-
Notifications
You must be signed in to change notification settings - Fork 26
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·396 lines (349 loc) · 17 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·396 lines (349 loc) · 17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
#!/bin/sh
#
# Install Nextcloud on FreeBSD/HardenedBSD
#
# Last update: 2026-05-19
# https://github.com/theGeeBee/NextCloudOnFreeBSD/
#
#
# Check for root privileges
#
if [ "$(id -u)" -ne 0 ]; then
echo "This script must be run with root privileges."
echo "Type 'su' to switch to root and remain in this directory."
exit 1
fi
# Check if HBSD is present in uname string
hbsd_test=$(uname -a | grep -o 'HBSD')
# Load config settings
CONFIG_FILE="${PWD}/install.conf"
if [ -f "$CONFIG_FILE" ]; then
. "$CONFIG_FILE"
else
echo "Config file '$CONFIG_FILE' not found. Please create the config file by running pre-install.sh and try again."
exit 1
fi
#
# Set `pkg` to use LATEST if set (default setting)
#
if [ "$FREEBSD_REPO" = "latest" ]; then
mkdir -p /usr/local/etc/pkg/repos
echo "FreeBSD: { enabled: no }" > /usr/local/etc/pkg/repos/FreeBSD.conf
cp /etc/pkg/FreeBSD.conf /usr/local/etc/pkg/repos/nextcloud.conf
sed -i '' "s|quarterly|latest|" /usr/local/etc/pkg/repos/nextcloud.conf
fi
#
# Install `pkg`, update repository, upgrade existing packages
#
echo "Installing pkg and updating repositories"
pkg bootstrap -y
pkg update
pkg upgrade -y
# Install required packages
xargs pkg install -y < "${PWD}/includes/requirements.txt"
# Check if not running in a jail + CREATE_DATASET_*=true
# then create datasets for mariaDB's databases and log files that are optimised
# Also create dataset for nextcloud data - this is not useful if you have multiple datasets
# because it creates it under the root dataset, so modify accordingly, or turn off and create as a directory
# use recommended settings from this script as a guide.
if [ "$(sysctl -n security.jail.jailed)" -ne 1 ] && [ "$CREATE_DATASET_MARIADB" = "true" ]; then
# Remove the directories created by MariaDB so that we can create new ZFS datasets in their place.
rm -r /var/db/mysql
rm -r /var/log/mysql
# Find the ZFS dataset containing the root file system
zfs_dataset=$(zfs list -H -o name -r -t filesystem -o name,mountpoint | awk 'NR==1 {print $1}')
# Check if the dataset is found
if [ -z "$zfs_dataset" ]; then
echo "Error: Root ZFS dataset not found."
exit 1
fi
# Create the MariaDB dataset with the desired properties, including primarycache=metadata
zfs create -o recordsize=16K -o aclmode=restricted -o mountpoint=/var/db/mysql -o primarycache=metadata -o compression=lz4 "$zfs_dataset"/mariadb_data
# Create the second dataset for /var/log/mysql with the same properties
zfs create -o recordsize=128K -o aclmode=restricted -o mountpoint=/var/log/mysql -o primarycache=metadata -o compression=lz4 "$zfs_dataset"/mariadb_logs
# Set ownership to the MySQL user for both datasets
chown -R mysql:mysql /var/db/mysql /var/log/mysql
fi
if [ "$(sysctl -n security.jail.jailed)" -ne 1 ] && [ "$CREATE_DATASET_DATA" = "true" ]; then
# Create Nextcloud dataset with the desired properties
zfs create -o recordsize=16K -o aclmode=restricted -o mountpoint="${DATA_DIRECTORY}" -o primarycache=metadata -o compression=lz4 "${zfs_dataset}/${DATASET}"
# Set ownership to the www user for the dataset
chown www:www "${DATA_DIRECTORY}"
else
# Create the Nextcloud data directory and set ownership to the www user
mkdir -p "${DATA_DIRECTORY}"
chown www:www "${DATA_DIRECTORY}"
fi
# Download virus definitions
freshclam
#
# Download and verify Nextcloud
#
clear
echo "Downloading Nextcloud v${NEXTCLOUD_VERSION}..."
