diff options
| author | Kamal Wickramanayake <kamal@inbox.lk> | 2026-07-03 21:10:32 +0530 |
|---|---|---|
| committer | Kamal Wickramanayake <kamal@inbox.lk> | 2026-07-03 21:10:32 +0530 |
| commit | a0f3f5a069153c46ac3a85fa75c3ec50fea6ea99 (patch) | |
| tree | 6e97c9b87c314a8a64a25d3ffe10e710db1740fc /microservices/01-oauth2-server/linux/deb/package | |
| parent | aa122113ade36f02dc8fdbebdf1232b5c4b8742c (diff) | |
Added Linux deb file creation scripts and build-all.sh
Diffstat (limited to 'microservices/01-oauth2-server/linux/deb/package')
11 files changed, 217 insertions, 0 deletions
diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles new file mode 100644 index 0000000..a52c085 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles @@ -0,0 +1,3 @@ +/etc/ceit-fs-auth-server/application.yaml +/etc/ceit-fs-auth-server/environment.env +/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control new file mode 100644 index 0000000..9239fb0 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control @@ -0,0 +1,8 @@ +Package: ceit-fs-auth-server +Version: 1.0.0-1 +Section: httpd +Priority: optional +Architecture: all +Depends: openjdk-25-jre | temurin-25-jre | openjdk-25-jdk | temurin-25-jdk +Maintainer: Kamal Wickramanayake <info@software.lk> +Description: A demo Debian package that bundles a Spring Boot application. diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst new file mode 100755 index 0000000..74509f4 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst @@ -0,0 +1,59 @@ +#!/bin/bash + +# Stop on error +set -e + +if [ "$1" == "configure" ] && [ -z "$2" ]; then + # Code here executes only during package install (but not during upgrade) + + # Create a system user + # -r: System user + # -s /sbin/nologin: Prevent the user from logging into the system interactively + # -d /var/lib/ceit-fs-auth-server: Set home directory of user + # ceit-fs-auth-server: Username + useradd -r -s /sbin/nologin -d /var/lib/ceit-fs-auth-server ceit-fs-auth-server || true + +fi + +# Set directory ownership and permissions - Application jar file not to be read by other system users +chown -R root:ceit-fs-auth-server /opt/ceit/ceit-fs-auth-server +chmod 755 /opt/ceit +chmod 750 /opt/ceit/ceit-fs-auth-server +chmod 750 /opt/ceit/ceit-fs-auth-server/app +chmod 640 /opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar + +# Set directory ownership and permissions - Config files not to be read by other system users +chown -R root:ceit-fs-auth-server /etc/ceit-fs-auth-server +chmod 750 /etc/ceit-fs-auth-server +chmod 640 /etc/ceit-fs-auth-server/application.yaml +chmod 640 /etc/ceit-fs-auth-server/environment.env + +if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then + if [ -d /run/systemd/system ]; then + # Reload systemd service configurations + systemctl daemon-reload > /dev/null || true + + if [ -n "$2" ]; then + # Upgrade + # Restart service + if systemctl is-enabled ceit-fs-auth-server > /dev/null; then + systemctl start ceit-fs-auth-server + fi + else + # First install (not upgrade) + # Enable service to start at boot time + systemctl enable ceit-fs-auth-server + # Start service + systemctl start ceit-fs-auth-server + fi + fi +fi + +if [ "$1" == "configure" ] && [ -z "$2" ]; then + # Code here executes only during package install (but not during upgrade) + echo "[INFO] ceit-fs-auth-server service installed." + echo "[INFO] Update /etc/ceit-fs-auth-server/application.yaml to update the configuration." + echo "[INFO] By default, TCP port 8085 is used by the installed server." + echo "[INFO] To allow access from remote systems, you may have to enable firewall for example by running:" + echo "[INFO] ufw allow 8085/tcp" +fi diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm new file mode 100755 index 0000000..261f7af --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm @@ -0,0 +1,14 @@ +#!/bin/bash +set -e + +# Check if the package is being purged (erased entirely including configs) +if [ -z "$DPKG_ROOT" ] && [ "$1" = "purge" ] ; then + update-rc.d ceit-fs-auth-server remove >/dev/null + deluser --quiet ceit-fs-auth-server || true +fi + +# Reload systemd service configuration files. +systemctl daemon-reload + +# postrm script must exit with 0 +exit 0 diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst new file mode 100755 index 0000000..61c2587 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst @@ -0,0 +1,8 @@ +#!