lot of stuff
This commit is contained in:
@@ -0,0 +1,66 @@
|
|||||||
|
server {
|
||||||
|
listen 80 default_server;
|
||||||
|
listen [::]:80 default_server;
|
||||||
|
|
||||||
|
# SSL configuration
|
||||||
|
#
|
||||||
|
# listen 443 ssl default_server;
|
||||||
|
# listen [::]:443 ssl default_server;
|
||||||
|
#
|
||||||
|
# Note: You should disable gzip for SSL traffic.
|
||||||
|
# See: https://bugs.debian.org/773332
|
||||||
|
#
|
||||||
|
# Read up on ssl_ciphers to ensure a secure configuration.
|
||||||
|
# See: https://bugs.debian.org/765782
|
||||||
|
#
|
||||||
|
# Self signed certs generated by the ssl-cert package
|
||||||
|
# Don't use them in a production server!
|
||||||
|
#
|
||||||
|
# include snippets/snakeoil.conf;
|
||||||
|
|
||||||
|
root /var/www/html;
|
||||||
|
|
||||||
|
# Add index.php to the list if you are using PHP
|
||||||
|
index index.html index.htm index.nginx-debian.html index.php;
|
||||||
|
|
||||||
|
server_name _;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
# First attempt to serve request as file, then
|
||||||
|
# as directory, then fall back to displaying a 404.
|
||||||
|
try_files $uri $uri/ =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
# pass PHP scripts to FastCGI server
|
||||||
|
location ~ \.php$ {
|
||||||
|
fastcgi_pass 127.0.0.1:9000;
|
||||||
|
fastcgi_index index.php;
|
||||||
|
include fastcgi.conf;
|
||||||
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||||
|
}
|
||||||
|
|
||||||
|
# deny access to .htaccess files, if Apache's document root
|
||||||
|
# concurs with nginx's one
|
||||||
|
location ~ /\.ht {
|
||||||
|
deny all;
|
||||||
|
}
|
||||||
|
|
||||||
|
## Images and static content is treated different
|
||||||
|
location ~* ^.+.(jpg|jpeg|gif|css|png|js|ico|xml)$ {
|
||||||
|
access_log off;
|
||||||
|
expires max;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~ /(libraries|setup/frames|setup/libs) {
|
||||||
|
deny all;
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /nginx_status {
|
||||||
|
stub_status on;
|
||||||
|
access_log off;
|
||||||
|
allow 127.0.0.1;
|
||||||
|
# allow CURRENT-SERVER-IP;
|
||||||
|
deny all;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en" dir="ltr">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<title>Alpine linux lemp</title>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<h1>Server is running</h1>
|
||||||
|
<?php phpinfo(); ?>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
apk add bash bash-doc bash-completion
|
||||||
|
|
||||||
|
sed -i 's/root:\/bin\/ash/root:\/bin\/bash/g' /etc/passwd
|
||||||
|
|||||||
@@ -0,0 +1,42 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
echo '
|
||||||
|
___ _ ___ _ _
|
||||||
|
| \ ___| |_| __(_) |___ ___
|
||||||
|
| |) / _ \ _| _|| | / -_|_-<
|
||||||
|
|___/\___/\__|_| |_|_\___/__/
|
||||||
|
'
|
||||||
|
#installing better prompt and some goodies
|
||||||
|
echo "Installing shell prompt for current user $USER "
