Compare commits
2 Commits
14dc3fdefd
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| d98c7b8bdb | |||
| b735996b8d |
10
README.md
10
README.md
@@ -29,14 +29,20 @@ cp terraform.tfvars.example
|
|||||||
fill with your secrets (do no push this file)
|
fill with your secrets (do no push this file)
|
||||||
|
|
||||||
|
|
||||||
## usefull commandes
|
## Usefull commands
|
||||||
```sh
|
```sh
|
||||||
opentofu.tofu init
|
opentofu.tofu init
|
||||||
opentofu.tofu plan
|
opentofu.tofu plan
|
||||||
opentofu.tofu apply
|
opentofu.tofu apply
|
||||||
opentofu.tofu destroy
|
opentofu.tofu destroy
|
||||||
```
|
```
|
||||||
### on WSL
|
|
||||||
|
### SOPS for .env and secret management
|
||||||
|
```sh
|
||||||
|
sops -e modules/apps/<service>/.env > modules/apps/<service>/.env.enc
|
||||||
|
```
|
||||||
|
|
||||||
|
### On WSL
|
||||||
ssh agent could be off
|
ssh agent could be off
|
||||||
if `ssh-add -L` gives
|
if `ssh-add -L` gives
|
||||||
```sh
|
```sh
|
||||||
|
|||||||
42
main.tf
42
main.tf
@@ -18,27 +18,6 @@ provider "proxmox" {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
# module "bookshelf" {
|
|
||||||
# source = "./modules/vm"
|
|
||||||
|
|
||||||
# providers = {}
|
|
||||||
|
|
||||||
# name = "bookshelf"
|
|
||||||
# hostname = "bookshelf"
|
|
||||||
# domain = "aldon.fr"
|
|
||||||
# vm_id = 210
|
|
||||||
# node_name = "mop"
|
|
||||||
|
|
||||||
# template_id = 103
|
|
||||||
|
|
||||||
# cores = 1
|
|
||||||
# memory = 1024
|
|
||||||
# disk_size = 16
|
|
||||||
|
|
||||||
# ssh_public_key = var.ssh_public_key
|
|
||||||
# proxmox_host_ip = var.proxmox_host_ip
|
|
||||||
# }
|
|
||||||
|
|
||||||
module "gitea" {
|
module "gitea" {
|
||||||
source = "./modules/apps/gitea"
|
source = "./modules/apps/gitea"
|
||||||
providers = {}
|
providers = {}
|
||||||
@@ -58,3 +37,24 @@ module "gitea" {
|
|||||||
ssh_public_key = var.ssh_public_key
|
ssh_public_key = var.ssh_public_key
|
||||||
proxmox_host_ip = var.proxmox_host_ip
|
proxmox_host_ip = var.proxmox_host_ip
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
module "bookshelf" {
|
||||||
|
source = "./modules/apps/bookshelf"
|
||||||
|
providers = {}
|
||||||
|
|
||||||
|
name = "bookshelf"
|
||||||
|
hostname = "bookshelf"
|
||||||
|
domain = "aldon.fr"
|
||||||
|
vm_id = 211
|
||||||
|
node_name = "mop"
|
||||||
|
|
||||||
|
template_id = 103
|
||||||
|
|
||||||
|
cores = 1
|
||||||
|
memory = 1024
|
||||||
|
disk_size = 16
|
||||||
|
|
||||||
|
ssh_public_key = var.ssh_public_key
|
||||||
|
proxmox_host_ip = var.proxmox_host_ip
|
||||||
|
}
|
||||||
|
|||||||
20
modules/apps/bookshelf/.env.example
Normal file
20
modules/apps/bookshelf/.env.example
Normal file
@@ -0,0 +1,20 @@
|
|||||||
|
ACT_RUNNER_VERSION=0.2.13
|
||||||
|
ACT_RUNNER_LOCATION=/usr/local/bin
|
||||||
|
ACT_RUNNER_USER=act_runner
|
||||||
|
ENV_FILE_LOCATION=/opt/bookshelf/secrets/bookshelf.env
|
||||||
|
GITEA_INSTANCE_URL=https://gitea.aldon.fr
|
||||||
|
GITEA_RUNNER_REGISTRATION_TOKEN=<gitea-repository-runner-token>
|
||||||
|
GITEA_BOOKSHELF_APPLICATION_TOKEN=<gitea-auth-token>
|
||||||
