221 lines
6.2 KiB
Bash
221 lines
6.2 KiB
Bash
systemLabel="[System]"
|
|
|
|
# Runs the full system installation flow.
|
|
function cmdInstallFull() {
|
|
systemApt || return 1
|
|
systemIpset || return 1
|
|
systemIptables || return 1
|
|
|
|
cmdK3sInstall || return 1
|
|
cmdK3sNamespaceAdd || return 1
|
|
|
|
cmdMariadbInstall || return 1
|
|
cmdRedisInstall || return 1
|
|
cmdOpenlitespeedInstall || return 1
|
|
cmdPostfixInstall || return 1
|
|
cmdWorkerInstall || return 1
|
|
cmdMetricInstall || return 1
|
|
}
|
|
|
|
# Displays numbered cron job list and stores selected job + current crontab in namerefs.
|
|
# Known jobs (cronJobs[]): green if installed, gray if missing.
|
|
# Unknown kube.sh jobs found in crontab: yellow, numbered after known jobs.
|
|
# $1 (varname): nameref for selected job string
|
|
# $2 (listvar): nameref for current crontab lines
|
|
function cmdCronSelect() {
|
|
local -n __cronJob="$1"
|
|
local -n __cronList="$2"
|
|
|
|
printRow
|
|
|
|
local error
|
|
run __cronList error systemCronList || { printDanger "Error retrieving the CRON job list: $error"; return 1; }
|
|
|
|
local -a shownJobs
|
|
local i job fontColor
|
|
for ((i=0; i<${#cronJobs[@]}; i++)); do
|
|
job="${cronJobs[$i]}"
|
|
shownJobs+=("$job")
|
|
grep -Fxq -- "$job" <<< "$__cronList" && fontColor="$fontGreen" || fontColor="$fontGray"
|
|
printf "%2d: %s\n" "$((i+1))" "$fontColor$job$fontReset"
|
|
done
|
|
while IFS= read -r job; do
|
|
[[ -z "$job" ]] && continue
|
|
grep -Fxq -- "$job" <(printf '%s\n' "${cronJobs[@]}") && continue
|
|
grep -Fq -- "$appPath/kube.sh" <<< "$job" || continue
|
|
shownJobs+=("$job")
|
|
printf "%2d: %s\n" "${#shownJobs[@]}" "$fontYellow$job$fontReset"
|
|
done <<< "$__cronList"
|
|
|
|
printRow
|
|
local input item
|
|
read -r -p "Specify the job number: " input
|
|
|
|
printRow
|
|
[[ -z "$input" ]] && input=0
|
|
[[ "$input" =~ ^[0-9]+$ ]] || { printDanger "Invalid job number"; return 1; }
|
|
item=$((10#$input - 1))
|
|
(( item < 0 || item >= ${#shownJobs[@]} )) && { printDanger "Unknown job number"; return 1; }
|
|
|
|
__cronJob="${shownJobs[$item]}"
|
|
}
|
|
|
|
# Interactively selects and adds a managed cron job to root crontab.
|
|
function cmdCronAdd() {
|
|
local selected jobList
|
|
cmdCronSelect selected jobList || return 1
|
|
printDotText "job" "$selected"
|
|
|
|
grep -Fxq -- "$selected" <(printf '%s\n' "${cronJobs[@]}") || {
|
|
printDotText "adding" "$labelFail"
|
|
printDanger "Cannot add unmanaged job"
|
|
return 1
|
|
}
|
|
|
|
if grep -Fxq -- "$selected" <<< "$jobList"; then
|
|
printDotText "adding" "$labelDone"
|
|
return 0
|
|
fi
|
|
|
|
local tmp
|
|
tmp=$(mktemp) || return 1
|
|
{ printf '%s\n' "$jobList"; printf '%s\n' "$selected"; } > "$tmp"
|
|
crontab -u root "$tmp" || {
|
|
rm -f "$tmp"
|
|
printDotText "adding" "$labelFail"
|
|
return 1
|
|
}
|
|
|
|
rm -f "$tmp"
|
|
printDotText "adding" "$labelDone"