|
||||||
|
sleep 2
|
||||||
|
#
|
||||||
|
# # get the current position
|
||||||
|
# _cwd="$(pwd)"
|
||||||
|
#
|
||||||
|
# # check for assets forlder
|
||||||
|
# _assets="$_cwd/assets"
|
||||||
|
# if [ ! -d "$_assets" ]; then
|
||||||
|
# _assets="$_cwd/../assets"
|
||||||
|
# if [ ! -d "$_assets" ]; then
|
||||||
|
# echo "!! can't find assets directory !!"
|
||||||
|
# exit
|
||||||
|
# fi
|
||||||
|
# fi
|
||||||
|
#
|
||||||
|
# cp "$_assets"/dotfiles/.vimrc /home/"$USER"/
|
||||||
|
# cp -r "$_assets"/dotfiles/.vim /home/"$USER"/
|
||||||
|
#
|
||||||
|
# cp "$_assets"/dotfiles/.inputrc /home/"$USER"/
|
||||||
|
|
||||||
|
|
||||||
|
# get the current position
|
||||||
|
_cwd="$(pwd)"
|
||||||
|
# go to user home
|
||||||
|
cd
|
||||||
|
echo "cloning https://figureslibres.io/gogs/bachir/dotfiles-server.git"
|
||||||
|
git clone https://figureslibres.io/gogs/bachir/dotfiles-server.git ~/.dotfiles-server && cd ~/.dotfiles-server && ./install.sh && cd ~
|
||||||
|
source ~/.bashrc
|
||||||
|
# return to working directory
|
||||||
|
cd "$_cwd"
|
||||||
|
|
||||||
|
echo "Dot files installed for $USER"
|
||||||
+10
-8
@@ -1,13 +1,12 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo '\033[35m
|
echo '
|
||||||
__ ______ ______
|
__ __ _ _
|
||||||
/ |/ / | / _/ /
|
| \/ |__ _(_) |
|
||||||
/ /|_/ / /| | / // /
|
| |\/| / _` | | |
|
||||||
/ / / / ___ |_/ // /___
|
|_| |_\__,_|_|_|
|
||||||
/_/ /_/_/ |_/___/_____/
|
'
|
||||||
\033[0m'
|
echo "Enable mail sending for php"
|
||||||
echo "\033[35;1mEnable mail sending for php \033[0m"
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
@@ -28,6 +27,9 @@ sleep 2
|
|||||||
|
|
||||||
apk add mailx postfix
|
apk add mailx postfix
|
||||||
|
|
||||||
|
mkdir /var/mail
|
||||||
|
postmap /etc/postfix/aliases
|
||||||
|
|
||||||
rc-update add postfix
|
rc-update add postfix
|
||||||
/etc/init.d/postfix start
|
/etc/init.d/postfix start
|
||||||
|
|
||||||
|
|||||||
+8
-9
@@ -1,13 +1,12 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
______ _ _____ __
|
___ _ _ ___ _
|
||||||
/ ____/___ _(_) /__ \ / /_ ____ _____
|
| __|_ _(_) |_ ) |__ __ _ _ _
|
||||||
/ /_ / __ `/ / /__/ // __ \/ __ `/ __ \
|
| _/ _` | | |/ /| ._ \/ _` | . \
|
||||||
/ __/ / /_/ / / // __// /_/ / /_/ / / / /
|
|_|\__,_|_|_/___|_.__/\__,_|_||_|
|
||||||
/_/ \__,_/_/_//____/_.___/\__,_/_/ /_/
|
'
|
||||||
\033[0m'
|
echo -e "Installing fall2ban"
|
||||||
echo -e "\033[35;1mInstalling fall2ban \033[0m"
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
@@ -21,4 +20,4 @@ rc-update add fail2ban
|
|||||||
# service fail2ban start
|
# service fail2ban start
|
||||||
/etc/init.d/fail2ban start
|
/etc/init.d/fail2ban start
|
||||||
|
|
||||||
echo -e "\033[92;1mfail2ban installed and configured\033[Om"
|
echo -e "fail2ban installed"
|
||||||
|
|||||||
