$TASK_NAME" ]; then
|
|
|
|
|
TASK="upgrade-$TASK_NAME"
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
install -m 664 -g 65534 /dev/null $SHARED/output/$TASK.json
|
|
|
|
|
echo $JSON_TARGET | base64 -d >$SHARED/output/$TASK.json
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
backup_query_state() {
|
|
|
|
|
|
|
|
|
|
echo "backup_query_state"
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
generate_backup_server_secrets () {
|
|
|
|
|
|
|
|
|
|
echo '{
|
|
|
|
|
"backupserver":{
|
|
|
|
|
"SSH_USER":"'$SSH_USER'",
|
|
|
|
|
"SSH_PORT":"'$SSH_PORT'",
|
|
|
|
|
"SSH_PASSWORD":"'$SSH_PASSWORD'"
|
|
|
|
|
"PASSWORD":"'$PASSWORD'",
|
|
|
|
|
"PERIOD":"'$PERIOD'",
|
|
|
|
|
"COMPRESSION":"'$COMPRESSION'",
|
|
|
|
|
"DIRECTORIES":"'$DIRECTORIES'",
|
|
|
|
|
"SERVICES":"'$SERVICES'",
|
|
|
|
|
"BACKUP_LOCAL_CLIENTS":"'$BACKUP_LOCAL_CLIENTS'",
|
|
|
|
|
"BACKUP_VPN_CLIENTS":"'$BACKUP_VPN_CLIENTS'"
|
|
|
|
|
}
|
|
|
|
|
}' | jq -r . > /etc/user/secret/backup/server/backup.json
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
create_backup_service () {
|
|
|
|
|
|
|
|
|
|
ADDITIONAL=""
|
|
|
|
|
ADDITIONAL='"EXTRA":"--rm","PRE_START":[],"DEPEND": [],"CMD":""'
|
|
|
|
|
|
|
|
|
|
BACKUP_SERVER='{
|
|
|
|
|
"main": {
|
|
|
|
|
"SERVICE_NAME": "backup-server"
|
|
|
|
|
},
|
|
|
|
|
"containers": [
|
|
|
|
|
{
|
|
|
|
|
"IMAGE": "alpine:latest",
|
|
|
|
|
"NAME": "backup-init",
|
|
|
|
|
"NETWORK": "host",
|
|
|
|
|
"UPDATE": "true",
|
|
|
|
|
"MEMORY": "64M",
|
|
|
|
|
"EXTRA": "--rm",
|
|
|
|
|
"VOLUMES":[
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "USER_DATA",
|
|
|
|
|
"DEST": "/etc/user/data/",
|
|
|
|
|
"TYPE": "rw"
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"ENTRYPOINT": "sh -c",
|
|
|
|
|
"CMD": "mkdir -p /etc/user/data/backup/server/",
|
|
|
|
|
"POST_START": []
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"IMAGE": "safebox/backup-server:latest",
|
|
|
|
|
"NAME": "backupserver",
|
|
|
|
|
"NETWORK": "'$NETWORK'",
|
|
|
|
|
"UPDATE": "true",
|
|
|
|
|
"MEMORY": "64M",
|
|
|
|
|
"VOLUMES":[
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "USER_DATA",
|
|
|
|
|
"DEST": "/etc/user/data/",
|
|
|
|
|
"TYPE": "ro"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "USER_CONFIG",
|
|
|
|
|
"DEST": "/etc/user/config/",
|
|
|
|
|
"TYPE": "ro"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "USER_SECRET",
|
|
|
|
|
"DEST": "/etc/user/secret/",
|
|
|
|
|
"TYPE": "ro"
|
|
|
|
|
},
|
|
|
|
|
"SOURCE": "/etc/user/data/backup/server/ssh",
|
|
|
|
|
"DEST": "/home/'$SSH_USER'/",
|
|
|
|
|
"TYPE": "rw"
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"ENV_FILES":["/etc/user/secret/backup/server/backup.json"],
|
|
|
|
|
'$ADDITIONAL'
|
|
|
|
|
"POST_START": []
|
|
|
|
|
},
|
|
|
|
|
]
|
|
|
|
|
}'
|
|
|
|
|
# create backup server secrets from variables
|
|
|
|
|
generate_backup_server_secrets
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
backup_set_service() {
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
local PASSWORD="$1"
|
|
|
|
|
local PERIOD="$2"
|
|
|
|
|
local COMPRESSION="$3"
|
|
|
|
|
|
|
|
|
|
local PLANNED_TIME="$(echo "$4" | base64 -d)"
|
|
|
|
|
local DIRECTRIES="$5"
|
|
|
|
|
local SERVICES="$6"
|
|
|
|
|
local BACKUP_LOCAL_CLIENTS="$7"
|
|
|
|
|
local BACKUP_VPN_CLIENTS="$8"
|
|
|
|
|
|
|
|
|
|
local VPN="$9"
|
|
|
|
|
local SSH_PORT="${10}"
|
|
|
|
|
local SSH_USER="${11}"
|
|
|
|
|
local SSH_PASSWORD="${12}"
|
|
|
|
|
local OPERATION="${13}"
|
|
|
|
|
|
|
|
|
|
if [ "$OPERATION" == "DELETE" ]; then
|
|
|
|
|
|
|
|
|
|
sed -i '/service-backup/d' /etc/user/data/cron/crontab.txt
|
|
|
|
|
# delete service
|
|
|
|
|
rm -f /etc/user/config/services/service-backup-server*
|
|
|
|
|
rm -rf /etc/user/data/backup/server
|
|
|
|
|
rm -rf /etc/user/secret/backup/server
|
|
|
|
|
debug "Service backup server service deleted."
