mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 10:28:22 +00:00
feat: refactored the systemd service to seperate package file
This commit is contained in:
@@ -4,91 +4,17 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"os"
|
"os"
|
||||||
"os/exec"
|
|
||||||
"os/signal"
|
"os/signal"
|
||||||
"path/filepath"
|
|
||||||
"runtime"
|
|
||||||
"syscall"
|
"syscall"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/Infisical/infisical-merge/packages/gateway"
|
"github.com/Infisical/infisical-merge/packages/gateway"
|
||||||
"github.com/Infisical/infisical-merge/packages/util"
|
"github.com/Infisical/infisical-merge/packages/util"
|
||||||
"github.com/rs/zerolog/log"
|
|
||||||
"github.com/posthog/posthog-go"
|
"github.com/posthog/posthog-go"
|
||||||
|
"github.com/rs/zerolog/log"
|
||||||
"github.com/spf13/cobra"
|
"github.com/spf13/cobra"
|
||||||
)
|
)
|
||||||
|
|
||||||
const systemdServiceTemplate = `[Unit]
|
|
||||||
Description=Infisical Gateway Service
|
|
||||||
After=network.target
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=simple
|
|
||||||
EnvironmentFile=/etc/infisical/gateway.conf
|
|
||||||
ExecStart=/usr/local/bin/infisical gateway
|
|
||||||
Restart=on-failure
|
|
||||||
InaccessibleDirectories=/home
|
|
||||||
PrivateTmp=yes
|
|
||||||
LimitCORE=infinity
|
|
||||||
LimitNOFILE=1000000
|
|
||||||
LimitNPROC=60000
|
|
||||||
LimitRTPRIO=infinity
|
|
||||||
LimitRTTIME=7000000
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=multi-user.target
|
|
||||||
`
|
|
||||||
|
|
||||||
func installSystemdService(token string, domain string) error {
|
|
||||||
if runtime.GOOS != "linux" {
|
|
||||||
log.Info().Msg("Skipping systemd service installation - not on Linux")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
if os.Geteuid() != 0 {
|
|
||||||
log.Info().Msg("Skipping systemd service installation - not running as root/sudo")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
configDir := "/etc/infisical"
|
|
||||||
if err := os.MkdirAll(configDir, 0755); err != nil {
|
|
||||||
return fmt.Errorf("failed to create config directory: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
configContent := fmt.Sprintf("INFISICAL_UNIVERSAL_AUTH_ACCESS_TOKEN=%s\n", token)
|
|
||||||
if domain != "" {
|
|
||||||
configContent += fmt.Sprintf("INFISICAL_API_URL=%s\n", domain)
|
|
||||||
} else {
|
|
||||||
configContent += "INFISICAL_API_URL=\n"
|
|
||||||
}
|
|
||||||
|
|
||||||
configPath := filepath.Join(configDir, "gateway.conf")
|
|
||||||
if err := os.WriteFile(configPath, []byte(configContent), 0600); err != nil {
|
|
||||||
return fmt.Errorf("failed to write config file: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
servicePath := "/etc/systemd/system/infisical-gateway.service"
|
|
||||||
if _, err := os.Stat(servicePath); err == nil {
|
|
||||||
log.Info().Msg("Systemd service file already exists")
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := os.WriteFile(servicePath, []byte(systemdServiceTemplate), 0644); err != nil {
|
|
||||||
return fmt.Errorf("failed to write systemd service file: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
reloadCmd := exec.Command("systemctl", "daemon-reload")
|
|
||||||
if err := reloadCmd.Run(); err != nil {
|
|
||||||
return fmt.Errorf("failed to reload systemd: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
log.Info().Msg("Successfully installed systemd service")
|
|
||||||
log.Info().Msg("To start the service, run: sudo systemctl start infisical-gateway")
|
|
||||||
log.Info().Msg("To enable the service on boot, run: sudo systemctl enable infisical-gateway")
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var gatewayCmd = &cobra.Command{
|
var gatewayCmd = &cobra.Command{
|
||||||
Example: `infisical gateway`,
|
Example: `infisical gateway`,
|
||||||
Short: "Used to infisical gateway",
|
Short: "Used to infisical gateway",
|
||||||
@@ -111,7 +37,7 @@ var gatewayCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Try to install systemd service if possible
|
// Try to install systemd service if possible
|
||||||
if err := installSystemdService(token.Token, domain); err != nil {
|
if err := gateway.InstallGatewaySystemdService(token.Token, domain); err != nil {
|
||||||
log.Warn().Msgf("Failed to install systemd service: %v", err)
|
log.Warn().Msgf("Failed to install systemd service: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,82 @@
|
|||||||
|
package gateway
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
|
"runtime"
|
||||||
|
|
||||||
|
"github.com/rs/zerolog/log"
|
||||||
|
)
|
||||||
|
|
||||||
|
const systemdServiceTemplate = `[Unit]
|
||||||
|
Description=Infisical Gateway Service
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
EnvironmentFile=/etc/infisical/gateway.conf
|
||||||
|
ExecStart=/usr/local/bin/infisical gateway
|
||||||
|
Restart=on-failure
|
||||||
|
InaccessibleDirectories=/home
|
||||||
|
PrivateTmp=yes
|
||||||
|
LimitCORE=infinity
|
||||||
|
LimitNOFILE=1000000
|
||||||
|
LimitNPROC=60000
|
||||||
|
LimitRTPRIO=infinity
|
||||||
|
LimitRTTIME=7000000
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
`
|
||||||
|
|
||||||
|
func InstallGatewaySystemdService(token string, domain string) error {
|
||||||
|
if runtime.GOOS != "linux" {
|
||||||
|
log.Info().Msg("Skipping systemd service installation - not on Linux")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
if os.Geteuid() != 0 {
|
||||||
|
log.Info().Msg("Skipping systemd service installation - not running as root/sudo")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
configDir := "/etc/infisical"
|
||||||
|
if err := os.MkdirAll(configDir, 0755); err != nil {
|
||||||
|
return fmt.Errorf("failed to create config directory: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
configContent := fmt.Sprintf("INFISICAL_UNIVERSAL_AUTH_ACCESS_TOKEN=%s\n", token)
|
||||||
|
if domain != "" {
|
||||||
|
configContent += fmt.Sprintf("INFISICAL_API_URL=%s\n", domain)
|
||||||
|
} else {
|
||||||
|
configContent += "INFISICAL_API_URL=\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
configPath := filepath.Join(configDir, "gateway.conf")
|
||||||
|
if err := os.WriteFile(configPath, []byte(configContent), 0600); err != nil {
|
||||||
|
return fmt.Errorf("failed to write config file: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
servicePath := "/etc/systemd/system/infisical-gateway.service"
|
||||||
|
if _, err := os.Stat(servicePath); err == nil {
|
||||||
|
log.Info().Msg("Systemd service file already exists")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
if err := os.WriteFile(servicePath, []byte(systemdServiceTemplate), 0644); err != nil {
|
||||||
|
return fmt.Errorf("failed to write systemd service file: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
reloadCmd := exec.Command("systemctl", "daemon-reload")
|
||||||
|
if err := reloadCmd.Run(); err != nil {
|
||||||
|
return fmt.Errorf("failed to reload systemd: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Info().Msg("Successfully installed systemd service")
|
||||||
|
log.Info().Msg("To start the service, run: sudo systemctl start infisical-gateway")
|
||||||
|
log.Info().Msg("To enable the service on boot, run: sudo systemctl enable infisical-gateway")
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user