#!/usr/bin/env bash # One-time root setup on Max for decePubClient at decepub.thepra.dev (static files, no unit). Idempotent. # rsync -a -e $MAX/ssh.sh deploy/ root@nuvola.xyz:/root/decepub-deploy/ # $MAX/run.sh bash /root/decepub-deploy/max/setup.sh set -euo pipefail SRC="${1:-/root/decepub-deploy}" HOST=decepub.thepra.dev RUNNER=build-runner ACME=/root/.acme.sh/acme.sh echo "== directories" install -d -o "$RUNNER" -g www-data -m 755 /var/www/$HOST install -d -o "$RUNNER" -g "$RUNNER" -m 750 /var/backups/$HOST echo "== nginx snippet and bootstrap vhost" install -m 644 "$SRC/nginx/decepub-headers.conf" /etc/nginx/snippets/decepub-headers.conf if [ -f /root/.acme.sh/${HOST}_ecc/fullchain.cer ]; then install -m 644 "$SRC/nginx/$HOST.conf" /etc/nginx/sites-available/$HOST.conf else awk '/^server \{/{n++} n==1' "$SRC/nginx/$HOST.conf" > /etc/nginx/sites-available/$HOST.conf fi ln -sf /etc/nginx/sites-available/$HOST.conf /etc/nginx/sites-enabled/$HOST.conf nginx -t systemctl reload nginx echo "== certificate" if [ -f /root/.acme.sh/${HOST}_ecc/fullchain.cer ]; then echo "$HOST: certificate present" else $ACME --issue --server letsencrypt -d $HOST -w /var/www/acme --renew-hook "systemctl reload nginx" fi echo "== full vhost" install -m 644 "$SRC/nginx/$HOST.conf" /etc/nginx/sites-available/$HOST.conf nginx -t systemctl reload nginx echo "setup complete"