Archive the non-ported remainder of the legacy KNELServerBuild repo
under archive/KNELServerBuild/ with its original structure intact,
completing the legacy repo merge for everything except the live
LibreNMS patterns (ported in the previous commit).
Exclusions:
- .git history (superseded; legacy repo remains at its original path)
- ported files (Agents/librenms, Modules/OAM/oam-librenms.sh,
ConfigFiles/SNMP/snmp-sudo.conf)
- vendored KNELShellFramework tree (byte-identical duplicate of the
copy already vendored at vendor/ in this repo)
- SSH authorized-keys files (live access-control material; carrying
them in an archive invites drift — key policy lives elsewhere)
The whole tree is skip-listed in tests/shellcheck.sh (archived legacy
code, not maintained — same standing as vendor/); check-rules.sh
already prunes archive/. Rule 9 (conflict markers) now also excludes
archive/ staged files: preserved-verbatim legacy scripts contain
decorative "====" banners that false-positive as conflict markers
(same archive exclusion precedent as rule 11).
AGENTS.md: note archive/KNELServerBuild and oam/librenms-agent in the
Repository Layout, and fix the stale KNELIAC path to
/home/reachableceo/projects/KNEL/KNELIAC.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
105 lines
2.9 KiB
Bash
105 lines
2.9 KiB
Bash
#!/bin/bash
|
|
|
|
#########################################
|
|
#Core framework functions...
|
|
#########################################
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
|
|
export PROJECT_ROOT_PATH
|
|
PROJECT_ROOT_PATH="$(cd "$SCRIPT_DIR/../../.." && pwd)"
|
|
|
|
export GIT_VENDOR_PATH_ROOT
|
|
GIT_VENDOR_PATH_ROOT="$PROJECT_ROOT_PATH/vendor/git@git.knownelement.com/29418/"
|
|
|
|
export KNELShellFrameworkRoot
|
|
KNELShellFrameworkRoot="$GIT_VENDOR_PATH_ROOT/KNEL/KNELShellFramework"
|
|
|
|
export CONFIGFILES_PATH
|
|
CONFIGFILES_PATH="$PROJECT_ROOT_PATH/ProjectCode/ConfigFiles"
|
|
|
|
source "$KNELShellFrameworkRoot/Framework-ConfigFiles/FrameworkVars"
|
|
|
|
for framework_include_file in "$KNELShellFrameworkRoot"/Framework-Includes/*; do
|
|
source "$framework_include_file"
|
|
done
|
|
|
|
for project_include_file in "$PROJECT_ROOT_PATH"/Project-Includes/*; do
|
|
source "$project_include_file"
|
|
done
|
|
|
|
|
|
#########################################
|
|
# Core script code begins here
|
|
#########################################
|
|
|
|
export SUBODEV_CHECK
|
|
SUBODEV_CHECK="$(getent passwd | grep -c subodev || true)"
|
|
|
|
export LOCALUSER_CHECK
|
|
LOCALUSER_CHECK="$(getent passwd | grep -c localuser || true)"
|
|
|
|
export ROOT_SSH_DIR
|
|
ROOT_SSH_DIR="/root/.ssh"
|
|
|
|
export LOCALUSER_SSH_DIR
|
|
LOCALUSER_SSH_DIR="/home/localuser/.ssh"
|
|
|
|
export SUBODEV_SSH_DIR
|
|
SUBODEV_SSH_DIR="/home/subodev/.ssh"
|
|
|
|
|
|
if [ ! -d $ROOT_SSH_DIR ]; then
|
|
mkdir /root/.ssh/
|
|
fi
|
|
|
|
cat "$CONFIGFILES_PATH/SSH/AuthorizedKeys/root-ssh-authorized-keys" >/root/.ssh/authorized_keys
|
|
chmod 400 /root/.ssh/authorized_keys
|
|
chown root: /root/.ssh/authorized_keys
|
|
|
|
if [ "$LOCALUSER_CHECK" -gt 0 ]; then
|
|
if [ ! -d $LOCALUSER_SSH_DIR ]; then
|
|
mkdir -p /home/localuser/.ssh/
|
|
fi
|
|
|
|
cat "$CONFIGFILES_PATH/SSH/AuthorizedKeys/localuser-ssh-authorized-keys" >/home/localuser/.ssh/authorized_keys
|
|
chown localuser /home/localuser/.ssh/authorized_keys &&
|
|
chmod 400 /home/localuser/.ssh/authorized_keys
|
|
fi
|
|
|
|
if [ "$SUBODEV_CHECK" = 1 ]; then
|
|
|
|
if [ ! -d $SUBODEV_SSH_DIR ]; then
|
|
mkdir /home/subodev/.ssh/
|
|
fi
|
|
|
|
cat "$CONFIGFILES_PATH/SSH/AuthorizedKeys/localuser-ssh-authorized-keys" >/home/subodev/.ssh/authorized_keys
|
|
chmod 400 /home/subodev/.ssh/authorized_keys &&
|
|
chown subodev: /home/subodev/.ssh/authorized_keys
|
|
fi
|
|
|
|
export DEV_WORKSTATION_CHECK
|
|
DEV_WORKSTATION_CHECK="$(hostname | egrep -c 'subopi-dev|CharlesDevServer' || true)"
|
|
|
|
if [ "$DEV_WORKSTATION_CHECK" -eq 0 ]; then
|
|
|
|
cat "$CONFIGFILES_PATH/SSH/Configs/tsys-sshd-config" >/etc/ssh/sshd_config
|
|
fi
|
|
|
|
|
|
#Don't deploy this config to a ubuntu server, it breaks openssh server. Works on kali/debian.
|
|
|
|
export UBUNTU_CHECK
|
|
UBUNTU_CHECK="$(distro | grep -c Ubuntu||true)"
|
|
|
|
if [ "$UBUNTU_CHECK" -ne 1 ]; then
|
|
cat "$CONFIGFILES_PATH/SSH/Configs/ssh-audit-hardening.conf" >/etc/ssh/sshd_config.d/ssh-audit_hardening.conf
|
|
chmod og-rwx /etc/ssh/sshd_config.d/*
|
|
fi
|
|
|
|
# Perms on sshd_config
|
|
chmod og-rwx /etc/ssh/sshd_config
|
|
|
|
#todo
|
|
|
|
# only strong MAC algos are used |