Skip to content
Snippets Groups Projects
freedombone-app-pleroma 47.3 KiB
Newer Older
Bob Mottram's avatar
Bob Mottram committed
    # get the repo
Bob Mottram's avatar
Bob Mottram committed
    if [ -f /repos/pleroma/index.html ]; then
        mv /repos/pleroma /repos/pleroma-fe
    fi
Bob Mottram's avatar
Bob Mottram committed
    if [ -d /repos/pleroma ]; then
        mkdir -p $PLEROMA_DIR
        cp -r -p /repos/pleroma/. $PLEROMA_DIR
Bob Mottram's avatar
Bob Mottram committed
        cd "$PLEROMA_DIR" || exit 834537453
Bob Mottram's avatar
Bob Mottram committed
        git pull
    else
        function_check git_clone
        git_clone $PLEROMA_REPO $PLEROMA_DIR
Bob Mottram's avatar
Bob Mottram committed
    if [ ! -d $PLEROMA_DIR ]; then
        echo $'Unable to clone pleroma backend repo'
        exit 783523
    fi


    # create user
    useradd -d $PLEROMA_DIR -s /bin/false pleroma


Bob Mottram's avatar
Bob Mottram committed
    # checkout the commit
Bob Mottram's avatar
Bob Mottram committed
    cd "$PLEROMA_DIR" || exit 62452428
Bob Mottram's avatar
Bob Mottram committed
    git checkout $PLEROMA_COMMIT -b $PLEROMA_COMMIT
    set_completion_param "pleroma commit" "$PLEROMA_COMMIT"
Bob Mottram's avatar
Bob Mottram committed
    chown -R pleroma:pleroma $PLEROMA_DIR
Bob Mottram's avatar
Bob Mottram committed


    # web config
    function_check add_ddns_domain
Bob Mottram's avatar
Bob Mottram committed
    add_ddns_domain "$PLEROMA_DOMAIN_NAME"
Bob Mottram's avatar
Bob Mottram committed

    PLEROMA_ONION_HOSTNAME=$(add_onion_service pleroma 80 ${PLEROMA_ONION_PORT})

    pleroma_nginx_site=/etc/nginx/sites-available/$PLEROMA_DOMAIN_NAME
    if [[ $ONION_ONLY == "no" ]]; then
        function_check nginx_http_redirect
Bob Mottram's avatar
Bob Mottram committed
        nginx_http_redirect "$PLEROMA_DOMAIN_NAME" "index index.html"
        { echo '';
Bob Mottram's avatar
Bob Mottram committed
          echo 'proxy_cache_path /tmp/pleroma-media-cache levels=1:2 keys_zone=pleroma_media_cache:10m max_size=100m inactive=80m use_temp_path=off;';
          echo '';
          echo 'server {';
          echo '  listen 443 ssl http2;';
          echo '  #listen [::]:443 ssl http2;';
          echo "  server_name $PLEROMA_DOMAIN_NAME;";
          echo '';
          echo '  # Security'; } >> "$pleroma_nginx_site"
Bob Mottram's avatar
Bob Mottram committed
        function_check nginx_ssl
Bob Mottram's avatar
Bob Mottram committed
        nginx_ssl "$PLEROMA_DOMAIN_NAME"
Bob Mottram's avatar
Bob Mottram committed

Bob Mottram's avatar
Bob Mottram committed
        function_check nginx_security_options
        nginx_security_options "$PLEROMA_DOMAIN_NAME"
Bob Mottram's avatar
Bob Mottram committed

