From 5ed24e7835428a1cd5160d985775580cb52b5dd8 Mon Sep 17 00:00:00 2001 From: samuel Date: Fri, 28 Aug 2026 13:03:39 +0200 Subject: [PATCH] feat: adapt on nginx versionning --- Makefile | 13 +++++++++---- README.md | 10 +++++----- files/nginx/0_security.conf | 22 +++++++++++----------- netoik-rp.spec | 36 ++++++++++++++++++++++++++++-------- 4 files changed, 53 insertions(+), 28 deletions(-) diff --git a/Makefile b/Makefile index 2576043..e6f7b7f 100644 --- a/Makefile +++ b/Makefile @@ -1,12 +1,13 @@ NAME = netoik-rp -VERSION = $(shell git describe --abbrev=0) -RELEASE = $(shell git rev-parse --short HEAD) +EPOCH = $(shell git describe --abbrev=0 | cut --delimiter=/ --fields=1) +VERSION = $(shell git describe --abbrev=0 | cut --delimiter=/ --fields=2 | cut --delimiter=- --fields=1) +RELEASE = $(shell git describe --abbrev=0 | cut --delimiter=/ --fields=2 | cut --delimiter=- --fields=2) ARCH = noarch OWNER = netoik SUMMARY = "Netoïk Reverse Proxy" LICENSE = "MIT" URL = "https://git.netoik.io/$(OWNER)/$(NAME)" -SOURCE0 = "$(NAME)-$(VERSION)-$(RELEASE).tar.gz" +SOURCE0 = "$(NAME)-$(EPOCH)-$(VERSION)-$(RELEASE).tar.gz" RPM_RPMDIR = $(shell rpm --eval '%{_rpmdir}') RPM_SBINDIR = $(shell rpm --eval '%{_sbindir}') @@ -25,6 +26,10 @@ help: name: ## Show project name @echo "$(NAME)" +.PHONY: epoch +epoch: ## Show project epoch + @echo "$(EPOCH)" + .PHONY: version version: ## Show current project version @echo "$(VERSION)" @@ -57,7 +62,7 @@ url: ## Show project homepage URL source0: ## Show rpm source0 file name @echo "$(SOURCE0)" -$(RPM_TARBALL_PATH): * +$(RPM_TARBALL_PATH): git archive --format=tar.gz \ --output="$@" \ --prefix="$(NAME)-$(VERSION)/" \ diff --git a/README.md b/README.md index abf48ef..91eb4a2 100644 --- a/README.md +++ b/README.md @@ -11,7 +11,7 @@ Build an RPM package which will install several tools. - `Certbot` certificates with: - ovh configuration to renew certs - a command tool certbot_renew - - a systemctl certbot renew timer + - a systemctl Certbot renew timer # Development @@ -32,7 +32,7 @@ A `Makefile` is integrated to let you run some basic commands. make tarball ``` -- Build an rpm package: +- Build a rpm package: ```shell rpmbuild -ba netoik-rp.spec ``` @@ -75,10 +75,10 @@ Some commands to deploy the RPM package on server dnf search --showduplicates netoik-rp ``` -- Create certbot ovh credentials here: +- Create Certbot ovh credentials here: [www.ovh.com/auth/api/createToken](https://www.ovh.com/auth/api/createToken) -- Setup environemnt file (fill values): +- Setup environment file (fill values): ```shell cat > ~/.netoik-rp.env << EOF OVH_ENDPOINT="" @@ -98,7 +98,7 @@ Some commands to deploy the RPM package on server set +a ``` -- Install or upgrade without certbot (for testing environment) +- Install or upgrade without Certbot (for testing environment) ```shell SKIP_CERTBOT=true dnf --nogpgcheck --refresh --assumeyes --best install netoik-rp ``` diff --git a/files/nginx/0_security.conf b/files/nginx/0_security.conf index 7d04bfb..26b8fbe 100644 --- a/files/nginx/0_security.conf +++ b/files/nginx/0_security.conf @@ -16,15 +16,15 @@ resolver 127.0.0.1; # see: https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html # And Nextcloud doc # see: https://docs.nextcloud.com/server/31/admin_manual/installation/harden_server.html -add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload;" always; -add_header X-Frame-Options "sameorigin" always; -add_header X-XSS-Protection "1;mode=block" always; -add_header X-Content-Type-Options "nosniff" always; -add_header X-Permitted-Cross-Domain-Policies "none" always; -add_header Referrer-Policy "strict-origin-when-cross-origin" always; +add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload;" always; +add_header X-Frame-Options "sameorigin" always; +add_header