+9
-10
@@ -2,14 +2,13 @@
|
|||||||
|
|
||||||
# TODO check if root
|
# TODO check if root
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
__ __ __
|
_ __ _
|
||||||
/ /______ ____ _____/ /______/ /
|
| |/ /_ _ ___ __| |__
|
||||||
/ //_/ __ \/ __ \/ ___/ //_/ __ /
|
| . <| . \/ _ \/ _| / /
|
||||||
/ ,< / / / / /_/ / /__/ ,< / /_/ /
|
|_|\_\_||_\___/\__|_\_\
|
||||||
/_/|_/_/ /_/\____/\___/_/|_|\__,_/
|
'
|
||||||
\033[0m'
|
echo -e "Installing knockd to control ssh port opening"
|
||||||
echo -e "\033[35;1mInstalling knockd to control ssh port opening\033[0m"
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
@@ -49,7 +48,7 @@ rc-update add knockd
|
|||||||
|
|
||||||
ufw delete allow ssh
|
ufw delete allow ssh
|
||||||
|
|
||||||
echo -e "\033[92;1mknockd installed and configured\033[Om"
|
echo -e "knockd installed and configured"
|
||||||
echo -e "\033[92;1mplease note this sequence for future ssh knocking\033[Om"
|
echo -e "please note this sequence for future ssh knocking"
|
||||||
echo "$sq"
|
echo "$sq"
|
||||||
sleep 3
|
sleep 3
|
||||||
|
|||||||
Executable → Regular
+275
@@ -1 +1,276 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
_
|
||||||
|
| |___ _ __ _ __
|
||||||
|
| / -_) ' \| '_ \
|
||||||
|
|_\___|_|_|_| .__/
|
||||||
|
|_|
|
||||||
|
'
|
||||||
|
echo -e "LEMP server (Nginx Mysql Php-fpm)"
|
||||||
|
|
||||||
|
. bin/checkroot.sh
|
||||||
|
|
||||||
|
# get the current position
|
||||||
|
_cwd="$(pwd)"
|
||||||
|
# check for assets forlder
|
||||||
|
_assets="$_cwd/assets"
|
||||||
|
if [ ! -d "$_assets" ]; then
|
||||||
|
_assets="$_cwd/../assets"
|
||||||
|
if [ ! -d "$_assets" ]; then
|
||||||
|
echo "!! can't find assets directory !!"
|
||||||
|
exit
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
sleep 2
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
_
|
||||||
|
_ __ _ _ ___ __ _| |
|
||||||
|
| . \ || (_-</ _` | |
|
||||||
|
|_|_|_\_, /__/\__, |_|
|
||||||
|
|__/ |_|
|
||||||
|
'
|
||||||
|
echo -e "installing Mysql"
|
||||||
|
sleep 3
|
||||||
|
apk add mariadb mariadb-client
|
||||||
|
|
||||||
|
# https://bugs.alpinelinux.org/issues/9046
|
||||||
|
|
||||||
|
DB_DATA_PATH="/var/lib/mysql"
|
||||||
|
DB_ROOT_PASS="mariadb_root_password"
|
||||||
|
DB_USER="mariadb_user"
|
||||||
|
DB_PASS="mariadb_user_password"
|
||||||
|
MAX_ALLOWED_PACKET="200M"
|
||||||
|
|
||||||
|
mysql_install_db --user=mysql --datadir=${DB_DATA_PATH}
|
||||||
|
|
||||||
|
rc-update add mariadb
|
||||||
|
service mariadb start
|
||||||
|
echo -e "mysql installed"
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
_
|
||||||
|
_ __| |_ _ __
|
||||||
|
| `_ \ ` \| `_ \
|
||||||
|
| .__/_||_| .__/
|
||||||
|
|_| |_|
|
||||||
|
'
|
||||||
|
echo -e "Installing PHP 7.0"
|
||||||
|
sleep 3
|
||||||
|