        { echo '  add_header Strict-Transport-Security max-age=0;';
Bob Mottram's avatar
Bob Mottram committed
          echo '';
          echo '  # Logs';
          echo '  access_log /dev/null;';
          echo '  error_log /dev/null;';
          echo '';
          echo "  root $PLEROMA_DIR;";
          echo '';
          echo '  index index.html;';
Bob Mottram's avatar
Bob Mottram committed
          echo '';
          echo '  gzip_vary on;';
          echo '  gzip_proxied any;';
          echo '  gzip_comp_level 6;';
          echo '  gzip_buffers 16 8k;';
          echo '  gzip_http_version 1.1;';
          echo '  gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript application/activity+json application/atom+xml;';
          echo '';
Bob Mottram's avatar
Bob Mottram committed
          echo '  location / {';
          echo '    client_max_body_size 15m;';
          echo '    client_body_buffer_size 15m;';
          echo '';
          echo '    limit_conn conn_limit_per_ip 50;';
          echo '    limit_req zone=req_limit_per_ip burst=50 nodelay;';
          echo '';
Bob Mottram's avatar
Bob Mottram committed
          echo "    add_header 'Access-Control-Allow-Origin' '*' always;";
          echo "    add_header 'Access-Control-Allow-Methods' 'POST, GET, OPTIONS' always;";
          echo "    add_header 'Access-Control-Allow-Headers' 'Authorization, Content-Type' always;";
          echo "    if (\$request_method = OPTIONS) {";
          echo '        return 204;';
          echo '    }';
          echo '';
          echo '    proxy_http_version 1.1;';
Bob Mottram's avatar
Bob Mottram committed
          echo "    proxy_set_header Upgrade \$http_upgrade;";
          echo '    proxy_set_header Connection "upgrade";';
          echo "    proxy_set_header Host \$http_host;";
          echo '';
Bob Mottram's avatar
Bob Mottram committed
          echo "    proxy_pass http://localhost:$PLEROMA_PORT;";
          echo '  }';
          echo '';
Bob Mottram's avatar
Bob Mottram committed
          echo '  location /proxy {';
          echo '    client_max_body_size 15m;';
          echo '    client_body_buffer_size 15m;';
          echo '';
          echo '    limit_conn conn_limit_per_ip 50;';
          echo '    limit_req zone=req_limit_per_ip burst=50 nodelay;';
          echo '';
          echo '    proxy_cache pleroma_media_cache;';
Bob Mottram's avatar
Bob Mottram committed
          echo '    proxy_cache_lock on;';
          echo "    proxy_pass http://localhost:$PLEROMA_PORT;";
          echo '  }';
          echo '  # include snippets/well-known.conf;';
          echo '}'; } >> "$pleroma_nginx_site"
Bob Mottram's avatar
Bob Mottram committed
    else
Bob Mottram's avatar
Bob Mottram committed
        echo 'proxy_cache_path /tmp/pleroma-media-cache levels=1:2 keys_zone=pleroma_media_cache:10m max_size=100m inactive=80m use_temp_path=off;' > "$pleroma_nginx_site"
        echo '' >> "$pleroma_nginx_site"
Bob Mottram's avatar
Bob Mottram committed
    fi
Bob Mottram's avatar
Bob Mottram committed
    { echo 'server {';
Bob Mottram's avatar
Bob Mottram committed
      echo "    listen 127.0.0.1:$PLEROMA_ONION_PORT default_server http2;";
Bob Mottram's avatar
Bob Mottram committed
      echo "    server_name $PLEROMA_ONION_HOSTNAME;";
      echo ''; } >> "$pleroma_nginx_site"
Bob Mottram's avatar
Bob Mottram committed
    function_check nginx_security_options
    nginx_security_options "$PLEROMA_DOMAIN_NAME"
Bob Mottram's avatar
Bob Mottram committed
    { echo '';
      echo '  # Logs';
      echo '  access_log /dev/null;';
      echo '  error_log /dev/null;';
      echo '';
      echo "  root $PLEROMA_DIR;";
      echo '';
      echo '  index index.html;';
Bob Mottram's avatar
Bob Mottram committed
      echo '';
      echo '  gzip_vary on;';
      echo '  gzip_proxied any;';
      echo '  gzip_comp_level 6;';
      echo '  gzip_buffers 16 8k;';
      echo '  gzip_http_version 1.1;';
      echo '  gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript application/activity+json application/atom+xml;';
      echo '';
Bob Mottram's avatar
Bob Mottram committed
      echo '  location / {';
      echo '    client_max_body_size 15m;';
      echo '    client_body_buffer_size 15m;';
      echo '';
      echo '    limit_conn conn_limit_per_ip 50;';
      echo '    limit_req zone=req_limit_per_ip burst=50 nodelay;';
      echo '';
Bob Mottram's avatar
Bob Mottram committed
      echo "    add_header 'Access-Control-Allow-Origin' '*' always;";
      echo "    add_header 'Access-Control-Allow-Methods' 'POST, GET, OPTIONS' always;";
      echo "    add_header 'Access-Control-Allow-Headers' 'Authorization, Content-Type' always;";
      echo "    if (\$request_method = OPTIONS) {";
      echo '        return 204;';
      echo '    }';
      echo '';
Bob Mottram's avatar
Bob Mottram committed
      echo '    proxy_http_version 1.1;';
      echo "    proxy_set_header Upgrade \$http_upgrade;";
      echo '    proxy_set_header Connection "upgrade";';
      echo "    proxy_set_header Host \$http_host;";
      echo '';
Bob Mottram's avatar
Bob Mottram committed
      echo "    proxy_pass http://localhost:$PLEROMA_PORT;";
Bob Mottram's avatar
Bob Mottram committed
      echo '  }';
      echo '';
Bob Mottram's avatar
Bob Mottram committed
      echo '  location /proxy {';
      echo '    client_max_body_size 15m;';
      echo '    client_body_buffer_size 15m;';
      echo '';
      echo '    limit_conn conn_limit_per_ip 50;';
      echo '    limit_req zone=req_limit_per_ip burst=50 nodelay;';
      echo '';
      echo '    proxy_cache pleroma_media_cache;';
Bob Mottram's avatar
Bob Mottram committed
      echo '    proxy_cache_lock on;';
      echo "    proxy_pass http://localhost:$PLEROMA_PORT;";
      echo '  }';
      echo '  # include snippets/well-known.conf;';
      echo '}'; } >> "$pleroma_nginx_site"
Bob Mottram's avatar
Bob Mottram committed

