set netdata user home directory; do not validate certs when sending alarms; attempt to detect ssl certs on static installations; fixes #3489
Costa Tsaousis (ktsaou) committed
Mar 1, 2018 at 00:23 UTC
c9aeb55675730000418262a691add94f235a40ec
4 files changed
+43
-10
installer/functions.sh
+10
-6
@@ -278,31 +278,33 @@ portable_check_user_in_group() {
278
}
279
280
portable_add_user() {
281
- local username="${1}"
281
+ local username="${1}" homedir="${2}"
282
+
283
+ [ -z "${homedir}" ] && homedir="/tmp"
284
285
portable_check_user_exists "${username}"
286
[ $? -eq 0 ] && echo >&2 "User '${username}' already exists." && return 0
287
286
- echo >&2 "Adding ${username} user account ..."
288
+ echo >&2 "Adding ${username} user account with home ${homedir} ..."
289
290
local nologin="$(which nologin 2>/dev/null || command -v nologin 2>/dev/null || echo '/bin/false')"
291
292
# Linux
293
if check_cmd useradd
294
then
293
- run useradd -r -g "${username}" -c "${username}" -s "${nologin}" -d / "${username}" && return 0
295
+ run useradd -r -g "${username}" -c "${username}" -s "${nologin}" --no-create-home -d "${homedir}" "${username}" && return 0
296
fi
297
298
# FreeBSD
299
if check_cmd pw
300
then
299
- run pw useradd "${username}" -d / -g "${username}" -s "${nologin}" && return 0
301
+ run pw useradd "${username}" -d "${homedir}" -g "${username}" -s "${nologin}" && return 0
302
fi
303
304
# BusyBox
305
if check_cmd adduser
306
then
305
- run adduser -D -G "${username}" "${username}" && return 0
307
+ run adduser -h "${homedir}" -s "${nologin}" -D -G "${username}" "${username}" && return 0
308
fi
309
310
echo >&2 "Failed to add ${username} user account !"
@@ -800,10 +802,12 @@ NETDATA_ADDED_TO_PROXY=0
802
NETDATA_ADDED_TO_SQUID=0
803
NETDATA_ADDED_TO_CEPH=0
804
add_netdata_user_and_group() {
805
+ local homedir="${1}"
806
+
807
if [ ${UID} -eq 0 ]
808
then
809
portable_add_group netdata || return 1
806
- portable_add_user netdata || return 1
810
+ portable_add_user netdata "${homedir}" || return 1
811
portable_add_user_to_group docker netdata && NETDATA_ADDED_TO_DOCKER=1
812
portable_add_user_to_group nginx netdata && NETDATA_ADDED_TO_NGINX=1
813
portable_add_user_to_group varnish netdata && NETDATA_ADDED_TO_VARNISH=1
makeself/install-or-update.sh
+28
-1
@@ -85,7 +85,7 @@ progress "Add user netdata to required user groups"
85
86
NETDATA_USER="root"
87
NETDATA_GROUP="root"
88
-add_netdata_user_and_group
88
+add_netdata_user_and_group "/opt/netdata"
89
if [ $? -eq 0 ]
90
then
91
NETDATA_USER="netdata"
@@ -94,6 +94,33 @@ else
94
run_failed "Failed to add netdata user and group"
95
fi
96
97
+[ ~netdata = / ] && cat <<USERMOD
98
+
99
+The netdata user has its home directory set to /
100
+You may want to change it, using this command:
101
+
102
+# usermod -m -d /opt/netdata netdata
103
+
104
+USERMOD
105
+
106
+
107
+# -----------------------------------------------------------------------------
108
+progress "Check SSL certificates paths"
109
+
110
+if [ ! -f "/etc/ssl/certs/ca-certificates.crt" ]
111
+then
112
+ if [ ! -f /opt/netdata/.curlrc ]
113
+ then
114
+ # CentOS
115
+ if [ -f "/etc/ssl/certs/ca-bundle.crt" ]
116
+ then
117
+ echo >/opt/netdata/.curlrc "cacert=/etc/ssl/certs/ca-bundle.crt"
118
+ else
119
+ run_failed "Failed to find /etc/ssl/certs/ca-certificates.crt"
120
+ fi
121
+ fi
122
+fi
123
+
124
125
# -----------------------------------------------------------------------------
126
progress "Install logrotate configuration for netdata"
netdata-installer.sh
+3
-1
@@ -642,7 +642,9 @@ run find ./system/ -type f -a \! -name \*.in -a \! -name Makefile\* -a \! -name
642
# -----------------------------------------------------------------------------
643
progress "Add user netdata to required user groups"
644
645
-add_netdata_user_and_group || run_failed "The installer does not run as root."
645
+homedir="${NETDATA_LIB_DIR}"
646
+[ ! -z "${NETDATA_PREFIX}" ] && homedir="${NETDATA_PREFIX}"
647
+add_netdata_user_and_group "${homedir}" || run_failed "The installer does not run as root."
648
649
650
# -----------------------------------------------------------------------------
plugins.d/alarm-notify.sh
+2
-2
@@ -120,7 +120,7 @@ docurl() {
120
echo >&2 "--- END curl command ---"
121
122
local out=$(mktemp /tmp/netdata-health-alarm-notify-XXXXXXXX)
123
- local code=$(${curl} --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
123
+ local code=$(${curl} --insecure --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
124
local ret=$?
125
echo >&2 "--- BEGIN received response ---"
126
cat >&2 "${out}"
@@ -132,7 +132,7 @@ docurl() {
132
return ${ret}
133
fi
134
135
- ${curl} --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
135
+ ${curl} --insecure --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
136
return $?
137
}
138