Compare commits

..

1 Commits

Author SHA1 Message Date
Nick Hepler
27237a866b Enhance UX and add error handling to the system setup script. 2024-11-04 21:48:28 -05:00

223
setup.sh
View File

@ -1,28 +1,23 @@
#!/bin/bash #!/bin/bash
#
# Script to perform system maintenance on a RHEL-based Linux system. # Script to update a RHEL-based Linux system, set the timezone, change the hostname,
# # add a limited user account, modify sshd_config settings, and optionally install Docker CE
# This script:
# - Updates package manager and installed packages
# - Sets the system timezone based on geolocation or user input
# - Changes the system hostname and updates /etc/hosts
# - Creates a limited user account and modifies SSH settings
# - Optionally installs Docker CE
#
# Prerequisites:
# - The script must be run as root or with sudo privileges
#
# Usage:
# - Run the script directly on the system or via SSH.
# - Respond to prompts as required during the script execution.
# Variables # Variables
timezone="America/New_York"
sshd_config="/etc/ssh/sshd_config" sshd_config="/etc/ssh/sshd_config"
docker_installed=false docker_installed=false
# Function to prompt for hostname # Function to prompt for hostname with validation
prompt_for_hostname() { prompt_for_hostname() {
while true; do
read -p "Please enter the desired hostname: " hostname read -p "Please enter the desired hostname: " hostname
if [[ -z "$hostname" ]]; then
echo "Hostname cannot be empty. Please try again."
else
break
fi
done
} }
# Function to add hostname and IP to /etc/hosts # Function to add hostname and IP to /etc/hosts
@ -41,22 +36,33 @@ update_hosts_file() {
fi fi
} }
# Function to prompt for Docker installation # Function to prompt for Docker installation with validation
prompt_for_docker_install() { prompt_for_docker_install() {
while true; do
read -p "Would you like to install Docker CE? (y/n): " install_docker read -p "Would you like to install Docker CE? (y/n): " install_docker
if [[ "$install_docker" =~ ^[Yy]$ ]]; then case "$install_docker" in
install_docker [Yy]*) install_docker ;;
else [Nn]*) echo "Skipping Docker installation."; break ;;
echo "Skipping Docker installation." *) echo "Invalid input. Please enter 'y' or 'n'." ;;
fi esac
done
} }
# Function to install Docker # Function to install Docker
install_docker() { install_docker() {
echo "Installing Docker CE..." echo "Installing Docker CE..."
curl -fsSL https://get.docker.com -o get-docker.sh curl -fsSL https://get.docker.com -o get-docker.sh
if [ $? -ne 0 ]; then
echo "Error downloading Docker installation script."
exit 1
fi
sh get-docker.sh sh get-docker.sh
if [ $? -ne 0 ]; then
echo "Error installing Docker."
exit 1
fi
# Start and enable Docker service # Start and enable Docker service
systemctl start docker systemctl start docker
systemctl enable docker systemctl enable docker
@ -64,23 +70,21 @@ install_docker() {
usermod -aG docker "$username" usermod -aG docker "$username"
echo "User $username added to the docker group." echo "User $username added to the docker group."
# Clean up get-docker.sh
rm -f get-docker.sh
} }
# Function to create a limited user account # Function to create a limited user account with validation
create_user_account() { create_user_account() {
while true; do
read -p "Please enter the username for the new user account: " username read -p "Please enter the username for the new user account: " username
if [[ -z "$username" ]]; then
echo "Username cannot be empty. Please try again."
else
break
fi
done
read -sp "Please enter the password for the new user account: " password read -sp "Please enter the password for the new user account: " password
echo echo
read -sp "Please confirm the password: " password_confirm
echo
if [ "$password" != "$password_confirm" ]; then
echo "Passwords do not match. Exiting."
exit 1
fi
# Create the user and add to the wheel group # Create the user and add to the wheel group
if id "$username" &>/dev/null; then if id "$username" &>/dev/null; then
@ -92,13 +96,16 @@ create_user_account() {
fi fi
} }
# Check if the script is run as root # Function to check if running as root
check_root() {
if [ "$(id -u)" -ne 0 ]; then if [ "$(id -u)" -ne 0 ]; then
echo "This script must be run as root. Please use sudo or switch to root." echo "This script must be run as root. Please use sudo or switch to root."
exit 1 exit 1
fi fi
}
# Update the package manager # Function to update package manager cache
update_package_manager() {
echo "Updating package manager..." echo "Updating package manager..."
if command -v dnf &> /dev/null; then if command -v dnf &> /dev/null; then
dnf -y makecache dnf -y makecache
@ -108,112 +115,37 @@ else
echo "Neither dnf nor yum found. This script only works on RHEL-based distributions." echo "Neither dnf nor yum found. This script only works on RHEL-based distributions."
exit 1 exit 1
fi fi
}
# Upgrade installed packages # Function to upgrade installed packages
upgrade_packages() {
echo "Upgrading installed packages..." echo "Upgrading installed packages..."
if command -v dnf &> /dev/null; then if command -v dnf &> /dev/null; then
dnf -y upgrade dnf -y upgrade
elif command -v yum &> /dev/null; then elif command -v yum &> /dev/null; then
yum -y update yum -y update