FILE="latest-${NEXTCLOUD_VERSION}.tar.bz2"
if ! fetch -o /tmp "https://download.nextcloud.com/server/releases/${FILE}" "https://download.nextcloud.com/server/releases/${FILE}".asc https://nextcloud.com/nextcloud.asc
then
echo "Failed to download Nextcloud"
exit 1
fi
gpg --import /tmp/nextcloud.asc
if ! gpg --verify "/tmp/${FILE}.asc"
then
echo "GPG Signature Verification Failed!"
echo "The Nextcloud download is corrupt."
exit 1
fi
# Set `sysctl` values (necessary for `redis`)
sysctl kern.ipc.somaxconn=1024
echo "kern.ipc.somaxconn=1024" >> /etc/sysctl.conf
# Fix that allows memories app to load correctly, should you choose to install it
ln -s /usr/local/bin/perl /usr/bin/perl
ln -s /usr/local/bin/perl5 /usr/bin/perl5
#
# Enable services
#
sysrc sendmail_enable="YES"
sysrc apache24_enable="YES"
sysrc mysql_enable="YES"
sysrc php_fpm_enable="YES"
sysrc redis_enable="YES"
sysrc clamav_clamd_enable="YES"
sysrc clamav_freshclam_enable="YES"
# Add user `www` to group `redis`
pw usermod www -G redis
# Extract Nextcloud and give `www` ownership of the directory
tar xjf "/tmp/${FILE}" -C "${WWW_DIR}/"
mv "${WWW_DIR}/nextcloud" "${WWW_DIR}/${HOST_NAME}"
chown -R www:www "${WWW_DIR}/${HOST_NAME}"
#
# Start services
#
service sendmail start
service redis start
apachectl start
service mysql-server start
service php_fpm start
service clamav_clamd onestart
# Create self-signed SSL certificate
if [ "$SSL_DIRECTORY" = "OFF" ]; then
echo "SSL is disabled on this host, please setup SSL on your reverse proxy"
elif [ "$SSL_DIRECTORY" = "PUBLIC" ]; then
SSL_DIRECTORY="/usr/local/etc/letsencrypt/live/${HOST_NAME}"
sed -i '' "s|nextcloud.crt|fullchain.pem|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|nextcloud.key|privkey.pem|" "${PWD}/includes/nextcloud.conf"
pkg install -y security/py-certbot-apache
certbot certonly --apache --agree-tos --email "$EMAIL_ADDRESS" -n -d "$HOST_NAME"
else
mkdir -p "${SSL_DIRECTORY}"
chown www:www "${SSL_DIRECTORY}"
OPENSSL_REQUEST="/C=${COUNTRY_CODE}/CN=${HOST_NAME}"
openssl req -x509 -nodes -days 3652 -sha512 -subj "$OPENSSL_REQUEST" -newkey rsa:2048 -keyout "${SSL_DIRECTORY}/nextcloud.key" -out "${SSL_DIRECTORY}/nextcloud.crt"
fi
# Update virus definitions again to report update to daemon
freshclam --quiet
#
# Copy pre-writting config files and edit in place
#
sed -i '' "s|HOST_NAME|${HOST_NAME}|g" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|IP_ADDRESS|${IP_ADDRESS}|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|IP_ADDRESS|${IP_ADDRESS}|" "${PWD}/includes/httpd.conf"
sed -i '' "s|EMAIL_ADDRESS|${EMAIL_ADDRESS}|" "${PWD}/includes/httpd.conf"
sed -i '' "s|WWW_DIR|${WWW_DIR}|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|SSL_DIRECTORY|${SSL_DIRECTORY}|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|MYTIMEZONE|${TIME_ZONE}|" "${PWD}/includes/php.ini"
sed -i '' "s|IP_ADDRESS|${IP_ADDRESS}|" "${PWD}/includes/certbot.conf"
sed -i '' "s|HOST_NAME|${HOST_NAME}|" "${PWD}/includes/certbot.conf"
# Disable self-signed SSL certificate if SSL_DIRECTORY="OFF"
if [ "$SSL_DIRECTORY" = "OFF" ]; then
sed -i '' "s|LISTEN_PORT|80|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|LISTEN_PORT|80|" "${PWD}/includes/httpd.conf"
sed -i '' "s|SSL_OFF_|# |" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|SSL_OFF_|# |" "${PWD}/includes/httpd.conf"
sed -i '' "s|Header|# Header|" "${PWD}/includes/nextcloud.conf"
else
sed -i '' "s|LISTEN_PORT|443|" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|LISTEN_PORT|443|" "${PWD}/includes/httpd.conf"
sed -i '' "s|SSL_OFF_||" "${PWD}/includes/nextcloud.conf"
sed -i '' "s|SSL_OFF_||" "${PWD}/includes/httpd.conf"
fi
# Disable PHP Just-in-Time compilation for HardenedBSD support
if [ "$hbsd_test" ]
then
sed -i '' "s|pcre.jit=1|pcre.jit=0|" "${PWD}/includes/php.ini"
sed -i '' "s|opcache.jit = 1255|opcache.jit = 0|" "${PWD}/includes/php.ini"
sed -i '' "s|opcache.jit_buffer_size = 8M|opcache.jit_buffer_size = 0|" "${PWD}/includes/php.ini"
fi
mkdir /usr/local/etc/apache24/vhosts
cp -f "${PWD}/includes/httpd.conf" /usr/local/etc/apache24/
cp -f "${PWD}/includes/php.ini" /usr/local/etc/php.ini
cp -f "${PWD}/includes/www.conf" /usr/local/etc/php-fpm.d/
cp -f "${PWD}/includes/redis.conf" /usr/local/etc/redis.conf
cp -f "${PWD}/includes/certbot.conf" /usr/local/etc/apache24/vhosts/certbot.conf
cp -f "${PWD}/includes/nextcloud.conf" "/usr/local/etc/apache24/vhosts/${HOST_NAME}.conf"
cp -f "${PWD}/includes/030_php-fpm.conf" /usr/local/etc/apache24/modules.d/
cp -f "${PWD}/includes/my.cnf" /usr/local/etc/mysql/
#
# Restart Services for modified configuration to take effect
#
apachectl restart
service php_fpm restart
service redis restart
service mysql-server restart
# Create Nextcloud log directory
mkdir -p /var/log/nextcloud/
chown www:www /var/log/nextcloud
#
# Create Nextcloud database, secure database, set MariaDB root password, create Nextcloud DB, user, and password
#
mariadb -u root -e "DELETE FROM mysql.user WHERE User='';"
mariadb -u root -e "DELETE FROM mysql.user WHERE User='root' AND Host NOT IN ('localhost', '127.0.0.1', '::1');"
mariadb -u root -e "DROP DATABASE IF EXISTS test;"
mariadb -u root -e "DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%';"
mariadb -u root -e "CREATE DATABASE ${DB_NAME} CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci;"
mariadb -u root -e "CREATE USER '${DB_USERNAME}'@'127.0.0.1' IDENTIFIED BY '${DB_PASSWORD}';"
mariadb -u root -e "GRANT ALL PRIVILEGES ON ${DB_NAME}.* TO '${DB_USERNAME}'@'127.0.0.1';"
mariadb -u root -e "FLUSH PRIVILEGES;"
mariadb-admin --user=root password "${DB_ROOT_PASSWORD}" reload
# The next two lines allow `root` to login to mysql> without a password
sed -i '' "s|MYPASSWORD|${DB_ROOT_PASSWORD}|" "${PWD}/includes/root_my.cnf"
cp -f "${PWD}/includes/root_my.cnf" /root/.my.cnf
#
# CLI installation and configuration of Nextcloud
#
clear
echo "Installing Nextcloud..."
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" maintenance:install --database="mysql" --database-name="${DB_NAME}" --database-user="${DB_USERNAME}" --database-pass="${DB_PASSWORD}" --database-host="127.0.0.1" --admin-user="${ADMIN_USERNAME}" --admin-pass="${ADMIN_PASSWORD}" --data-dir="${DATA_DIRECTORY}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" db:add-missing-primary-keys
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" db:add-missing-indices
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" db:add-missing-columns
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" db:convert-filecache-bigint --no-interaction
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" maintenance:mimetype:update-db
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set allow_local_remote_servers --value=true --type=boolean
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set maintenance_window_start --value=1 --type=integer
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set default_phone_region --value="${COUNTRY_CODE}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set logtimezone --value="${TIME_ZONE}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set logdateformat --value="Y-m-d H:i:s T"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set log_type --value=file
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set logfile --value="/var/log/nextcloud/${INSTANCE_NAME}.log"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set loglevel --value=2 --type=integer
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set logrotate_size --value=104847600 --type=integer
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set filelocking.enabled --value=true --type=boolean
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set memcache.local --value="\OC\Memcache\APCu"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set redis host --value=/var/run/redis/redis.sock
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set redis port --value=0 --type=integer
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set memcache.distributed --value="\OC\Memcache\Redis"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set memcache.locking --value="\OC\Memcache\Redis"
if [ "$USE_HOSTNAME" = "true" ]; then
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set trusted_domains 0 --value="${HOST_NAME}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set overwritehost --value="${HOST_NAME}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set overwrite.cli.url --value="https://${HOST_NAME}"
else
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set trusted_domains 0 --value="${IP_ADDRESS}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set trusted_domains 1 --value="${HOST_NAME}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set overwrite.cli.url --value="https://${IP_ADDRESS}"
fi
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set overwriteprotocol --value=https
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set htaccess.RewriteBase --value=/
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" maintenance:update:htaccess
# Set Nextcloud to use sendmail (you can change this later in the GUI)
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set mail_smtpmode --value=sendmail
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set mail_sendmailmode --value=pipe
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set mail_domain --value="${HOST_NAME}"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:system:set mail_from_address --value="${SERVER_EMAIL}"
# Disable contactsinteraction because the behaviour is unwanted, and confusing
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:disable contactsinteraction
