2020-07-15 20:54:57 +02:00
|
|
|
#!/bin/env bash
|
|
|
|
|
|
|
|
# Prepended to this automatically are the following:
|
|
|
|
#SERVER=
|
|
|
|
#HOSTNAME=
|
2022-06-23 21:00:40 +02:00
|
|
|
#FULL_ROLES=
|
2020-07-15 20:54:57 +02:00
|
|
|
#REPO_URL=
|
|
|
|
#BRANCH=
|
|
|
|
#SSH_SECRET_ID=
|
|
|
|
|
2022-10-29 00:40:32 +02:00
|
|
|
if ! curl -fLs -m 5 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 10" >/dev/null; then
|
2020-07-15 20:54:57 +02:00
|
|
|
echo "This should be run on AWS instances, not locally."
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
set -e
|
|
|
|
set -x
|
|
|
|
|
|
|
|
# Set the hostname early
|
2020-10-15 04:55:57 +02:00
|
|
|
echo "$HOSTNAME" >/etc/hostname
|
2020-07-15 20:54:57 +02:00
|
|
|
hostname "$HOSTNAME"
|
|
|
|
sed -i "s/localhost$/localhost $HOSTNAME $SERVER/" /etc/hosts
|
|
|
|
|
|
|
|
# Make sure root doesn't have a password
|
|
|
|
passwd -d root
|
|
|
|
|
|
|
|
# Allow root logins
|
|
|
|
sed -i 's/disable_root: true/disable_root: false/' /etc/cloud/cloud.cfg
|
|
|
|
|
2020-10-15 09:29:38 +02:00
|
|
|
# Ensure all apt updates (here and in the installer) are non-interactive
|
|
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
|
|
|
2020-07-15 20:54:57 +02:00
|
|
|
# Dependencies to install AWS CLI
|
|
|
|
(
|
|
|
|
apt-get -qy update
|
2022-06-20 23:29:19 +02:00
|
|
|
apt-get -qy --with-new-pkgs -o "Dpkg::Options::=--force-confdef" -o "Dpkg::Options::=--force-confold" upgrade
|
2021-06-25 01:28:27 +02:00
|
|
|
apt-get -qy install jq unzip curl
|
2020-07-15 20:54:57 +02:00
|
|
|
apt-get -qy autoclean
|
|
|
|
)
|
|
|
|
|
2021-06-25 03:24:21 +02:00
|
|
|
# The following line gets subbed in with the contents of bootstrap-awscli.sh
|
2020-07-15 20:54:57 +02:00
|
|
|
AWS=
|
|
|
|
|
bootstrap-aws-installer: Drop "credential_source" in .aws/config.
Setting `credential_source` is used when assuming role credentials --
that is, when running as one role, use the AssumeRole right to become
someone else.
The AWS command-line tools only do this if `role_arn`, the role to
assume, is also set -- if it is not set, it transparently falls
through to IAM role attached to the EC2 instance profile. However,
with the `aws-sdk-go` package, used by Teleport, this configuration
produces an error.
Remove the `credential_source = Ec2InstanceMetadata` line, which isn't
necessary for the AWS CLI, and interferes with Teleport operation.
2022-10-29 00:34:13 +02:00
|
|
|
# Set up a bare-bones AWS configuration
|
2020-07-15 20:54:57 +02:00
|
|
|
mkdir -p /root/.aws
|
|
|
|
cat >/root/.aws/config <<EOF
|
|
|
|
[default]
|
|
|
|
region = us-east-1
|
|
|
|
output = text
|
bootstrap-aws-installer: Drop "credential_source" in .aws/config.
Setting `credential_source` is used when assuming role credentials --
that is, when running as one role, use the AssumeRole right to become
someone else.
The AWS command-line tools only do this if `role_arn`, the role to
assume, is also set -- if it is not set, it transparently falls
through to IAM role attached to the EC2 instance profile. However,
with the `aws-sdk-go` package, used by Teleport, this configuration
produces an error.