|
GITEA_BOOKSHELF_REPOSITORY=mop/bookshelf
|
||||||
|
|
||||||
|
USERNAME=bookshelf
|
||||||
|
BOOKSHELF_BACKUPS_DIR=/backups/bookshelf
|
||||||
|
BOOKSHELF_BACKUP_PREFIX=bookshelf-dump
|
||||||
|
|
||||||
|
MARIADB_USER=bookshelf
|
||||||
|
MARIADB_PASSWORD=<mariadb-password>
|
||||||
|
MARIADB_DATABASE=Biblio
|
||||||
|
MARIADB_ROOT_PASSWORD=<mariadb-root-password>
|
||||||
|
SERVICE_SECRET_KEY=<bookshelf-secret-key>
|
||||||
|
SERVICE_ORIGIN=https://bookshelf.aldon.fr
|
||||||
|
SERVICE_ROOT_FQDN=https://bookshelf.aldon.fr/api
|
||||||
94
modules/apps/bookshelf/cloud-init/service.yaml
Normal file
94
modules/apps/bookshelf/cloud-init/service.yaml
Normal file
@@ -0,0 +1,94 @@
|
|||||||
|
#cloud-config
|
||||||
|
hostname: ${hostname}
|
||||||
|
local-hostname: ${hostname}
|
||||||
|
fqdn: ${hostname}.${domain}
|
||||||
|
manage_etc_hosts: true
|
||||||
|
|
||||||
|
users:
|
||||||
|
- default
|
||||||
|
- name: ${hostname}
|
||||||
|
groups: sudo
|
||||||
|
shell: /bin/bash
|
||||||
|
sudo: ALL=(ALL) NOPASSWD:ALL
|
||||||
|
ssh_authorized_keys:
|
||||||
|
- ${ssh_key}
|
||||||
|
|
||||||
|
disable_root: true
|
||||||
|
|
||||||
|
package_update: true
|
||||||
|
package_upgrade: false
|
||||||
|
|
||||||
|
packages:
|
||||||
|
- git
|
||||||
|
- nfs-common
|
||||||
|
- docker.io
|
||||||
|
- docker-compose
|
||||||
|
- curl
|
||||||
|
- jq
|
||||||
|
|
||||||
|
write_files:
|
||||||
|
- path: /etc/fstab
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${proxmox_host_ip}:/main/backups /backups nfs defaults,_netdev,x-systemd.requires=network-online.target 0 0
|
||||||
|
- path: /opt/bookshelf/env.sh
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${environment-setup-script}
|
||||||
|
- path: /opt/bookshelf/secrets/bookshelf.env
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${env-file-content}
|
||||||
|
- path: /usr/local/bin/restore-backup.sh
|
||||||
|
permissions: "0755"
|
||||||
|
content: |
|
||||||
|
${restore-backup-script}
|
||||||
|
- path: /etc/systemd/system/restore-backup.service
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${restore-backup-service}
|
||||||
|
- path: /usr/local/bin/backup.sh
|
||||||
|
permissions: "0755"
|
||||||
|
content: |
|
||||||
|
${create-backup-script}
|
||||||
|
- path: /etc/systemd/system/weekly-backup.timer
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${create-backup-timer}
|
||||||
|
- path: /etc/systemd/system/weekly-backup.service
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${create-backup-service}
|
||||||
|
- path: /etc/systemd/system/act_runner.service
|
||||||
|
permissions: "0644"
|
||||||
|
content: |
|
||||||
|
${act_runner-service}
|
||||||
|
- path: /opt/bookshelf/install-runner.sh
|
||||||
|
permissions: "0755"
|
||||||
|
content: |
|
||||||
|
${act_runner-install-script}
|
||||||
|
- path: /opt/bookshelf/install-bookshelf.sh
|
||||||
|
permissions: "0755"
|
||||||
|
content: |
|
||||||
|
${bookshelf-install-script}
|
||||||
|
|
||||||
|
runcmd:
|
||||||
|
# Backup setup
|
||||||
|
- mkdir -p /backups
|
||||||
|
- mount -t nfs ${proxmox_host_ip}:/main/backups /backups
