#!/usr/bin/env bash # deploy.sh — nx9-auth installer for Debian/Ubuntu systems # # Usage: sudo bash deploy.sh [path/to/nx9-auth-binary] # Requires: root, systemd set -euo pipefail BINARY_PATH="${1:-./target/release/nx9-auth}" SERVICE_USER="nx9-auth" INSTALL_BIN="/usr/local/bin/nx9-auth" CONFIG_DIR="/etc/nx9-auth" DATA_DIR="/var/lib/nx9-auth" LOG_DIR="/var/log/nx9-auth" SERVICE_FILE="/etc/systemd/system/nx9-auth.service" # ── Colours ─────────────────────────────────────────────────────────────────── RED='\033[0;31m'; GREEN='\033[0;32m'; YELLOW='\033[1;33m'; NC='\033[0m' ok() { echo -e "${GREEN} ✓${NC} $*"; } warn() { echo -e "${YELLOW} !${NC} $*"; } fail() { echo -e "${RED} ✗${NC} $*"; exit 1; } # ── Prerequisites ───────────────────────────────────────────────────────────── [[ $EUID -eq 0 ]] || fail "This script must be run as root." [[ -f "$BINARY_PATH" ]] || fail "Binary not found at: $BINARY_PATH — build with 'cargo build --release' first." echo "" echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" echo " nx9-auth deploy" echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" echo "" # ── Create system user ──────────────────────────────────────────────────────── if id -u "$SERVICE_USER" &>/dev/null; then warn "System user '$SERVICE_USER' already exists — skipping creation." else useradd --system --no-create-home --shell /usr/sbin/nologin "$SERVICE_USER" ok "Created system user: $SERVICE_USER" fi # ── Create directories ──────────────────────────────────────────────────────── for dir in "$CONFIG_DIR" "$DATA_DIR" "$LOG_DIR"; do mkdir -p "$dir" chown "$SERVICE_USER:$SERVICE_USER" "$dir" chmod 750 "$dir" done ok "Directories created: $CONFIG_DIR, $DATA_DIR, $LOG_DIR" # ── Install binary ──────────────────────────────────────────────────────────── cp "$BINARY_PATH" "$INSTALL_BIN" chmod 755 "$INSTALL_BIN" ok "Binary installed: $INSTALL_BIN" # ── Write default config if not present ────────────────────────────────────── if [[ ! -f "$CONFIG_DIR/config.toml" ]]; then cat > "$CONFIG_DIR/config.toml" <<'EOF' [server] host = "0.0.0.0" port = 8655 [database] path = "/var/lib/nx9-auth/auth.db" [security] session_ttl_hours = 24 session_absolute_ttl_days = 30 token_ttl_days = 365 argon2_memory = 65536 argon2_iterations = 3 argon2_parallelism = 1 [audit] enabled = true EOF chown root:"$SERVICE_USER" "$CONFIG_DIR/config.toml" chmod 640 "$CONFIG_DIR/config.toml" ok "Default config written: $CONFIG_DIR/config.toml" else warn "Config already exists — skipping: $CONFIG_DIR/config.toml" fi # ── Install systemd service ─────────────────────────────────────────────────── cat > "$SERVICE_FILE" <