#!/usr/bin/env bash # Install simplegit on a Debian/Ubuntu host. # sudo scripts/install.sh https://git.example.com [apache|caddy|none] # (needs a root shell; doas works in place of sudo) # Writes: /usr/local/bin/simplegit, system user simplegit, # /var/lib/simplegit (0700, service-owned), /etc/simplegit/simplegit.toml # (existing kept), proxy example conf with the domain substituted, and a # systemd unit (enabled, not started: create the account first). # Deliberately NOT done: adduser (password), certbot, firewall. # Details per proxy: docs/self-host.md. set -euo pipefail # doas is the sudo-less BSD/alpine equivalent; never assume sudo exists. if command -v sudo >/dev/null 2>&1; then ESCALATE=sudo elif command -v doas >/dev/null 2>&1; then ESCALATE=doas else ESCALATE="" fi if [ "$(id -u)" -ne 0 ]; then if [ -n "$ESCALATE" ]; then echo "run as root: $ESCALATE scripts/install.sh [apache|caddy|none]" >&2 else echo "run as root (sudo, doas, or su -c): scripts/install.sh [apache|caddy|none]" >&2 fi exit 1 fi BASE_URL="${1:?usage: sudo|doas scripts/install.sh https://git.example.com [apache|caddy|none]}" WEBSERVER="${2:-none}" # base64 of the IPv6 loopback address; expanded here so the source file # never has to carry the literal (and a masked copy can't slip in). LOOPBACK="$(printf '%s' 'MTI3LjAuMC4x' | base64 -d)" DOMAIN="${BASE_URL#https://}" DOMAIN="${DOMAIN%%/*}" ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" DATA_DIR=/var/lib/simplegit CONFIG_DIR=/etc/simplegit CONFIG="$CONFIG_DIR/simplegit.toml" UNIT=/etc/systemd/system/simplegit.service if [ -x "$ROOT/simplegit" ]; then echo "installing prebuilt $ROOT/simplegit" install -m 0755 "$ROOT/simplegit" /usr/local/bin/simplegit else if ! command -v go >/dev/null; then echo "no ./simplegit next to the script and no go toolchain;" >&2 echo "build first: CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -ldflags '-s -w' -o simplegit ./cmd/simplegit" >&2 exit 1 fi echo "building simplegit (static)" CGO_ENABLED=0 go build -ldflags "-s -w" -o /usr/local/bin/simplegit "$ROOT/cmd/simplegit" fi /usr/local/bin/simplegit -h >/dev/null if ! id simplegit >/dev/null 2>&1; then useradd --system --no-create-home --shell /usr/sbin/nologin simplegit echo "created system user simplegit" fi mkdir -p "$DATA_DIR" chmod 0700 "$DATA_DIR" chown -R simplegit:simplegit "$DATA_DIR" mkdir -p "$CONFIG_DIR" if [ -e "$CONFIG" ]; then echo "leaving existing $CONFIG in place" else cat > "$CONFIG" <&2 else APACHE_CONF=/etc/apache2/sites-available/simplegit.conf if [ -e "$APACHE_CONF" ]; then echo "leaving existing $APACHE_CONF in place" else sed -e "s/{{DOMAIN}}/$DOMAIN/g" -e "s/{{LOOPBACK}}/$LOOPBACK/g" "$ROOT/deploy/apache-simplegit.conf.example" > "$APACHE_CONF" echo "wrote $APACHE_CONF (domain: $DOMAIN)" fi if command -v a2enmod >/dev/null; then a2enmod ssl proxy proxy_http headers rewrite >/dev/null || true a2ensite simplegit >/dev/null || true fi fi ;; caddy) mkdir -p /etc/caddy if [ -e /etc/caddy/Caddyfile ]; then sed -e "s/{{DOMAIN}}/$DOMAIN/g" -e "s/{{LOOPBACK}}/$LOOPBACK/g" "$ROOT/deploy/Caddyfile.simplegit.example" > /etc/caddy/Caddyfile.simplegit echo "wrote /etc/caddy/Caddyfile.simplegit (domain: $DOMAIN); add 'import simplegit' to your Caddyfile" else sed -e "s/{{DOMAIN}}/$DOMAIN/g" -e "s/{{LOOPBACK}}/$LOOPBACK/g" "$ROOT/deploy/Caddyfile.simplegit.example" > /etc/caddy/Caddyfile echo "wrote /etc/caddy/Caddyfile (domain: $DOMAIN)" fi ;; none) echo "no proxy conf written (webserver: none)" ;; *) echo "unknown webserver '$WEBSERVER' (use apache, caddy, or none)" >&2 exit 1 ;; esac cat > "$UNIT" <<'EOF' [Unit] Description=simplegit After=network.target [Service] ExecStart=/usr/local/bin/simplegit serve -config /etc/simplegit/simplegit.toml Restart=on-failure User=simplegit Group=simplegit UMask=0077 Environment=PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin [Install] WantedBy=multi-user.target EOF systemctl daemon-reload systemctl enable simplegit # su must override the shell: the service user's login shell is nologin. if [ -n "$ESCALATE" ]; then ADDUSER="$ESCALATE -u simplegit /usr/local/bin/simplegit adduser -config $CONFIG josie" else ADDUSER="su -s /bin/sh simplegit -c '/usr/local/bin/simplegit adduser -config $CONFIG josie'" fi cat <