#!/bin/bash # Stop on error set -e if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) # Create a system user # -r: System user # -s /sbin/nologin: Prevent the user from logging into the system interactively # -d /var/lib/ceit-fs-auth-server: Set home directory of user # ceit-fs-auth-server: Username useradd -r -s /sbin/nologin -d /var/lib/ceit-fs-auth-server ceit-fs-auth-server || true fi # Set directory ownership and permissions - Application jar file not to be read by other system users chown -R root:ceit-fs-auth-server /opt/ceit/ceit-fs-auth-server chmod 755 /opt/ceit chmod 750 /opt/ceit/ceit-fs-auth-server chmod 750 /opt/ceit/ceit-fs-auth-server/app chmod 640 /opt/ceit/ceit-fs-auth-server/app/ceit-fs-auth-server.jar # Set directory ownership and permissions - Config files not to be read by other system users chown -R root:ceit-fs-auth-server /etc/ceit-fs-auth-server chmod 750 /etc/ceit-fs-auth-server chmod 640 /etc/ceit-fs-auth-server/application.yaml chmod 640 /etc/ceit-fs-auth-server/environment.env if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then if [ -d /run/systemd/system ]; then # Reload systemd service configurations systemctl daemon-reload > /dev/null || true if [ -n "$2" ]; then # Upgrade # Restart service if systemctl is-enabled ceit-fs-auth-server > /dev/null; then systemctl start ceit-fs-auth-server fi else # First install (not upgrade) # Enable service to start at boot time systemctl enable ceit-fs-auth-server # Start service systemctl start ceit-fs-auth-server fi fi fi if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) echo "[INFO] ceit-fs-auth-server service installed." echo "[INFO] Update /etc/ceit-fs-auth-server/application.yaml to update the configuration." echo "[INFO] By default, TCP port 8085 is used by the installed server." echo "[INFO] To allow access from remote systems, you may have to enable firewall for example by running:" echo "[INFO] ufw allow 8085/tcp" fi