|
|
|
|
|
|
|
|
|
|
elif [ "$OPERATION" == "MODIFY" ]; then
|
|
|
|
|
|
|
|
|
|
# modify only secrets for backup server, it will be affected at the next cron job
|
|
|
|
|
generate_backup_server_secrets
|
|
|
|
|
|
|
|
|
|
else
|
|
|
|
|
|
|
|
|
|
if [ -z "$SSH_PORT" ] ; then
|
|
|
|
|
SSH_PORT=20022
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ "$VPN" == "true" ]; then
|
|
|
|
|
NETWORK=$VPN_NETWORK
|
|
|
|
|
create_backup_service
|
|
|
|
|
else
|
|
|
|
|
NETWORK="host"
|
|
|
|
|
create_backup_service
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ -n "$PLANNED_TIME" ]; then
|
|
|
|
|
if [ "$VPN" == "true" ]; then
|
|
|
|
|
if [ -n "$BACKUP_SERVER" ] ; then
|
|
|
|
|
echo "$BACKUP_SERVER" | jq -r . >/etc/user/config/services/service-backup-server-vpn.json
|
|
|
|
|
fi
|
|
|
|
|
echo "'$PLANNED_TIME' service service-backup-server-vpn" >> /etc/user/data/cron/crontab.txt
|
|
|
|
|
else
|
|
|
|
|
if [ -n "$BACKUP_SERVER" ] ; then
|
|
|
|
|
echo "$BACKUP_SERVER" | jq -r . >/etc/user/config/services/service-backup-server-local.json
|
|
|
|
|
fi
|
|
|
|
|
echo "'$PLANNED_TIME' service service-backup-server-local" >> /etc/user/data/cron/crontab.txt
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
backup_set_client() {
|
|
|
|
|
|
|
|
|
|
local NAME="$1"
|
|
|
|
|
local SIZE="$2"
|
|
|
|
|
local VPN="$3"
|
|
|
|
|
local SSH_PORT="$4"
|
|
|
|
|
local SSH_USER="$5"
|
|
|
|
|
local SSH_PASSWORD="$6"
|
|
|
|
|
local OPERATION="$7"
|
|
|
|
|
local VPN_KEY="$8"
|
|
|
|
|
|
|
|
|
|
if [ "$OPERATION" == "DELETE" ]; then
|
|
|
|
|
# delete service
|
|
|
|
|
if [ -f "/etc/user/config/services/service-backup-client-$NAME.json" ]; then
|
|
|
|
|
|
|
|
|
|
debug "service-backup-client-$NAME.json stop force dns-remove"
|
|
|
|
|
$service_exec service-backup-client-$NAME.json stop force dns-remove
|
|
|
|
|
rm -f /etc/user/config/services/service-backup-client-$NAME.json
|
|
|
|
|
debug "Service backup client $NAME deleted."
