Upgrade ZNC role to match reality

Signed-off-by: decentral1se's avatarLuke Murphy <lukewm@riseup.net>
parent 5b4333f6
AnonIPLimit = 10
ConnectDelay = 5
ConnectDelay = 30
HideVersion = false
LoadModule = webadmin
MaxBufferSize = 500
ProtectWebSessions = true
SSLCertFile = /home/znc/.znc/znc.pem
SSLCertFile = /home/{{ znc_system_user }}/.znc/znc.pem
ServerThrottle = 30
Version = 1.6.5
......@@ -49,7 +49,6 @@ Version = 1.6.5
JoinDelay = 0
LoadModule = simple_away
Server = chat.freenode.net +6697
</Network>
<Pass password>
......@@ -57,4 +56,5 @@ Version = 1.6.5
Method = {{ znc_pass_method }}
Salt = {{ znc_pass_salt }}
</Pass>
</User>
......@@ -4,6 +4,7 @@
gather_facts: false
roles:
- role: znc
znc_system_user: znc
znc_domain: znc.kstraat.casa
znc_config: templates/znc.conf.j2
znc_user: !vault |
......
---
- name: Stop ZNC.
systemd:
name: znc
state: stopped
- name: Restart ZNC.
systemd:
name: znc
state: restarted
......@@ -4,6 +4,7 @@
assert:
that: "{{ item }} is defined"
loop:
- znc_system_user
- znc_config
- znc_domain
......@@ -12,59 +13,37 @@
name: znc
state: present
- name: Copy the systemd ZNC script over.
become: true
template:
src: znc.j2
dest: /etc/init.d/znc
owner: root
group: root
mode: 0755
notify: "Stop ZNC."
- name: Initialise the systemd ZNC script.
become: true
command: update-rc.d znc defaults
args:
warn: false
- name: Reload the systemd scripts.
become: true
command: systemctl daemon-reload
args:
warn: false
- name: Add a new ZNC user.
become: true
user:
name: znc
name: "{{ znc_system_user }}"
system: true
- name: Create ZNC root directory.
become: true
become_user: znc
become_user: "{{ znc_system_user }}"
file:
path: /home/znc/.znc/
path: "/home/{{ znc_system_user }}/.znc/"
state: directory
owner: znc
group: znc
owner: "{{ znc_system_user }}"
group: "{{ znc_system_user }}"
mode: 0750
- name: Create ZNC configuration directory.
become: true
become_user: znc
become_user: "{{ znc_system_user }}"
file:
path: /home/znc/.znc/configs/
path: "/home/{{ znc_system_user }}/.znc/configs/"
state: directory
owner: znc
group: znc
owner: "{{ znc_system_user }}"
group: "{{ znc_system_user }}"
mode: 0750
- name: Copy over the ZNC configuration.
become: true
template:
src: "{{ znc_config }}"
dest: /home/znc/.znc/configs/znc.conf
notify: "Restart ZNC."
dest: "/home/{{ znc_system_user }}/.znc/configs/znc.conf"
- name: Create SSL certificate.
become: true
......@@ -73,18 +52,36 @@
fullchain: "/etc/letsencrypt/live/{{ znc_domain }}/fullchain.pem"
shell: "cat {{ privkey }} > znc.pem && cat {{ fullchain }} >> znc.pem"
args:
chdir: /home/znc/.znc
creates: /home/znc/.znc/znc.pem
chdir: "/home/{{ znc_system_user }}/.znc"
creates: "/home/{{ znc_system_user }}/.znc/znc.pem"
warn: false
notify: "Restart ZNC."
- name: Copy over the /etc/letsencrypt/renewal-hooks/deploy script.
become: true
template:
src: update-znc-pem.j2
dest: /etc/letsencrypt/renewal-hooks/deploy/update-znc-pem.sh
force: true
mode: 0744
- name: Set file permissions.
become: true
file:
path: "{{ item }}"
owner: "{{ znc_system_user }}"
group: "{{ znc_system_user }}"
mode: 0600
loop:
- "/home/{{ znc_system_user }}/.znc/configs/znc.conf"
- "/home/{{ znc_system_user }}/.znc/znc.pem"
- name: Set file permissions.
