From d7d49caeff78fc2a98190dc650ebefd68a579d5d Mon Sep 17 00:00:00 2001 From: yohan <783b8c87@scimetis.net> Date: Sat, 14 Dec 2019 23:22:13 +0100 Subject: [PATCH] Launch script now retrieve secrets from encrypted secret archive. --- README | 2 -- start_or_update.sh | 7 +++++++ 2 files changed, 7 insertions(+), 2 deletions(-) delete mode 100644 README diff --git a/README b/README deleted file mode 100644 index f552426..0000000 --- a/README +++ /dev/null @@ -1,2 +0,0 @@ -A secret must be defined before starting the stack : -echo "FIXME" > .env diff --git a/start_or_update.sh b/start_or_update.sh index b16699b..de12d9c 100755 --- a/start_or_update.sh +++ b/start_or_update.sh @@ -1,4 +1,11 @@ #!/bin/bash +test -z ${KEY} && { echo "KEY variable is not defined."; exit 1; } +test -f ~/secrets.tar.gz.enc || curl -o ~/secrets.tar.gz.enc "https://cloud.scimetis.net/s/${KEY}/download?path=%2F&files=secrets.tar.gz.enc" +openssl enc -aes-256-cbc -d -in ~/secrets.tar.gz.enc | tar -zxv --strip 2 secrets/docker-coturn-stack/secret +sudo chown root. secret +sudo chmod a-r secret +sudo mv -f secret .env + unset VERSION_COTURN VERSION_COTURN=$(git ls-remote https://git.scimetis.net/yohan/docker-coturn.git| head -1 | cut -f 1|cut -c -10) \ sudo -E bash -c 'docker-compose up -d'