apk add php7 php7-fpm php7-pdo_mysql php7-opcache php7-curl php7-mbstring php7-zip php7-xml php7-gd php7-mcrypt php7-imagick
|
||||||
|
|
||||||
|
echo -e "Configuring PHP"
|
||||||
|
|
||||||
|
sed -i "s/memory_limit\ =\ 128M/memory_limit = 512M/g" /etc/php7/php.ini
|
||||||
|
|
||||||
|
TIMEZONE="Europe/Helsinki"
|
||||||
|
sed -i "s|;*date.timezone =.*|date.timezone = ${TIMEZONE}|i" /etc/php7/php.ini
|
||||||
|
|
||||||
|
rc-update add php-fpm7
|
||||||
|
service php-fpm7 start
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
echo -e "php installed"
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
_
|
||||||
|
_ _ __ _(_)_ _ __ __
|
||||||
|
| ` \/ _` | | ` \\ \ /
|
||||||
|
|_||_\__, |_|_||_/_\_\
|
||||||
|
|___/
|
||||||
|
'
|
||||||
|
echo -e "Installing Nginx"
|
||||||
|
sleep 3
|
||||||
|
apk add nginx
|
||||||
|
|
||||||
|
adduser -D -g 'www' www
|
||||||
|
mkdir -p /var/www/html
|
||||||
|
chown -R www:www /var/lib/nginx
|
||||||
|
chown -R www:www /var/www/html
|
||||||
|
|
||||||
|
mv /etc/nginx/conf.d/default.conf /etc/nginx/conf.d/default.ori
|
||||||
|
cp "$_assets"/default.nginxconf /etc/nginx/conf.d/default.conf
|
||||||
|
cp "$_assets"/index.php /var/www/html/
|
||||||
|
|
||||||
|
rc-update add nginx
|
||||||
|
service nginx start
|
||||||
|
echo -e "Nginx installed"
|
||||||
|
|
||||||
|
# echo -e '
|
||||||
|
# _ __ __ _ _ _
|
||||||
|
# _ __| |_ _ __| \/ |_ _ /_\ __| |_ __ (_)_ _
|
||||||
|
# | `_ \ ` \| `_ \ |\/| | || |/ _ \/ _` | ` \| | ` \
|
||||||
|
# | .__/_||_| .__/_| |_|\_, /_/ \_\__,_|_|_|_|_|_||_|
|
||||||
|
# |_| |_| |__/
|
||||||
|
# '
|
||||||
|
# echo -e "Installing phpMyAdmin"
|
||||||
|
# apk add phpmyadmin
|
||||||
|
# ln -s /usr/share/phpmyadmin /var/www/html/
|
||||||
|
# cp "$_assets"/nginx-phpmyadmin.conf > /etc/nginx/sites-available/phpmyadmin.conf
|
||||||
|
# ln -s /etc/nginx/sites-available/phpmyadmin.conf /etc/nginx/sites-enabled/phpmyadmin.conf
|
||||||
|
#
|
||||||
|
# # echo -e "securing phpMyAdmin"
|
||||||
|
# # sed -i "s/DirectoryIndex index.php/DirectoryIndex index.php\nAllowOverride all/"
|
||||||
|
# # cp "$_assets"/phpmyadmin_htaccess > /usr/share/phpmyadmin/.htaccess
|
||||||
|
# # echo -n "define a user name for phpmyadmin : "
|
||||||
|
# # read un
|
||||||
|
# # htpasswd -c /etc/phpmyadmin/.htpasswd $un
|
||||||
|
# # service apache2 restart
|
||||||
|
# echo -e "phpMyAdmin installed"
|
||||||
|
# echo -e "You can access it at yourip/phpmyadmin"
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
____ ___
|
||||||
|
/ __ \___ ____/ (_)____
|
||||||
|
/ /_/ / _ \/ __ / / ___/
|
||||||
|
/ _, _/ __/ /_/ / (__ )
|
||||||
|
/_/ |_|\___/\__,_/_/____/
|
||||||
|
'
|
||||||
|
echo -e "Installing Redis"
|
||||||
|
sleep 3
|
||||||
|
apk add redis-server php-redis
|
||||||
|
|
||||||
|
# TODO set maxmemory=2gb
|
||||||
|
# TODO set maxmemory-policy=volatile-lru
|
