Compare commits

..

1 Commits

Author SHA1 Message Date
Nick Hepler
27237a866b Enhance UX and add error handling to the system setup script. 2024-11-04 21:48:28 -05:00

271
setup.sh
View File

@ -1,28 +1,23 @@
#!/bin/bash #!/bin/bash
#
# Script to perform system maintenance on a RHEL-based Linux system. # Script to update a RHEL-based Linux system, set the timezone, change the hostname,
# # add a limited user account, modify sshd_config settings, and optionally install Docker CE
# This script:
# - Updates package manager and installed packages
# - Sets the system timezone based on geolocation or user input
# - Changes the system hostname and updates /etc/hosts
# - Creates a limited user account and modifies SSH settings
# - Optionally installs Docker CE
#
# Prerequisites:
# - The script must be run as root or with sudo privileges
#
# Usage:
# - Run the script directly on the system or via SSH.
# - Respond to prompts as required during the script execution.
# Variables # Variables
timezone="America/New_York"
sshd_config="/etc/ssh/sshd_config" sshd_config="/etc/ssh/sshd_config"
docker_installed=false docker_installed=false
# Function to prompt for hostname # Function to prompt for hostname with validation
prompt_for_hostname() { prompt_for_hostname() {
while true; do
read -p "Please enter the desired hostname: " hostname read -p "Please enter the desired hostname: " hostname
if [[ -z "$hostname" ]]; then
echo "Hostname cannot be empty. Please try again."
else
break
fi
done
} }
# Function to add hostname and IP to /etc/hosts # Function to add hostname and IP to /etc/hosts
@ -41,22 +36,33 @@ update_hosts_file() {
fi fi
} }
# Function to prompt for Docker installation # Function to prompt for Docker installation with validation
prompt_for_docker_install() { prompt_for_docker_install() {
while true; do
read -p "Would you like to install Docker CE? (y/n): " install_docker read -p "Would you like to install Docker CE? (y/n): " install_docker
if [[ "$install_docker" =~ ^[Yy]$ ]]; then case "$install_docker" in
install_docker [Yy]*) install_docker ;;
else [Nn]*) echo "Skipping Docker installation."; break ;;
echo "Skipping Docker installation." *) echo "Invalid input. Please enter 'y' or 'n'." ;;
fi esac
done
} }
# Function to install Docker # Function to install Docker
install_docker() { install_docker() {
echo "Installing Docker CE..." echo "Installing Docker CE..."
curl -fsSL https://get.docker.com -o get-docker.sh curl -fsSL https://get.docker.com -o get-docker.sh
if [ $? -ne 0 ]; then
echo "Error downloading Docker installation script."
exit 1
fi
sh get-docker.sh sh get-docker.sh
if [ $? -ne 0 ]; then
echo "Error installing Docker."
exit 1
fi
# Start and enable Docker service # Start and enable Docker service
systemctl start docker systemctl start docker
systemctl enable docker systemctl enable docker
@ -64,23 +70,21 @@ install_docker() {
usermod -aG docker "$username" usermod -aG docker "$username"
echo "User $username added to the docker group." echo "User $username added to the docker group."
# Clean up get-docker.sh
rm -f get-docker.sh
} }
# Function to create a limited user account # Function to create a limited user account with validation
create_user_account() { create_user_account() {
while true; do
read -p "Please enter the username for the new user account: " username read -p "Please enter the username for the new user account: " username
if [[ -z "$username" ]]; then
echo "Username cannot be empty. Please try again."
else
break
fi
done
read -sp "Please enter the password for the new user account: " password read -sp "Please enter the password for the new user account: " password
echo echo
read -sp "Please confirm the password: " password_confirm
echo
if [ "$password" != "$password_confirm" ]; then
echo "Passwords do not match. Exiting."
exit 1
fi
# Create the user and add to the wheel group # Create the user and add to the wheel group
if id "$username" &>/dev/null; then if id "$username" &>/dev/null; then
@ -92,128 +96,56 @@ create_user_account() {
fi fi
} }
# Check if the script is run as root # Function to check if running as root
if [ "$(id -u)" -ne 0 ]; then check_root() {
if [ "$(id -u)" -ne 0 ]; then
echo "This script must be run as root. Please use sudo or switch to root." echo "This script must be run as root. Please use sudo or switch to root."
exit 1 exit 1
fi fi
}
# Update the package manager # Function to update package manager cache
echo "Updating package manager..." update_package_manager() {
if command -v dnf &> /dev/null; then echo "Updating package manager..."
if command -v dnf &> /dev/null; then
dnf -y makecache dnf -y makecache
elif command -v yum &> /dev/null; then elif command -v yum &> /dev/null; then
yum -y makecache yum -y makecache
else else
echo "Neither dnf nor yum found. This script only works on RHEL-based distributions." echo "Neither dnf nor yum found. This script only works on RHEL-based distributions."
exit 1 exit 1
fi fi
}
# Upgrade installed packages # Function to upgrade installed packages
echo "Upgrading installed packages..." upgrade_packages() {
if command -v dnf &> /dev/null; then echo "Upgrading installed packages..."
if command -v dnf &> /dev/null; then
dnf -y upgrade dnf -y upgrade
elif command -v yum &> /dev/null; then elif command -v yum &> /dev/null; then
yum -y update yum -y update
fi
# Change the timezone
# Function to set the timezone to UTC in case of an error
set_utc_timezone() {