X-XSS-Protection "1;mode=block" always; +add_header X-Content-Type-Options "nosniff" always; +add_header X-Permitted-Cross-Domain-Policies "none" always; +add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Content-Security-Policy "default-src 'self' 'unsafe-inline' data:; frame-ancestors 'self'; form-action 'self';" always; -add_header Cross-Origin-Opener-Policy "same-origin" always; -add_header Cross-Origin-Resource-Policy "same-site" always; -add_header Permissions-Policy "geolocation=(), camera=(), microphone=()" always; -add_header Server "webserver" always; -add_header X-Robots-Tag "noindex, nofollow" always; +add_header Cross-Origin-Opener-Policy "same-origin" always; +add_header Cross-Origin-Resource-Policy "same-site" always; +add_header Permissions-Policy "geolocation=(), camera=(), microphone=()" always; +add_header Server "webserver" always; +add_header X-Robots-Tag "noindex, nofollow" always; diff --git a/netoik-rp.spec b/netoik-rp.spec index ac23c7d..ebf6118 100644 --- a/netoik-rp.spec +++ b/netoik-rp.spec @@ -1,8 +1,10 @@ %define debug_package %{nil} Name: %(make name) +Epoch: %(make epoch) Version: %(make version) -Release: %(make release) +Release: %(make release)%{?dist} + Summary: %(make summary) License: %(make license) URL: %(make url) @@ -10,7 +12,13 @@ URL: %(make url) Source0: %(make source0) Buildarch: %(make arch) BuildRequires: make -Requires: nginx python3 python-devel (augeas-devel or augeas-libs) gcc openssl + +Requires: nginx = %{epoch}:%{version}-%{release} +Requires: python3 +Requires: python-devel +Requires: (augeas-devel or augeas-libs) +Requires: gcc +Requires: openssl %description Install the reverse proxy called nginx with a predefined configuration and with TLS certificates attached to netoik.io @@ -45,12 +53,24 @@ if [ -z $SKIP_CERTBOT ]; then # Create certbot certificates if ! certbot certificates --cert-name netoik.io | grep --quiet netoik.io; then - certbot certonly --cert-name netoik.io --non-interactive --agree-tos --email samuel.campos@netoik.io --dns-ovh --dns-ovh-credentials %{_sysconfdir}/certbot/ovh.ini -d *.netoik.io -d *.samuel-campos.fr + certbot certonly --cert-name netoik.io \ + --non-interactive \ + --agree-tos \ + --email samuel.campos@netoik.io \ + --dns-ovh --dns-ovh-credentials %{_sysconfdir}/certbot/ovh.ini \ + -d *.netoik.io \ + -d *.samuel-campos.fr fi else # Skipping certbot, so create self-signed certificate mkdir --parents /etc/letsencrypt/live/netoik.io - openssl req -newkey rsa:4096 -nodes -keyout /etc/letsencrypt/live/netoik.io/privkey.pem -x509 -days 365 -out /etc/letsencrypt/live/netoik.io/fullchain.pem -subj "/C=US/ST=State/L=City/O=Organization/OU=Department/CN=netoik.io" + openssl req -newkey rsa:4096 \ + -nodes \ + -keyout /etc/letsencrypt/live/netoik.io/privkey.pem \ + -x509 \ + -days 365 \ + -out /etc/letsencrypt/live/netoik.io/fullchain.pem \ + -subj "/C=US/ST=State/L=City/O=Organization/OU=Department/CN=netoik.io" fi # Create ssl dh params if not already exists @@ -66,14 +86,14 @@ systemctl restart nginx.service certbot-renew.timer %postun # Remove folders after uninstall if [ $1 == 0 ]; then - /opt/certbot/bin/certbot delete --cert-name netoik.io --non-interactive + /opt/certbot/bin/certbot delete --cert-name netoik.io --non-interactive rm --recursive --force /opt/certbot - rm --recursive --force %{_sysconfdir}/certbot + rm --recursive --force %{_sysconfdir}/certbot fi %files -%attr(644, root, root) %{_sysconfdir}/nginx/conf.d/0_security.conf -%attr(644, root, root) %{_sysconfdir}/nginx/conf.d/z_default.conf +%config %attr(644, root, root) %{_sysconfdir}/nginx/conf.d/0_security.conf +%config %attr(644, root, root) %{_sysconfdir}/nginx/conf.d/z_default.conf %attr(755, root, root) %dir %{_sysconfdir}/certbot %attr(600, root, root) %{_sysconfdir}/certbot/ovh.ini