X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/a449993c2f97f5bfa7c66e8bc1e453946fe25bc7..6cf4a14058d61863ecb4522df528b59e83ec5edf:/cookbooks/otrs/recipes/default.rb diff --git a/cookbooks/otrs/recipes/default.rb b/cookbooks/otrs/recipes/default.rb index 03eb43aa0..f16931b32 100644 --- a/cookbooks/otrs/recipes/default.rb +++ b/cookbooks/otrs/recipes/default.rb @@ -1,14 +1,14 @@ # -# Cookbook Name:: otrs +# Cookbook:: otrs # Recipe:: default # -# Copyright 2012, OpenStreetMap Foundation +# Copyright:: 2012, OpenStreetMap Foundation # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # -# http://www.apache.org/licenses/LICENSE-2.0 +# https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, @@ -17,27 +17,65 @@ # limitations under the License. # -include_recipe "tools" +include_recipe "accounts" +include_recipe "apache" +include_recipe "exim" include_recipe "postgresql" -include_recipe "apache::ssl" +include_recipe "tools" passwords = data_bag_item("otrs", "passwords") -package "libapache2-mod-perl2" -package "libapache2-reload-perl" - -package "libgd-gd2-perl" -package "libgd-graph-perl" -package "libgd-text-perl" -package "libjson-xs-perl" -package "libmail-imapclient-perl" -package "libnet-ldap-perl" -package "libpdf-api2-perl" -package "libsoap-lite-perl" -package "libyaml-libyaml-perl" -package "libcrypt-eksblowfish-perl" - +package %w[ + tar + bzip2 + libapache-dbi-perl + libapache2-reload-perl + libarchive-zip-perl + libauthen-ntlm-perl + libauthen-sasl-perl + libcrypt-eksblowfish-perl + libcss-minifier-xs-perl + libdatetime-perl + libdbd-mysql-perl + libencode-hanextra-perl + libexcel-writer-xlsx-perl + libgd-gd2-perl + libgd-graph-perl + libgd-text-perl + libhtml-parser-perl + libio-socket-ssl-perl + libjavascript-minifier-xs-perl + libjson-perl + libjson-xs-perl + liblocale-codes-perl + libmail-imapclient-perl + libmoo-perl + libnet-dns-perl + libnet-ldap-perl + libpdf-api2-perl + libsisimai-perl + libsoap-lite-perl + libspreadsheet-xlsx-perl + libtemplate-perl + libtext-csv-xs-perl + libtext-diff-perl + libtimedate-perl + libxml-libxml-perl + libxml-libxml-simple-perl + libxml-libxslt-perl + libxml-parser-perl + libxml-simple-perl + libyaml-libyaml-perl + libyaml-perl +] + +apache_module "perl" do + package "libapache2-mod-perl2" +end + +apache_module "deflate" apache_module "headers" +apache_module "rewrite" version = node[:otrs][:version] user = node[:otrs][:user] @@ -46,6 +84,7 @@ database_name = node[:otrs][:database_name] database_user = node[:otrs][:database_user] database_password = passwords[node[:otrs][:database_password]] site = node[:otrs][:site] +site_aliases = node[:otrs][:site_aliases] || [] postgresql_user database_user do cluster database_cluster @@ -57,20 +96,20 @@ postgresql_database database_name do owner database_user end -remote_file "#{Chef::Config[:file_cache_path]}/otrs-#{version}.tar.bz2" do - source "http://ftp.otrs.org/pub/otrs/otrs-#{version}.tar.bz2" - not_if { File.exist?("/opt/otrs-#{version}") } +remote_file "#{Chef::Config[:file_cache_path]}/znuny-#{version}.tar.bz2" do + source "https://download.znuny.org/releases/znuny-#{version}.tar.bz2" + not_if { ::File.exist?("/opt/znuny-#{version}") } end -execute "untar-otrs-#{version}" do - command "tar jxf #{Chef::Config[:file_cache_path]}/otrs-#{version}.tar.bz2" +execute "untar-znuny-#{version}" do + command "tar jxf #{Chef::Config[:file_cache_path]}/znuny-#{version}.tar.bz2" cwd "/opt" user "root" group "root" - not_if { File.exist?