|
||||||
|
- systemctl enable --now weekly-backup.timer
|
||||||
|
# Docker setup
|
||||||
|
- systemctl enable docker
|
||||||
|
- systemctl start docker
|
||||||
|
- usermod -aG docker ${hostname}
|
||||||
|
# Act_runner install
|
||||||
|
- /opt/bookshelf/install-runner.sh
|
||||||
|
- systemctl daemon-reload
|
||||||
|
- systemctl enable act_runner.service
|
||||||
|
- systemctl start act_runner.service
|
||||||
|
# Bookshelf install
|
||||||
|
- /opt/bookshelf/install-bookshelf.sh
|
||||||
|
|
||||||
|
|
||||||
|
final_message: |
|
||||||
|
Base system ready for ${hostname}
|
||||||
8
modules/apps/bookshelf/lib/scripts/create-backup.sh
Normal file
8
modules/apps/bookshelf/lib/scripts/create-backup.sh
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
source /opt/bookshelf/env.sh
|
||||||
|
|
||||||
|
TIMESTAMP=$(date +'%Y-%m-%d_%H%M%S')
|
||||||
|
docker exec bookshelf-database-1 mariadb-dump --all-database -u root -p"$MARIADB_ROOT_PASSWORD" > $BOOKSHELF_BACKUPS_DIR/bookshelf-dump-$TIMESTAMP.sql
|
||||||
|
|
||||||
|
ls -1dt $BOOKSHELF_BACKUPS_DIR/$BOOKSHELF_BACKUP_PREFIX-*.zip | tail -n +5 | xargs -r rm -f
|
||||||
4
modules/apps/bookshelf/lib/scripts/env.sh
Normal file
4
modules/apps/bookshelf/lib/scripts/env.sh
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -a
|
||||||
|
[ -f /opt/bookshelf/secrets/bookshelf.env ] && source /opt/bookshelf/secrets/bookshelf.env
|
||||||
|
set +a
|
||||||
38
modules/apps/bookshelf/lib/scripts/install-bookshelf.sh
Normal file
38
modules/apps/bookshelf/lib/scripts/install-bookshelf.sh
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
source /opt/bookshelf/env.sh
|
||||||
|
|
||||||
|
# trigger manually a CI/CD pipeline
|
||||||
|
curl -X POST -H "Authorization: token $GITEA_BOOKSHELF_APPLICATION_TOKEN" \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
$GITEA_INSTANCE_URL/api/v1/repos/$GITEA_BOOKSHELF_REPOSITORY/actions/workflows/deploy.yaml/dispatches \
|
||||||
|
-d '{"ref": "main", "inputs": {"ref": "main"}}'
|
||||||
|
|
||||||
|
RUN_ID=$(curl -s -H "Authorization: token $GITEA_BOOKSHELF_APPLICATION_TOKEN" \
|
||||||
|
$GITEA_INSTANCE_URL/api/v1/repos/$GITEA_BOOKSHELF_REPOSITORY/actions/runs \
|
||||||
|
| jq -r '.workflow_runs | sort_by(.created_at) | .[0].id')
|
||||||
|
|
||||||
|
while true; do
|
||||||
|
STATUS=$(curl -s -H "Authorization: token $GITEA_BOOKSHELF_APPLICATION_TOKEN" \
|
||||||
|
$GITEA_INSTANCE_URL/api/v1/repos/$GITEA_BOOKSHELF_REPOSITORY/actions/runs/$RUN_ID \
|
||||||
|
| jq -r '.status')
|
||||||
|
|
||||||
|
if [ "$STATUS" = "completed" ]; then
|
||||||
|
CONCLUSION=$(curl -s -H "Authorization: token $GITEA_BOOKSHELF_APPLICATION_TOKEN" \
|
||||||
|
$GITEA_INSTANCE_URL/api/v1/repos/$GITEA_BOOKSHELF_REPOSITORY/actions/runs/$RUN_ID \
|
||||||
|
| jq -r '.conclusion')
|
||||||
|
echo "Workflow finished with status: $CONCLUSION"
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Waiting 10 seconds..."
|
||||||
|
sleep 10
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$CONCLUSION" = "success" ]; then
|
||||||
|
echo "Launching command..."
|
||||||
|
systemctl start restore-backup.service
|
||||||
|
else
|
||||||
|
echo "Workflow failed or was cancelled, aborting."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
59
modules/apps/bookshelf/lib/scripts/install-runner.sh
Normal file
59
modules/apps/bookshelf/lib/scripts/install-runner.sh
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
source /opt/bookshelf/env.sh
|
||||||
|
|
||||||
|
if ! id -u $ACT_RUNNER_USER >/dev/null 2>&1; then
|
||||||
|
adduser \
|
||||||
|
--system \
|
||||||
|
--shell /bin/bash \
|
||||||
|
--gecos 'Action runner user' \
|
||||||
|
--ingroup docker\
|
||||||
|
--disabled-password \
|
||||||
|
--home /home/$ACT_RUNNER_USER \
|
||||||
|
$ACT_RUNNER_USER
|
||||||
|
fi
|
||||||
|
|
||||||
|
wget -O $ACT_RUNNER_LOCATION/act_runner https://dl.gitea.com/act_runner/$ACT_RUNNER_VERSION/act_runner-$ACT_RUNNER_VERSION-linux-amd64
|
||||||
|
chmod +x $ACT_RUNNER_LOCATION/act_runner
|
||||||
|
|
||||||
|
cat <<EOF > /home/$ACT_RUNNER_USER/config.yaml
|
||||||
|
log:
|
||||||
|
level: info
|
||||||
|
runner:
|
||||||
|
file: .runner
|
||||||
|
capacity: 1
|
||||||
|
timeout: 3h
|
||||||
|
shutdown_timeout: 0s
|
||||||
|
insecure: false
|
||||||
|
fetch_timeout: 5s
|
||||||
|
env_file: $ENV_FILE_LOCATION
|
||||||
|
fetch_interval: 2s
|
||||||
|
github_mirror: ''
|
||||||
|
labels:
|
||||||
|
- "ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
|
||||||
|
- "ubuntu-22.04:docker://docker.gitea.com/runner-images:ubuntu-22.04"
|
||||||
|
- "ubuntu-20.04:docker://docker.gitea.com/runner-images:ubuntu-20.04"
|
||||||
|
cache:
|
||||||
|
enabled: true
|
||||||
|
dir: ""
|
||||||
|
host: ""
|
||||||
|
port: 0
|
||||||
|
external_server: ""
|
||||||
|
container:
|
||||||
|
network: ""
|
||||||
|
privileged: false
|
||||||
|
options:
|
||||||
|
workdir_parent:
|
||||||
|
valid_volumes: []
|
||||||
|
docker_host: ""
|
||||||
|
force_pull: true
|
||||||
|
force_rebuild: false
|
||||||
|
require_docker: false
|
||||||
|
docker_timeout: 0s
|
||||||
|
host:
|
||||||
|
workdir_parent:
|
||||||
|
EOF
|
||||||
|
|
||||||
|
cd /home/act_runner
|
||||||
|
sudo -u $ACT_RUNNER_USER act_runner register --no-interactive --instance $GITEA_INSTANCE_URL --token $GITEA_RUNNER_REGISTRATION_TOKEN --name $USERNAME --labels $USERNAME $REPOSITORY
|
||||||
|
chown -R $ACT_RUNNER_USER:docker /home/$ACT_RUNNER_USER
|
||||||
9
modules/apps/bookshelf/lib/scripts/restore-backup.sh
Normal file
9
modules/apps/bookshelf/lib/scripts/restore-backup.sh
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
source /opt/bookshelf/env.sh
|
||||||
|
|
||||||
|
LATEST_BACKUP=$(ls -1 $BOOKSHELF_BACKUPS_DIR/$BOOKSHELF_BACKUP_PREFIX-*.sql 2>/dev/null | sort | tail -n1)
|
||||||
|
|
||||||
|
if [ -n "$LATEST_BACKUP" ] && [ -f "$LATEST_BACKUP" ]; then
|
||||||
|
cat $LATEST_BACKUP | docker exec -i bookshelf-database-1 mariadb -u root -p"$MARIADB_ROOT_PASSWORD" -D $MARIADB_DATABASE
|
||||||
|
fi
|
||||||
16
modules/apps/bookshelf/lib/services/act_runner.service
Normal file
16
modules/apps/bookshelf/lib/services/act_runner.service
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Gitea Actions runner
|
||||||
|
Documentation=https://gitea.com/gitea/act_runner
|
||||||
|
After=docker.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/local/bin/act_runner daemon --config /home/act_runner/config.yaml
|
||||||
|
ExecReload=/bin/kill -s HUP $MAINPID
|
||||||