# Enable external storage support (Example: mount a SMB share in Nextcloud).
# Users are not allowed to mount external storage, but can be allowed under Settings -> Admin -> External Storage
if [ "$EXTERNAL_STORAGE" = "true" ]; then
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:enable files_external
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_external allow_user_mounting --value=no
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_external user_mounting_backends --value="ftp,dav,owncloud,sftp,amazons3,swift,smb,\\OC\\Files\\Storage\\SFTP_Key,\\OC\\Files\\Storage\\SMB_OC"
fi
#
# Install Nextcloud Featured Apps if (alphabetical)
#
if [ "$INSTALL_APPS" = "true" ]; then
clear
echo "Nextcloud is now installed, installing recommended Apps..."
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install calendar
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install contacts
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install deck
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install mail
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install notes
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install spreed # Nextcloud Talk
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install tasks
fi
#
# Install Antivirus for Files
#
clear
echo "Now installing and configuring Antivirus for File using ClamAV..."
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:install files_antivirus
### set correct value for path on FreeBSD and set default action
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_antivirus av_mode --value=socket
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_antivirus av_socket --value=/var/run/clamav/clamd.sock
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_antivirus av_stream_max_length --value=104857600 --type=integer
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set files_antivirus av_infected_action --value=only_log
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" config:app:set activity notify_notification_virus_detected --value=1 --type=integer
#
# SERVER SIDE ENCRYPTION
# Server-side encryption makes it possible to encrypt files which are uploaded to this server.
# This comes with limitations like a performance penalty, so enable this only if needed.
#
if [ "$ENCRYPT_DATA" = "true" ]; then
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" app:enable encryption
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" encryption:enable
fi
# Set Nextcloud to run maintenance tasks as a cron job
sed -i '' "s|WWW_DIR|${WWW_DIR}|" "${PWD}/includes/www-crontab"
sed -i '' "s|HOST_NAME|${HOST_NAME}|" "${PWD}/includes/www-crontab"
mdo -u www php "${WWW_DIR}/${HOST_NAME}/occ" background:cron
crontab -u www "${PWD}/includes/www-crontab"
# Create reference file
if [ "$SSL_DIRECTORY" = "OFF" ]; then
cat >> "/root/${HOST_NAME}_reference.txt" <<EOL
Nextcloud installation details:
===============================
Server address : http://${HOST_NAME} or http://${IP_ADDRESS}
Data directory : ${DATA_DIRECTORY}
Nextcloud GUI Login:
--------------------
Username : ${ADMIN_USERNAME}
Password : ${ADMIN_PASSWORD}
MariaDB Information:
------------------
Database name : ${DB_NAME}
Database username : ${DB_USERNAME}
Database password : ${DB_PASSWORD}
DB root password : ${DB_ROOT_PASSWORD}
EOL
else
cat >> "/root/${HOST_NAME}_reference.txt" <<EOL
Nextcloud installation details:
===============================
Server address : https://${HOST_NAME} or https://${IP_ADDRESS}
Data directory : ${DATA_DIRECTORY}
Nextcloud GUI Login:
--------------------
Username : ${ADMIN_USERNAME}
Password : ${ADMIN_PASSWORD}
MariaDB Information:
------------------
Database name : ${DB_NAME}
Database username : ${DB_USERNAME}
Database password : ${DB_PASSWORD}
DB root password : ${DB_ROOT_PASSWORD}
EOL
fi
#
# All done!
# Print copy of reference info to console.
#
clear
echo "Installation Complete!"
echo ""
cat "/root/${HOST_NAME}_reference.txt"
echo "These details have also been written to /root/${HOST_NAME}_reference.txt"
# Run the Nextcloud background task for the first time
mdo -u www /usr/local/bin/php -f "${WWW_DIR}/${HOST_NAME}/cron.php" &