Files
syno-scripts/Bash/TESTING/nextcloud_install.sh
T

176 lines
5.7 KiB
Bash
Executable File

#!/bin/bash
# Variablen setzen
DOMAIN="iot.heim.lan"
CERT_DIR="/etc/pki/tls/certs"
PRIVATE_DIR="/etc/pki/tls/private"
APACHE_CONF="/etc/httpd/conf.d/nextcloud.conf"
NEXTCLOUD_DIR="/var/www/html/nextcloud"
NC_DATASTORE="/volume1/DATEN1/nextcloud-data"
DB_NAME="nextcloud"
DB_USER="nextclouduser"
DB_PASSWORD="P@ssw0rd"
SYNOLOGY_IP="192.168.31.250"
SYNOLOGY_USER="Madzone"
SYNOLOGY_PW="P@ssw0rd"
SYNOLOGY_PATH_SERVER="/volume1/DATEN1/HEIMLAN/IOT-NC.IOT.HEIM.LAN"
SYNOLOGY_PATH_SubCA="/volume1/DATEN1/HEIMLAN/SubCA"
SYNOLOGY_PATH_RootCA="/volume1/DATEN1/HEIMLAN/RootCA"
CERT_NAME_SRV="CERT_iot-nc.iot.heim.lan.crt"
KEY_NAME_SRV="KEY_iot-nc.iot.heim.lan.pem"
CERT_NAME_ROOT="CERT_HEIMLAN_RootCA.crt"
CERT_NAME_SUBCA="CERT_HEIMLAN_SubCA.crt"
# System-Updates und erforderliche Pakete installieren
00_system_update(){
echo "System-Updates und erforderliche Pakete installieren"
yum update -y
#yum install -y epel-release
subscription-manager repos --enable codeready-builder-for-rhel-8-$(arch)-rpms
yum -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm
dnf install -y https://rpms.remirepo.net/enterprise/remi-release-8.rpm
dnf module enable php:remi-8.3 -y
yum install -y httpd mariadb-server php php-mysqlnd php-xml php-mbstring php-gd php-curl php-intl php-zip php-bcmath wget unzip mod_ssl sshpass
}
# Zertifikate von Synology kopieren
01_cert_import(){
mkdir -p ~/.ssh
sudo mkdir -p /root/.ssh
sudo chmod 700 /root/.ssh
sudo ssh-keyscan -H $SYNOLOGY_IP >> ~/.ssh/known_hosts
ssh-keyscan -H $SYNOLOGY_IP >> ~/.ssh/known_hosts
sshpass -p $SYNOLOGY_PW scp $SYNOLOGY_USER@$SYNOLOGY_IP:$SYNOLOGY_PATH_SERVER/$CERT_NAME_SRV $CERT_DIR/$CERT_NAME_SRV
sshpass -p $SYNOLOGY_PW scp $SYNOLOGY_USER@$SYNOLOGY_IP:$SYNOLOGY_PATH_SERVER/$KEY_NAME_SRV $PRIVATE_DIR/$KEY_NAME_SRV
sshpass -p $SYNOLOGY_PW scp $SYNOLOGY_USER@$SYNOLOGY_IP:$SYNOLOGY_PATH_SubCA/$CERT_NAME_SUBCA $CERT_DIR/$CERT_NAME_SUBCA
sshpass -p $SYNOLOGY_PW scp $SYNOLOGY_USER@$SYNOLOGY_IP:$SYNOLOGY_PATH_RootCA/$CERT_NAME_ROOT $CERT_DIR/$CERT_NAME_ROOT
}
# Dienste starten und aktivieren
02_service_start(){
systemctl start httpd mariadb
systemctl enable httpd mariadb
}
# Nextcloud herunterladen und entpacken
03_download_nc(){
echo "Nextcloud herunterladen und entpacken"
cd /var/www/html
wget https://download.nextcloud.com/server/releases/latest.zip
unzip latest.zip
chown -R apache:apache $NEXTCLOUD_DIR
chmod -R 755 $NEXTCLOUD_DIR
}
# MariaDB konfigurieren
04_install_db(){
echo "MariaDB konfigurieren"
mysql_secure_installation<<EOF
y
$DB_PASSWORD
$DB_PASSWORD
y
y
y
y
EOF
}
# Nextcloud-Datenbank und Benutzer erstellen
05_config_nc_db(){
echo "Nextcloud-Datenbank und Benutzer erstellen"
mysql -u root -p$DB_PASSWORD<<EOF
CREATE DATABASE $DB_NAME;
CREATE USER '$DB_USER'@'localhost' IDENTIFIED BY '$DB_PASSWORD';
GRANT ALL PRIVILEGES ON $DB_NAME.* TO '$DB_USER'@'localhost';
FLUSH PRIVILEGES;
EXIT;
EOF
echo "Nextcloud-Datenbank mit Name $DB_NAME und Benutzer $DB_USER erstellt"
}
#
# OnlyOffice Document Server installieren (falls erforderlich)
07_install_onlyoffice(){
echo "OnlyOffice Document Server installieren"
yum install -y onlyoffice-documentserver
}
# Apache-Konfiguration erstellen
07_config_webserver(){
echo "Apache-Konfiguration erstellen"
cat <<EOF > $APACHE_CONF
<VirtualHost *:443>
DocumentRoot "$NEXTCLOUD_DIR"
ServerName $DOMAIN
SSLEngine on
SSLCertificateFile $CERT_DIR/$CERT_NAME_SRV
SSLCertificateKeyFile $PRIVATE_DIR/$KEY_NAME_SRV
SSLCertificateChainFile $CERT_DIR/$CERT_NAME_SUBCA
<Directory "$NEXTCLOUD_DIR">
AllowOverride All
Require all granted
</Directory>
ErrorLog /var/log/httpd/nextcloud_error.log
CustomLog /var/log/httpd/nextcloud_access.log combined
</VirtualHost>
EOF
}
# Firewall-Einstellungen
08_config_firewall(){
echo "Firewall-Einstellungen"
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
}
# Apache neu starten
09_restart_webserver(){
echo "Apache neu starten"
systemctl restart httpd
}
10_ending(){
echo "Installation abgeschlossen. Nextcloud ist unter https://"hostname-f" verfügbar."
}
# OPTIONAL FALLS ERFORDERLICH
# Diese Funktionen sind bei Fehler der PHP Version und bei Aufruf der Website ( Fehlende Berechtigung ) nötig
11_php_update(){
echo "PHP Version wird von 7.2 auf 8.X von REMI aktuallisiert!!!....."
sudo dnf install -y https://rpms.remirepo.net/enterprise/remi-release-8.rpm
sudo dnf module list php -y
sudo dnf install -y dnf-utils
dnf update -y
rpm -qi epel-release
dnf module reset php -y
dnf module enable php:remi-8.2 -y
dnf install php -y
}
12_SELINUX(){
sudo chcon -R -t httpd_sys_rw_content_t /var/www/html/nextcloud/
}
13_external_datastore(){
echo "Einrichtigung des External Data Storage......"
echo "$SYNOLOGY_IP:$NC_DATASTORE /mnt/nextcloud-data nfs defaults 0 0" >> /etc/fstab
sudo mkdir -p /mnt/nextcloud-data
sudo mount -a
echo "Berechtigungen fuer den External Storage werden gesetzt......"
sudo chown -R apache:apache /mnt/nextcloud-data
sudo chmod -R 755 /mnt/nextcloud-data
echo "****************************************************************************************"
echo "************* Die Einstellung wurden erfolgreich gesetzt und durchgeführt **************"
echo "****************************************************************************************"
}
#Aufruf der Funktionen
#00_system_update
#01_cert_import
#02_service_start
#03_download_nc
04_install_db
05_config_nc_db
06_install_onlyoffice
07_config_webserver
08_config_firewall
09_restart_webserver
10_ending
# OPTIONAL
11_php_update
12_SELINUX
13_external_datastore