|
WorkingDirectory=/home/act_runner
|
||||||
|
TimeoutSec=0
|
||||||
|
RestartSec=10
|
||||||
|
Restart=always
|
||||||
|
User=act_runner
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
11
modules/apps/bookshelf/lib/services/restore-backup.service
Normal file
11
modules/apps/bookshelf/lib/services/restore-backup.service
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Restore latest Bookshelf backup
|
||||||
|
After=network.target
|
||||||
|
Requires=docker.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
User=root
|
||||||
|
ExecStart=/usr/local/bin/restore-backup.sh
|
||||||
|
WorkingDirectory=/home/bookshelf
|
||||||
|
TimeoutStartSec=600
|
||||||
10
modules/apps/bookshelf/lib/services/weekly-backup.service
Normal file
10
modules/apps/bookshelf/lib/services/weekly-backup.service
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Weekly Bookshelf Backup
|
||||||
|
Wants=network.target
|
||||||
|
After=network.target docker.service
|
||||||
|
Before=shutdown.target reboot.target halt.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
User=root
|
||||||
|
ExecStart=/usr/local/bin/backup.sh
|
||||||
9
modules/apps/bookshelf/lib/services/weekly-backup.timer
Normal file
9
modules/apps/bookshelf/lib/services/weekly-backup.timer
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Run Bookshelf backup weekly
|
||||||
|
|
||||||
|
[Timer]
|
||||||
|
OnCalendar=Sun *-*-* 01:00:00
|
||||||
|
Persistent=true
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=timers.target
|
||||||
38
modules/apps/bookshelf/main.tf
Normal file
38
modules/apps/bookshelf/main.tf
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
module "vm" {
|
||||||
|
source = "../../vm"
|
||||||
|
name = var.name
|
||||||
|
hostname = var.hostname
|
||||||
|
domain = var.domain
|
||||||
|
vm_id = var.vm_id
|
||||||
|
node_name = var.node_name
|
||||||
|
vm_ip_address = "192.168.1.91"
|
||||||
|
|
||||||
|
template_id = var.template_id
|
||||||
|
|
||||||
|
cores = var.cores
|
||||||
|
memory = var.memory
|
||||||
|
disk_size = var.disk_size
|
||||||
|
|
||||||
|
ssh_public_key = var.ssh_public_key
|
||||||
|
proxmox_host_ip = var.proxmox_host_ip
|
||||||
|
cloudinit_config = templatefile(
|
||||||
|
"${path.module}/cloud-init/service.yaml",
|
||||||
|
{
|
||||||
|
hostname = var.hostname
|
||||||
|
domain = var.domain
|
||||||
|
ssh_key = var.ssh_public_key
|
||||||
|
proxmox_host_ip = var.proxmox_host_ip
|
||||||
|
environment-setup-script = indent(6, file("${path.module}/lib/scripts/env.sh"))
|
||||||
|
restore-backup-script = indent(6, file("${path.module}/lib/scripts/restore-backup.sh"))
|
||||||
|
restore-backup-service = indent(6, file("${path.module}/lib/services/restore-backup.service"))
|
||||||
|
create-backup-script = indent(6, file("${path.module}/lib/scripts/create-backup.sh"))
|
||||||
|
create-backup-service = indent(6, file("${path.module}/lib/services/weekly-backup.service"))
|
||||||
|
create-backup-timer = indent(6, file("${path.module}/lib/services/weekly-backup.timer"))
|
||||||
|
act_runner-service = indent(6, file("${path.module}/lib/services/act_runner.service"))
|
||||||
|
act_runner-install-script = indent(6, file("${path.module}/lib/scripts/install-runner.sh"))
|
||||||
|
bookshelf-install-script = indent(6, file("${path.module}/lib/scripts/install-bookshelf.sh"))
|
||||||
|
|
||||||
|
env-file-content = indent(6, file("${path.module}/.env"))