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
else
|
|
|
|
|
|
|
|
|
|
if [ -z "$SSH_PORT" ] ; then
|
|
|
|
|
SSH_PORT=20022
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ "$VPN" == "true" ]; then
|
|
|
|
|
NETWORK=$NAME
|
|
|
|
|
PORT='"PORTS": [{"SOURCE":"null","DEST":"'$SSH_PORT'","TYPE":"tcp"}],'
|
|
|
|
|
else
|
|
|
|
|
NETWORK="host"
|
|
|
|
|
PORT='"PORTS": [{"SOURCE":"'$SSH_PORT'","DEST":"'$SSH_PORT'","TYPE":"tcp"}],'
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
ADDITIONAL=""
|
|
|
|
|
ADDITIONAL='"EXTRA":"--restart=always","PRE_START":[],"DEPEND":[],"CMD": ""'
|
|
|
|
|
ENVS='"ENVS": [{"SSH_USER":"'$SSH_USER'"},{"SSH_PORT":"'$SSH_PORT'"},{"SSH_PASSWORD":"'$SSH_PASSWORD'"},{"VPN_CLIENT_KEY":"'$VPN_KEY'"}],'
|
|
|
|
|
|
|
|
|
|
echo '{
|
|
|
|
|
"main": {
|
|
|
|
|
"SERVICE_NAME": "'$NAME'"
|
|
|
|
|
},
|
|
|
|
|
"containers": [
|
|
|
|
|
{
|
|
|
|
|
"IMAGE": "alpine:latest",
|
|
|
|
|
"NAME": "'$NAME'-init",
|
|
|
|
|
"NETWORK": "host",
|
|
|
|
|
"UPDATE": "true",
|
|
|
|
|
"MEMORY": "64M",
|
|
|
|
|
"EXTRA": "--rm",
|
|
|
|
|
"VOLUMES":[
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "USER_DATA",
|
|
|
|
|
"DEST": "/etc/user/data/",
|
|
|
|
|
"TYPE": "rw"
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"ENTRYPOINT": "sh -c",
|
|
|
|
|
"CMD": "mkdir -p /etc/user/data/backup/clients/'$NAME'/backup && mkdir -p /etc/user/data/backup/clients/'$NAME'/ssh",
|
|
|
|
|
"POST_START": []
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"IMAGE": "safebox/backup-client:latest",
|
|
|
|
|
"NAME": "'$NAME'",
|
|
|
|
|
"UPDATE": "true",
|
|
|
|
|
"MEMORY": "64M",
|
|
|
|
|
"NETWORK": "'$NETWORK'",
|
|
|
|
|
'$ADDITIONAL',
|
|
|
|
|
'$ENVS'
|
|
|
|
|
'$PORT'
|
|
|
|
|
"VOLUMES":[
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "/etc/user/data/backup/clients/'$NAME'/backup",
|
|
|
|
|
"DEST": "/backup",
|
|
|
|
|
"TYPE": "rw"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"SOURCE": "/etc/user/data/backup/clients/'$NAME'/ssh",
|
|
|
|
|
"DEST": "/home/'$SSH_USER'/",
|
|
|
|
|
"TYPE": "rw"
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"POST_START": []
|
|
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}' | jq -r . >/etc/user/config/services/service-backup-client-$NAME.json
|
|
|
|
|
|
|
|
|
|
debug "service-backup-client-$NAME.json stop force dns-remove"
|
|
|
|
|
$service_exec service-backup-client-$NAME.json start &
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
backup_challenge_clients() {
|
|
|
|
|
|
|
|
|
|
echo "backup_challenge_clients"
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
restore_from_backup() {
|
|
|
|
|
|
|
|
|
|
echo "restore_from_backup"
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
create_htpasswd_file() {
|
|
|
|
|
|
|
|
|
@@ -575,7 +846,7 @@ check_update() {
|
|
|
|
|
debug "$REMOTE_URL not accessible, http error code: $CURL_CHECK_CODE"
|
|
|
|
|
|
|
|
|
|
echo "Force image pull has started without digest check..."
|
|
|
|
|
DOCKER_PULL="docker pull $IMAGE"
|
|
|
|
|
DOCKER_PULL="/usr/bin/docker pull $IMAGE"
|
|
|
|
|
eval $DOCKER_PULL
|
|
|
|
|
STATUS=$?
|
|
|
|
|
debug "PULL STATUS: $STATUS"
|
|
|
|
@@ -589,7 +860,19 @@ check_update() {
|
|
|
|
|
|
|
|
|
|
upgrade_scheduler() {
|
|
|
|
|
|
|
|
|
|
DOCKER_START="--entrypoint=sh $DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION -c '/scripts/upgrade.sh'"
|
|
|
|
|
# Upgrading framework scheduler
|
|
|
|
|
debug "Upgrading framework scheduler..."