become: true
file:
path: "{{ item }}"
owner: znc
group: znc
owner: "{{ znc_system_user }}"
group: "{{ znc_system_user }}"
mode: 0600
loop:
- /home/znc/.znc/configs/znc.conf
- /home/znc/.znc/znc.pem
- "/home/{{ znc_system_user }}/.znc/configs/znc.conf"
- "/home/{{ znc_system_user }}/.znc/znc.pem"
#!/bin/bash
YOURDOMAIN="{{ znc_domain }}"
[[ $RENEWED_LINEAGE != "/etc/letsencrypt/live/$YOURDOMAIN" ]] && exit 0
echo "Updating certs"
cat /etc/letsencrypt/live/$YOURDOMAIN/{privkey,fullchain}.pem > /home/{{ znc_user }}/.znc/znc.pem
#! /bin/sh
### BEGIN INIT INFO
# Provides: znc
# Required-Start: $remote_fs $syslog
# Required-Stop: $remote_fs $syslog
# Default-Start: 2 3 4 5
# Default-Stop: 0 1 6
# Short-Description: ZNC IRC bouncer
# Description: ZNC is an IRC bouncer
### END INIT INFO
PATH=/sbin:/usr/sbin:/bin:/usr/bin
DESC="ZNC daemon"
NAME=znc
DAEMON=/usr/bin/$NAME
DATADIR=/home/znc/.znc
DAEMON_ARGS="--datadir=$DATADIR"
PIDDIR=/home/znc/.znc
PIDFILE=$PIDDIR/$NAME.pid
SCRIPTNAME=/etc/init.d/$NAME
USER=znc
GROUP=znc
# Exit if the package is not installed
[ -x "$DAEMON" ] || exit 0
# Read configuration variable file if it is present
[ -r /etc/default/$NAME ] && . /etc/default/$NAME
# Load the VERBOSE setting and other rcS variables
. /lib/init/vars.sh
# Define LSB log_* functions.
# Depend on lsb-base (>= 3.2-14) to ensure that this file is present
# and status_of_proc is working.
. /lib/lsb/init-functions
#
# Function that starts the daemon/service
#
do_start()
{
# Return
# 0 if daemon has been started
# 1 if daemon was already running
# 2 if daemon could not be started
if [ ! -d $PIDDIR ]
then
mkdir $PIDDIR
fi
chown $USER:$GROUP $PIDDIR
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON --test --chuid $USER > /dev/null || return 1
start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON --chuid $USER -- $DAEMON_ARGS > /dev/null || return 2
}
#
# Function that stops the daemon/service
#
do_stop()
{
# Return
# 0 if daemon has been stopped
# 1 if daemon was already stopped
# 2 if daemon could not be stopped
# other if a failure occurred
start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME --chuid $USER
RETVAL="$?"
[ "$RETVAL" = 2 ] && return 2
# Wait for children to finish too if this is a daemon that forks
# and if the daemon is only ever run from this initscript.
# If the above conditions are not satisfied then add some other code
# that waits for the process to drop all resources that could be
# needed by services started subsequently. A last resort is to
# sleep for some time.
start-stop-daemon --stop --quiet --oknodo --retry=0/30/KILL/5 --exec $DAEMON --chuid $USER
[ "$?" = 2 ] && return 2
# Many daemons don't delete their pidfiles when they exit.
rm -f $PIDFILE
return "$RETVAL"
}
#
# Function that sends a SIGHUP to the daemon/service
#
do_reload() {
start-stop-daemon --stop --signal 1 --quiet --pidfile $PIDFILE --name $NAME --chuid $USER
return 0
}
case "$1" in
start)
[ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
do_start
case "$?" in
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
esac
;;
stop)
[ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
do_stop
case "$?" in
0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
esac
;;
status)
status_of_proc -p $PIDFILE "$DAEMON" "$NAME" && exit 0 || exit $?
;;
reload)
log_daemon_msg "Reloading $DESC" "$NAME"
do_reload
log_end_msg $?
;;
restart)
log_daemon_msg "Restarting $DESC" "$NAME"
do_stop
case "$?" in
0|1)
do_start
case "$?" in
0) log_end_msg 0 ;;
1) log_end_msg 1 ;; # Old process is still running
*) log_end_msg 1 ;; # Failed to start
esac
;;
*)
# Failed to stop
log_end_msg 1
;;
esac
;;
*)
echo "Usage: $SCRIPTNAME {status|start|stop|reload|restart}" >&2
exit 3
;;
esac
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment