Give the mastodon user a /home/mastodon home
The mastodon user's home was /opt/mastodon, i.e. the clone destination, so writing the SSH deploy key into ~/.ssh made the directory non-empty and Chef's git resource silently skipped cloning (it only clones into an empty directory). Use a dedicated /home/mastodon home for the user and keep the clone destination separate. Also clear a non-git (partial) clone destination before cloning.
This commit is contained in:
3 files changed
+28
-12
No files matched your search
@@ -13,6 +13,7 @@ postgresql_credentials = data_bag_item('credentials', 'postgresql')
|
||||
|
||||
mastodon_path = node["kosmos-mastodon"]["directory"]
|
||||
mastodon_user = "mastodon"
|
||||
mastodon_home = "/home/#{mastodon_user}"
|
||||
|
||||
ruby_version = node["kosmos-mastodon"]["ruby_version"]
|
||||
ruby_path = "/opt/ruby_build/builds/#{ruby_version}"
|
||||
@@ -32,7 +33,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production
|
||||
deploy_env = {
|
||||
# FIXME: /usr/bin was missing from PATH when running `yarn install`
|
||||
"PATH" => "#{ruby_path}/bin:/usr/bin:$PATH",
|
||||
"HOME" => mastodon_path,
|
||||
"HOME" => mastodon_home,
|
||||
"RAILS_ENV" => rails_env,
|
||||
"NODE_ENV" => rails_env,
|
||||
"COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0"
|
||||
@@ -44,14 +45,15 @@ build_uptodate = "test -f #{mastodon_path}/tmp/built-revision && " \
|
||||
|
||||
credentials = data_bag_item('credentials', 'mastodon')
|
||||
|
||||
# The repository is private; clone it with a read-only SSH deploy key.
|
||||
directory "#{mastodon_path}/.ssh" do
|
||||
# The repository is private; clone it with a read-only SSH deploy key kept in
|
||||
# the mastodon user's home (outside the clone destination).
|
||||
directory "#{mastodon_home}/.ssh" do
|
||||
owner mastodon_user
|
||||
group mastodon_user
|
||||
mode "0700"
|
||||
end
|
||||
|
||||
file "#{mastodon_path}/.ssh/id_ed25519" do
|
||||
file "#{mastodon_home}/.ssh/id_ed25519" do
|
||||
# OpenSSH's PEM parser rejects a private key without a trailing newline
|
||||
content lazy { credentials["repo_deploy_key"].to_s.chomp + "\n" }
|
||||
owner mastodon_user
|
||||
@@ -60,26 +62,33 @@ file "#{mastodon_path}/.ssh/id_ed25519" do
|
||||
sensitive true
|
||||
end
|
||||
|
||||
file "#{mastodon_path}/.ssh/known_hosts" do
|
||||
file "#{mastodon_home}/.ssh/known_hosts" do
|
||||
content "#{node['kosmos-mastodon']['gitea_ssh_host_key']}\n"
|
||||
owner mastodon_user
|
||||
group mastodon_user
|
||||
mode "0644"
|
||||
end
|
||||
|
||||
file "#{mastodon_path}/.ssh/config" do
|
||||
file "#{mastodon_home}/.ssh/config" do
|
||||
content <<-EOF
|
||||
Host gitea.kosmos.org
|
||||
IdentityFile #{mastodon_path}/.ssh/id_ed25519
|
||||
IdentityFile #{mastodon_home}/.ssh/id_ed25519
|
||||
IdentitiesOnly yes
|
||||
StrictHostKeyChecking yes
|
||||
UserKnownHostsFile #{mastodon_path}/.ssh/known_hosts
|
||||
UserKnownHostsFile #{mastodon_home}/.ssh/known_hosts
|
||||
EOF
|
||||
owner mastodon_user
|
||||
group mastodon_user
|
||||
mode "0600"
|
||||
end
|
||||
|
||||
# Chef's git resource silently skips cloning when the destination is non-empty
|
||||
# and not a git clone, so make sure we start from a clean directory.
|
||||
execute "clear non-git repository directory" do
|
||||
command "find #{mastodon_path} -mindepth 1 -delete"
|
||||
only_if { ::Dir.exist?(mastodon_path) && !::File.exist?("#{mastodon_path}/.git") }
|
||||
end
|
||||
|
||||
git mastodon_path do
|
||||
user mastodon_user
|
||||
group mastodon_user
|
||||
@@ -87,8 +96,8 @@ git mastodon_path do
|
||||
repository node["kosmos-mastodon"]["repo"]
|
||||
revision node["kosmos-mastodon"]["revision"]
|
||||
environment "GIT_SSH_COMMAND" =>
|
||||
"ssh -i #{mastodon_path}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \
|
||||
"-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_path}/.ssh/known_hosts"
|
||||
"ssh -i #{mastodon_home}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \
|
||||
"-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_home}/.ssh/known_hosts"
|
||||
end
|
||||
|
||||
ldap_config = {
|
||||
|
||||
@@ -49,6 +49,7 @@ elasticsearch_service 'elasticsearch'
|
||||
|
||||
mastodon_path = node["kosmos-mastodon"]["directory"]
|
||||
mastodon_user = "mastodon"
|
||||
mastodon_home = "/home/#{mastodon_user}"
|
||||
|
||||
group mastodon_user do
|
||||
gid 62786
|
||||
@@ -59,7 +60,13 @@ user mastodon_user do
|
||||
uid 62786
|
||||
gid 62786
|
||||
shell "/bin/bash"
|
||||
home mastodon_path
|
||||
home mastodon_home
|
||||
end
|
||||
|
||||
directory mastodon_home do
|
||||
owner mastodon_user
|
||||
group mastodon_user
|
||||
mode "0755"
|
||||
end
|
||||
|
||||
directory mastodon_path do
|
||||
|
||||
@@ -24,7 +24,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production
|
||||
deploy_env = {
|
||||
# FIXME: /usr/bin was missing from PATH when running `yarn install`
|
||||
"PATH" => "#{ruby_path}/bin:/usr/bin:$PATH",
|
||||
"HOME" => mastodon_path,
|
||||
"HOME" => "/home/#{mastodon_user}",
|
||||
"RAILS_ENV" => rails_env,
|
||||
"NODE_ENV" => rails_env,
|
||||
"COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0"
|
||||
|
||||
Reference in new issue
Block a user