|
||||||
|
}
|
||||||
|
)
|
||||||
|
}
|
||||||
52
modules/apps/bookshelf/variables.tf
Normal file
52
modules/apps/bookshelf/variables.tf
Normal file
@@ -0,0 +1,52 @@
|
|||||||
|
variable "name" {
|
||||||
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "vm_id" {
|
||||||
|
type = number
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "node_name" {
|
||||||
|
type = string
|
||||||
|
default = "mop"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "cores" {
|
||||||
|
type = number
|
||||||
|
default = 2
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "memory" {
|
||||||
|
type = number
|
||||||
|
default = 2048
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "template_id" {
|
||||||
|
type = number
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "ssh_public_key" {
|
||||||
|
type = string
|
||||||
|
description = "Public SSH key for cloud-init user"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "hostname" {
|
||||||
|
description = "VM hostname"
|
||||||
|
type = string
|
||||||
|
default = "test"
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "domain" {
|
||||||
|
description = "VM domain"
|
||||||
|
type = string
|
||||||
|
default = ""
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "disk_size" {
|
||||||
|
type = number
|
||||||
|
default = 10
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "proxmox_host_ip" {
|
||||||
|
type = string
|
||||||
|
}
|
||||||
@@ -1,209 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
sudo apt install postgresql postgresql-client unzip -y
|
|
||||||
|
|
||||||
GITEA_HOME="/var/lib/gitea"
|
|
||||||
GITEA_CONF="$GITEA_HOME/app.ini"
|
|
||||||
GITEA_USER="git"
|
|
||||||
GITEA_VERSION="1.25.3"
|
|
||||||
GITEA_BINARY="/usr/local/bin/gitea"
|
|
||||||
GITEA_SERVICE="/etc/systemd/system/gitea.service"
|
|
||||||
DB_NAME="giteadb"
|
|
||||||
DB_USER="gitea"
|
|
||||||
GITEA_BACKUPS_DIR="/backups/gitea"
|
|
||||||
|
|
||||||
# Gitea user
|
|
||||||
if ! id -u $GITEA_USER >/dev/null 2>&1; then
|
|
||||||
adduser \
|
|
||||||
--system \
|
|
||||||
--shell /bin/bash \
|
|
||||||
--gecos 'Git Version Control' \
|
|
||||||
--group \
|
|
||||||
--disabled-password \
|
|
||||||
--home /home/git \
|
|
||||||
$GITEA_USER
|
|
||||||
fi
|
|
||||||
echo "---- Gitea user created ----"
|
|
||||||
|
|
||||||
# Gitea folder structure
|
|
||||||
mkdir -p $GITEA_HOME/{custom,data,log}
|
|
||||||
chown -R $GITEA_USER:$GITEA_USER $GITEA_HOME
|
|
||||||
chmod -R 750 $GITEA_HOME
|
|
||||||
|
|
||||||
if [ ! -f $GITEA_BINARY ]; then
|
|
||||||
wget -O /tmp/gitea "https://dl.gitea.com/gitea/$GITEA_VERSION/gitea-$GITEA_VERSION-linux-amd64"
|
|
||||||
chmod +x /tmp/gitea
|
|
||||||
mv /tmp/gitea $GITEA_BINARY
|
|
||||||
fi
|
|
||||||
echo "---- Gitea folder structure created ----"
|
|
||||||
|
|
||||||
# Postgres first config
|
|
||||||
DB_PASS=$(openssl rand -base64 12)
|
|
||||||
sudo -u postgres psql <<EOF
|
|
||||||
CREATE ROLE $DB_USER WITH LOGIN PASSWORD '$DB_PASS';
|
|
||||||
CREATE DATABASE $DB_NAME WITH OWNER $DB_USER TEMPLATE template0 ENCODING UTF8 LC_COLLATE 'en_US.UTF-8' LC_CTYPE 'en_US.UTF-8';
|
|
||||||
EOF
|
|
||||||
|
|
||||||
# Create restore-backup.sh script
|
|
||||||
cat > /usr/local/bin/restore-backup.sh <<RESTORE_EOF
|
|
||||||
sudo -u postgres psql <<DROP_DB_USER
|
|
||||||
DO \$\$
|
|
||||||
BEGIN
|
|
||||||
