From c68422f884314db91c86b3166a3f37a2643a60fa Mon Sep 17 00:00:00 2001
From: "p.delpy@dkfz-heidelberg.de"
Date: Mon, 30 Sep 2024 14:06:57 +0200
Subject: [PATCH] refactor: set bridgehead config and component directory as
variable in prerequisites.sh
---
lib/prerequisites.sh | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/lib/prerequisites.sh b/lib/prerequisites.sh
index 235826a..c2d3904 100755
--- a/lib/prerequisites.sh
+++ b/lib/prerequisites.sh
@@ -3,14 +3,16 @@
source lib/functions.sh
detectCompose
+configDirectory="/etc/bridgehead/"
+componentDirectory="/srv/docker/bridgehead/"
if ! id "bridgehead" &>/dev/null; then
log ERROR "User bridgehead does not exist. Please run bridgehead install $PROJECT"
exit 1
fi
-checkOwner /srv/docker/bridgehead bridgehead || exit 1
-checkOwner /etc/bridgehead bridgehead || exit 1
+checkOwner ${configDirectory} bridgehead || exit 1
+checkOwner ${componentDirectory} bridgehead || exit 1
## Check if user is a su
log INFO "Checking if all prerequisites are met ..."
@@ -32,31 +34,31 @@ fi
log INFO "Checking configuration ..."
## Download submodule
-if [ ! -d "/etc/bridgehead/" ]; then
- fail_and_report 1 "Please set up the config folder at /etc/bridgehead. Instruction are in the readme."
+if [ ! -d ${configDirectory} ]; then
+ fail_and_report 1 "Please set up the config folder at ${configDirectory}. Instruction are in the readme."
fi
# TODO: Check all required variables here in a generic loop
#check if project env is present
-if [ -d "/etc/bridgehead/${PROJECT}.conf" ]; then
- fail_and_report 1 "Project config not found. Please copy the template from ${PROJECT} and put it under /etc/bridgehead-config/${PROJECT}.conf."
+if [ -d "${configDirectory}${PROJECT}.conf" ]; then
+ fail_and_report 1 "Project config not found. Please copy the template from ${PROJECT} and put it under ${configDirectory}${PROJECT}.conf."
fi
# TODO: Make sure you're in the right directory, or, even better, be independent from the working directory.
log INFO "Checking ssl cert for accessing bridgehead via https"
-if [ ! -d "/etc/bridgehead/traefik-tls" ]; then
+if [ ! -d "${configDirectory}traefik-tls" ]; then
log WARN "TLS certs for accessing bridgehead via https missing, we'll now create a self-signed one. Please consider getting an officially signed one (e.g. via Let's Encrypt ...) and put into /etc/bridgehead/traefik-tls"
mkdir -p /etc/bridgehead/traefik-tls
fi
-if [ ! -e "/etc/bridgehead/traefik-tls/fullchain.pem" ]; then
+if [ ! -e "${configDirectory}traefik-tls/fullchain.pem" ]; then
openssl req -x509 -newkey rsa:4096 -nodes -keyout /etc/bridgehead/traefik-tls/privkey.pem -out /etc/bridgehead/traefik-tls/fullchain.pem -days 3650 -subj "/CN=$HOST"
fi
-if [ -e /etc/bridgehead/vault.conf ]; then
+if [ -e $configDirectory}vault.conf ]; then
if [ "$(stat -c "%a %U" /etc/bridgehead/vault.conf)" != "600 bridgehead" ]; then
fail_and_report 1 "/etc/bridgehead/vault.conf has wrong owner/permissions. To correct this issue, run chmod 600 /etc/bridgehead/vault.conf && chown bridgehead /etc/bridgehead/vault.conf."
fi
@@ -64,7 +66,7 @@ fi
log INFO "Checking network access ($BROKER_URL_FOR_PREREQ) ..."
-source /etc/bridgehead/${PROJECT}.conf
+source ${configDirectory}${PROJECT}.conf
source ${PROJECT}/vars
if [ "${PROJECT}" != "minimal" ]; then
@@ -92,10 +94,10 @@ if [ "${PROJECT}" != "minimal" ]; then
fi
fi
checkPrivKey() {
- if [ -e /etc/bridgehead/pki/${SITE_ID}.priv.pem ]; then
+ if [ -e ${configDirectory}pki/${SITE_ID}.priv.pem ]; then
log INFO "Success - private key found."
else
- log ERROR "Unable to find private key at /etc/bridgehead/pki/${SITE_ID}.priv.pem. To fix, please run\n bridgehead enroll ${PROJECT}\nand follow the instructions."
+ log ERROR "Unable to find private key at ${configDirectory}pki/${SITE_ID}.priv.pem. To fix, please run\n bridgehead enroll ${PROJECT}\nand follow the instructions."
return 1
fi
return 0