209 lines
5.4 KiB
Bash
209 lines
5.4 KiB
Bash
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
sudo apt install postgresql postgresql-client unzip -y
|
|
|
|
GITEA_HOME="/var/lib/gitea"
|
|
GITEA_CONF="$GITEA_HOME/app.ini"
|
|
GITEA_USER="git"
|
|
GITEA_VERSION="1.25.3"
|
|
GITEA_BINARY="/usr/local/bin/gitea"
|
|
GITEA_SERVICE="/etc/systemd/system/gitea.service"
|
|
DB_NAME="giteadb"
|
|
DB_USER="gitea"
|
|
GITEA_BACKUPS_DIR="/backups/gitea"
|
|
|
|
# Gitea user
|
|
if ! id -u $GITEA_USER >/dev/null 2>&1; then
|
|
adduser \
|
|
--system \
|
|
--shell /bin/bash \
|
|
--gecos 'Git Version Control' \
|
|
--group \
|
|
--disabled-password \
|
|
--home /home/git \
|
|
$GITEA_USER
|
|
fi
|
|
echo "---- Gitea user created ----"
|
|
|
|
# Gitea folder structure
|
|
mkdir -p $GITEA_HOME/{custom,data,log}
|
|
chown -R $GITEA_USER:$GITEA_USER $GITEA_HOME
|
|
chmod -R 750 $GITEA_HOME
|
|
|
|
if [ ! -f $GITEA_BINARY ]; then
|
|
wget -O /tmp/gitea "https://dl.gitea.com/gitea/$GITEA_VERSION/gitea-$GITEA_VERSION-linux-amd64"
|
|
chmod +x /tmp/gitea
|
|
mv /tmp/gitea $GITEA_BINARY
|
|
fi
|
|
echo "---- Gitea folder structure created ----"
|
|
|
|
# Postgres first config
|
|
DB_PASS=$(openssl rand -base64 12)
|
|
sudo -u postgres psql <<EOF
|
|
CREATE ROLE $DB_USER WITH LOGIN PASSWORD '$DB_PASS';
|
|
CREATE DATABASE $DB_NAME WITH OWNER $DB_USER TEMPLATE template0 ENCODING UTF8 LC_COLLATE 'en_US.UTF-8' LC_CTYPE 'en_US.UTF-8';
|
|
EOF
|
|
|
|
# Create restore-backup.sh script
|
|
cat > /usr/local/bin/restore-backup.sh <<RESTORE_EOF
|
|
sudo -u postgres psql <<DROP_DB_USER
|
|
DO \$\$
|
|
BEGIN
|
|
IF EXISTS (SELECT FROM pg_database WHERE datname = '$DB_NAME') THEN
|
|
EXECUTE 'DROP DATABASE $DB_NAME';
|
|
END IF;
|
|
IF EXISTS (SELECT FROM pg_roles WHERE rolname = '$DB_USER') THEN
|
|
EXECUTE 'DROP ROLE $DB_USER';
|
|
END IF;
|
|
END
|
|
\$\$;
|
|
DROP_DB_USER
|
|
|
|
LATEST_BACKUP=$(ls -1 $GITEA_BACKUPS_DIR/gitea-dump-*.zip 2>/dev/null | sort | tail -n1)
|
|
# Restore backup database, data, repos, logs if exist
|
|
if [ -n "\$LATEST_BACKUP" ] && [ -f "\$LATEST_BACKUP" ]; then
|
|
TMP_DIR=$(mktemp -d)
|
|
unzip -o \$LATEST_BACKUP -d \$TMP_DIR
|
|
if [ -d \$TMP_DIR/data ]; then
|
|
cp -a \$TMP_DIR/data/* /var/lib/gitea/data/
|
|
fi
|
|
if [ -d \$TMP_DIR/log ]; then
|
|
cp -a \$TMP_DIR/log/* /var/lib/gitea/log/
|
|
fi
|
|
if [ -d \$TMP_DIR/repos ]; then
|
|
cp -aH \$TMP_DIR/repos/. /var/lib/gitea/data/repositories/
|
|
fi
|
|
chown -R $GITEA_USER:$GITEA_USER $GITEA_HOME
|
|
sudo -u postgres psql -d $DB_NAME < \$TMP_DIR/gitea-db.sql
|
|
sudo -u postgres psql <<EOF
|
|
ALTER ROLE $DB_USER WITH PASSWORD '$DB_PASS';
|
|
ALTER DATABASE $DB_NAME OWNER TO $DB_USER;
|
|
EOF
|
|
sudo -u postgres psql -d "$DB_NAME" <<EOF
|
|
DO \$\$
|
|
DECLARE
|
|
r RECORD;
|
|
BEGIN
|
|
-- Tables
|
|
FOR r IN
|
|
SELECT schemaname, tablename
|
|
FROM pg_tables
|
|
WHERE schemaname = 'public'
|
|
LOOP
|
|
EXECUTE format(
|
|
'ALTER TABLE %I.%I OWNER TO $DB_USER;',
|
|
r.schemaname,
|
|
r.tablename
|
|
);
|
|
END LOOP;
|
|
|
|
-- Sequences
|
|
FOR r IN
|
|
