Compare commits

...

10 Commits

13 changed files with 129 additions and 42 deletions

View File

@ -6,6 +6,7 @@ cd ./public_html
echo "" echo ""
echo "Pulling down latest code." echo "Pulling down latest code."
git pull --ff-only origin prod git pull --ff-only origin prod
git submodule update --init --recursive
echo "" echo ""
echo "Clearing drush caches." echo "Clearing drush caches."
drush cache-clear drush drush cache-clear drush

View File

@ -116,7 +116,7 @@ server {
fastcgi_intercept_errors on; fastcgi_intercept_errors on;
# fastcgi_buffer_size 16k; # fastcgi_buffer_size 16k;
# fastcgi_buffers 4 16k; # fastcgi_buffers 4 16k;
fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_pass unix:/run/php/php8.1-fpm.sock;
} }
# Fighting with Styles? This little gem is amazing. # Fighting with Styles? This little gem is amazing.
# location ~ ^/sites/.*/files/imagecache/ { # For Drupal <= 6 # location ~ ^/sites/.*/files/imagecache/ { # For Drupal <= 6

View File

@ -48,7 +48,7 @@ server {
location ~ \.php$ { location ~ \.php$ {
fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:/run/php/php7.4-fpm.sock; fastcgi_pass unix:/run/php/php8.1-fpm.sock;
fastcgi_index index.php; fastcgi_index index.php;
include fastcgi_params; include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;

View File

@ -24,7 +24,7 @@ server {
location ~ \.php$ { location ~ \.php$ {
fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:/run/php/php7.4-fpm.sock; fastcgi_pass unix:/run/php/php8.1-fpm.sock;
fastcgi_index index.php; fastcgi_index index.php;
include fastcgi_params; include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;

View File

@ -1,7 +1,8 @@
#!/bin/bash #!/bin/bash
# update bare repos # update bare repos
git --git-dir=git-repositories/DOMAIN.git fetch origin prod:prod echo "Updating bare repos"
su -c "git --git-dir=git-repositories/DOMAIN.git fetch origin prod:prod" USER
# deploy prod # deploy prod
cd www/DOMAIN/ cd www/DOMAIN/
./deploy.sh su -c "./deploy.sh" USER

View File

@ -0,0 +1 @@
UserParameter=linux.system.name.version,(lsb_release -d > dev/null 2>&1) && lsb_release -d || (cat /etc/centos-release > /dev/null > /dev/null 2>&1 && cat /etc/centos-release || cat /etc/redhat-release)

View File

@ -111,11 +111,11 @@ if [ "$vh" = "yes" ]; then
chmod +x post-receive # pre-receive chmod +x post-receive # pre-receive
# setup git repo on site folder # setup git repo on site folder
chown -R "$user":"$user" /home/"$user"/www/"$_domain"/public_html
cd /home/"$user"/www/"$_domain"/public_html cd /home/"$user"/www/"$_domain"/public_html
git init su -c "git init" $user
# link to the bare repo # link to the bare repo
git remote add origin /home/"$user"/git-repositories/"$_domain".git su -c "git remote add origin /home/$user/git-repositories/$_domain.git" $user
chown -R "$user":"$user" /home/"$user"/www/"$_domain"
cd "$_cwd" cd "$_cwd"