||||||
|
# TODO comment all save line
|
||||||
|
|
||||||
|
|
||||||
|
systemctl enable redis-server
|
||||||
|
systemctl restart redis-server
|
||||||
|
systemctl restart php7.0-fpm
|
||||||
|
echo -e "Redis installed"
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
______
|
||||||
|
/ ____/___ ____ ___ ____ ____ ________ _____
|
||||||
|
/ / / __ \/ __ `__ \/ __ \/ __ \/ ___/ _ \/ ___/
|
||||||
|
/ /___/ /_/ / / / / / / /_/ / /_/ (__ ) __/ /
|
||||||
|
\____/\____/_/ /_/ /_/ .___/\____/____/\___/_/
|
||||||
|
/_/
|
||||||
|
'
|
||||||
|
echo -e "Installing Composer"
|
||||||
|
sleep 3
|
||||||
|
export COMPOSER_HOME=/usr/local/composer
|
||||||
|
curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer
|
||||||
|
|
||||||
|
echo -e "Composer installed"
|
||||||
|
|
||||||
|
|
||||||
|
echo -e '
|
||||||
|
____ __
|
||||||
|
/ __ \_______ _______/ /_
|
||||||
|
/ / / / ___/ / / / ___/ __ \
|
||||||
|
/ /_/ / / / /_/ (__ ) / / /
|
||||||
|
/_____/_/ \__,_/____/_/ /_/
|
||||||
|
'
|
||||||
|
echo -e "Installing Drush and DrupalConsole"
|
||||||
|
sleep 3
|
||||||
|
curl https://drupalconsole.com/installer -L -o /usr/local/bin/drupal
|
||||||
|
chmod +x /usr/local/bin/drupal
|
||||||
|
curl https://github.com/drush-ops/drush-launcher/releases/download/0.6.0/drush.phar -L -o /usr/local/bin/drush
|
||||||
|
chmod +x /usr/local/bin/drush
|
||||||
|
echo -e "Drush and DrupalConsoleinstalled"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# TODO supervising
|
||||||
|
# echo -e '
|
||||||
|
# __ ___ _ __ __ __ ___ _
|
||||||
|
# / |/ /__ ___ (_) /_ _/_/ / |/ /_ _____ (_)__
|
||||||
|
# / /|_/ / _ \/ _ \/ / __/ _/_/ / /|_/ / // / _ \/ / _ \
|
||||||
|
# /_/ /_/\___/_//_/_/\__/ /_/ /_/ /_/\_,_/_//_/_/_//_/
|
||||||
|
#'
|
||||||
|
# echo -e "Installing Munin"
|
||||||
|
# sleep 3
|
||||||
|
# # https://www.howtoforge.com/tutorial/server-monitoring-with-munin-and-monit-on-debian/
|
||||||
|
# apt-get --yes --force-yes install munin munin-node munin-plugins-extra
|
||||||
|
# # Configure Munin
|
||||||
|
# # enable plugins
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_ /etc/munin/plugins/mysql_
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_bytes /etc/munin/plugins/mysql_bytes
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_innodb /etc/munin/plugins/mysql_innodb
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_isam_space_ /etc/munin/plugins/mysql_isam_space_
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_queries /etc/munin/plugins/mysql_queries
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_slowqueries /etc/munin/plugins/mysql_slowqueries
|
||||||
|
# ln -s /usr/share/munin/plugins/mysql_threads /etc/munin/plugins/mysql_threads
|
||||||
|
#
|
||||||
|
# ln -s /usr/share/munin/plugins/apache_accesses /etc/munin/plugins/
|