Remove the `credential_source = Ec2InstanceMetadata` line, which isn't
necessary for the AWS CLI, and interferes with Teleport operation.
2022-10-29 00:34:13 +02:00
|
|
|
# Credentials are from the IAM role attached to the EC2 instance
|
2020-07-15 20:54:57 +02:00
|
|
|
EOF
|
|
|
|
|
|
|
|
# Set up public keys for root, so we can fetch the repo; this is a
|
|
|
|
# function so we do can it again later with the zulip user
|
|
|
|
function install_keys() {
|
|
|
|
USERNAME="$1"
|
2020-10-15 04:55:57 +02:00
|
|
|
SSHDIR="$(getent passwd "$USERNAME" | cut -d: -f6)/.ssh"
|
2020-07-15 20:54:57 +02:00
|
|
|
KEYDATA="$($AWS --output text \
|
2020-10-15 04:55:57 +02:00
|
|
|
secretsmanager get-secret-value \
|
|
|
|
--secret-id "$SSH_SECRET_ID" \
|
|
|
|
--query SecretString)"
|
2020-07-15 20:54:57 +02:00
|
|
|
mkdir -p "$SSHDIR"
|
2020-10-27 21:00:20 +01:00
|
|
|
for KEYFILE in $(echo "$KEYDATA" | jq -r 'keys[]'); do
|
|
|
|
echo "$KEYDATA" | jq -r ".[\"$KEYFILE\"]" | base64 -d >"$SSHDIR/$KEYFILE"
|
|
|
|
if [[ "$KEYFILE" != *".pub" ]]; then
|
|
|
|
chmod 600 "$SSHDIR/$KEYFILE"
|
|
|
|
fi
|
|
|
|
done
|
2020-10-15 04:55:57 +02:00
|
|
|
chown -R "$USERNAME:$USERNAME" "$SSHDIR"
|
2020-07-15 20:54:57 +02:00
|
|
|
}
|
|
|
|
install_keys root
|
|
|
|
|
|
|
|
# Provide GitHub known_hosts setup; you can verify against fingerprints at
|
|
|
|
# https://docs.github.com/en/github/authenticating-to-github/githubs-ssh-key-fingerprints
|
|
|
|
# via `ssh-keygen -lf`
|
|
|
|
cat >/root/.ssh/known_hosts <<EOF
|
2022-10-28 23:28:48 +02:00
|
|
|
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
|
2023-03-24 15:05:01 +01:00
|
|
|
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
|
2020-07-15 20:54:57 +02:00
|
|
|
EOF
|
|
|
|
|
|
|
|
cd /root
|
|
|
|
git clone "$REPO_URL" zulip -b "$BRANCH"
|
|
|
|
git -C zulip checkout "$BRANCH"
|
|
|
|
|
|
|
|
(
|
2022-06-23 21:00:40 +02:00
|
|
|
VIRTUALENV_NEEDED=$(if echo "$FULL_ROLES" | grep -q app_frontend; then echo -n yes; else echo -n no; fi)
|
2020-07-15 20:54:57 +02:00
|
|
|
export VIRTUALENV_NEEDED
|
2022-06-23 21:00:40 +02:00
|
|
|
export PUPPET_CLASSES="$FULL_ROLES"
|
2020-10-15 09:29:38 +02:00
|
|
|
export APT_OPTIONS="-o Dpkg::Options::=--force-confnew"
|
2020-07-15 20:54:57 +02:00
|
|
|
/root/zulip/scripts/setup/install \
|
|
|
|
--self-signed-cert \
|
|
|
|
--no-init-db
|
|
|
|
)
|
|
|
|
|
|
|
|
install_keys zulip
|
|
|
|
|
2022-06-23 20:46:09 +02:00
|
|
|
# Delete the ubuntu user
|
|
|
|
userdel ubuntu
|
|
|
|
|
2020-07-15 20:54:57 +02:00
|
|
|
reboot
|