View File

@ -58,10 +58,13 @@ sleep 3
# apt-get --yes install php7.4-fpm php7.4-mysql php7.4-opcache php7.4-curl php7.4-mbstring php7.4-zip php7.4-xml php7.4-gd php-memcached php7.4-imagick php7.4-apcu # apt-get --yes install php7.4-fpm php7.4-mysql php7.4-opcache php7.4-curl php7.4-mbstring php7.4-zip php7.4-xml php7.4-gd php-memcached php7.4-imagick php7.4-apcu
# php7.4-mcrypt ?? # php7.4-mcrypt ??
apt-get --yes install php8.1-fpm php8.1-mysql php8.1-opcache php8.1-curl php8.1-mbstring php8.1-zip php8.1-xml php8.1-gd php-memcached php8.1-imagick php8.1-apcu php8.1-redis php8.1-bz2 php8.1-bcmath apt-get --yes install php8.1-fpm php8.1-mysql php8.1-opcache php8.1-curl php8.1-mbstring php8.1-zip php8.1-xml php8.1-gd php8.1-memcached php8.1-imagick php8.1-apcu php8.1-redis php8.1-bz2 php8.1-bcmath
# apt-get --yes install php8.2-fpm php8.2-mysql php8.2-opcache php8.2-curl php8.2-mbstring php8.2-zip php8.2-xml php8.2-gd php-memcached php8.2-imagick php8.2-apcu php8.2-redis php8.2-bz2 php8.2-bcmath # apt-get --yes install php8.2-fpm php8.2-mysql php8.2-opcache php8.2-curl php8.2-mbstring php8.2-zip php8.2-xml php8.2-gd php-memcached php8.2-imagick php8.2-apcu php8.2-redis php8.2-bz2 php8.2-bcmath
# apt-get --yes install php8.3-fpm php8.3-mysql php8.3-opcache php8.3-curl php8.3-mbstring php8.3-zip php8.3-xml php8.3-gd php8.3-memcached php8.3-imagick php8.3-apcu php8.3-redis php8.3-bz2 php8.3-bcmath
mv /etc/php/8.1/fpm/php.ini /etc/php/8.1/fpm/php.ini.back mv /etc/php/8.1/fpm/php.ini /etc/php/8.1/fpm/php.ini.back
cp "$_assets"/php8.1-fpm.ini /etc/php/8.1/fpm/php.ini cp "$_assets"/php8.1-fpm.ini /etc/php/8.1/fpm/php.ini
@ -126,6 +129,9 @@ if [ "$installmysql" = "yes" ]; then
cp "$_assets"/mysql/innodb-file-per-table.cnf /etc/mysql/conf.d/ cp "$_assets"/mysql/innodb-file-per-table.cnf /etc/mysql/conf.d/
# you may increase memory
# innodb_buffer_pool_size = 1024M
systemctl enable mariadb.service systemctl enable mariadb.service
systemctl restart mariadb.service systemctl restart mariadb.service
echo -e "\033[92;1mmysql installed\033[Om" echo -e "\033[92;1mmysql installed\033[Om"
@ -222,11 +228,9 @@ echo -e '\033[35m
/ /_/ / / / /_/ (__ ) / / / / /_/ / / / /_/ (__ ) / / /
/_____/_/ \__,_/____/_/ /_/ /_____/_/ \__,_/____/_/ /_/
\033[0m' \033[0m'
echo -e "\033[35;1mInstalling Drush and DrupalConsole\033[0m" echo -e "\033[35;1mInstalling Drush\033[0m"
sleep 3 sleep 3
curl https://drupalconsole.com/installer -L -o /usr/local/bin/drupal
chmod +x /usr/local/bin/drupal
# curl https://github.com/drush-ops/drush-launcher/releases/download/0.6.0/drush.phar -L -o /usr/local/bin/drush # curl https://github.com/drush-ops/drush-launcher/releases/download/0.6.0/drush.phar -L -o /usr/local/bin/drush
wget -O /usr/local/bin/drush https://github.com/drush-ops/drush-launcher/releases/latest/download/drush.phar wget -O /usr/local/bin/drush https://github.com/drush-ops/drush-launcher/releases/latest/download/drush.phar
chmod +x /usr/local/bin/drush chmod +x /usr/local/bin/drush
echo -e "\033[92;1mDrush and DrupalConsoleinstalled\033[Om" echo -e "\033[92;1mDrush\033[Om"

44
bin/nfs.sh Normal file
View File

@ -0,0 +1,44 @@
#!/bin/sh
echo -e '\033[35m
__
_ __ / _|___
| _ \| |_/ __|
| | | | _\__ \
|_| |_|_| |___/
\033[0m'
echo -e "\033[35;1mLEMP server (Nginx Mysql Php-fpm) \033[0m"
apt install nfs-kernel-server
vim /etc/exports
mkdir /home/proxmox-backup
mkdir /home/urbackup
ufw allow from 37.187.134.71 to any port nfs
ufw allow from 37.187.134.71 to any port 111
ufw allow proto udp from 37.187.134.71 to any port 32764:32769
ufw allow proto tcp from 37.187.134.71 to any port 32764:32769
ufw allow from 37.187.93.155 to any port nfs
ufw allow from 37.187.93.155 to any port 111
ufw allow proto udp from 37.187.93.155 to any port 32764:32769
ufw allow proto tcp from 37.187.93.155 to any port 32764:32769
ufw allow from 37.187.128.147 to any port nfs
ufw allow from 37.187.128.147 to any port 111
ufw allow proto udp from 37.187.128.147 to any port 32764:32769
ufw allow proto tcp from 37.187.128.147 to any port 32764:32769
ufw allow from 94.23.8.104 to any port nfs
ufw allow from 94.23.8.104 to any port 111
ufw allow proto udp from 94.23.8.104 to any port 32764:32769
ufw allow proto tcp from 94.23.8.104 to any port 32764:32769
systemctl restart nfs-server
systemctl enable nfs-server
vim /etc/ufw/user.rules