|
|
|
|
|
/usr/bin/docker pull "$DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION"
|
|
|
|
|
|
|
|
|
|
if [ "$DEBUG_MODE" == "true" ]; then
|
|
|
|
|
DOCKER_START="--entrypoint=sh $DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION -c 'sleep 86400'"
|
|
|
|
|
SET_DEBUG_MODE="--env DEBUG_MODE=true"
|
|
|
|
|
else
|
|
|
|
|
DOCKER_START="$DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION"
|
|
|
|
|
SET_DEBUG_MODE=""
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
FRAMEWORK_SCHEDULER_NAME="$FRAMEWORK_SCHEDULER_NAME-$(head /dev/urandom | tr -dc '0-9' | head -c 6)"
|
|
|
|
|
|
|
|
|
|
DOCKER_RUN="/usr/bin/docker run -d \
|
|
|
|
|
-v SHARED:/var/tmp/shared \
|
|
|
|
@@ -601,6 +884,8 @@ upgrade_scheduler() {
|
|
|
|
|
-v USER_CONFIG:/etc/user/config \
|
|
|
|
|
-v USER_SECRET:/etc/user/secret \
|
|
|
|
|
--restart=always \
|
|
|
|
|
--name $FRAMEWORK_SCHEDULER_NAME \
|
|
|
|
|
$SET_DEBUG_MODE \
|
|
|
|
|
--env WEBSERVER_PORT=$WEBSERVER_PORT \
|
|
|
|
|
--network $FRAMEWORK_SCHEDULER_NETWORK \
|
|
|
|
|
--env RUN_FORCE=$RUN_FORCE \
|
|
|
|
@@ -612,20 +897,20 @@ upgrade_scheduler() {
|
|
|
|
|
upgrade() {
|
|
|
|
|
local NAME=$1
|
|
|
|
|
|
|
|
|
|
if [ "$NAME" == "web-installer" ]; then
|
|
|
|
|
|
|
|
|
|
debug "$service_exec service-framework.containers.webserver stop force"
|
|
|
|
|
$service_exec service-framework.containers.webserver stop force
|
|
|
|
|
debug "$service_exec service-framework.containers.webserver start info"
|
|
|
|
|
$service_exec service-framework.containers.webserver start info &
|
|
|
|
|
|
|
|
|
|
if [ "$NAME" == "webserver" ]; then
|
|
|
|
|
debug "$service_exec service-framework.containers.$NAME stop force"
|
|
|
|
|
$service_exec service-framework.containers.$NAME stop force
|
|
|
|
|
debug "$service_exec service-framework.containers.$NAME start info"
|
|
|
|
|
$service_exec service-framework.containers.$NAME start info &
|
|
|
|
|
else
|
|
|
|
|
|
|
|
|
|
debug "$service_exec $NAME.json stop force"
|
|
|
|
|
$service_exec $NAME.json stop force
|
|
|
|
|
debug "$service_exec $NAME.json start info"
|
|
|
|
|
$service_exec $NAME.json start info &
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
PID=$!
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
@@ -668,7 +953,13 @@ execute_task() {
|
|
|
|
|
|
|
|
|
|
if [ "$REQUEST" == "requested" ]; then
|
|
|
|
|
echo "New certificate for $DOMAIN is requested."
|
|
|
|
|
touch /etc/system/data/ssl/keys/$DOMAIN/new_certificate
|
|
|
|
|
echo "Modifying $DOMAIN_FILE.json for $DOMAIN"
|
|
|
|
|
jq '.containers[0].ENVS |= map(if has("OPERATION") then .OPERATION = "MODIFY" else . end) | \
|
|
|
|
|
.containers[0].ENVS |= map(if has("DOMAIN") then .DOMAIN = "'$DOMAIN'" else . end)' \
|
|
|
|
|
/etc/user/config/services/$DOMAIN_FILE.json > /tmp/$DOMAIN_FILE.json && \
|
|
|
|
|
mv /tmp/$DOMAIN_FILE.json /etc/user/config/services/$DOMAIN_FILE.json
|
|
|
|
|
debug "$service_exec $DOMAIN_FILE.json start info"
|
|
|
|
|
$service_exec $DOMAIN_FILE.json start info &
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
JSON_TARGET=$B64_JSON
|
|
|
|
@@ -798,10 +1089,12 @@ execute_task() {
|
|
|
|
|
elif [ "$TASK_NAME" == "deployments" ]; then
|
|
|
|
|
DEPLOYMENTS=""
|
|
|
|
|
TREES=$(get_repositories)
|
|
|
|
|
for TREE in $TREES; do
|
|
|
|
|
for TREE in "$TREES"; do
|
|
|
|
|
APPS=$(jq -rc '.apps[]' $TREE)
|
|
|
|
|
for APP in $APPS; do
|
|
|
|
|
#for APP in "$APPS"; do #space problem
|
|
|
|
|
while IFS= read -r APP; do
|
|
|
|
|
APP_NAME=$(echo "$APP" | jq -r '.name')
|
|
|
|
|
APP_SUBTITLE="$(echo "$APP" | jq -r '.subtitle')"
|
|
|
|
|
APP_VERSION=$(echo "$APP" | jq -r '.version')
|
|
|
|
|
APP_ICON=$(echo "$APP" | jq -r '.icon')
|
|
|
|
|
if [ "$DEPLOYMENTS" != "" ]; then
|
|
|
|
@@ -809,8 +1102,8 @@ execute_task() {
|
|
|
|
|
else
|
|
|
|
|
SEP=""
|
|
|
|
|
fi
|
|
|
|
|
DEPLOYMENTS=$DEPLOYMENTS$SEP'"'$APP_NAME'": {"version": "'$APP_VERSION'", "icon": "'$APP_ICON'"}'
|
|
|
|
|
done
|
|
|
|
|
DEPLOYMENTS="$DEPLOYMENTS"$SEP'"'$APP_NAME'":{"subtitle":"'"$APP_SUBTITLE"'","version":"'"$APP_VERSION"'","icon":"'"$APP_ICON"'"}'
|
|
|
|
|
done < <(echo "$APPS") # preserve DEPLOYMENTS variable
|
|
|
|
|
done
|
|
|
|
|
if [ "$DEPLOYMENTS" == "" ]; then
|
|
|
|
|
DEPLOYMENTS='"deployments": "NONE"'
|
|
|
|
@@ -844,20 +1137,22 @@ execute_task() {
|
|
|
|
|
|
|
|
|
|
for TREE in $TREES; do
|
|
|
|
|
APPS=$(jq -rc '.apps[]' $TREE)
|
|
|
|
|
for APP in $APPS; do
|
|
|
|
|
#for APP in $APPS; do
|
|
|
|
|
while IFS= read -r APP; do
|
|
|
|
|
APP_NAME=$(echo "$APP" | jq -r '.name' | awk '{print tolower($0)}')
|
|
|
|
|
APP_SUBTITLE=$(echo "$APP" | jq -r '.subtitle')
|
|
|
|
|
APP_VERSION=$(echo "$APP" | jq -r '.version')
|
|
|
|
|
APP_DIR=$(dirname $TREE)"/"$APP_NAME
|
|
|
|
|
debug "$APP_TEMPLATE"
|
|
|
|
|
if [ "$APP_NAME" == "$DEPLOY_NAME" ]; then
|
|
|
|
|
if [ "$DEPLOY_ACTION" == "ask" ]; then
|
|
|
|
|
APP_TEMPLATE=$APP_DIR"/template.json"
|
|
|
|
|
TEMPLATE=$(cat $APP_TEMPLATE | base64 -w0)
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "STATUS": "0", "TEMPLATE": "'$TEMPLATE'" }' | jq -r . | base64 -w0)
|
|
|
|
|
debug "$APP_TEMPLATE"
|
|
|
|
|
JSON_TARGET=$(echo '{"DATE":"'$DATE'","STATUS": "0","TEMPLATE":"'$TEMPLATE'"}' | jq -r . | base64 -w0)
|
|
|
|
|
elif [ "$DEPLOY_ACTION" == "reinstall" ]; then
|
|
|
|
|
APP_TEMPLATE=$APP_DIR"/template.json"
|
|
|
|
|
TEMPLATE=$(cat $APP_TEMPLATE)
|
|
|
|
|
for LINE in $(cat $SERVICE_DIR/service-$DEPLOY_NAME.json | jq -rc '.containers[].ENVS[] | to_entries[]'); do
|
|
|
|
|
for LINE in $(cat $SERVICE_DIR/service-$DEPLOY_NAME.json | jq -rc '.containers[].ENVS[] | to_entries[]' 2>/dev/null); do
|
|
|
|
|
KEY=$(echo $LINE | jq -r .key)
|
|
|
|
|
VALUE=$(echo $LINE | jq -r .value)
|
|
|
|
|
debug "$KEY: $VALUE"
|
|
|
|
@@ -866,14 +1161,14 @@ execute_task() {
|
|
|
|
|
TEMPLATE=$(echo "$TEMPLATE" | jq -r '.fields |= map(if .key == "'$KEY'" then .value = "'$VALUE'" else . end)')
|
|
|
|
|
done
|
|
|
|
|
# write ENV value from domain file to template value by key name
|
|
|
|
|
for LINE in $(cat $SERVICE_DIR/domain-$DEPLOY_NAME.json | jq -rc '.containers[].ENVS[] | to_entries[]'); do
|
|
|
|
|
for LINE in $(cat $SERVICE_DIR/domain-$DEPLOY_NAME.json | jq -rc '.containers[].ENVS[] | to_entries[]' 2>/dev/null); do
|
|
|
|
|
KEY=$(echo $LINE | jq -r .key)
|
|
|
|
|
VALUE=$(echo $LINE | jq -r .value)
|
|
|
|
|
debug "$KEY: $VALUE"
|
|
|
|
|
