Correction de bugs au redémarrage
Ajout de vérification de la présence des configurations dans les fichiers de sshd et de sudoers afin de ne pas répéter l'inscription des paramètres à chaque redémarrage du conteneur. Ce problème n'apparaissait pas lors des redéploiements du conteneur, uniquement lors des redémarrages. Correction également d'un bug faisant crasher SSHD lors d'un redémarrage du conteneur et empêchant l'execution du service.
This commit is contained in:
parent
e4b9cb633b
commit
4c500700ab
@ -1,11 +1,11 @@
|
|||||||
FROM alpine:3.20.0 AS monosphere-builder
|
FROM alpine:3.20.0 AS monosphere-builder
|
||||||
#~The open Monosphere Project~
|
#~The open Monosphere Project~
|
||||||
#Version : 0.5.6
|
#Version : 0.5.7
|
||||||
#Autor : Siphonight :)
|
#Autor : Siphonight :)
|
||||||
|
|
||||||
|
|
||||||
#Setting default settings, please change them at run
|
#Setting default settings, please change them at run
|
||||||
ARG MONOSPHERE_VERSION="0.5.6 Alpha"
|
ARG MONOSPHERE_VERSION="0.5.7 Alpha"
|
||||||
|
|
||||||
|
|
||||||
#Defining build settings
|
#Defining build settings
|
||||||
|
|||||||
@ -59,7 +59,6 @@ Ci-dessous une liste non exhaustive des objectifs des prochaines mises à jour d
|
|||||||
- [x] Intégration de ttyrec pour la sauvegarde des sessions effectuées sur le bastion.
|
- [x] Intégration de ttyrec pour la sauvegarde des sessions effectuées sur le bastion.
|
||||||
|
|
||||||
Correction en cours pour les bugs ci dessous :
|
Correction en cours pour les bugs ci dessous :
|
||||||
- Ajout de vérification de la présence des configurations afin de ne pas répéter les paramètres dans les fichiers à chaque redémarrage du conteneur.
|
|
||||||
- Correction d'un bug autorisant systématiquement des utilisateurs du bastion à se connecter sur les serveurs distants si le compte d'accès à ce dernier porte le même nom que l'utilisateur du bastion.
|
- Correction d'un bug autorisant systématiquement des utilisateurs du bastion à se connecter sur les serveurs distants si le compte d'accès à ce dernier porte le même nom que l'utilisateur du bastion.
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|||||||
@ -1,47 +1,49 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
echo "Monosphere sshd service daemon is verifying its configuration..."
|
if ! grep -qo "^Port ${PORT}$" /etc/ssh/sshd_config; then
|
||||||
echo "Port ${PORT}" >> /etc/ssh/sshd_config
|
echo "Génération de la configuration de SSH pour le bastion Monosphere..."
|
||||||
echo "#Last authentication configurations" >> /etc/ssh/sshd_config
|
echo "Port ${PORT}" >> /etc/ssh/sshd_config
|
||||||
if [ "${PASSWORD_AUTH}" -eq "1" ]; then
|
echo "#Last authentication configurations" >> /etc/ssh/sshd_config
|
||||||
|
if [ "${PASSWORD_AUTH}" -eq "1" ]; then
|
||||||
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
||||||
else
|
else
|
||||||
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
|
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
|
||||||
fi
|
fi
|
||||||
if [ "${KEY_AUTH}" -eq "1" ]; then
|
if [ "${KEY_AUTH}" -eq "1" ]; then
|
||||||
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config
|
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config
|
||||||
else
|
else
|
||||||
echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config
|
echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
sshd -t
|
sshd -t
|
||||||
echo "Monosphere sshd service daemon configuration verified"
|
echo "Configuration du service SSHD de Monosphere vérifiée."
|
||||||
|
|
||||||
echo "Monosphere is enabling and executing custom scripts..."
|
echo "Monosphere active et execute les scripts personalisés"
|
||||||
chown -R root:root /opt/custom
|
chown -R root:root /opt/custom
|
||||||
chmod 700 /opt/custom/scripts/*.sh
|
chmod 700 /opt/custom/scripts/*.sh
|
||||||
bash /opt/custom/scripts/*.sh
|
bash /opt/custom/scripts/*.sh
|
||||||
echo "Monosphere custom scripts are successfully enabled"
|
echo "Execution des scripts personalisés terminée."