echo "Error occurred while determining the timezone. Falling back to UTC."
timedatectl set-timezone UTC
}
# Function to get the timezone from the ipinfo.io API
get_timezone_from_api() {
# Fetch geolocation information using the ipinfo.io API
response=$(curl -s https://ipinfo.io)
# Check if the curl command succeeded and the response contains the 'timezone' field
if [ $? -eq 0 ] && echo "$response" | grep -q "timezone"; then
# Extract the timezone directly from the JSON response
timezone=$(echo "$response" | jq -r '.timezone')
echo "Detected timezone: $timezone"
return 0
else
set_utc_timezone
return 1
fi fi
} }
# Function to prompt the user to choose a timezone # Function to change the timezone
prompt_for_timezone() { set_timezone() {
echo "" echo "Setting timezone to $timezone..."
echo "Choose a timezone option:" timedatectl set-timezone "$timezone"
echo "1) Use the detected timezone ($1)"
echo "2) Use UTC"
echo "3) Enter a custom timezone"
# Read user choice
read -p "Enter the number corresponding to your choice: " choice
case "$choice" in
1)
echo "You chose to use the detected timezone: $1"
timedatectl set-timezone "$1"
;;
2)
echo "You chose to use UTC."
timedatectl set-timezone UTC
;;
3)
# Ask for a custom timezone
read -p "Enter your preferred timezone (e.g., Europe/London, America/New_York): " custom_timezone
if timedatectl list-timezones | grep -q "$custom_timezone"; then
timedatectl set-timezone "$custom_timezone"
else
echo "Invalid timezone. Falling back to UTC."
timedatectl set-timezone UTC
fi
;;
*)
echo "Invalid choice. Falling back to UTC."
timedatectl set-timezone UTC
;;
esac
} }
# Main script execution starts here # Function to change the hostname
echo "Attempting to detect and set the timezone..." set_hostname() {
prompt_for_hostname
echo "Setting hostname to $hostname..."
hostnamectl set-hostname "$hostname"
}
# Try to get the detected timezone from the API # Function to modify sshd_config
if get_timezone_from_api; then modify_sshd_config() {
# If the timezone was successfully detected, prompt the user for their choice echo "Modifying SSH configuration..."
prompt_for_timezone "$timezone" if [ -f "$sshd_config" ]; then
else
# If no timezone was detected, ask the user to fall back to UTC
echo "Unable to detect timezone. Falling back to UTC."
timedatectl set-timezone UTC
fi
# Change the hostname
prompt_for_hostname
echo "Setting hostname to $hostname..."
hostnamectl set-hostname "$hostname"
# Update /etc/hosts
update_hosts_file
# Create a limited user account
create_user_account
# Modify sshd_config
echo "Modifying SSH configuration..."
if [ -f "$sshd_config" ]; then
# Set PermitRootLogin to no # Set PermitRootLogin to no
if ! grep -q "^PermitRootLogin" "$sshd_config"; then sed -i 's/^PermitRootLogin .*/PermitRootLogin no/' "$sshd_config" || echo "PermitRootLogin no" >> "$sshd_config"
echo "PermitRootLogin no" >> "$sshd_config"
else
sed -i 's/^PermitRootLogin.*/PermitRootLogin no/' "$sshd_config"
fi
# Set PasswordAuthentication to no # Set PasswordAuthentication to no
if grep -q '^#PasswordAuthentication' "$sshd_config"; then if grep -q '^#PasswordAuthentication' "$sshd_config"; then
@ -228,41 +160,52 @@ if [ -f "$sshd_config" ]; then
else else
sed -i 's/^AddressFamily .*/AddressFamily inet/' "$sshd_config" || echo "AddressFamily inet" >> "$sshd_config" sed -i 's/^AddressFamily .*/AddressFamily inet/' "$sshd_config" || echo "AddressFamily inet" >> "$sshd_config"
fi fi
else else
echo "sshd_config file not found. Exiting." echo "sshd_config file not found. Exiting."
exit 1 exit 1
fi fi
}
# Get the IP address of the machine # Function to restart SSH service
ip_address=$(hostname -I | awk '{print $1}') restart_ssh() {
echo "Restarting SSH service..."
systemctl restart sshd
}
# Prompt the user to copy their public key # Function to wait for SSH key copy
echo "Please copy your public SSH key to the server using the following command:" wait_for_key_copy() {
echo "ssh-copy-id $username@$ip_address" echo "Waiting for your public key to be copied..."
while true; do
# Wait until the authorized_keys file is no longer empty
echo "Waiting for your public key to be copied..."
while true; do
if [ -s "/home/$username/.ssh/authorized_keys" ]; then if [ -s "/home/$username/.ssh/authorized_keys" ]; then
echo "Public key has been successfully copied." echo "Public key has been successfully copied."
break break
fi fi
sleep 2 sleep 2
done done
}
# Restart SSH service to apply changes # Function to clean up unused packages
echo "Restarting SSH service..." cleanup() {
systemctl restart sshd echo "Cleaning up..."
if command -v dnf &> /dev/null; then
# Prompt for Docker installation
prompt_for_docker_install
# Clean up
echo "Cleaning up..."
if command -v dnf &> /dev/null; then
dnf -y autoremove dnf -y autoremove
elif command -v yum &> /dev/null; then elif command -v yum &> /dev/null; then
yum -y autoremove yum -y autoremove
fi fi
}
echo "System update complete! Timezone set to ${timezone:-UTC}, hostname set to $hostname, limited user created, sshd_config modified, and Docker installation completed if selected." # Main execution
check_root
update_package_manager
upgrade_packages
set_timezone
set_hostname
update_hosts_file
create_user_account
modify_sshd_config
restart_ssh
wait_for_key_copy
prompt_for_docker_install
cleanup
echo "System update complete! Timezone set to $timezone, hostname set to $hostname, limited user created, sshd_config modified, and Docker installation completed if selected."