2018-03-27 20:55:33 +02:00
|
|
|
#!/bin/bash
|
|
|
|
|
2018-04-16 21:30:07 +02:00
|
|
|
# Setup
|
|
|
|
|
|
|
|
GROUPNAME="bitwarden"
|
2018-03-28 04:57:30 +02:00
|
|
|
USERNAME="bitwarden"
|
2018-04-16 21:30:07 +02:00
|
|
|
|
2018-05-31 18:05:26 +02:00
|
|
|
LUID=${LOCAL_UID:-0}
|
|
|
|
LGID=${LOCAL_GID:-0}
|
2018-04-16 21:30:07 +02:00
|
|
|
|
2018-05-31 18:05:26 +02:00
|
|
|
# Step down from host root to well-known nobody/nogroup user
|
2018-03-28 04:57:30 +02:00
|
|
|
|
2018-05-31 18:05:26 +02:00
|
|
|
if [ $LUID -eq 0 ]
|
2018-04-16 21:30:07 +02:00
|
|
|
then
|
2018-05-31 18:05:26 +02:00
|
|
|
LUID=65534
|
2018-04-16 21:30:07 +02:00
|
|
|
fi
|
2018-05-31 18:05:26 +02:00
|
|
|
if [ $LGID -eq 0 ]
|
2018-03-28 04:57:30 +02:00
|
|
|
then
|
2018-05-31 18:05:26 +02:00
|
|
|
LGID=65534
|
2018-03-28 04:57:30 +02:00
|
|
|
fi
|
|
|
|
|
2018-05-31 18:05:26 +02:00
|
|
|
# Create user and group
|
2018-04-16 21:30:07 +02:00
|
|
|
|
2018-05-31 18:05:26 +02:00
|
|
|
groupadd -o -g $LGID $GROUPNAME >/dev/null 2>&1 ||
|
|
|
|
groupmod -o -g $LGID $GROUPNAME >/dev/null 2>&1
|
|
|
|
useradd -o -u $LUID -g $GROUPNAME -s /bin/false $USERNAME >/dev/null 2>&1 ||
|
|
|
|
usermod -o -u $LUID -g $GROUPNAME -s /bin/false $USERNAME >/dev/null 2>&1
|
|
|
|
mkhomedir_helper $USERNAME
|
2018-04-03 03:11:32 +02:00
|
|
|
|
2018-04-16 21:30:07 +02:00
|
|
|
# The rest...
|
|
|
|
|
|
|
|
chown -R $USERNAME:$GROUPNAME /app
|
2018-03-27 20:55:33 +02:00
|
|
|
mkdir -p /bitwarden/env
|
|
|
|
mkdir -p /bitwarden/docker
|
|
|
|
mkdir -p /bitwarden/ssl
|
|
|
|
mkdir -p /bitwarden/letsencrypt
|
|
|
|
mkdir -p /bitwarden/identity
|
|
|
|
mkdir -p /bitwarden/nginx
|
2018-07-19 22:45:27 +02:00
|
|
|
mkdir -p /bitwarden/ca-certificates
|
2018-04-16 21:30:07 +02:00
|
|
|
chown -R $USERNAME:$GROUPNAME /bitwarden
|
2018-03-27 20:55:33 +02:00
|
|
|
|
2018-07-19 23:33:53 +02:00
|
|
|
cp /bitwarden/ca-certificates/*.crt /usr/local/share/ca-certificates/ >/dev/null 2>&1 \
|
2018-07-19 22:45:27 +02:00
|
|
|
&& update-ca-certificates
|
|
|
|
|
2018-04-16 21:30:07 +02:00
|
|
|
exec gosu $USERNAME:$GROUPNAME "$@"
|