|
||||||
|
|
||||||
echo "Monosphere is configuring public directory..."
|
echo "Monosphere configure le répertoire public."
|
||||||
chown -R root:root /opt/public
|
chown -R root:root /opt/public
|
||||||
chmod -R 755 /opt/public
|
chmod -R 755 /opt/public
|
||||||
echo "Monosphere public directory successfully configured"
|
echo "Répertoire public configuré."
|
||||||
|
|
||||||
#User accounts creation step
|
#User accounts creation step
|
||||||
|
|
||||||
|
echo "Création des groupes d'utilisateurs."
|
||||||
if ! grep -q "bastionuser" /etc/group; then
|
if ! grep -q "bastionuser" /etc/group; then
|
||||||
addgroup bastionuser
|
addgroup bastionuser
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ ! -f "/root/scripts/users/bastion_users.txt" ]; then
|
if ! grep -q "bastionadmin" /etc/group; then
|
||||||
echo "No userfile detected, creating default user. Please change the default password for security purposes..."
|
addgroup bastionadmin
|
||||||
adduser --disabled-password --gecos "" bastion --shell /bin/bash
|
fi
|
||||||
usermod -aG bastionuser bastion
|
echo "Fin de la création des groupes d'utilisateurs."
|
||||||
echo bastion:bastion | chpasswd
|
|
||||||
else
|
echo "Création des utilisateurs en cours..."
|
||||||
echo "Monosphere is creating the bastion users..."
|
userfile=$(cat /root/scripts/users/bastion_users.txt)
|
||||||
userfile=$(cat /root/scripts/users/bastion_users.txt)
|
for userinfo in $userfile; do
|
||||||
for userinfo in $userfile; do
|
|
||||||
user=$(echo "$userinfo" | cut -d ';' -f 1)
|
user=$(echo "$userinfo" | cut -d ';' -f 1)
|
||||||
is_bastion=$(echo "$userinfo" | cut -d ';' -f 2)
|
is_bastion=$(echo "$userinfo" | cut -d ';' -f 2)
|
||||||
password=$(echo "$userinfo" | cut -d ';' -f 3)
|
password=$(echo "$userinfo" | cut -d ';' -f 3)
|
||||||
@ -52,8 +54,11 @@ else
|
|||||||
if [ "$is_bastion" -eq "1" ]; then
|
if [ "$is_bastion" -eq "1" ]; then
|
||||||
usermod -aG bastionuser "$user"
|
usermod -aG bastionuser "$user"
|
||||||
elif [ "$is_bastion" -eq "0" ]; then
|
elif [ "$is_bastion" -eq "0" ]; then
|
||||||
|
usermod -aG bastionadmin "$user"
|
||||||
|
if ! grep -qo "^$user ALL=(ALL) NOPASSWD:" /etc/sudoers; then
|
||||||
echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
|
echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
|
||||||
echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
|
echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
|
||||||
|
fi
|
||||||
mkdir /home/"$user"
|
mkdir /home/"$user"
|
||||||
ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh
|
ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh
|
||||||
fi
|
fi
|
||||||
@ -71,17 +76,15 @@ else
|
|||||||
chown -R "$user":"$user" /home/"$user"/.ssh
|
chown -R "$user":"$user" /home/"$user"/.ssh
|
||||||
chmod 600 /home/"$user"/.ssh/*
|
chmod 600 /home/"$user"/.ssh/*
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
fi
|
echo "Création des utilisateurs terminée."
|
||||||
echo "Monosphere user creation is finished"
|
echo "Monosphere a bien été configuré et démarré avec succès."
|
||||||
|
|
||||||
echo "Monosphere sshd service daemon is starting..."
|
echo "Démarrage du service SSHD de Monosphere."
|
||||||
rc-status
|
rc-status
|
||||||
rc-service sshd start
|
rc-service sshd restart
|
||||||
echo "Monosphere sshd service daemon is successfully started"
|
|
||||||
|
|
||||||
echo "Monosphere bastion is successfully started"
|
echo "Le bastion Monosphere est désormais en marche."
|
||||||
|
|
||||||
# Keep the container running
|
# Keep the container running
|
||||||
tail -f /dev/null
|
tail -f /dev/null
|
||||||
echo "Monosphere bastion is successfully started"
|
|
||||||
Loading…
x
Reference in New Issue
Block a user