#!/bin/bash # Stop on error set -e if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) # Create a system user # -r: System user # -s /sbin/nologin: Prevent the user from logging into the system interactively # -d /var/lib/fs-spring-boot-kamal: Set home directory of user # fs-spring-boot-kamal: Username useradd -r -s /sbin/nologin -d /var/lib/fs-spring-boot-kamal fs-spring-boot-kamal || true fi # Set directory ownership and permissions - Application jar file not to be read by other system users chown -R root:fs-spring-boot-kamal /opt/mycompany/fs-spring-boot-kamal chmod 755 /opt/mycompany chmod 750 /opt/mycompany/fs-spring-boot-kamal chmod 750 /opt/mycompany/fs-spring-boot-kamal/app chmod 640 /opt/mycompany/fs-spring-boot-kamal/app/fs-spring-boot-kamal.jar # Set directory ownership and permissions - Config files not to be read by other system users chown -R root:fs-spring-boot-kamal /etc/fs-spring-boot-kamal chmod 750 /etc/fs-spring-boot-kamal chmod 640 /etc/fs-spring-boot-kamal/application.yaml chmod 640 /etc/fs-spring-boot-kamal/environment.env if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then if [ -d /run/systemd/system ]; then # Reload systemd service configurations systemctl daemon-reload > /dev/null || true if [ -n "$2" ]; then # Upgrade # Restart service if systemctl is-enabled fs-spring-boot-kamal > /dev/null; then systemctl start fs-spring-boot-kamal fi else # First install (not upgrade) # Enable service to start at boot time systemctl enable fs-spring-boot-kamal # Start service systemctl start fs-spring-boot-kamal fi fi fi if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) echo "[INFO] fs-spring-boot-kamal service installed." echo "[INFO] Update /etc/fs-spring-boot-kamal/application.yaml to update the configuration." echo "[INFO] By default, TCP port 8085 is used by the installed server." echo "[INFO] To allow access from remote systems, you may have to enable firewall for example by running:" echo "[INFO] ufw allow 8085/tcp" fi