View File

@ -41,16 +41,15 @@ apt install build-essential "g++" "libcrypto++-dev" libz-dev -y
# wget -P /tmp/ https://hndl.urbackup.org/Client/latest/urbackup-client-2.3.4.0.tar.gz # wget -P /tmp/ https://hndl.urbackup.org/Client/latest/urbackup-client-2.3.4.0.tar.gz
# wget -P /tmp/ https://hndl.urbackup.org/Client/2.4.11/urbackup-client-2.4.11.0.tar.gz # wget -P /tmp/ https://hndl.urbackup.org/Client/2.4.11/urbackup-client-2.4.11.0.tar.gz
# wget -P /tmp/ https://hndl.urbackup.org/Client/2.5.20/urbackup-client-2.5.20.0.tar.gz # wget -P /tmp/ https://hndl.urbackup.org/Client/2.5.20/urbackup-client-2.5.20.0.tar.gz
wget -P /tmp/ https://hndl.urbackup.org/Client/2.5.20/urbackup-client-2.5.24.0.tar.gz # wget -P /tmp/ https://hndl.urbackup.org/Client/2.5.20/urbackup-client-2.5.24.0.tar.gz
wget -P /tmp/ https://hndl.urbackup.org/Client/2.5.25/urbackup-client-2.5.25.0.tar.gz
cd /tmp cd /tmp
# tar xzf /tmp/urbackup-client-2.3.4.0.tar.gz
# tar xzf /tmp/urbackup-client-2.5.20.0.tar.gz tar xzf /tmp/urbackup-client-2.5.25.0.tar.gz
tar xzf /tmp/urbackup-client-2.5.24.0.tar.gz
# Build the UrBackup client and install it # Build the UrBackup client and install it
# cd /tmp/urbackup-client-2.3.4.0 # cd /tmp/urbackup-client-2.3.4.0
cd /tmp/urbackup-client-2.5.24.0 cd /tmp/urbackup-client-2.5.25.0
./configure --enable-headless ./configure --enable-headless
make -j4 make -j4
make install make install

View File

@ -90,10 +90,11 @@ apt-get install webhook
git --git-dir=/home/"$user"/git-repositories/"$_domain.git" remote add origin "$_remote" git --git-dir=/home/"$user"/git-repositories/"$_domain.git" remote add origin "$_remote"
# hook deploy script # hook deploy script
cp -f "$_assets"/webhook-deploy.sh /home/"$user"/webhook_deploy_"$_id".sh cp -f "$_assets"/webhook-deploy.sh /home/"$user"/webhook-deploy-"$_id".sh
sed -i -r "s/DOMAIN/$_domain/g" /home/"$user"/webhook_deploy_"$_id".sh sed -i -r "s/DOMAIN/$_domain/g" /home/"$user"/webhook-deploy-"$_id".sh
chowm $user:$user /home/"$user"/webhook_deploy_"$_id".sh sed -i -r "s/USER/$user/g" /home/"$user"/webhook-deploy-"$_id".sh
chmod +x /home/"$user"/webhook_deploy_"$_id".sh chowm $user:$user /home/"$user"/webhook-deploy-"$_id".sh
chmod +x /home/"$user"/webhook-deploy-"$_id".sh
# remove git bare repos hook # remove git bare repos hook
mv /home/"$user"/git-repositories/"$_domain".git/hooks/post-receive /home/"$user"/git-repositories/"$_domain".git/hooks/post-receive.back mv /home/"$user"/git-repositories/"$_domain".git/hooks/post-receive /home/"$user"/git-repositories/"$_domain".git/hooks/post-receive.back
@ -116,4 +117,6 @@ systemctl restart webhook
ufw allow 9000 ufw allow 9000
echo "webhook done"
echo "you can configure your webhook trigger with the following url :"
echo "http://$_domain:9000/hooks/deploy_app_$_id" echo "http://$_domain:9000/hooks/deploy_app_$_id"

