You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

38 lines
1.0 KiB

  1. #!/bin/bash
  2. set -eux # -x for verbose logging to juju debug-log
  3. ## ``--force-yes`` is required as kal-manage is not signed correctly.
  4. ## kal-manage provides the script /usr/lib/kal/dusk/sbin/ssh-cmd-validate
  5. ## used to validate any entrant connection to SSH.
  6. apt-get install -y --force-yes rsync kal-manage
  7. mkdir -p /var/mirror
  8. mkdir -p /var/lib/rsync
  9. groupadd -r rsync
  10. useradd -r rsync -d /var/lib/rsync -g rsync
  11. chown rsync:rsync /var/lib/rsync
  12. ## build silently a key for 'rsync' user:
  13. su -c 'ssh-keygen -t rsa -N "" -f ~/.ssh/id_rsa -q' - rsync
  14. ## /etc/sudoers
  15. cat <<EOF >> /etc/sudoers
  16. ## allow rsync to access /var/mirror
  17. rsync ALL=(root) NOPASSWD: /usr/bin/rsync --server -vlogDtprRz --delete . /var/mirror/*
  18. rsync ALL=(root) NOPASSWD: /usr/bin/rsync --server -vlogDtprRze.iLs --delete . /var/mirror/*
  19. rsync ALL=(root) NOPASSWD: /usr/bin/rsync --server -vlogDtprRze.iLsf --delete . /var/mirror/*
  20. rsync ALL=(root) NOPASSWD: /usr/bin/rsync --server -vlogDtprRze.iLsf --bwlimit=200 --delete . /var/mirror/*
  21. EOF