-#!/bin/sh -e
-
-case $1 in
- adduser)
- echo "I would create MySQL user $2 with password $3."
- ;;
- createdb)
- echo "I would create MySQL table $2_$3 for user $2."
- ;;
- *)
- echo "Usage: domtool-mysql [adduser <user> | createdb <user> <table>]"
- ;;
-esac
+#!/bin/bash -e
+
+WHERE="'%.hcoop.net'"
+
+case $1 in
+ adduser)
+ USERNAME=$2
+ PASSWORD=$3
+
+ sudo -H mysql -e "CREATE USER '$USERNAME'@$WHERE IDENTIFIED BY '$PASSWORD';"
+ ;;
+
+ passwd)
+ USERNAME=$2
+ PASSWORD=$3
+
+ sudo -H mysql -e "SET PASSWORD FOR '$USERNAME'@$WHERE = PASSWORD('$PASSWORD');"
+ ;;
+
+ createdb)
+ USERNAME=$2
+ DBNAME_BASE=$3
+ DBNAME="${USERNAME}_${DBNAME_BASE}"
+ DIR=/afs/hcoop.net/common/databases/${USERNAME:0:1}/${USERNAME:0:2}/$USERNAME/mysql
+
+ kinit -k -t /etc/keytabs/root.admin.keytab root/admin
+ aklog
+
+ if [ ! -d $DIR ]; then
+ echo WARNING: $DIR must already exist!
+ fi
+
+ mkdir $DIR/$DBNAME
+ chown mysql:mysql $DIR/$DBNAME
+ chmod 770 $DIR/$DBNAME
+ ln -sf $DIR/$DBNAME /var/lib/mysql/$DBNAME
+ fs setacl -dir $DIR/$DBNAME/ -acl system:mysql all
+ sudo -H mysql -e "GRANT CREATE,SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE VIEW,SHOW VIEW,LOCK TABLES,GRANT OPTION ON TABLE * TO '$USERNAME'@$WHERE;" $DBNAME
+
+ sudo -H mysql -e "FLUSH PRIVILEGES;"
+ ;;
+
+ dropdb)
+ USERNAME=$2
+ DBNAME_BASE=$3
+ DBNAME="${USERNAME}_${DBNAME_BASE}"
+
+ sudo -H mysql -e "DROP DATABASE $DBNAME;"
+ ;;
+
+ grant)
+ USERNAME=$2
+ DBNAME_BASE=$3
+ DBNAME="${USERNAME}_${DBNAME_BASE}"
+
+ sudo -H mysql -e "GRANT CREATE,SELECT,INSERT,UPDATE,DELETE,INDEX,ALTER,CREATE VIEW,SHOW VIEW,LOCK TABLES,GRANT OPTION ON TABLE * TO '$USERNAME'@$WHERE;" $DBNAME
+ ;;
+
+ *)
+ echo "Usage: domtool-mysql [adduser <user> <password> | passwd <user> <password> | createdb <user> <db> | dropdb <user> <db> | grant <user> <db>]"
+ ;;
+esac