@cryptotaxi247 / netdata-1 / commits / c9aeb5567

set netdata user home directory; do not validate certs when sending alarms; attempt to detect ssl certs on static installations; fixes #3489

Costa Tsaousis (ktsaou) committed Mar 1, 2018 at 00:23 UTC c9aeb55675730000418262a691add94f235a40ec
4 files changed +43 -10
installer/functions.sh
+10 -6
@@ -278,31 +278,33 @@ portable_check_user_in_group() {
278 }
279
280 portable_add_user() {
281 - local username="${1}"
281 + local username="${1}" homedir="${2}"
282 +
283 + [ -z "${homedir}" ] && homedir="/tmp"
284
285 portable_check_user_exists "${username}"
286 [ $? -eq 0 ] && echo >&2 "User '${username}' already exists." && return 0
287
286 - echo >&2 "Adding ${username} user account ..."
288 + echo >&2 "Adding ${username} user account with home ${homedir} ..."
289
290 local nologin="$(which nologin 2>/dev/null || command -v nologin 2>/dev/null || echo '/bin/false')"
291
292 # Linux
293 if check_cmd useradd
294 then
293 - run useradd -r -g "${username}" -c "${username}" -s "${nologin}" -d / "${username}" && return 0
295 + run useradd -r -g "${username}" -c "${username}" -s "${nologin}" --no-create-home -d "${homedir}" "${username}" && return 0
296 fi
297
298 # FreeBSD
299 if check_cmd pw
300 then
299 - run pw useradd "${username}" -d / -g "${username}" -s "${nologin}" && return 0
301 + run pw useradd "${username}" -d "${homedir}" -g "${username}" -s "${nologin}" && return 0
302 fi
303
304 # BusyBox
305 if check_cmd adduser
306 then
305 - run adduser -D -G "${username}" "${username}" && return 0
307 + run adduser -h "${homedir}" -s "${nologin}" -D -G "${username}" "${username}" && return 0
308 fi
309
310 echo >&2 "Failed to add ${username} user account !"
@@ -800,10 +802,12 @@ NETDATA_ADDED_TO_PROXY=0
802 NETDATA_ADDED_TO_SQUID=0
803 NETDATA_ADDED_TO_CEPH=0
804 add_netdata_user_and_group() {
805 + local homedir="${1}"
806 +
807 if [ ${UID} -eq 0 ]
808 then
809 portable_add_group netdata || return 1
806 - portable_add_user netdata || return 1
810 + portable_add_user netdata "${homedir}" || return 1
811 portable_add_user_to_group docker netdata && NETDATA_ADDED_TO_DOCKER=1
812 portable_add_user_to_group nginx netdata && NETDATA_ADDED_TO_NGINX=1
813 portable_add_user_to_group varnish netdata && NETDATA_ADDED_TO_VARNISH=1
makeself/install-or-update.sh
+28 -1
@@ -85,7 +85,7 @@ progress "Add user netdata to required user groups"
85
86 NETDATA_USER="root"
87 NETDATA_GROUP="root"
88 -add_netdata_user_and_group
88 +add_netdata_user_and_group "/opt/netdata"
89 if [ $? -eq 0 ]
90 then
91 NETDATA_USER="netdata"
@@ -94,6 +94,33 @@ else
94 run_failed "Failed to add netdata user and group"
95 fi
96
97 +[ ~netdata = / ] && cat <<USERMOD
98 +
99 +The netdata user has its home directory set to /
100 +You may want to change it, using this command:
101 +
102 +# usermod -m -d /opt/netdata netdata
103 +
104 +USERMOD
105 +
106 +
107 +# -----------------------------------------------------------------------------
108 +progress "Check SSL certificates paths"
109 +
110 +if [ ! -f "/etc/ssl/certs/ca-certificates.crt" ]
111 +then
112 + if [ ! -f /opt/netdata/.curlrc ]
113 + then
114 + # CentOS
115 + if [ -f "/etc/ssl/certs/ca-bundle.crt" ]
116 + then
117 + echo >/opt/netdata/.curlrc "cacert=/etc/ssl/certs/ca-bundle.crt"
118 + else
119 + run_failed "Failed to find /etc/ssl/certs/ca-certificates.crt"
120 + fi
121 + fi
122 +fi
123 +
124
125 # -----------------------------------------------------------------------------
126 progress "Install logrotate configuration for netdata"
netdata-installer.sh
+3 -1
@@ -642,7 +642,9 @@ run find ./system/ -type f -a \! -name \*.in -a \! -name Makefile\* -a \! -name
642 # -----------------------------------------------------------------------------
643 progress "Add user netdata to required user groups"
644
645 -add_netdata_user_and_group || run_failed "The installer does not run as root."
645 +homedir="${NETDATA_LIB_DIR}"
646 +[ ! -z "${NETDATA_PREFIX}" ] && homedir="${NETDATA_PREFIX}"
647 +add_netdata_user_and_group "${homedir}" || run_failed "The installer does not run as root."
648
649
650 # -----------------------------------------------------------------------------
plugins.d/alarm-notify.sh
+2 -2
@@ -120,7 +120,7 @@ docurl() {
120 echo >&2 "--- END curl command ---"
121
122 local out=$(mktemp /tmp/netdata-health-alarm-notify-XXXXXXXX)
123 - local code=$(${curl} --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
123 + local code=$(${curl} --insecure --write-out %{http_code} --output "${out}" --silent --show-error "${@}")
124 local ret=$?
125 echo >&2 "--- BEGIN received response ---"
126 cat >&2 "${out}"
@@ -132,7 +132,7 @@ docurl() {
132 return ${ret}
133 fi
134
135 - ${curl} --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
135 + ${curl} --insecure --write-out %{http_code} --output /dev/null --silent --show-error "${@}"
136 return $?
137 }
138