## Problem - Using the new `inst.listen_on` boot option to disable remote access to the server looks inconsistent (for disabling the SSH access you can use the `systemd.mask=sshd.service` boot option) - Simplify the implementation, limiting access to some interface or IP address was not requested - Related to https://github.com/agama-project/agama/pull/3269 ## Solution - Use systemd services to implement disabling the remote access - ~~Implement new `agama-web-server-local` and `agama-web-server-remote` services~~ - ~~By default the remote service is enabled, but the user can disable it and enable the local service instead using the `systemd.mask=agama-web-server-remote.service systemd.wants=agama-web-server-local.service` boot parameters.~~ - Support new `inst.remote=0` boot option ## Testing - Tested manually ## Notes I tried several approaches but either they did not work or were a bit hacky: 1. First a wanted to be the both local and remote services enabled by default. Because of conflicts only one of them should be running at a time. I used `Before` and `After` so the remote service starts first and the conflict should block the local service from running. Disabling the remote service allows running the local service automatically. The problem was that there is probably some race condition and sometimes the local service was actually running instead of the remote by default. I tried several changes but nothing helped. 2. Then I added code to the local service to explicitly check whether the remote service is disabled or not (using `ExecCondition` attribute). But that feels a bit hacky and it is a hidden magic. 3. Then I realized that the same way how you can disable a service at boot using `systemd.mask` option you can also enable a disabled service using the `systemd.wants` parameter. So instead of enabling both services enable only the default remote one. The users then can explicitly disable the remote service and enable the local one using the `systemd.mask=agama-web-server-remote.service systemd.wants=agama-web-server-local.service` boot options. But that turned out to be quite complicated. 4. So let's implement simple `inst.remote=0` boot option which disables the remotes access to the Agama installer. The SSH service can be disabled using the standard `systemd.mask=sshd.service` option.
77 lines
3.2 KiB
Bash
Executable file
77 lines
3.2 KiB
Bash
Executable file
#!/bin/bash
|
|
set -eu
|
|
# After building this part of Agama, install it so that it is ready for run time
|
|
# This is used by agama.spec and testing-in-container.sh
|
|
|
|
# The caller (RPM .spec) is expected to set these environment variables:
|
|
# NAME=%{name}
|
|
# SRCDIR=.
|
|
# DESTDIR=%{buildroot}
|
|
# bindir=%{_bindir}
|
|
# datadir=%{_datadir}
|
|
# pamvendordir=%{_pam_vendordir}
|
|
# unitdir=%{_unitdir}
|
|
# libexecdir=%{_libexecdir}
|
|
# mandir=%{_mandir}
|
|
# pamvendordir=%{_pam_vendordir}
|
|
: ${RUST_TARGET:=release}
|
|
|
|
if [ "${1-}" = --system ]; then
|
|
SRCDIR=.
|
|
DESTDIR=""
|
|
NAME=agama
|
|
RUST_TARGET=debug
|
|
bindir=/usr/bin
|
|
datadir=/usr/share
|
|
mandir=/usr/share/man
|
|
libexecdir=/usr/lib
|
|
unitdir=/usr/lib/systemd/system
|
|
pamvendordir=/etc/pam.d
|
|
fi
|
|
|
|
# install regular file, with mode 644 (not an executable with mode 755)
|
|
install6() {
|
|
install -m 0644 "$@"
|
|
}
|
|
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-autoinstall"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-proxy-setup"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/target/${RUST_TARGET}/agama-web-server"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-journal"
|
|
install -D -t "${DESTDIR}${bindir}" "${SRCDIR}/share/agama-zypp-journal"
|
|
|
|
install6 -D -p "${SRCDIR}"/share/agama.pam "${DESTDIR}${pamvendordir}"/agama
|
|
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/dasd.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/iscsi.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/profile.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/software.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/zfcp.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/schema "${SRCDIR}"/agama-lib/share/storage.model.schema.json
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/jsonnet "${SRCDIR}"/share/agama.libsonnet
|
|
|
|
install -D -t "${DESTDIR}${libexecdir}" "${SRCDIR}"/share/agama-scripts.sh
|
|
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-autoinstall.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-proxy-setup.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-scripts.service
|
|
install6 -D -t "${DESTDIR}${unitdir}" "${SRCDIR}"/share/agama-web-server.service
|
|
|
|
# create the licenses directory
|
|
install -d -m 0755 "${DESTDIR}${datadir}"/agama/eula
|
|
|
|
# install manpages
|
|
install6 -D -t "${DESTDIR}${mandir}"/man1 "${SRCDIR}"/out/man/*
|
|
|
|
# install shell completion scripts
|
|
install6 -D "${SRCDIR}"/out/shell/"${NAME}".bash "${DESTDIR}${datadir}/bash-completion/completions/${NAME}"
|
|
install6 -D -t "${DESTDIR}${datadir}"/zsh/site-functions "${SRCDIR}"/out/shell/_"${NAME}"
|
|
install6 -D -t "${DESTDIR}${datadir}"/fish/vendor_completions.d "${SRCDIR}"/out/shell/"${NAME}".fish
|
|
|
|
# install OpenAPI specification
|
|
install6 -D -t "${DESTDIR}${datadir}"/agama/openapi "${SRCDIR}"/out/openapi/*
|
|
|
|
# install translations
|
|
make -C "${SRCDIR}/po" install DESTDIR="${DESTDIR}" datadir="${datadir}"
|