monosphere-bastion/entrypoint.sh
Siphonight 8ccc9e6499 Optimisations et correction de bugs
Ajout d'un lien symbolique pour l'accès au script par les comptes internes du bastion. Correction d'un bug concernant les clés ssh qui utilisait la systématiquement la dernière clé SSH déclarée. Optimization du script de menu serveurs en retirant les utilisations répétées de whoami et en ajoutant une vérification de la séléction choisie qui prends désormais en compte l'abscence d'input utilisateur sans envoyer une erreur de script.
2024-06-19 10:55:57 +02:00

87 lines
3.0 KiB
Bash

#!/bin/bash
echo "Monosphere sshd service daemon is verifying its configuration..."
echo "Port ${PORT}" >> /etc/ssh/sshd_config
echo "#Last authentication configurations" >> /etc/ssh/sshd_config
if [ "${PASSWORD_AUTH}" -eq "1" ]; then
echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
else
echo "PasswordAuthentication no" >> /etc/ssh/sshd_config
fi
if [ "${KEY_AUTH}" -eq "1" ]; then
echo "PubkeyAuthentication yes" >> /etc/ssh/sshd_config
else
echo "PubkeyAuthentication no" >> /etc/ssh/sshd_config
fi
sshd -t
echo "Monosphere sshd service daemon configuration verified"
echo "Monosphere is enabling and executing custom scripts..."
chown -R root:root /opt/custom
chmod 700 /opt/custom/scripts/*.sh
bash /opt/custom/scripts/*.sh
echo "Monosphere custom scripts are successfully enabled"
echo "Monosphere is configuring public directory..."
chown -R root:root /opt/public
chmod -R 755 /opt/public
echo "Monosphere public directory successfully configured"
#User accounts creation step
if ! grep -q "bastionuser" /etc/group; then
addgroup bastionuser
fi
if [ ! -f "/root/scripts/users/bastion_users.txt" ]; then
echo "No userfile detected, creating default user. Please change the default password for security purposes..."
adduser --disabled-password --gecos "" bastion --shell /bin/bash
usermod -aG bastionuser bastion
echo bastion:bastion | chpasswd
else
echo "Monosphere is creating the bastion users..."
userfile=$(cat /root/scripts/users/bastion_users.txt)
for userinfo in $userfile; do
user=$(echo "$userinfo" | cut -d ';' -f 1)
is_bastion=$(echo "$userinfo" | cut -d ';' -f 2)
password=$(echo "$userinfo" | cut -d ';' -f 3)
setkeys=$(echo "$userinfo" | cut -d ';' -f 4)
adduser --disabled-password --gecos "" "$user" --shell /bin/bash
if [ "$is_bastion" -eq "1" ]; then
usermod -aG bastionuser "$user"
elif [ "$is_bastion" -eq "0" ]; then
echo "$user ALL=(ALL) NOPASSWD: /usr/local/bin/ttyplay*" | sudo EDITOR='tee -a' visudo
echo "$user ALL=(ALL) NOPASSWD: /bin/ls*" | sudo EDITOR='tee -a' visudo
mkdir /home/"$user"
ln -s /opt/public/scripts/server_menu.sh /home/"$user"/server_menu.sh
fi
if [ "$password" != "0" ]; then
echo "$user:$password" | chpasswd
else
echo "$user:$user" | chpasswd
fi
if [ "$setkeys" -eq "1" ]; then
mkdir -p /home/"$user"/.ssh
chmod 700 /home/"$user"/.ssh
cp -r /root/scripts/users/"$user"/* /home/"$user"/.ssh/
chown -R "$user":"$user" /home/"$user"/.ssh
chmod 600 /home/"$user"/.ssh/*
fi
done
fi
echo "Monosphere user creation is finished"
echo "Monosphere sshd service daemon is starting..."
rc-status
rc-service sshd start
echo "Monosphere sshd service daemon is successfully started"
echo "Monosphere bastion is successfully started"
# Keep the container running
tail -f /dev/null
echo "Monosphere bastion is successfully started"