TEMPLATE=$(echo "$TEMPLATE" | jq -r '.fields |= map(if .key == "'$KEY'" then .value = "'$VALUE'" else . end)')
|
|
|
|
|
done
|
|
|
|
|
# write ENV value from secret file to template value by key name
|
|
|
|
|
for LINE in $(cat $SECRET_DIR/$DEPLOY_NAME/$DEPLOY_NAME.json | jq -rc '.[] | to_entries[]'); do
|
|
|
|
|
for LINE in $(cat $SECRET_DIR/$DEPLOY_NAME/$DEPLOY_NAME.json | jq -rc '.[] | to_entries[]' 2>/dev/null); do
|
|
|
|
|
KEY=$(echo $LINE | jq -r .key)
|
|
|
|
|
VALUE=$(echo $LINE | jq -r .value)
|
|
|
|
|
debug "$KEY: $VALUE"
|
|
|
|
@@ -901,7 +1196,7 @@ execute_task() {
|
|
|
|
|
sh /scripts/check_pid.sh "$PID" "$SHARED" "deploy-$DEPLOY_NAME" "$DATE" "$DEBUG" &
|
|
|
|
|
|
|
|
|
|
elif [ "$DEPLOY_ACTION" == "edit" ]; then
|
|
|
|
|
|
|
|
|
|
JSON_TARGET=""
|
|
|
|
|
DEPLOY_PAYLOAD=$(echo "$JSON" | jq -r .PAYLOAD) # base64 list of key-value pairs in JSON
|
|
|
|
|
|
|
|
|
|
# stop service before edit
|
|
|
|
@@ -920,7 +1215,7 @@ execute_task() {
|
|
|
|
|
JSON_TARGET=""
|
|
|
|
|
fi
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
done < <(echo "$APPS") # preserve variables
|
|
|
|
|
done
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_NAME" == "repositories" ]; then
|
|
|
|
@@ -961,6 +1256,9 @@ execute_task() {
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_NAME" == "save_vpn" ]; then
|
|
|
|
|
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "STATUS": "0", "RESULT": "" }' | jq -r . | base64 -w0)
|
|
|
|
|
add_json_target
|
|
|
|
|
|
|
|
|
|
VPN_PROXY_REPO="wireguard-proxy-client"
|
|
|
|
|
if [ ! -d "/tmp/$VPN_PROXY_REPO" ]; then
|
|
|
|
|
git clone https://git.format.hu/safebox/$VPN_PROXY_REPO.git /tmp/$VPN_PROXY_REPO >/dev/null
|
|
|
|
@@ -978,21 +1276,90 @@ execute_task() {
|
|
|
|
|
# install vpn only
|
|
|
|
|
sh /scripts/install.sh "$B64_JSON" "$service_exec" "vpn" "$GLOBAL_VERSION"
|
|
|
|
|
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "STATUS": "'$VPN_STATUS'", "RESULT": "'$VPN_RESULT'" }' | jq -r . | base64 -w0)
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "STATUS": "1", "RESULT": "'$VPN_RESULT'" }' | jq -r . | base64 -w0)
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_NAME" == "containers" ]; then # not in use
|
|
|
|
|
CONTAINERS=$(docker ps -a --format '{{.Names}} {{.Status}}' | grep -v framework-scheduler)
|
|
|
|
|
RESULT=$(echo "$CONTAINERS" | base64 -w0)
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "RESULT": "'$RESULT'" }' | jq -r . | base64 -w0)
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_NAME" == "backup" ]; then
|
|
|
|
|
|
|
|
|
|
TASK_TYPE=$(echo $B64_JSON | base64 -d | jq -r '.TASK_TYPE')
|
|
|
|
|
|
|
|
|
|
if [ "$TASK_TYPE" == "backup_query_state" ]; then
|
|
|
|
|
echo "task type is backup_query_state"
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_TYPE" == "backup_set_service" ]; then
|
|
|
|
|
|
|
|
|
|
PASSWORD="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_SERVER_PASSWORD')"
|
|
|
|
|
PERIOD="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_PERIOD')"
|
|
|
|
|
COMPRESSION="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_COMPRESSION')"
|
|
|
|
|
PLANNED_TIME="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_PLANNED_TIME')"