IF EXISTS (SELECT FROM pg_database WHERE datname = '$DB_NAME') THEN
|
|
||||||
EXECUTE 'DROP DATABASE $DB_NAME';
|
|
||||||
END IF;
|
|
||||||
IF EXISTS (SELECT FROM pg_roles WHERE rolname = '$DB_USER') THEN
|
|
||||||
EXECUTE 'DROP ROLE $DB_USER';
|
|
||||||
END IF;
|
|
||||||
END
|
|
||||||
\$\$;
|
|
||||||
DROP_DB_USER
|
|
||||||
|
|
||||||
LATEST_BACKUP=$(ls -1 $GITEA_BACKUPS_DIR/gitea-dump-*.zip 2>/dev/null | sort | tail -n1)
|
|
||||||
# Restore backup database, data, repos, logs if exist
|
|
||||||
if [ -n "\$LATEST_BACKUP" ] && [ -f "\$LATEST_BACKUP" ]; then
|
|
||||||
TMP_DIR=$(mktemp -d)
|
|
||||||
unzip -o \$LATEST_BACKUP -d \$TMP_DIR
|
|
||||||
if [ -d \$TMP_DIR/data ]; then
|
|
||||||
cp -a \$TMP_DIR/data/* /var/lib/gitea/data/
|
|
||||||
fi
|
|
||||||
if [ -d \$TMP_DIR/log ]; then
|
|
||||||
cp -a \$TMP_DIR/log/* /var/lib/gitea/log/
|
|
||||||
fi
|
|
||||||
if [ -d \$TMP_DIR/repos ]; then
|
|
||||||
cp -aH \$TMP_DIR/repos/. /var/lib/gitea/data/repositories/
|
|
||||||
fi
|
|
||||||
chown -R $GITEA_USER:$GITEA_USER $GITEA_HOME
|
|
||||||
sudo -u postgres psql -d $DB_NAME < \$TMP_DIR/gitea-db.sql
|
|
||||||
sudo -u postgres psql <<EOF
|
|
||||||
ALTER ROLE $DB_USER WITH PASSWORD '$DB_PASS';
|
|
||||||
ALTER DATABASE $DB_NAME OWNER TO $DB_USER;
|
|
||||||
EOF
|
|
||||||
sudo -u postgres psql -d "$DB_NAME" <<EOF
|
|
||||||
DO \$\$
|
|
||||||
DECLARE
|
|
||||||
r RECORD;
|
|
||||||
BEGIN
|
|
||||||
-- Tables
|
|
||||||
FOR r IN
|
|
||||||
SELECT schemaname, tablename
|
|
||||||
FROM pg_tables
|
|
||||||
WHERE schemaname = 'public'
|
|
||||||
LOOP
|
|
||||||
EXECUTE format(
|
|
||||||
'ALTER TABLE %I.%I OWNER TO $DB_USER;',
|
|
||||||
r.schemaname,
|
|
||||||
r.tablename
|
|
||||||
);
|
|
||||||
END LOOP;
|
|
||||||
|
|
||||||
-- Sequences
|
|
||||||
FOR r IN
|
|
||||||
SELECT sequence_schema, sequence_name
|
|
||||||
FROM information_schema.sequences
|
|
||||||
WHERE sequence_schema = 'public'
|
|
||||||
LOOP
|
|
||||||
EXECUTE format(
|
|
||||||
'ALTER SEQUENCE %I.%I OWNER TO $DB_USER;',
|
|
||||||
r.sequence_schema,
|
|
||||||
r.sequence_name
|
|
||||||
);
|
|
||||||
END LOOP;
|
|
||||||
END
|
|
||||||
\$\$;
|
|
||||||
EOF
|
|
||||||
rm -rf /tmp/backup
|
|
||||||
echo "---- Gitea restore from existing backup /backup/gitea ----"
|
|
||||||
|
|
||||||
fi
|
|
||||||
RESTORE_EOF
|
|
||||||
chmod +x /usr/local/bin/restore-backup.sh
|
|
||||||
|
|
||||||
if ls -1 "$GITEA_BACKUPS_DIR"/gitea-dump-*.zip >/dev/null 2>&1; then
|
|
||||||
echo "---- Backup found, restoring Gitea ----"
|
|
||||||
/usr/local/bin/restore-backup.sh
|
|
||||||
else
|
|
||||||
echo "---- No backup found in $GITEA_BACKUPS_DIR, skipping restore ----"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Save restore backup service
|
|
||||||
cat > /etc/systemd/system/weekly-backup.service <<EOF
|
|
||||||
${BACKUP_RESTORE_SERVICE}
|
|
||||||
EOF
|
|
||||||
|
|
||||||
sudo chown -R $GITEA_USER:$GITEA_USER $GITEA_BACKUPS_DIR
|
|
||||||
sudo chmod -R 770 $GITEA_BACKUPS_DIR
|
|
||||||
# Create systemd timer for weekly backup
|
|
||||||
cat > /usr/local/bin/backup.sh <<EOF
|
|
||||||
#!/bin/bash
|
|
||||||
TIMESTAMP=$(date +'%Y-%m-%d_%H%M%S')
|
|
||||||
sudo -u "$GITEA_USER" gitea dump -c "$GITEA_HOME/app.ini" -f $GITEA_BACKUPS_DIR/gitea-dump-\$TIMESTAMP.zip"
|
|
||||||
ls -1dt $GITEA_BACKUPS_DIR/gitea-dump-*.zip | tail -n +5 | xargs -r rm -f
|
|
||||||
echo "Gitea backup completed at \$TIMESTAMP"