    # back end
Bob Mottram's avatar
Bob Mottram committed
    cd "$PLEROMA_DIR" || exit 246824684
Bob Mottram's avatar
Bob Mottram committed
    chown -R pleroma:pleroma "$PLEROMA_DIR/"*
Bob Mottram's avatar
Bob Mottram committed
    if ! sudo -u pleroma mix local.hex --force; then
Bob Mottram's avatar
Bob Mottram committed
        echo $'mix local.hex failed'
        exit 1745673
    fi
Bob Mottram's avatar
Bob Mottram committed
    if ! sudo -u pleroma mix deps.get --force; then
Bob Mottram's avatar
Bob Mottram committed
        echo $'mix deps.get failed'
        exit 7325733
    fi
Bob Mottram's avatar
Bob Mottram committed

    function_check pleroma_create_database
    pleroma_create_database

Bob Mottram's avatar
Bob Mottram committed
    "${PROJECT_NAME}-pass" -u "$MY_USERNAME" -a pleroma -p "$PLEROMA_ADMIN_PASSWORD"
Bob Mottram's avatar
Bob Mottram committed

    # NOTE: we don't need to install the frontend separately,
    # since the backend contains a precompiled version of it

    install_gnusocial_default_background "pleroma" "$PLEROMA_DOMAIN_NAME"
Bob Mottram's avatar
Bob Mottram committed
    if [ ! -f "$PLEROMA_DIR/priv/static/static/config.json" ]; then
Bob Mottram's avatar
Bob Mottram committed
        echo $"$PLEROMA_DIR/priv/static/static/config.json file missing"
Bob Mottram's avatar
Bob Mottram committed
    sed -i 's|"theme":.*|"theme": "base16-summerfruit-dark.css",|g' "$PLEROMA_DIR/priv/static/static/config.json"
Bob Mottram's avatar
Bob Mottram committed

Bob Mottram's avatar
Bob Mottram committed
    if [ "$PLEROMA_BACKGROUND_IMAGE_URL" ]; then
        pleroma_set_background_image_from_url $PLEROMA_DIR/priv/static "$PLEROMA_DOMAIN_NAME" "$PLEROMA_BACKGROUND_IMAGE_URL" "$PLEROMA_TITLE"
    # Get certificate
    function_check create_site_certificate
Bob Mottram's avatar
Bob Mottram committed
    create_site_certificate "$PLEROMA_DOMAIN_NAME" 'yes'

    function_check nginx_ensite
Bob Mottram's avatar
Bob Mottram committed
    nginx_ensite "$PLEROMA_DOMAIN_NAME"

    systemctl restart postgresql
    systemctl restart nginx

    set_completion_param "pleroma domain" "$PLEROMA_DOMAIN_NAME"

Bob Mottram's avatar
Bob Mottram committed
    # We need to set up the url option again because it somehow gets
    # lost during mix compile
    if ! grep -q 'watchers: [],' $pleroma_secret; then
Bob Mottram's avatar
Bob Mottram committed
        sed -i 's|watchers: \[\]|watchers: \[\],|g' $pleroma_secret
Bob Mottram's avatar
Bob Mottram committed
    fi
    if ! grep -q 'url:' $pleroma_secret; then
        if [[ $ONION_ONLY == 'no' ]]; then
Bob Mottram's avatar
Bob Mottram committed
            sed -i "/watchers: /a url: [host: \"$PLEROMA_DOMAIN_NAME\", scheme: \"https\", port: 443]" $pleroma_secret
Bob Mottram's avatar
Bob Mottram committed
        else
Bob Mottram's avatar
Bob Mottram committed
            sed -i "/watchers: /a url: [host: \"$PLEROMA_ONION_HOSTNAME\", scheme: \"http\", port: 80]" $pleroma_secret
Bob Mottram's avatar
Bob Mottram committed
    create_pleroma_blocklist

Bob Mottram's avatar
Bob Mottram committed
    # daemon
Bob Mottram's avatar
Bob Mottram committed
    { echo '[Unit]';
      echo 'Description=Pleroma social network';
      echo 'After=network.target postgresql.service';
      echo '';
      echo '[Service]';
      echo 'User=pleroma';
      echo "WorkingDirectory=$PLEROMA_DIR";
      echo "Environment=\"HOME=$PLEROMA_DIR\"";
      echo 'ExecStart=/usr/local/bin/mix phx.server';
      echo "ExecReload=/bin/kill \$MAINPID";
      echo 'KillMode=process';
      echo 'Restart=on-failure';
      echo '';
      echo '[Install]';
      echo 'WantedBy=multi-user.target';
      echo 'Alias=pleroma.service'; } > /etc/systemd/system/pleroma.service

    # avoid mixed content warnings
    sed -i '/config :pleroma, :media_proxy/!b;n;c####enabled: true,' $PLEROMA_DIR/config/config.exs
    sed -i 's|####enabled|  enabled|g' $PLEROMA_DIR/config/config.exs
Bob Mottram's avatar
Bob Mottram committed
    sed -i 's|redirect_on_failure:.*|redirect_on_failure: false|g' $PLEROMA_DIR/config/config.exs
    sed -i 's|:chat, enabled:.*|:chat, enabled: false|g' $PLEROMA_DIR/config/config.exs
    # set registrations open initially
    sed -i 's|registrations_open:.*|registrations_open: true,|g' $PLEROMA_DIR/config/config.exs
    sed -i 's|"registrationOpen":.*|"registrationOpen": true,|g' $PLEROMA_DIR/priv/static/static/config.json

    if ! grep -q "media_proxy" $PLEROMA_DIR/priv/static/static/config.json; then
        sed -i '/"name":/a "media_proxy": true,' $PLEROMA_DIR/priv/static/static/config.json
        sed -i 's|"media_proxy"|  "media_proxy"|g' $PLEROMA_DIR/priv/static/static/config.json
    else
        sed -i 's|"media_proxy".*|"media_proxy": false,|g' $PLEROMA_DIR/priv/static/static/config.json
    fi
    sed -i 's|"chatDisabled":.*|"chatDisabled": true,|g' $PLEROMA_DIR/priv/static/static/config.json
Bob Mottram's avatar
Bob Mottram committed
    systemctl daemon-reload
    systemctl enable pleroma
    systemctl start pleroma

    cd $PLEROMA_DIR || exit 1935638
    mix register_user "$MY_USERNAME" "$MY_USERNAME" "$MY_EMAIL_ADDRESS" $"Your bio goes here" "$PLEROMA_ADMIN_PASSWORD"

Bob Mottram's avatar
Bob Mottram committed
    APP_INSTALLED=1
}

# NOTE: deliberately there is no "exit 0"