|
|
|
|
|
DIRECTRIES="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_DIRECTORIES')"
|
|
|
|
|
SERVICES="$(echo $B64_JSON | base64 -d | jq -r '.SERVICES')"
|
|
|
|
|
BACKUP_LOCAL_CLIENTS="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_LOCAL_CLIENTS')"
|
|
|
|
|
BACKUP_VPN_CLIENTS="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_VPN_CLIENTS')"
|
|
|
|
|
VPN="$(echo $B64_JSON | base64 -d | jq -r '.VPN')"
|
|
|
|
|
SSH_PORT="$(echo $B64_JSON | base64 -d | jq -r '.SSH_PORT')"
|
|
|
|
|
SSH_USER="$(echo $B64_JSON | base64 -d | jq -r '.SSH_USER')"
|
|
|
|
|
SSH_PASSWORD="$(echo $B64_JSON | base64 -d | jq -r '.SSH_PASSWORD')"
|
|
|
|
|
OPERATION="$(echo $B64_JSON | base64 -d | jq -r '.OPERATION')"
|
|
|
|
|
|
|
|
|
|
echo "task type is backup_set_service"
|
|
|
|
|
backup_set_service "$PASSWORD" "$PERIOD" "$COMPRESSION" "$PLANNED_TIME" "$DIRECTRIES" "$SERVICES" "$BACKUP_LOCAL_CLIENTS" "$BACKUP_VPN_CLIENTS" "$VPN" "$SSH_PORT" "$SSH_USER" "$SSH_PASSWORD" "$OPERATION"
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_TYPE" == "backup_set_client" ]; then
|
|
|
|
|
|
|
|
|
|
NAME="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_NAME')"
|
|
|
|
|
SIZE="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_SIZE')"
|
|
|
|
|
VPN="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_VPN')"
|
|
|
|
|
SSH_PORT="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_SSH_PORT')"
|
|
|
|
|
SSH_USER="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_SSH_USER')"
|
|
|
|
|
SSH_PASSWORD="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_SSH_PASSWORD')"
|
|
|
|
|
OPERATION="$(echo $B64_JSON | base64 -d | jq -r '.BACKUP_CLIENT_OPERATION')"
|
|
|
|
|
|
|
|
|
|
debug "task type is backup_set_client for $NAME"
|
|
|
|
|
backup_set_client "$NAME" "$SIZE" "$VPN" "$SSH_PORT" "$SSH_USER" "$SSH_PASSWORD" "$OPERATION"
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_TYPE" == "backup_challenge_clients" ]; then
|
|
|
|
|
echo "task type is backup_challenge_clients"
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_TYPE" == "restore_from_backup" ]; then
|
|
|
|
|
echo "task type is restore_from_backup"
|
|
|
|
|
|
|
|
|
|
else
|
|
|
|
|
echo "Unknown task type: $TASK_TYPE"
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
RESULT=$(echo "$CONTAINERS" | base64 -w0)
|
|
|
|
|
JSON_TARGET=$(echo '{ "DATE": "'$DATE'", "RESULT": "'$RESULT'" }' | jq -r . | base64 -w0)
|
|
|
|
|
|
|
|
|
|
elif [ "$TASK_NAME" == "upgrade" ]; then
|
|
|
|
|
JSON="$(echo $B64_JSON | base64 -d)"
|
|
|
|
|
NAME=$(echo "$JSON" | jq -r .NAME | awk '{print tolower($0)}')
|
|
|
|
|
if [ "$NAME" == "framework" ]; then
|
|
|
|
|
upgrade "web-installer"
|
|
|
|
|
JSON_TARGET=$(echo '{"DATE":"'$DATE'","INSTALL_STATUS":0}' | jq -r . | base64 -w0)
|
|
|
|
|
add_json_target $NAME
|
|
|
|
|
echo "Upgrading service: webserver"
|
|
|
|
|
upgrade webserver
|
|
|
|
|
|
|
|
|
|
echo "Upgrading framework scheduler..."
|
|
|
|
|
echo "Cleaning temporary files..."
|
|
|
|
|
|
|
|
|
|
rm -rf /var/tmp/shared/input/*
|
|
|
|
|
rm -rf /var/tmp/shared/output/*
|
|
|
|
|
|
|
|
|
|
upgrade_scheduler
|
|
|
|
|
echo "Removing old framework scheduler container..."