|
|
||||||
EOF
|
|
||||||
chmod +x /usr/local/bin/backup.sh
|
|
||||||
|
|
||||||
# Systemd service for backup
|
|
||||||
cat > /etc/systemd/system/weekly-backup.service <<EOF
|
|
||||||
${BACKUP_SERVICE}
|
|
||||||
EOF
|
|
||||||
|
|
||||||
# Systemd timer for backup
|
|
||||||
cat > /etc/systemd/system/weekly-backup.timer <<EOF
|
|
||||||
${BACKUP_SERVICE_TIMER}
|
|
||||||
EOF
|
|
||||||
|
|
||||||
# Generate /var/lib/gitea/app.ini with secrets.
|
|
||||||
GITEA_SECRET_KEY=$("$GITEA_BINARY" generate secret SECRET_KEY)
|
|
||||||
GITEA_JWT_SECRET=$("$GITEA_BINARY" generate secret JWT_SECRET)
|
|
||||||
GITEA_INTERNAL_TOKEN=$("$GITEA_BINARY" generate secret INTERNAL_TOKEN)
|
|
||||||
|
|
||||||
mkdir -p $(dirname "$GITEA_CONF")
|
|
||||||
cat > "$GITEA_CONF" <<EOF
|
|
||||||
[database]
|
|
||||||
DB_TYPE = postgres
|
|
||||||
HOST = 127.0.0.1:5432
|
|
||||||
NAME = $DB_NAME
|
|
||||||
USER = $DB_USER
|
|
||||||
PASSWD = $DB_PASS
|
|
||||||
SSL_MODE = disable
|
|
||||||
|
|
||||||
[security]
|
|
||||||
INSTALL_LOCK = true
|
|
||||||
SECRET_KEY = $GITEA_SECRET_KEY
|
|
||||||
JWT_SECRET = $GITEA_JWT_SECRET
|
|
||||||
INTERNAL_TOKEN = $GITEA_INTERNAL_TOKEN
|
|
||||||
|
|
||||||
[server]
|
|
||||||
DOMAIN = gitea.aldon.fr
|
|
||||||
HTTP_PORT = 3000
|
|
||||||
ROOT_URL = https://gitea.aldon.fr
|
|
||||||
DISABLE_SSH = false
|
|
||||||
SSH_PORT = 22
|
|
||||||
|
|
||||||
[repository]
|
|
||||||
ROOT = /var/lib/gitea/data/repositories
|
|
||||||
|
|
||||||
[service]
|
|
||||||
DISABLE_REGISTRATION = true
|
|
||||||
EOF
|
|
||||||
echo "---- Generated Gitea app.ini with secrets ----"
|
|
||||||
|
|
||||||
chown git:git $GITEA_CONF
|
|
||||||
chmod 640 $GITEA_CONF
|
|
||||||
|
|
||||||
if [ ! -f "$GITEA_SERVICE" ]; then
|
|
||||||
cat <<'EOF' > "$GITEA_SERVICE"
|
|
||||||
${GITEA_SERVICE_CONTENT}
|
|
||||||
EOF
|
|
||||||
systemctl daemon-reload
|
|
||||||
systemctl enable gitea
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Enable timer for backup
|
|
||||||
sudo systemctl enable --now weekly-backup.timer
|
|
||||||
sudo systemctl status weekly-backup.timer
|
|
||||||
|
|
||||||
systemctl is-active --quiet gitea || systemctl start gitea
|
|
||||||
echo "---- Gitea installation completed ----"
|
|
||||||
@@ -77,6 +77,9 @@ ROOT = /var/lib/gitea/data/repositories
|
|||||||
|
|
||||||
[service]
|
[service]
|
||||||
DISABLE_REGISTRATION = true
|
DISABLE_REGISTRATION = true
|
||||||
|
|
||||||
|
[actions]
|
||||||
|
ENABLED=true
|
||||||
EOF
|
EOF
|
||||||
echo "---- Generated Gitea app.ini with secrets ----"
|
echo "---- Generated Gitea app.ini with secrets ----"
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ module "vm" {
|
|||||||
domain = var.domain
|
domain = var.domain
|
||||||
vm_id = var.vm_id
|
vm_id = var.vm_id
|
||||||
node_name = var.node_name
|
node_name = var.node_name
|
||||||
|
vm_ip_address = "192.168.1.90"
|
||||||
|
|
||||||
template_id = var.template_id
|
template_id = var.template_id
|
||||||
|
|
||||||
|
|||||||
@@ -70,6 +70,13 @@ resource "proxmox_virtual_environment_vm" "vm" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
initialization {
|
initialization {
|
||||||
|
ip_config {
|
||||||
|
ipv4 {
|
||||||
|
address = "${var.vm_ip_address}/24"
|
||||||
|
gateway = "192.168.1.1"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
datastore_id = "local-lvm"
|
datastore_id = "local-lvm"
|
||||||
interface = "ide2"
|
interface = "ide2"
|
||||||
user_data_file_id = proxmox_virtual_environment_file.cloud_user_config.id
|
user_data_file_id = proxmox_virtual_environment_file.cloud_user_config.id
|
||||||
|
|||||||
@@ -53,4 +53,8 @@ variable "proxmox_host_ip" {
|
|||||||
|
|
||||||
variable "cloudinit_config" {
|
variable "cloudinit_config" {
|
||||||
type = string
|
type = string
|
||||||
|
}
|
||||||
|
|
||||||
|
variable "vm_ip_address" {
|
||||||
|
type = string
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user