X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/5fb7a990481702f72801bc430b0f01675af38f94..524d90d022751710980613df6b943291fc1498d6:/cookbooks/donate/recipes/default.rb diff --git a/cookbooks/donate/recipes/default.rb b/cookbooks/donate/recipes/default.rb index e98e5c361..daa31fe4c 100644 --- a/cookbooks/donate/recipes/default.rb +++ b/cookbooks/donate/recipes/default.rb @@ -1,14 +1,14 @@ # -# Cookbook Name:: donate +# Cookbook:: donate # Recipe:: default # -# Copyright 2016, OpenStreetMap Foundation +# Copyright:: 2016, OpenStreetMap Foundation # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # -# http://www.apache.org/licenses/LICENSE-2.0 +# https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, @@ -17,19 +17,22 @@ # limitations under the License. # -include_recipe "apache::ssl" -include_recipe "mysql" +include_recipe "accounts" +include_recipe "apache" include_recipe "git" +include_recipe "mysql" +include_recipe "php::fpm" -package "php" -package "php-cli" -package "php-curl" -package "php-mbstring" -package "php-mysql" -package "php-gd" +package %w[ + php-cli + php-curl + php-mysql + php-gd +] -apache_module "php7.0" apache_module "headers" +apache_module "proxy" +apache_module "proxy_fcgi" passwords = data_bag_item("donate", "passwords") @@ -43,29 +46,59 @@ mysql_database "donate" do permissions "donate@localhost" => :all end +directory "/srv/donate.openstreetmap.org" do + owner "donate" + group "donate" + mode "755" +end + git "/srv/donate.openstreetmap.org" do action :sync - repository "git://github.com/osmfoundation/donation-drive.git" + repository "https://github.com/osmfoundation/donation-drive.git" + depth 1 user "donate" group "donate" end -apache_site "donate.openstreetmap.org" do - template "apache.erb" +directory "/srv/donate.openstreetmap.org/data" do + owner "donate" + group "donate" + mode "755" end -template "/etc/cron.d/osmf-donate" do - source "cron.erb" +template "/srv/donate.openstreetmap.org/scripts/db-connect.inc.php" do + source "db-connect.inc.php.erb" owner "root" - group "root" - mode 0o600 + group "donate" + mode "644" variables :passwords => passwords end +ssl_certificate "donate.openstreetmap.org" do + domains ["donate.openstreetmap.org", "donate.openstreetmap.com", + "donate.openstreetmap.net", "donate.osm.org"] + notifies :reload, "service[apache2]" +end + +php_fpm "donate.openstreetmap.org" do + php_admin_values "open_basedir" => "/srv/donate.openstreetmap.org/:/usr/share/php/:/tmp/", + "disable_functions" => "exec,shell_exec,system,passthru,popen,proc_open" +end + +apache_site "donate.openstreetmap.org" do + template "apache.erb" +end + +cron_d "osmf-donate" do + minute "*/2" + user "donate" + command "cd /srv/donate.openstreetmap.org/scripts/; /usr/bin/php /srv/donate.openstreetmap.org/scripts/update_csv_donate2016.php" +end + template "/etc/cron.daily/osmf-donate-backup" do source "backup.cron.erb" owner "root" group "root" - mode 0o750 + mode "750" variables :passwords => passwords end