Give the mastodon user a /home/mastodon home

The mastodon user's home was /opt/mastodon, i.e. the clone destination, so writing the SSH deploy key into ~/.ssh made the directory non-empty and Chef's git resource silently skipped cloning (it only clones into an empty directory). Use a dedicated /home/mastodon home for the user and keep the clone destination separate. Also clear a non-git (partial) clone destination before cloning.
This commit is contained in:
raucao committed 2026-10-08 11:43:47 +02:00
1 parent 0696d03374
commit 1b564c285d
3 files changed
+28 -12

No files matched your search

+19 -10
View File
@@ -13,6 +13,7 @@ postgresql_credentials = data_bag_item('credentials', 'postgresql')
mastodon_path = node["kosmos-mastodon"]["directory"]
mastodon_user = "mastodon"
mastodon_home = "/home/#{mastodon_user}"
ruby_version = node["kosmos-mastodon"]["ruby_version"]
ruby_path = "/opt/ruby_build/builds/#{ruby_version}"
@@ -32,7 +33,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production
deploy_env = {
# FIXME: /usr/bin was missing from PATH when running `yarn install`
"PATH" => "#{ruby_path}/bin:/usr/bin:$PATH",
"HOME" => mastodon_path,
"HOME" => mastodon_home,
"RAILS_ENV" => rails_env,
"NODE_ENV" => rails_env,
"COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0"
@@ -44,14 +45,15 @@ build_uptodate = "test -f #{mastodon_path}/tmp/built-revision && " \
credentials = data_bag_item('credentials', 'mastodon')
# The repository is private; clone it with a read-only SSH deploy key.
directory "#{mastodon_path}/.ssh" do
# The repository is private; clone it with a read-only SSH deploy key kept in
# the mastodon user's home (outside the clone destination).
directory "#{mastodon_home}/.ssh" do
owner mastodon_user
group mastodon_user
mode "0700"
end
file "#{mastodon_path}/.ssh/id_ed25519" do
file "#{mastodon_home}/.ssh/id_ed25519" do
# OpenSSH's PEM parser rejects a private key without a trailing newline
content lazy { credentials["repo_deploy_key"].to_s.chomp + "\n" }
owner mastodon_user
@@ -60,26 +62,33 @@ file "#{mastodon_path}/.ssh/id_ed25519" do
sensitive true
end
file "#{mastodon_path}/.ssh/known_hosts" do
file "#{mastodon_home}/.ssh/known_hosts" do
content "#{node['kosmos-mastodon']['gitea_ssh_host_key']}\n"
owner mastodon_user
group mastodon_user
mode "0644"
end
file "#{mastodon_path}/.ssh/config" do
file "#{mastodon_home}/.ssh/config" do
content <<-EOF
Host gitea.kosmos.org
IdentityFile #{mastodon_path}/.ssh/id_ed25519
IdentityFile #{mastodon_home}/.ssh/id_ed25519
IdentitiesOnly yes
StrictHostKeyChecking yes
UserKnownHostsFile #{mastodon_path}/.ssh/known_hosts
UserKnownHostsFile #{mastodon_home}/.ssh/known_hosts
EOF
owner mastodon_user
group mastodon_user
mode "0600"
end
# Chef's git resource silently skips cloning when the destination is non-empty
# and not a git clone, so make sure we start from a clean directory.
execute "clear non-git repository directory" do
command "find #{mastodon_path} -mindepth 1 -delete"
only_if { ::Dir.exist?(mastodon_path) && !::File.exist?("#{mastodon_path}/.git") }
end
git mastodon_path do
user mastodon_user
group mastodon_user
@@ -87,8 +96,8 @@ git mastodon_path do
repository node["kosmos-mastodon"]["repo"]
revision node["kosmos-mastodon"]["revision"]
environment "GIT_SSH_COMMAND" =>
"ssh -i #{mastodon_path}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \
"-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_path}/.ssh/known_hosts"
"ssh -i #{mastodon_home}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \
"-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_home}/.ssh/known_hosts"
end
ldap_config = {
@@ -49,6 +49,7 @@ elasticsearch_service 'elasticsearch'
mastodon_path = node["kosmos-mastodon"]["directory"]
mastodon_user = "mastodon"
mastodon_home = "/home/#{mastodon_user}"
group mastodon_user do
gid 62786
@@ -59,7 +60,13 @@ user mastodon_user do
uid 62786
gid 62786
shell "/bin/bash"
home mastodon_path
home mastodon_home
end
directory mastodon_home do
owner mastodon_user
group mastodon_user
mode "0755"
end
directory mastodon_path do
@@ -24,7 +24,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production
deploy_env = {
# FIXME: /usr/bin was missing from PATH when running `yarn install`
"PATH" => "#{ruby_path}/bin:/usr/bin:$PATH",
"HOME" => mastodon_path,
"HOME" => "/home/#{mastodon_user}",
"RAILS_ENV" => rails_env,
"NODE_ENV" => rails_env,
"COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0"