sync

Backup service to store encrypted wallet databases (experimental)
Log | Files | Refs | Submodules | README | LICENSE

README-packaging.md (2215B)


      1 This file contains some notes about packaging.
      2 
      3 ## Systemd Units
      4 
      5 The main units are sync-httpd2.service and sync-httpd2.socket.
      6 
      7 The socket unit listens on `/run/sync/httpd/sync-httpd2.sock`, owned by the
      8 `sync-httpd` system user with group `www-data` and mode 0660, so that the
      9 Web server (Apache or Nginx) can connect to the backend through the socket.
     10 
     11 The service unit runs `/usr/bin/sync-httpd2 -c /etc/sync/sync.conf`.
     12 The service is socket-activated: enable (or start) the socket and the
     13 service will be pulled in on the first connection.  The service is
     14 restarted on exit (unless it exits with status 9, which is used to
     15 indicate a configuration error).
     16 
     17 The database connection is configured through
     18 `/etc/sync/secrets/sync-db.secret.conf`, referenced from
     19 `/etc/sync/sync.conf` via `@inline-secret@`.  The file is root-owned with
     20 mode 640 (set via dpkg-statoverride) so the `sync-httpd` user can read it
     21 while other users cannot.  Use `sync-dbconfig` to create the database
     22 and prepare the configuration:
     23 
     24     # sync-dbconfig -c /etc/sync/sync.conf
     25 
     26 ## libmicrohttpd2
     27 
     28 sync-httpd2 is built against GNU libmicrohttpd 2.x (the MHD2 API), which
     29 Debian does not (yet) package.  The CI containers build it from source
     30 (see contrib/ci/Containerfile, pinned to a revision of
     31 git.gnunet.org/libmicrohttpd2), so there is deliberately no
     32 `libmicrohttpd2-dev` in Build-Depends.  The resulting binary needs the
     33 libmicrohttpd2 shared library at runtime (`libgnutls30` is declared
     34 because MHD2 links GnuTLS); make sure the target system provides it.
     35 
     36 ## Web Server Integration
     37 
     38 The package installs ready-made configuration fragments for both Apache
     39 and Nginx that proxy the `/sync/` path to the Unix socket (see
     40 `/etc/apache2/sites-available/sync.conf` and
     41 `/etc/nginx/sites-available/sync`).  Only one of the two should be
     42 enabled, adjust them to your site, and terminate TLS in the Web server.
     43 
     44 ## Database
     45 
     46 The PostgreSQL database is created with `sync-dbinit` (run via
     47 `sync-dbconfig`).  The SQL schema files are installed under
     48 `/usr/share/sync/sql/`.  Note that the schema version is tracked in the
     49 `versioning.sql` file; do not run `sync-dbinit` from a different version
     50 of the package than the one installed.