From a0f3f5a069153c46ac3a85fa75c3ec50fea6ea99 Mon Sep 17 00:00:00 2001 From: Kamal Wickramanayake Date: Fri, 3 Jul 2026 21:10:32 +0530 Subject: Added Linux deb file creation scripts and build-all.sh --- .../01-oauth2-server/linux/deb/.gitignore | 1 + microservices/01-oauth2-server/linux/deb/README | 59 +++++++++++++++++++++ microservices/01-oauth2-server/linux/deb/build.sh | 36 +++++++++++++ .../linux/deb/package/DEBIAN/conffiles | 3 ++ .../linux/deb/package/DEBIAN/control | 8 +++ .../linux/deb/package/DEBIAN/postinst | 59 +++++++++++++++++++++ .../linux/deb/package/DEBIAN/postrm | 14 +++++ .../linux/deb/package/DEBIAN/preinst | 8 +++ .../linux/deb/package/DEBIAN/prerm | 9 ++++ .../etc/ceit-fs-auth-server/application.yaml | 40 ++++++++++++++ .../etc/ceit-fs-auth-server/environment.env | 2 + .../fs-auth-server.dev.ceit.pdn.ac.lk | 61 ++++++++++++++++++++++ .../etc/systemd/system/ceit-fs-auth-server.service | 12 +++++ .../opt/ceit/ceit-fs-auth-server/app/.gitignore | 1 + 14 files changed, 313 insertions(+) create mode 100644 microservices/01-oauth2-server/linux/deb/.gitignore create mode 100644 microservices/01-oauth2-server/linux/deb/README create mode 100755 microservices/01-oauth2-server/linux/deb/build.sh create mode 100644 microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles create mode 100644 microservices/01-oauth2-server/linux/deb/package/DEBIAN/control create mode 100755 microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst create mode 100755 microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm create mode 100755 microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst create mode 100755 microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm create mode 100644 microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml create mode 100644 microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env create mode 100644 microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk create mode 100644 microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service create mode 100644 microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore (limited to 'microservices/01-oauth2-server/linux') diff --git a/microservices/01-oauth2-server/linux/deb/.gitignore b/microservices/01-oauth2-server/linux/deb/.gitignore new file mode 100644 index 0000000..c00df13 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/.gitignore @@ -0,0 +1 @@ +*.deb diff --git a/microservices/01-oauth2-server/linux/deb/README b/microservices/01-oauth2-server/linux/deb/README new file mode 100644 index 0000000..a9b2810 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/README @@ -0,0 +1,59 @@ +This directory contains everything to build a deb package that bundles a Spring Boot app that starts a web server. + +#### + +Executable scripts: + + create-new-project.sh - This script can be used to create a new deb package project similar to this project that uses a different name (than ceit-fs-auth-server). Output will be placed inside 'out' directory. + + build.sh - This script builds the deb package. If the above script is used, go to the corresponding directory inside out directory to find a copy of this build.sh script. + +#### + +To create a new deb package project that uses 'mycompany-myapp' as the name, run the following command: + + ./create-new-project.sh mycompany mycompany-myapp + + The newly generated project files will be found inside the out directory. + +#### + +To build, run the following command: + + ./build.sh + + Note that the Spring Boot application has not been bundled with this. You need to build it seperately and put it in the correct directory (run build.sh for further details). + +#### + +To install the build deb package run the following commands replacing the package.deb with the correct name of the deb file. + + cp package.deb /tmp + cd /tmp + apt install ./package.deb + +The above "apt install" will download dependencies if needed. Otherwise, dpkg command can just be used to install or upgrade the package: + + dpkg -i package.deb + +After installing the package, update the configuration file /etc/ceit-fs-auth-server/application.yaml . + +Enable service to start at boot time: + + systemctl enable ceit-fs-auth-server + +Start service: + + systemctl start ceit-fs-auth-server + +View service log: + + journalctl -u ceit-fs-auth-server -f + + (Press CTRL+C to terminate log viewing) + +Access the service: + + http://server-ip-or-hostname:8085/ + + (Instead of 8085, use the port configured in application.yaml file) diff --git a/microservices/01-oauth2-server/linux/deb/build.sh b/microservices/01-oauth2-server/linux/deb/build.sh new file mode 100755 index 0000000..994b132 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/build.sh @@ -0,0 +1,36 @@ +#!