fi fi
# Change the timezone
# Function to set the timezone to UTC in case of an error
set_utc_timezone() {
echo "Error occurred while determining the timezone. Falling back to UTC."
timedatectl set-timezone UTC
} }
# Function to get the timezone from the ipinfo.io API # Function to change the timezone
get_timezone_from_api() { set_timezone() {
# Fetch geolocation information using the ipinfo.io API echo "Setting timezone to $timezone..."
response=$(curl -s https://ipinfo.io) timedatectl set-timezone "$timezone"
# Check if the curl command succeeded and the response contains the 'timezone' field
if [ $? -eq 0 ] && echo "$response" | grep -q "timezone"; then
# Extract the timezone directly from the JSON response
timezone=$(echo "$response" | jq -r '.timezone')
echo "Detected timezone: $timezone"
return 0
else
set_utc_timezone
return 1
fi
} }
# Function to prompt the user to choose a timezone # Function to change the hostname
prompt_for_timezone() { set_hostname() {
echo ""
echo "Choose a timezone option:"
echo "1) Use the detected timezone ($1)"
echo "2) Use UTC"
echo "3) Enter a custom timezone"
# Read user choice
read -p "Enter the number corresponding to your choice: " choice
case "$choice" in
1)
echo "You chose to use the detected timezone: $1"
timedatectl set-timezone "$1"
;;
2)
echo "You chose to use UTC."
timedatectl set-timezone UTC
;;
3)
# Ask for a custom timezone
read -p "Enter your preferred timezone (e.g., Europe/London, America/New_York): " custom_timezone
if timedatectl list-timezones | grep -q "$custom_timezone"; then
timedatectl set-timezone "$custom_timezone"
else
echo "Invalid timezone. Falling back to UTC."
timedatectl set-timezone UTC
fi
;;
*)
echo "Invalid choice. Falling back to UTC."
timedatectl set-timezone UTC
;;
esac
}
# Main script execution starts here
echo "Attempting to detect and set the timezone..."
# Try to get the detected timezone from the API
if get_timezone_from_api; then
# If the timezone was successfully detected, prompt the user for their choice
prompt_for_timezone "$timezone"
else
# If no timezone was detected, ask the user to fall back to UTC
echo "Unable to detect timezone. Falling back to UTC."
timedatectl set-timezone UTC
fi
# Change the hostname
prompt_for_hostname prompt_for_hostname
echo "Setting hostname to $hostname..." echo "Setting hostname to $hostname..."
hostnamectl set-hostname "$hostname" hostnamectl set-hostname "$hostname"
}
# Update /etc/hosts # Function to modify sshd_config
update_hosts_file modify_sshd_config() {
# Create a limited user account
create_user_account
# Modify sshd_config
echo "Modifying SSH configuration..." echo "Modifying SSH configuration..."
if [ -f "$sshd_config" ]; then if [ -f "$sshd_config" ]; then
# Set PermitRootLogin to no # Set PermitRootLogin to no
if ! grep -q "^PermitRootLogin" "$sshd_config"; then sed -i 's/^PermitRootLogin .*/PermitRootLogin no/' "$sshd_config" || echo "PermitRootLogin no" >> "$sshd_config"
echo "PermitRootLogin no" >> "$sshd_config"
else
sed -i 's/^PermitRootLogin.*/PermitRootLogin no/' "$sshd_config"
fi
# Set PasswordAuthentication to no # Set PasswordAuthentication to no
if grep -q '^#PasswordAuthentication' "$sshd_config"; then if grep -q '^#PasswordAuthentication' "$sshd_config"; then
@ -232,15 +164,16 @@ else
echo "sshd_config file not found. Exiting." echo "sshd_config file not found. Exiting."
exit 1 exit 1
fi fi
}
# Get the IP address of the machine # Function to restart SSH service
ip_address=$(hostname -I | awk '{print $1}') restart_ssh() {
echo "Restarting SSH service..."
systemctl restart sshd
}
# Prompt the user to copy their public key # Function to wait for SSH key copy
echo "Please copy your public SSH key to the server using the following command:" wait_for_key_copy() {
echo "ssh-copy-id $username@$ip_address"
# Wait until the authorized_keys file is no longer empty
echo "Waiting for your public key to be copied..." echo "Waiting for your public key to be copied..."
while true; do while true; do
if [ -s "/home/$username/.ssh/authorized_keys" ]; then if [ -s "/home/$username/.ssh/authorized_keys" ]; then
@ -249,20 +182,30 @@ while true; do
fi fi
sleep 2 sleep 2
done done
}
# Restart SSH service to apply changes # Function to clean up unused packages
echo "Restarting SSH service..." cleanup() {
systemctl restart sshd
# Prompt for Docker installation
prompt_for_docker_install
# Clean up
echo "Cleaning up..." echo "Cleaning up..."
if command -v dnf &> /dev/null; then if command -v dnf &> /dev/null; then
dnf -y autoremove dnf -y autoremove
elif command -v yum &> /dev/null; then elif command -v yum &> /dev/null; then
yum -y autoremove yum -y autoremove
fi fi
}
echo "System update complete! Timezone set to ${timezone:-UTC}, hostname set to $hostname, limited user created, sshd_config modified, and Docker installation completed if selected." # Main execution
check_root
update_package_manager
upgrade_packages
set_timezone
set_hostname
update_hosts_file
create_user_account
modify_sshd_config
restart_ssh
wait_for_key_copy
prompt_for_docker_install
cleanup
echo "System update complete! Timezone set to $timezone, hostname set to $hostname, limited user created, sshd_config modified, and Docker installation completed if selected."