#!/bin/bash # Stop on error set -e if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) # Create a system user # -r: System user # -s /sbin/nologin: Prevent the user from logging into the system interactively # -d /var/lib/ceit-fs-api-gateway: Set home directory of user # ceit-fs-api-gateway: Username useradd -r -s /sbin/nologin -d /var/lib/ceit-fs-api-gateway ceit-fs-api-gateway || true fi # Set directory ownership and permissions - Application jar file not to be read by other system users chown -R root:ceit-fs-api-gateway /opt/ceit/ceit-fs-api-gateway chmod 755 /opt/ceit chmod 750 /opt/ceit/ceit-fs-api-gateway chmod 750 /opt/ceit/ceit-fs-api-gateway/app chmod 640 /opt/ceit/ceit-fs-api-gateway/app/ceit-fs-api-gateway.jar # Set directory ownership and permissions - Config files not to be read by other system users chown -R root:ceit-fs-api-gateway /etc/ceit-fs-api-gateway chmod 750 /etc/ceit-fs-api-gateway chmod 640 /etc/ceit-fs-api-gateway/application.yaml chmod 640 /etc/ceit-fs-api-gateway/environment.env if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ] || [ "$1" = "abort-deconfigure" ] || [ "$1" = "abort-remove" ] ; then if [ -d /run/systemd/system ]; then # Reload systemd service configurations systemctl daemon-reload > /dev/null || true if [ -n "$2" ]; then # Upgrade # Restart service if systemctl is-enabled ceit-fs-api-gateway > /dev/null; then systemctl start ceit-fs-api-gateway fi else # First install (not upgrade) # Enable service to start at boot time systemctl enable ceit-fs-api-gateway # Start service systemctl start ceit-fs-api-gateway fi fi fi if [ "$1" == "configure" ] && [ -z "$2" ]; then # Code here executes only during package install (but not during upgrade) echo "[INFO] ceit-fs-api-gateway service installed." echo "[INFO] Update /etc/ceit-fs-api-gateway/application.yaml to update the configuration." echo "[INFO] By default, TCP port 8085 is used by the installed server." echo "[INFO] To allow access from remote systems, you may have to enable firewall for example by running:" echo "[INFO] ufw allow 8085/tcp" fi