/bin/bash + +# Define a function that sends messages to stderr. +errcho() { + echo "$@" 1>&2; +} + +# Check if fakeroot command is available +if ! command -v fakeroot > /dev/null 2>&1; then + errcho "[ERROR] fakeroot command not found. Install the fakeroot package."; + exit 1 +fi + +# Check if dpkg-deb command is available +if ! command -v dpkg-deb > /dev/null 2>&1; then + errcho "[ERROR] dpkg-deb command not found. dpkg package contains it. Are you not running this script on a Debian based system?"; + exit 1 +fi + +# Get the directory of this script +DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" + +# Check if the spring boot jar is in the correct location +if [ ! -f $DIR/package/opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar ]; then + errcho "[ERROR] Jar file missing: package/opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar" + errcho "[ERROR] Run this build script only after placing the jar file in that location." + exit 1 +fi + +# Remove the deb files found inside DIR. Don't prompt the user before deleting. +if ls $DIR/*.deb 1> /dev/null 2>&1; then + rm $DIR/*.deb +fi + +# Build the deb package +fakeroot dpkg-deb --build $DIR/package $DIR diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles new file mode 100644 index 0000000..a52c085 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/conffiles @@ -0,0 +1,3 @@ +/etc/ceit-fs-auth-server/application.yaml +/etc/ceit-fs-auth-server/environment.env +/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control new file mode 100644 index 0000000..9239fb0 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/control @@ -0,0 +1,8 @@ +Package: ceit-fs-auth-server +Version: 1.0.0-1 +Section: httpd +Priority: optional +Architecture: all +Depends: openjdk-25-jre | temurin-25-jre | openjdk-25-jdk | temurin-25-jdk +Maintainer: Kamal Wickramanayake +Description: A demo Debian package that bundles a Spring Boot application. diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst new file mode 100755 index 0000000..74509f4 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postinst @@ -0,0 +1,59 @@ +#!/bin/bash + +# Stop on error +set -e + +if [ "$1" == "configure" ] && [ -z "$2" ]; then + # Code here executes only during package install (but not during upgrade) + + # Create a system user + # -r: System user + # -s /sbin/nologin: Prevent the user from logging into the system interactively + # -d /var/lib/ceit-fs-auth-server: Set home directory of user + # ceit-fs-auth-server: Username + useradd -r -s /sbin/nologin -d /var/lib/ceit-fs-auth-server ceit-fs-auth-server || true + +fi + +# Set directory ownership and permissions - Application jar file not to be read by other system users +chown -R root:ceit-fs-auth-server /opt/ceit/ceit-fs-auth-server +chmod 755 /opt/ceit +chmod 750 /opt/ceit/ceit-fs-auth-server +chmod 750 /opt/ceit/ceit-fs-auth-server/app +chmod 640 /opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar + +# Set directory ownership and permissions - Config files not to be read by other system users +chown -R root:ceit-fs-auth-server /etc/ceit-fs-auth-server +chmod 750 /etc/ceit-fs-auth-server +chmod 640 /etc/ceit-fs-auth-server/application.yaml +chmod 640 /etc/ceit-fs-auth-server/environment.env + +if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then + if [ -d /run/systemd/system ]; then + # Reload systemd service configurations + systemctl daemon-reload > /dev/null || true + + if [ -n "$2" ]; then + # Upgrade + # Restart service + if systemctl is-enabled ceit-fs-auth-server > /dev/null; then + systemctl start ceit-fs-auth-server + fi + else + # First install (not upgrade) + # Enable service to start at boot time + systemctl enable ceit-fs-auth-server + # Start service + systemctl start ceit-fs-auth-server + fi + fi +fi + +if [ "$1" == "configure" ] && [ -z "$2" ]; then + # Code here executes only during package install (but not during upgrade) + echo "[INFO] ceit-fs-auth-server service installed." + echo "[INFO] Update /etc/ceit-fs-auth-server/application.yaml to update the configuration." + echo "[INFO] By default, TCP port 8085 is used by the installed server." + echo "[INFO] To allow access from remote systems, you may have to enable firewall for example by running:" + echo "[INFO] ufw allow 8085/tcp" +fi diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm new file mode 100755 index 0000000..261f7af --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/postrm @@ -0,0 +1,14 @@ +#!/bin/bash +set -e + +# Check if the package is being purged (erased entirely including configs) +if [ -z "$DPKG_ROOT" ] && [ "$1" = "purge" ] ; then + update-rc.d ceit-fs-auth-server remove >/dev/null + deluser --quiet ceit-fs-auth-server || true +fi + +# Reload systemd service configuration files. +systemctl daemon-reload + +# postrm script must exit with 0 +exit 0 diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst new file mode 100755 index 0000000..61c2587 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/preinst @@ -0,0 +1,8 @@ +#!/bin/bash + +set -e + +# Put commands that should execute before the pckage is installed. + +# Example: Just print a message +echo "preinst script running..." diff --git a/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm new file mode 100755 index 0000000..cd4bf94 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/DEBIAN/prerm @@ -0,0 +1,9 @@ +#!/bin/bash +set -e + +# Stop service before files are removed +systemctl stop ceit-fs-auth-server || true + +# prerm script must exit with 0 +exit 0 + diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml new file mode 100644 index 0000000..0ce4a3d --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/application.yaml @@ -0,0 +1,40 @@ +server: + port: 8051 + address: 127.0.0.1 + forward-headers-strategy: native + +#logging: +# level: +# org.springframework.security: trace + +spring: + application: + name: oauth2-server + security: + oauth2: + authorizationserver: + client: + oidc-client: + registration: + client-id: "api-gateway" + client-secret: "{noop}apiGatewayPassword1234" + client-authentication-methods: + - "client_secret_basic" + authorization-grant-types: + - "authorization_code" + - "refresh_token" + redirect-uris: + - "https://fs-react-app.dev.ceit.pdn.ac.lk/bff/login/oauth2/code/api-gateway" + post-logout-redirect-uris: + - "https://fs-react-app.dev.ceit.pdn.ac.lk/" + scopes: + - "openid" + - "profile" + require-authorization-consent: false + +app: + users: + - username: admin + password: "{noop}abc123" + - username: user1 + password: "{noop}abc123" diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env new file mode 100644 index 0000000..5423533 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/ceit-fs-auth-server/environment.env @@ -0,0 +1,2 @@ +# Which Spring profile should be active? +#SPRING_PROFILES_ACTIVE=prod diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk b/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk new file mode 100644 index 0000000..73c5b50 --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/nginx/sites-available/fs-auth-server.dev.ceit.pdn.ac.lk @@ -0,0 +1,61 @@ +server { + listen 81; + listen [::]:81; + + server_name fs-auth-server.dev.ceit.pdn.ac.lk ; + + root /home/ceit_fs_auth_server/public_web; + index index.html; + + access_log /var/log/nginx/fs-auth-server.dev.ceit.pdn.ac.lk_access.log; + error_log /var/log/nginx/fs-auth-server.dev.ceit.pdn.ac.lk_error.log; + + location / { + try_files $uri $uri/ =404; + } + + location /.well-known/ { + alias /home/ceit_fs_auth_server/well-known/; + } + + location /.well-known/acme-challenge { + alias /var/lib/letsencrypt/.well-known/acme-challenge/; + } + + # Block access to "hidden" files and directories whose names begin with a + # period. This includes directories used by version control systems such + # as Subversion or Git to store control files. + location ~ (^|/)\.(?!well-known).* { + return 403; + } +} + +server { + listen 443 ssl; + listen [::]:443 ssl; + + server_name fs-auth-server.dev.ceit.pdn.ac.lk ; + + location / { + proxy_pass http://127.0.0.1:8051; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-Port 443; + proxy_set_header Host $host; + } + + # + # To create a self signed certificate, run the below command + # + # openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.key -out /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.crt + # + # Or non-intractively + # + # openssl req -new -newkey rsa:4096 -days 365 -nodes -x509 -subj "/C=AB/ST=ABC/L=ABCD/O=ABCDE/CN=fs-auth-server.dev.ceit.pdn.ac.lk" -keyout /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.key -out /etc/nginx/ssl/fs-auth-server.dev.ceit.pdn.ac.lk/server.crt + ssl_certificate /etc/letsencrypt/live/fs-auth-server.dev.ceit.pdn.ac.lk/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/fs-auth-server.dev.ceit.pdn.ac.lk/privkey.pem; # managed by Certbot + + ssl_dhparam /etc/nginx/ssl/dhparams.pem; + +} diff --git a/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service b/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service new file mode 100644 index 0000000..a26e76b --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/etc/systemd/system/ceit-fs-auth-server.service @@ -0,0 +1,12 @@ +[Unit] +Description=ceit-fs-auth-server + +[Service] +User=ceit-fs-auth-server +EnvironmentFile=/etc/ceit-fs-auth-server/environment.env +ExecStart=/usr/bin/java -Dspring.config.import=optional:file:/etc/ceit-fs-auth-server/application.yaml -jar /opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar +Restart=always +RestartSec=30 + +[Install] +WantedBy=multi-user.target diff --git a/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore b/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore new file mode 100644 index 0000000..d392f0e --- /dev/null +++ b/microservices/01-oauth2-server/linux/deb/package/opt/ceit/ceit-fs-auth-server/app/.gitignore @@ -0,0 +1 @@ +*.jar -- cgit v1.2.3