#!/bin/sh # What https://get.unicornproxy.net serves (issue #20): # # curl -fsSL https://get.unicornproxy.net | sudo bash -s -- --env staging # # It downloads the installer and its signature and runs the installer only if the release key # below signed it; the installer then checks the agent package with the same key. CI fills in # the key when it publishes this file (release.yml); an unfilled copy refuses to run. set -eu BASE=${UPX_GET_BASE:-https://get.unicornproxy.net} tmp=$(mktemp -d) trap 'rm -rf "$tmp"' EXIT cat > "$tmp/release.pub" <<'KEY' -----BEGIN PUBLIC KEY----- MCowBQYDK2VwAyEA13Z/0E7oBdwyjAMt9kSvsAihui7irKCLpFPTPv/5eyg= -----END PUBLIC KEY----- KEY grep -q "BEGIN PUBLIC KEY" "$tmp/release.pub" || { echo "get: this copy has no release key" >&2; exit 1; } curl -fsSL "$BASE/install.sh" -o "$tmp/install.sh" curl -fsSL "$BASE/install.sh.sig" -o "$tmp/install.sh.sig" if ! openssl pkeyutl -verify -pubin -inkey "$tmp/release.pub" -rawin -in "$tmp/install.sh" \ -sigfile "$tmp/install.sh.sig" 2>/dev/null | grep -q "Signature Verified Successfully"; then echo "get: the installer isn't signed by the Unicorn Proxy release key: not running it" >&2 exit 1 fi bash "$tmp/install.sh" --base "$BASE" --release-pub "$tmp/release.pub" "$@"