||||||
|
# ln -s /usr/share/munin/plugins/apache_processes /etc/munin/plugins/
|
||||||
|
# ln -s /usr/share/munin/plugins/apache_volume /etc/munin/plugins/
|
||||||
|
#
|
||||||
|
# # ln -s /usr/share/munin/plugins/fail2ban /etc/munin/plugins/
|
||||||
|
#
|
||||||
|
# # dbdir, htmldir, logdir, rundir, and tmpldir
|
||||||
|
# sed -i 's/^#dbdir/dbdir/' /etc/munin/munin.conf
|
||||||
|
# sed -i 's/^#htmldir/htmldir/' /etc/munin/munin.conf
|
||||||
|
# sed -i 's/^#logdir/logdir/' /etc/munin/munin.conf
|
||||||
|
# sed -i 's/^#rundir/rundir/' /etc/munin/munin.conf
|
||||||
|
# sed -i 's/^#tmpldir/tmpldir/' /etc/munin/munin.conf
|
||||||
|
#
|
||||||
|
# sed -i "s/^\[localhost.localdomain\]/[${HOSTNAME}]/" /etc/munin/munin.conf
|
||||||
|
#
|
||||||
|
# # ln -s /etc/munin/apache24.conf /etc/apache2/conf-enabled/munin.conf
|
||||||
|
# sed -i 's/Require local/Require all granted\nOptions FollowSymLinks SymLinksIfOwnerMatch/g' /etc/munin/apache24.conf
|
||||||
|
# htpasswd -c /etc/munin/munin-htpasswd admin
|
||||||
|
# sed -i 's/Require all granted/AuthUserFile \/etc\/munin\/munin-htpasswd\nAuthName "Munin"\nAuthType Basic\nRequire valid-user/g' /etc/munin/apache24.conf
|
||||||
|
#
|
||||||
|
#
|
||||||
|
# service apache2 restart
|
||||||
|
# service munin-node restart
|
||||||
|
# echo -e "Munin installed"
|
||||||
|
#
|
||||||
|
# echo -e "Installing Monit"
|
||||||
|
# sleep 3
|
||||||
|
# # https://www.howtoforge.com/tutorial/server-monitoring-with-munin-and-monit-on-debian/2/
|
||||||
|
# apt-get --yes --force-yes install monit
|
||||||
|
# # TODO setup monit rc
|
||||||
|
# cat "$_assets"/monitrc > /etc/monit/monitrc
|
||||||
|
#
|
||||||
|
# # TODO setup webaccess
|
||||||
|
# passok=0
|
||||||
|
# while [ "$passok" = "0" ]
|
||||||
|
# do
|
||||||
|
# echo -n "Write web access password to monit"
|
||||||
|
# read passwda
|
||||||
|
# echo -n "ReWrite web access password to monit"
|
||||||
|
# read passwdb
|
||||||
|
# if [ "$passwda" = "$passwdb" ]; then
|
||||||
|
# sed -i 's/PASSWD_TO_REPLACE/$passwda/g' /etc/monit/monitrc
|
||||||
|
# passok=1
|
||||||
|
# else
|
||||||
|
# echo -e "pass words don't match, please try again"
|
||||||
|
# fi
|
||||||
|
# done
|
||||||
|
#
|
||||||
|
# # TODO setup mail settings
|
||||||
|
# sed -i "s/server1\.example\.com/$HOSTNAME/g" /etc/monit/monitrc
|
||||||
|
#
|
||||||
|
# mkdir /var/www/html/monit
|
||||||
|
# echo -e "hello" > /var/www/html/monit/token
|
||||||
|
#
|
||||||
|
# service monit start
|
||||||
|
#
|
||||||
|
# echo -e "Monit installed"
|
||||||
|
|
||||||
|
|
||||||
|
# echo -e '
|
||||||
|
# ___ __ __
|
||||||
|
# / |_ _______/ /_____ _/ /_
|
||||||
|
# / /| | | /| / / ___/ __/ __ `/ __/
|
||||||
|
# / ___ | |/ |/ (__ ) /_/ /_/ / /_
|
||||||
|
# /_/ |_|__/|__/____/\__/\__,_/\__/
|
||||||
|
#'