|
|
}
|
|
|
|
# Interactively selects and removes a managed cron job from root crontab.
|
|
function cmdCronRemove() {
|
|
local selected jobList
|
|
cmdCronSelect selected jobList || return 1
|
|
printDotText "job" "$selected"
|
|
|
|
if ! grep -Fxq -- "$selected" <<< "$jobList"; then
|
|
printDotText "removing" "$labelDone"
|
|
return 0
|
|
fi
|
|
|
|
local tmp
|
|
tmp=$(mktemp) || return 1
|
|
grep -Fxv -- "$selected" <<< "$jobList" > "$tmp"
|
|
crontab -u root "$tmp" || {
|
|
rm -f "$tmp"
|
|
printDotText "removing" "$labelFail"
|
|
return 1
|
|
}
|
|
|
|
rm -f "$tmp"
|
|
printDotText "removing" "$labelDone"
|
|
}
|
|
|
|
# Shows managed cron jobs; installed entries in green, missing in gray, unknown in yellow.
|
|
function cmdCronList() {
|
|
local jobList error job fontColor list=""
|
|
run jobList error systemCronList || {
|
|
printDanger "systemCronList: $error";
|
|
return 1;
|
|
}
|
|
for ((i=0; i<${#cronJobs[@]}; i++)); do
|
|
grep -Fxq -- "${cronJobs[$i]}" <<< "$jobList" && fontColor="$fontGreen" || fontColor="$fontGray"
|
|
list+=$'\n'"$fontColor${cronJobs[$i]}$fontReset"
|
|
done
|
|
while IFS= read -r job; do
|
|
[[ -z "$job" ]] && continue
|
|
grep -Fxq -- "$job" <(printf '%s\n' "${cronJobs[@]}") && continue
|
|
grep -Fq -- "$appPath/kube.sh" <<< "$job" || continue
|
|
list+=$'\n'"$fontYellow$job$fontReset"
|
|
done <<< "$jobList"
|
|
|
|
printRow
|
|
local i=0 line total
|
|
total=$(grep -c . <<< "$list")
|
|
while IFS= read -r line; do
|
|
[[ -n "$line" ]] || continue
|
|
((i++))
|
|
num=$(printf "%${#total}d" "$i")
|
|
printDotFix 20 "$num: $line"
|
|
done <<< "$list"
|
|
}
|
|
|
|
# Lists users in the SFTP access group.
|
|
function cmdSftpUserList() {
|
|
local output error
|
|
|
|
printRow
|
|
|
|
if ! run output error sftpUserList "$@"; then
|
|
printDanger "$error"
|
|
else
|
|
printText "$output"
|
|
fi
|
|
}
|
|
|
|
# Enables SFTP access for a domain user.
|
|
function cmdSftpAccessEnable() {
|
|
local error
|
|
|
|
printRow
|
|
|
|
if ! runError error sftpAccessEnable "$@"; then
|
|
printDotText "SFTP access enable" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "SFTP access enable" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Disables SFTP access for a domain user by removing them from the SFTP group.
|
|
function cmdSftpAccessDisable() {
|
|
local error
|
|
|
|
printRow
|
|
|
|
if ! runError error sftpAccessDisable "$@"; then
|
|
printDotText "SFTP access enable" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "SFTP access enable" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# Sets the SFTP password for a domain user from site config.
|
|
function cmdSftpPasswordSet() {
|
|
local error
|
|
|
|
printRow
|
|
|
|
if ! runError error sftpPasswordSet "$@"; then
|
|
printDotText "SFTP password set" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "SFTP password set" "$labelDone"
|
|
fi
|
|
}
|
|
|
|
# [WARNING] Patches sshd_config to enable SFTP via internal-sftp with group-based chroot.
|
|
function cmdSftpAddingSupport() {
|
|
local error
|
|
|
|
printSection "Add SFTP support"
|
|
if ! runError error sftpAddingSupport; then
|
|
printDotText "adding" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "adding" "$labelDone"
|
|
fi
|
|
|
|
printSection "Update fail2ban config"
|
|
if ! runError error fail2banConfigUpdate; then
|
|
printDotText "updating" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "updating" "$labelDone"
|
|
fi
|
|
}
|