changes for buster linode
[distro-setup] / rootsshsync
1 #!/bin/bash
2 # Copyright (C) 2016 Ian Kelling
3
4 # Licensed under the Apache License, Version 2.0 (the "License");
5 # you may not use this file except in compliance with the License.
6 # You may obtain a copy of the License at
7
8 # http://www.apache.org/licenses/LICENSE-2.0
9
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS,
12 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 # See the License for the specific language governing permissions and
14 # limitations under the License.
15
16 set -eE -o pipefail
17 trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR
18
19 [[ $EUID == 0 ]] || exec sudo -E "${BASH_SOURCE[0]}" "$@"
20
21 dest=/root/.ssh
22
23 # leftover
24 if [[ -L $dest ]]; then
25 rm $dest
26 fi
27 mkdir -p $dest
28 chmod 700 $dest
29
30 user=$(id -un)
31 if [[ $SUDO_USER ]]; then
32 user=$SUDO_USER
33 fi
34
35 user_ssh_dir=$(eval echo ~$user)/.ssh
36
37 # remove broken links, or else rsync has error about them.
38 find $user_ssh_dir -xtype l -exec rm '{}' \;
39 # -t times, so it won't rewrite the file every time,
40 # -L resolve links
41 rsync -rtL --delete $user_ssh_dir/ $dest
42 chown -R root:root /root/.ssh
43
44
45 d=/etc/initramfs-tools
46 if [[ -e $d ]] && ! diff -q /root/.ssh/authorized_keys $d/root/.ssh/authorized_keys &>/dev/null; then
47 mkdir -p $d/root/.ssh /etc/dropbear-initramfs
48 chmod 700 $d/root $d/root/.ssh
49 cp -p /root/.ssh/authorized_keys $d/root/.ssh/authorized_keys
50 cp -p /root/.ssh/authorized_keys /etc/dropbear-initramfs
51 update-initramfs -u -k all
52 fi