|
||||||
|
# echo -e "Installing Awstat"
|
||||||
|
# sleep 3
|
||||||
|
# apt-get --yes --force-yes install awstats
|
||||||
|
# # Configure AWStats
|
||||||
|
# temp=`grep -i sitedomain /etc/awstats/awstats.conf.local | wc -l`
|
||||||
|
# if [ $temp -lt 1 ]; then
|
||||||
|
# echo SiteDomain="$_domain" >> /etc/awstats/awstats.conf.local
|
||||||
|
# fi
|
||||||
|
# # Disable Awstats from executing every 10 minutes. Put a hash in front of any line.
|
||||||
|
# sed -i 's/^[^#]/#&/' /etc/cron.d/awstats
|
||||||
|
# echo -e "Awstat installed"
|
||||||
|
|||||||
+10
-8
@@ -1,13 +1,11 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
__ ____
|
__ __ _
|
||||||
/ |/ (_)_________
|
| \/ (_)___ __
|
||||||
/ /|_/ / / ___/ ___/
|
| |\/| | (_-</ _|
|
||||||
/ / / / (__ ) /__
|
|_| |_|_/__/\__|
|
||||||
/_/ /_/_/____/\___/
|
'
|
||||||
|
|
||||||
\033[0m'
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
@@ -24,5 +22,9 @@ apk add vim curl
|
|||||||
# dpkg-reconfigure tzdata
|
# dpkg-reconfigure tzdata
|
||||||
apk add tmux etckeeper htop lynx unzip # needrestart
|
apk add tmux etckeeper htop lynx unzip # needrestart
|
||||||
|
|
||||||
|
apk add tzdata
|
||||||
|
TIMEZONE="Europe/Paris"
|
||||||
|
cp /usr/share/zoneinfo/${TIMEZONE} /etc/localtime
|
||||||
|
echo "${TIMEZONE}" > /etc/timezone
|
||||||
|
|
||||||
echo -e "\033[92;1mMisc done \033[Om"
|
echo -e "\033[92;1mMisc done \033[Om"
|
||||||
|
|||||||
+8
-9
@@ -1,17 +1,16 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo '\033[35m
|
echo '
|
||||||
__________ __ __
|
_
|
||||||
/ ___/ ___// / / /
|
_____| |_
|
||||||
\__ \\__ \/ /_/ /
|
(_-<_-< . \
|
||||||
___/ /__/ / __ /
|
/__/__/_||_|
|
||||||
/____/____/_/ /_/
|
'
|
||||||
\033[0m'
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
sed -i 's/#PermitRootLogin\ prohibit-password/PermitRootLogin no/g' /etc/ssh/sshd_config
|
sed -i 's/#PermitRootLogin\ prohibit-password/PermitRootLogin prohibit-password/g' /etc/ssh/sshd_config
|
||||||
sed -i 's/#PermitEmptyPasswords\ yes/PermitEmptyPasswords no/g' /etc/ssh/sshd_config
|
sed -i 's/#PermitEmptyPasswords\ yes/PermitEmptyPasswords no/g' /etc/ssh/sshd_config
|
||||||
|
|
||||||
/etc/init.d/sshd restart
|
/etc/init.d/sshd restart
|
||||||
echo "\033[92;1mSSH secured\033[Om"
|
echo "SSH secured"
|
||||||
|
|||||||
+8
-9
@@ -1,13 +1,12 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
______________ _______ _____ __ __
|
_ _ _____ __
|
||||||
/ ____/ _/ __ \/ ____/ | / / | / / / /
|
| | | | __\ \ / /
|
||||||
/ /_ / // /_/ / __/ | | /| / / /| | / / / /
|
| |_| | _| \ \/\/ /
|
||||||
/ __/ _/ // _, _/ /___ | |/ |/ / ___ |/ /___/ /___
|
\___/|_| \_/\_/
|
||||||
/_/ /___/_/ |_/_____/ |__/|__/_/ |_/_____/_____/
|
'
|
||||||
\033[0m'
|
echo -e "Installing ufw and setup firewall (allowing only ssh and http)"
|
||||||
echo -e "\033[35;1mInstalling ufw and setup firewall (allowing only ssh and http) \033[0m"
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
sleep 2
|
sleep 2
|
||||||
@@ -23,4 +22,4 @@ ufw allow https
|
|||||||
|
|
||||||
ufw enable
|
ufw enable
|
||||||
ufw status verbose
|
ufw status verbose
|
||||||
echo -e "\033[92;1mufw installed and firwall configured\033[Om"
|
echo -e "ufw installed and firwall configured"
|
||||||
|
|||||||
+7
-7
@@ -2,13 +2,13 @@
|
|||||||
|
|
||||||
# TODO check if root
|
# TODO check if root
|
||||||
|
|
||||||
echo '\033[35m