View File

@ -41,8 +41,6 @@ echo -n "Please provide the zabbix-server's ip : "
read _ip read _ip
echo -n "Please provide the hostname of this agent : " echo -n "Please provide the hostname of this agent : "
read _host_name read _host_name
echo -n "Please provide the mysql root password : "
read _root_mysql_passwd
_agent_conf_d="/etc/zabbix/zabbix_agentd.d" # for debian 8 _agent_conf_d="/etc/zabbix/zabbix_agentd.d" # for debian 8
if [ ! -d "$_agent_conf_d" ]; then if [ ! -d "$_agent_conf_d" ]; then
@ -69,27 +67,44 @@ cp "$_assets"/zabbix/apt.conf "$_agent_conf_d"/
# MYSQL # MYSQL
# https://serverfault.com/questions/737018/zabbix-user-parameter-mysql-status-setting-home # https://serverfault.com/questions/737018/zabbix-user-parameter-mysql-status-setting-home
# create zabbix user home # create zabbix user home
mkdir /var/lib/zabbix
# generate random password for zabbix mysql user echo -n "monitor mysql? [Y|n] "
_passwd="$(< /dev/urandom tr -dc _A-Z-a-z-0-9 | head -c12)" read yn
# add mysql credentials to zabbix home yn=${yn:-y}
printf "[client]\n if [ "$yn" = "Y" ] || [ "$yn" = "y" ]; then
user=zabbix\n echo -n "Please provide the mysql root password : "
password=$_passwd" > /var/lib/zabbix/.my.cnf read _root_mysql_passwd
# create zabbix mysql user
mysql -uroot -p"$_root_mysql_passwd" -e "CREATE USER 'zabbix' IDENTIFIED BY '$_passwd';" mkdir /var/lib/zabbix
mysql -uroot -p"$_root_mysql_passwd" -e "GRANT USAGE ON *.* TO 'zabbix'@'localhost' IDENTIFIED BY '$_passwd';" # generate random password for zabbix mysql user
# add zabbix-agent parameter _passwd="$(< /dev/urandom tr -dc _A-Z-a-z-0-9 | head -c12)"
cp "$_assets"/zabbix/userparameter_mysql.conf "$_agent_conf_d"/ # add mysql credentials to zabbix home
printf "[client]\n
user=zabbix\n
password=$_passwd" > /var/lib/zabbix/.my.cnf
# create zabbix mysql user
mysql -uroot -p"$_root_mysql_passwd" -e "CREATE USER 'zabbix' IDENTIFIED BY '$_passwd';"
mysql -uroot -p"$_root_mysql_passwd" -e "GRANT USAGE ON *.* TO 'zabbix'@'localhost' IDENTIFIED BY '$_passwd';"
# add zabbix-agent parameter
cp "$_assets"/zabbix/userparameter_mysql.conf "$_agent_conf_d"/
fi
# NGINX # NGINX
# https://github.com/sfuerte/zbx-nginx # https://github.com/sfuerte/zbx-nginx
# nginxconf already included in default.nginxconf asset # nginxconf already included in default.nginxconf asset
sed -i "s/# allow CURRENT-SERVER-IP/allow $_cur_ip/g" /etc/nginx/sites-available/default
cp "$_assets"/zabbix/userparameter_nginx.conf "$_agent_conf_d"/ echo -n "Monitor nginx? [Y|n] "
mkdir /etc/zabbix/zabbix_agentd.scripts read yn
cp "$_assets"/zabbix/scripts/nginx-stat.py /etc/zabbix/zabbix_agentd.scripts/ yn=${yn:-y}
chmod +x /etc/zabbix/zabbix_agentd.scripts/nginx-stat.py if [ "$yn" = "Y" ] || [ "$yn" = "y" ]; then
sed -i "s/# allow CURRENT-SERVER-IP/allow $_cur_ip/g" /etc/nginx/sites-available/default
cp "$_assets"/zabbix/userparameter_nginx.conf "$_agent_conf_d"/
mkdir /etc/zabbix/zabbix_agentd.scripts
cp "$_assets"/zabbix/scripts/nginx-stat.py /etc/zabbix/zabbix_agentd.scripts/
chmod +x /etc/zabbix/zabbix_agentd.scripts/nginx-stat.py
fi
echo -n "This is box is a proxmox CT? [Y|n] " echo -n "This is box is a proxmox CT? [Y|n] "
read yn read yn
@ -101,6 +116,8 @@ fi
# SYSTEMD # SYSTEMD
# https://github.com/MogiePete/zabbix-systemd-service-monitoring # https://github.com/MogiePete/zabbix-systemd-service-monitoring
cp "$_assets"/zabbix/userparameter_systemd_services.conf "$_agent_conf_d"/ cp "$_assets"/zabbix/userparameter_systemd_services.conf "$_agent_conf_d"/
# https://www.zabbix.com/forum/zabbix-cookbook/23024-monitor-the-version-of-centos-debian-ubuntu?p=386466#post386466
cp "$_assets"/zabbix/userparameter_linux_name_version.conf "$_agent_conf_d"/
# disble unused system units # disble unused system units
systemctl disable rsync systemctl disable rsync

View File

@ -32,6 +32,23 @@ chmod a+x install.sh
``` ```
5 steps
* misc.sh
* dotfliles.sh
* user.sh
* ssh.sh
* firewall.sh
* fail2ban.sh
* email.sh
* lemp.sh
* mysqlbackup.sh
* vhost.sh
* gitbarrerepos.sh
* webhook.sh
* urbackup.sh
* zabbix.sh
*
## ref ## ref
http://www.debian.org/doc/manuals/securing-debian-howto/ http://www.debian.org/doc/manuals/securing-debian-howto/