-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcloud-init.conf
More file actions
54 lines (54 loc) · 2.37 KB
/
Copy pathcloud-init.conf
File metadata and controls
54 lines (54 loc) · 2.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
#cloud-config
users:
- name: once
groups: sudo
shell: /bin/bash
sudo: ['ALL=(ALL) NOPASSWD:ALL']
ssh-authorized-keys:
- ssh-rsa
packages:
- nginx
- python-dev
- python-pip
- python-webpy
- git
- ufw
- ntp
- jq
runcmd:
# set environment vars for config
- export PUBLIC_IPV4=$(curl -s http://169.254.169.254/metadata/v1/interfaces/public/0/ipv4/address)
- export DROPLET_ID=$(curl -s http://169.254.169.254/metadata/v1/id)
- export DROPLET_NAME=$(curl -s http://169.254.169.254/metadata/v1/hostname)
- export DOMAIN=
- export DO_API_TOKEN=
- 'export EMAIL=$(curl -X GET -H "Content-Type: application/json" -H "Authorization: Bearer $DO_API_TOKEN" https://api.digitalocean.com/v2/account | jq -r ".account.email")'
# install certbot, update
- add-apt-repository ppa:certbot/certbot -y
- apt-get update
- apt-get upgrade -y
- apt install python-certbot-nginx -y
# add domain name to nginx config, restart it
- sed -i 's/server_name _;/server_name '$DROPLET_NAME"."$DOMAIN';/' /etc/nginx/sites-available/default
- systemctl restart nginx
# create a subdomain a-record for this droplet
- 'curl -X POST -H "Content-Type: application/json" -H "Authorization: Bearer $DO_API_TOKEN" -d "{\"type\":\"A\", \"name\":\"$DROPLET_NAME\", \"data\":\"$PUBLIC_IPV4\"}" https://api.digitalocean.com/v2/domains/$DOMAIN/records'
- sleep 10s
- certbot --nginx -n -d $DROPLET_NAME"."$DOMAIN --email $EMAIL --agree-tos --redirect --hsts
- sudo openssl dhparam -out /etc/ssl/certs/dhparam.pem 2048
# write ssl_dhparam directive to nginx config
- sed -i '0,/server_name/s/server_name/ssl_dhparam \/etc\/ssl\/certs\/dhparam.pem;\n\tserver_name/' /etc/nginx/sites-available/default
# INSTALL REQUIRED PYTHON PACKAGES, CLONE GIT REPOS
- pip install --upgrade shortuuid pyyaml pycrypto
- git clone https://github.com/ruf-io/once.git /var/once
- ln -s /var/once/nginx.conf /etc/nginx/sites-enabled/once.conf
- rm /etc/nginx/sites-enabled/default
- ln -s /var/once/once.service /etc/systemd/system/multi-user.target.wants/once.service
- systemctl daemon-reload
- systemctl enable once.service
# DISABLE ROOT SSH LOGIN, ONLY ALLOW once LOGIN
- sed -i "s/PermitRootLogin yes/PermitRootLogin no/" /etc/ssh/sshd_config
# CHANGE OWNER OF ALL FILES TO once
- usermod -a -G www-data once
- chown -R once:www-data /var/once
- chmod -R 0750 /var/once