|
|
|
|
|
JSON_TARGET=$(echo '{"DATE":"'$DATE'","INSTALL_STATUS":1,"VERSION":'$VERSION'}' | jq -r . | base64 -w0)
|
|
|
|
|
add_json_target $NAME
|
|
|
|
|
sleep 1
|
|
|
|
|
/usr/bin/docker rm -f $HOSTNAME
|
|
|
|
|
|
|
|
|
|
#CONTAINERS=$(docker ps -a --format '{{.Names}} {{.Status}}' | grep -E 'framework-scheduler|webserver')
|
|
|
|
|
else
|
|
|
|
|
echo "Upgrading service: $NAME"
|
|
|
|
|
upgrade "$NAME"
|
|
|
|
|
#CONTAINERS=$(docker ps -a --format '{{.Names}} {{.Status}}' | grep -w "$NAME")
|
|
|
|
|
fi
|
|
|
|
@@ -1005,9 +1372,7 @@ execute_task() {
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
if [ "$JSON_TARGET" != "" ]; then
|
|
|
|
|
#redis-cli -h $REDIS_SERVER -p $REDIS_PORT SET $TASK "$JSON_TARGET"
|
|
|
|
|
install -m 664 -g 65534 /dev/null $SHARED/output/$TASK.json
|
|
|
|
|
echo $JSON_TARGET | base64 -d >$SHARED/output/$TASK.json
|
|
|
|
|
add_json_target
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
@@ -1077,39 +1442,15 @@ check_redis_availability() {
|
|
|
|
|
done
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
start_framework_scheduler() {
|
|
|
|
|
|
|
|
|
|
if [ "$DEBUG_MODE" == "true" ]; then
|
|
|
|
|
DOCKER_START="--entrypoint=sh $DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION -c 'sleep 86400'"
|
|
|
|
|
else
|
|
|
|
|
DOCKER_START="$DOCKER_REGISTRY_URL/$FRAMEWORK_SCHEDULER_IMAGE:$FRAMEWORK_SCHEDULER_VERSION"
|
|
|
|
|
fi
|
|
|
|
|
DOCKER_RUN="/usr/bin/docker run -d \
|
|
|
|
|
-v SHARED:/var/tmp/shared \
|
|
|
|
|
-v /var/run/docker.sock:/var/run/docker.sock \
|
|
|
|
|
-v SYSTEM_DATA:/etc/system/data \
|
|
|
|
|
-v SYSTEM_CONFIG:/etc/system/config \
|
|
|
|
|
-v SYSTEM_LOG:/etc/system/log \
|
|
|
|
|
-v USER_DATA:/etc/user/data \
|
|
|
|
|
-v USER_CONFIG:/etc/user/config \
|
|
|
|
|
-v USER_SECRET:/etc/user/secret \
|
|
|
|
|
--restart=always \
|
|
|
|
|
--name $FRAMEWORK_SCHEDULER_NAME \
|
|
|
|
|
--env WEBSERVER_PORT=$WEBSERVER_PORT \
|
|
|
|
|
--network $FRAMEWORK_SCHEDULER_NETWORK \
|
|
|
|
|
--env RUN_FORCE=$RUN_FORCE \
|
|
|
|
|
--env DOCKER_REGISTRY_URL=$DOCKER_REGISTRY_URL \
|
|
|
|
|
$DOCKER_START"
|
|
|
|
|
eval "$DOCKER_RUN"
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
### SYSTEM INITIALIZATION ###
|
|
|
|
|
## Start prevously deployed firewall rules depend on framework scheduler startup at first time
|
|
|
|
|
|
|
|
|
|
## DOCKER NETWORK VARIABLES
|
|
|
|
|
## FILESYSTEM VARIABLES
|
|
|
|
|
## PORTS VARIABLES
|
|
|
|
|
### RESTART SCHEDULER IF NEEDED
|
|
|
|
|
if [ -d /etc/user/config/services ]; then
|
|
|
|
|
cd /etc/user/config/services
|
|
|
|
|
for FIREWALL in $(ls firewall*.json); do
|
|
|
|
|
$service_exec $FIREWALL start &
|
|
|
|
|
done
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
SN=$(check_subnets)
|
|
|
|
|
if [ "$SN" != "1" ]; then
|
|
|
|
@@ -1126,7 +1467,7 @@ fi
|
|
|
|
|
|
|
|
|
|
VOL=$(check_volumes)
|
|
|
|
|
if [ "$VOL" != "1" ]; then
|
|
|
|
|
start_framework_scheduler
|
|
|
|
|
upgrade_scheduler
|
|
|
|
|
/usr/bin/docker rm -f $HOSTNAME
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
@@ -1138,15 +1479,12 @@ if [ "$DF" != "1" ]; then
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
#RS=$(docker ps | grep redis-server)
|
|
|
|
|
WS=$(docker ps | grep webserver)
|
|
|
|
|
WS=$(/usr/bin/docker ps | grep -o webserver)
|
|
|
|
|
|
|
|
|
|
#if [[ "$WS" == "" && "$RS" == "" ]]; then
|
|
|
|
|
if [ "$WS" == "" ]; then
|
|
|
|
|
|
|
|
|
|
# START SERVICES
|
|
|
|
|
#$service_exec service-framework.containers.redis-server start &
|
|
|
|
|
echo "Starting webserver"
|
|
|
|
|
$service_exec service-framework.containers.webserver start &
|
|
|
|
|
sleep 5
|
|
|
|
|
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|