|
echo -e '
|
||||||
__ ______ __________ ___ ____ ______
|
_ _ _
|
||||||
/ / / / __ \/ ____/ __ \/ | / __ \/ ____/
|
| | | |_ __ __ _ _ _ __ _ __| |___
|
||||||
/ / / / /_/ / / __/ /_/ / /| | / / / / __/
|
| |_| | ._ \/ _` | ._/ _. / _. / -_)
|
||||||
/ /_/ / ____/ /_/ / _, _/ ___ |/ /_/ / /___
|
\___/| .__/\__, |_| \__,_\__,_\___|
|
||||||
\____/_/ \____/_/ |_/_/ |_/_____/_____/
|
|_| |___/
|
||||||
\033[0m'
|
'
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
|
|||||||
+12
-9
@@ -1,13 +1,12 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
__ _______ __________
|
_ _
|
||||||
/ / / / ___// ____/ __ \
|
| | | |___ ___ _ _
|
||||||
/ / / /\__ \/ __/ / /_/ /
|
| |_| (_-</ -_) ._|
|
||||||
/ /_/ /___/ / /___/ _, _/
|
\___//__/\___|_|
|
||||||
\____//____/_____/_/ |_|
|
'
|
||||||
\033[0m'
|
echo -e "Create new user (you will be asked a user name and a password)"
|
||||||
echo -e "\033[35;1mCreate new user (you will be asked a user name and a password) \033[0m"
|
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
|
|
||||||
@@ -37,10 +36,14 @@ done
|
|||||||
|
|
||||||
# read -p "Continue? (Y/N): " confirm && [[ $confirm == [yY] || $confirm == [yY][eE][sS] ]] || exit 1
|
# read -p "Continue? (Y/N): " confirm && [[ $confirm == [yY] || $confirm == [yY][eE][sS] ]] || exit 1
|
||||||
adduser "$user"
|
adduser "$user"
|
||||||
|
|
||||||
|
sed -i "s/$user:\/bin\/ash/$user:\/bin\/bash/g" /etc/passwd
|
||||||
|
|
||||||
# TODO limiting su to the admin group
|
# TODO limiting su to the admin group
|
||||||
# echo "adding $user to admin group and limiting su to the admin group"
|
# echo "adding $user to admin group and limiting su to the admin group"
|
||||||
# groupadd admin
|
# groupadd admin
|
||||||
# usermod -a -G admin "$user"
|
# usermod -a -G admin "$user"
|
||||||
# allow admin group to su
|
# allow admin group to su
|
||||||
# dpkg-statoverride --update --add root admin 4750 /bin/su
|
# dpkg-statoverride --update --add root admin 4750 /bin/su
|
||||||
# echo -e "\033[92;1muser $user configured\033[Om"
|
|
||||||
|
echo -e "user $user configured"
|
||||||
|
|||||||
+8
-6
@@ -1,12 +1,12 @@
|
|||||||
#! /bin/sh
|
#! /bin/sh
|
||||||
|
|
||||||
echo -e '\033[35m
|
echo -e '
|
||||||
_ _ _ _ ___ __ __ ___
|
_ _ _ _ ___ __ __ ___
|
||||||
/_\ | |_ __(_)_ _ ___ | | | __| \/ | _ \
|
/_\ | |_ __(_)_ _ ___ | | | __| \/ | _ \
|
||||||
/ _ \| | '_ \ | ' \/ -_) | |__| _|| |\/| | _/
|
/ _ \| | ._ \ | . \/ -_) | |__| _|| |\/| | _/
|
||||||
/_/ \_\_| .__/_|_||_\___| |____|___|_| |_|_|
|
/_/ \_\_| .__/_|_||_\___| |____|___|_| |_|_|
|
||||||
|_|
|
|_|
|
||||||
\033[0m'
|
'
|
||||||
echo -e "\033[35;1mThis script has been tested only on Alpine Linux \033[0m"
|
echo -e "\033[35;1mThis script has been tested only on Alpine Linux \033[0m"
|
||||||
|
|
||||||
. bin/checkroot.sh
|
. bin/checkroot.sh
|
||||||
@@ -23,11 +23,13 @@ fi
|
|||||||
_cwd="$(pwd)"
|
_cwd="$(pwd)"
|
||||||
|
|
||||||
. bin/upgrade
|
. bin/upgrade
|
||||||
|
. bin/dotfiles.sh
|
||||||
|
. bin/bash
|
||||||
. bin/user.sh
|
. bin/user.sh
|
||||||
|
. bin/ssh.sh
|
||||||
. bin/misc.sh
|
. bin/misc.sh
|
||||||
. bin/ufw.sh
|
. bin/ufw.sh
|
||||||
. bin/fail2ban.sh
|
. bin/fail2ban.sh
|
||||||
. bin/knockd.sh
|
. bin/knockd.sh
|
||||||
|
# . bin/email.sh
|
||||||
|
. bin/lemp.sh
|
||||||
# . bin/lemp.sh
|
|
||||||
|
|||||||
Reference in New Issue
Block a user