SELECT sequence_schema, sequence_name
|
|
FROM information_schema.sequences
|
|
WHERE sequence_schema = 'public'
|
|
LOOP
|
|
EXECUTE format(
|
|
'ALTER SEQUENCE %I.%I OWNER TO $DB_USER;',
|
|
r.sequence_schema,
|
|
r.sequence_name
|
|
);
|
|
END LOOP;
|
|
END
|
|
\$\$;
|
|
EOF
|
|
rm -rf /tmp/backup
|
|
echo "---- Gitea restore from existing backup /backup/gitea ----"
|
|
|
|
fi
|
|
RESTORE_EOF
|
|
chmod +x /usr/local/bin/restore-backup.sh
|
|
|
|
if ls -1 "$GITEA_BACKUPS_DIR"/gitea-dump-*.zip >/dev/null 2>&1; then
|
|
echo "---- Backup found, restoring Gitea ----"
|
|
/usr/local/bin/restore-backup.sh
|
|
else
|
|
echo "---- No backup found in $GITEA_BACKUPS_DIR, skipping restore ----"
|
|
fi
|
|
|
|
# Save restore backup service
|
|
cat > /etc/systemd/system/weekly-backup.service <<EOF
|
|
${BACKUP_RESTORE_SERVICE}
|
|
EOF
|
|
|
|
sudo chown -R $GITEA_USER:$GITEA_USER $GITEA_BACKUPS_DIR
|
|
sudo chmod -R 770 $GITEA_BACKUPS_DIR
|
|
# Create systemd timer for weekly backup
|
|
cat > /usr/local/bin/backup.sh <<EOF
|
|
#!/bin/bash
|
|
TIMESTAMP=$(date +'%Y-%m-%d_%H%M%S')
|
|
sudo -u "$GITEA_USER" gitea dump -c "$GITEA_HOME/app.ini" -f $GITEA_BACKUPS_DIR/gitea-dump-\$TIMESTAMP.zip"
|
|
ls -1dt $GITEA_BACKUPS_DIR/gitea-dump-*.zip | tail -n +5 | xargs -r rm -f
|
|
echo "Gitea backup completed at \$TIMESTAMP"
|
|
EOF
|
|
chmod +x /usr/local/bin/backup.sh
|
|
|
|
# Systemd service for backup
|
|
cat > /etc/systemd/system/weekly-backup.service <<EOF
|
|
${BACKUP_SERVICE}
|
|
EOF
|
|
|
|
# Systemd timer for backup
|
|
cat > /etc/systemd/system/weekly-backup.timer <<EOF
|
|
${BACKUP_SERVICE_TIMER}
|
|
EOF
|
|
|
|
# Generate /var/lib/gitea/app.ini with secrets.
|
|
GITEA_SECRET_KEY=$("$GITEA_BINARY" generate secret SECRET_KEY)
|
|
GITEA_JWT_SECRET=$("$GITEA_BINARY" generate secret JWT_SECRET)
|
|
GITEA_INTERNAL_TOKEN=$("$GITEA_BINARY" generate secret INTERNAL_TOKEN)
|
|
|
|
mkdir -p $(dirname "$GITEA_CONF")
|
|
cat > "$GITEA_CONF" <<EOF
|
|
[database]
|
|
DB_TYPE = postgres
|
|
HOST = 127.0.0.1:5432
|
|
NAME = $DB_NAME
|
|
USER = $DB_USER
|
|
PASSWD = $DB_PASS
|
|
SSL_MODE = disable
|
|
|
|
[security]
|
|
INSTALL_LOCK = true
|
|
SECRET_KEY = $GITEA_SECRET_KEY
|
|
JWT_SECRET = $GITEA_JWT_SECRET
|
|
INTERNAL_TOKEN = $GITEA_INTERNAL_TOKEN
|
|
|
|
[server]
|
|
DOMAIN = gitea.aldon.fr
|
|
HTTP_PORT = 3000
|
|
ROOT_URL = https://gitea.aldon.fr
|
|
DISABLE_SSH = false
|
|
SSH_PORT = 22
|
|
|
|
[repository]
|
|
ROOT = /var/lib/gitea/data/repositories
|
|
|
|
[service]
|
|
DISABLE_REGISTRATION = true
|
|
EOF
|
|
echo "---- Generated Gitea app.ini with secrets ----"
|
|
|
|
chown git:git $GITEA_CONF
|
|
chmod 640 $GITEA_CONF
|
|
|
|
if [ ! -f "$GITEA_SERVICE" ]; then
|
|
cat <<'EOF' > "$GITEA_SERVICE"
|
|
${GITEA_SERVICE_CONTENT}
|
|
EOF
|
|
systemctl daemon-reload
|
|
systemctl enable gitea
|
|
fi
|
|
|
|
# Enable timer for backup
|
|
sudo systemctl enable --now weekly-backup.timer
|
|
sudo systemctl status weekly-backup.timer
|
|
|
|
systemctl is-active --quiet gitea || systemctl start gitea
|
|
echo "---- Gitea installation completed ----" |