("/opt/otrs-#{version}") } + not_if { ::File.exist?("/opt/znuny-#{version}") } end -config = edit_file "/opt/otrs-#{version}/Kernel/Config.pm.dist" do |line| +config = edit_file "/opt/znuny-#{version}/Kernel/Config.pm.dist" do |line| line.gsub!(/^( *)\$Self->{Database} = 'otrs'/, "\\1$Self->{Database} = '#{database_name}'") line.gsub!(/^( *)\$Self->{DatabaseUser} = 'otrs'/, "\\1$Self->{DatabaseUser} = '#{database_user}'") line.gsub!(/^( *)\$Self->{DatabasePw} = 'some-pass'/, "\\1$Self->{DatabasePw} = '#{database_password}'") @@ -78,87 +117,62 @@ config = edit_file "/opt/otrs-#{version}/Kernel/Config.pm.dist" do |line| line.gsub!(/^( *\$Self->{DatabaseDSN} = "DBI:mysql:)/, "#\\1") line.gsub!(/^#( *\$Self->{DatabaseDSN} = "DBI:Pg:.*;host=)/, "\\1") line.gsub!(/^( *)# (\$Self->{CheckMXRecord} = 0)/, "\\1\\2") + line.gsub!(/^( *)# \$Self->{SessionUseCookie} = 0/, "\\1$Self->{SessionCheckRemoteIP} = 0") line end -file "/opt/otrs-#{version}/Kernel/Config.pm" do +file "/opt/znuny-#{version}/Kernel/Config.pm" do owner user group "www-data" - mode 0o664 + mode "664" content config + notifies :restart, "service[otrs]" end -generic_agent = edit_file "/opt/otrs-#{version}/Kernel/Config/GenericAgent.pm.dist" do |line| - line -end - -file "/opt/otrs-#{version}/Kernel/Config/GenericAgent.pm" do - owner user - group "www-data" - mode 0o664 - content generic_agent -end - -link "/opt/otrs" do - to "/opt/otrs-#{version}" -end - -execute "/opt/otrs/bin/otrs.SetPermissions.pl" do - action :run - command "/opt/otrs/bin/otrs.SetPermissions.pl --otrs-user=#{user} --web-user=www-data --otrs-group=www-data --web-group=www-data /opt/otrs-#{version}" +execute "/opt/znuny-#{version}/bin/otrs.SetPermissions.pl" do + action :nothing + command "/opt/znuny-#{version}/bin/otrs.SetPermissions.pl --otrs-user=#{user} --web-group=www-data /opt/znuny-#{version}" user "root" group "root" - only_if { File.stat("/opt/otrs/README.md").uid != Etc.getpwnam("otrs").uid } + subscribes :run, "execute[untar-znuny-#{version}]" end -execute "/opt/otrs/bin/otrs.RebuildConfig.pl" do - action :run - command "/opt/otrs/bin/otrs.RebuildConfig.pl" - user "root" - group "root" - not_if { File.exist?("/opt/otrs/Kernel/Config/Files/ZZZAAuto.pm") } +link "/opt/otrs" do + to "/opt/znuny-#{version}" end -execute "/opt/otrs/bin/Cron.sh" do - action :nothing - command "/opt/otrs/bin/Cron.sh restart" +systemd_service "otrs" do + description "OTRS Daemon" + type "forking" user "otrs" group "otrs" + exec_start "/opt/otrs/bin/otrs.Daemon.pl start" + private_tmp true + protect_system "strict" + protect_home true + read_write_paths ["/opt/znuny-#{version}/var", "/var/log/exim4", "/var/spool/exim4"] end -Dir.glob("/opt/otrs/var/cron/*.dist") do |distname| - name = distname.sub(".dist", "") - - file name do - owner "otrs" - group "www-data" - mode 0o664 - content IO.read(distname) - notifies :run, "execute[/opt/otrs/bin/Cron.sh]" - end +service "otrs" do + action [:enable, :start] + subscribes :restart, "link[/opt/otrs]" + subscribes :restart, "systemd_service[otrs]" end ssl_certificate site do - domains site - fallback_certificate "openstreetmap" + domains [site] + site_aliases notifies :reload, "service[apache2]" end apache_site site do template "apache.erb" -end - -template "/etc/sudoers.d/otrs" do - source "sudoers.erb" - owner "root" - group "root" - mode 0o440 + variables :aliases => site_aliases end template "/etc/cron.daily/otrs-backup" do source "backup.cron.erb" owner "root" group "root" - mode 0o755 + mode "755" end