/bin/bash + +set -e + +# Put commands that should execute before the pckage is installed. + +# Example: Just print a message +echo "preinst script running..." diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm new file mode 100755 index 0000000..cd4bf94 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm @@ -0,0 +1,9 @@ +#!/bin/bash +set -e + +# Stop service before files are removed +systemctl stop ceit-fs-auth-server || true + +# prerm script must exit with 0 +exit 0 + diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml new file mode 100644 index 0000000..0ce4a3d --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml @@ -0,0 +1,40 @@ +server: + port: 8051 + address: 127.0.0.1 + forward-headers-strategy: native + +#logging: +# level: +# org.springframework.security: trace + +spring: + application: + name: oauth2-server + security: + oauth2: + authorizationserver: + client: + oidc-client: + registration: + client-id: "api-gateway" + client-secret: "{noop}apiGatewayPassword1234" + client-authentication-methods: + - "client_secret_basic" + authorization-grant-types: + - "authorization_code" + - "refresh_token" + redirect-uris: + - "https://fs-react-app.dev.ceit.pdn.ac.lk/bff/login/oauth2/code/api-gateway" + post-logout-redirect-uris: + - "https://fs-react-app.dev.ceit.pdn.ac.lk/" + scopes: + - "openid" + - "profile" + require-authorization-consent: false + +app: + users: + - username: admin + password: "{noop}abc123" + - username: user1 + password: "{noop}abc123" diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env new file mode 100644 index 0000000..5423533 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env @@ -0,0 +1,2 @@ +# Which Spring profile should be active? +#SPRING_PROFILES_ACTIVE=prod diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk b/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk new file mode 100644 index 0000000..73c5b50 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk @@ -0,0 +1,61 @@ +server { + listen 81; + listen [::]:81; + + server_name fs-auth-server.dev.ceit.pdn.ac.lk ; + + root /home/ceit_fs_auth_server/public_web; + index index.html; + + access_log /var/log/nginx/fs-auth-server.dev.ceit.pdn.ac.lk_access.log; + error_log /var/log/nginx/fs-auth-server.dev.ceit.pdn.ac.lk_error.log; + + location / { + try_files $uri $uri/ =404; + } + + location /.well-known/ { + alias /home/ceit_fs_auth_server/well-known/; + } + + location /.well-known/acme-challenge { + alias /var/lib/letsencrypt/.well-known/acme-challenge/; + } + + # Block access to "hidden" files and directories whose names begin with a + # period. This includes directories used by version control systems such + # as Subversion or Git to store control files. + location ~ (^|/)\.(?!well-known).* { + return 403; + } +} + +server { + listen 443 ssl; + listen [::]:443 ssl; + + server_name fs-auth-server.dev.ceit.pdn.ac.lk ; + + location / { + proxy_pass http://127.0.0.1:8051; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-Port 443; + proxy_set_header Host $host; + } + + # + # To create a self signed certificate, run the below command + # + # openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.key -out /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.crt + # + # Or non-intractively + # + # openssl req -new -newkey rsa:4096 -days 365 -nodes -x509 -subj "/C=AB/ST=ABC/L=ABCD/O=ABCDE/CN=fs-auth-server.dev.ceit.pdn.ac.lk" -keyout /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.key -out /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.crt + ssl_certificate /etc/letsencrypt/live/fs-auth-server.dev.ceit.pdn.ac.lk/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/fs-auth-server.dev.ceit.pdn.ac.lk/privkey.pem; # managed by Certbot + + ssl_dhparam /etc/nginx/ssl/dhparams.pem; + +} diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service b/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service new file mode 100644 index 0000000..a26e76b --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service @@ -0,0 +1,12 @@ +[Unit] +Description=ceit-fs-auth-server + +[Service] +User=ceit-fs-auth-server +EnvironmentFile=/etc/ceit-fs-auth-server/environment.env +ExecStart=/usr/bin/java -Dspring.config.import=optional:file:/etc/ceit-fs-auth-server/application.yaml -jar /opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar +Restart=always +RestartSec=30 + +[Install] +WantedBy=multi-user.target diff --git a/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore b/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore new file mode 100644 index 0000000..d392f0e --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore @@ -0,0 +1 @@ +*.jar |
