From 1b564c285d7b6f6381ffed929bae7320c435cc49 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A2u=20Cao?= Date: Thu, 8 Oct 2026 11:43:47 +0200 Subject: [PATCH] Give the mastodon user a /home/mastodon home The mastodon user's home was /opt/mastodon, i.e. the clone destination, so writing the SSH deploy key into ~/.ssh made the directory non-empty and Chef's git resource silently skipped cloning (it only clones into an empty directory). Use a dedicated /home/mastodon home for the user and keep the clone destination separate. Also clear a non-git (partial) clone destination before cloning. --- .../kosmos-mastodon/recipes/build.rb | 29 ++++++++++++------- .../kosmos-mastodon/recipes/dependencies.rb | 9 +++++- .../kosmos-mastodon/recipes/deploy.rb | 2 +- 3 files changed, 28 insertions(+), 12 deletions(-) diff --git a/site-cookbooks/kosmos-mastodon/recipes/build.rb b/site-cookbooks/kosmos-mastodon/recipes/build.rb index 2ed880f..ea369e0 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/build.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/build.rb @@ -13,6 +13,7 @@ postgresql_credentials = data_bag_item('credentials', 'postgresql') mastodon_path = node["kosmos-mastodon"]["directory"] mastodon_user = "mastodon" +mastodon_home = "/home/#{mastodon_user}" ruby_version = node["kosmos-mastodon"]["ruby_version"] ruby_path = "/opt/ruby_build/builds/#{ruby_version}" @@ -32,7 +33,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production deploy_env = { # FIXME: /usr/bin was missing from PATH when running `yarn install` "PATH" => "#{ruby_path}/bin:/usr/bin:$PATH", - "HOME" => mastodon_path, + "HOME" => mastodon_home, "RAILS_ENV" => rails_env, "NODE_ENV" => rails_env, "COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0" @@ -44,14 +45,15 @@ build_uptodate = "test -f #{mastodon_path}/tmp/built-revision && " \ credentials = data_bag_item('credentials', 'mastodon') -# The repository is private; clone it with a read-only SSH deploy key. -directory "#{mastodon_path}/.ssh" do +# The repository is private; clone it with a read-only SSH deploy key kept in +# the mastodon user's home (outside the clone destination). +directory "#{mastodon_home}/.ssh" do owner mastodon_user group mastodon_user mode "0700" end -file "#{mastodon_path}/.ssh/id_ed25519" do +file "#{mastodon_home}/.ssh/id_ed25519" do # OpenSSH's PEM parser rejects a private key without a trailing newline content lazy { credentials["repo_deploy_key"].to_s.chomp + "\n" } owner mastodon_user @@ -60,26 +62,33 @@ file "#{mastodon_path}/.ssh/id_ed25519" do sensitive true end -file "#{mastodon_path}/.ssh/known_hosts" do +file "#{mastodon_home}/.ssh/known_hosts" do content "#{node['kosmos-mastodon']['gitea_ssh_host_key']}\n" owner mastodon_user group mastodon_user mode "0644" end -file "#{mastodon_path}/.ssh/config" do +file "#{mastodon_home}/.ssh/config" do content <<-EOF Host gitea.kosmos.org - IdentityFile #{mastodon_path}/.ssh/id_ed25519 + IdentityFile #{mastodon_home}/.ssh/id_ed25519 IdentitiesOnly yes StrictHostKeyChecking yes - UserKnownHostsFile #{mastodon_path}/.ssh/known_hosts + UserKnownHostsFile #{mastodon_home}/.ssh/known_hosts EOF owner mastodon_user group mastodon_user mode "0600" end +# Chef's git resource silently skips cloning when the destination is non-empty +# and not a git clone, so make sure we start from a clean directory. +execute "clear non-git repository directory" do + command "find #{mastodon_path} -mindepth 1 -delete" + only_if { ::Dir.exist?(mastodon_path) && !::File.exist?("#{mastodon_path}/.git") } +end + git mastodon_path do user mastodon_user group mastodon_user @@ -87,8 +96,8 @@ git mastodon_path do repository node["kosmos-mastodon"]["repo"] revision node["kosmos-mastodon"]["revision"] environment "GIT_SSH_COMMAND" => - "ssh -i #{mastodon_path}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \ - "-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_path}/.ssh/known_hosts" + "ssh -i #{mastodon_home}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \ + "-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_home}/.ssh/known_hosts" end ldap_config = { diff --git a/site-cookbooks/kosmos-mastodon/recipes/dependencies.rb b/site-cookbooks/kosmos-mastodon/recipes/dependencies.rb index 22ff78e..a71f1cd 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/dependencies.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/dependencies.rb @@ -49,6 +49,7 @@ elasticsearch_service 'elasticsearch' mastodon_path = node["kosmos-mastodon"]["directory"] mastodon_user = "mastodon" +mastodon_home = "/home/#{mastodon_user}" group mastodon_user do gid 62786 @@ -59,7 +60,13 @@ user mastodon_user do uid 62786 gid 62786 shell "/bin/bash" - home mastodon_path + home mastodon_home +end + +directory mastodon_home do + owner mastodon_user + group mastodon_user + mode "0755" end directory mastodon_path do diff --git a/site-cookbooks/kosmos-mastodon/recipes/deploy.rb b/site-cookbooks/kosmos-mastodon/recipes/deploy.rb index b0d4fed..8346257 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/deploy.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/deploy.rb @@ -24,7 +24,7 @@ rails_env = node.chef_environment == "development" ? "development" : "production deploy_env = { # FIXME: /usr/bin was missing from PATH when running `yarn install` "PATH" => "#{ruby_path}/bin:/usr/bin:$PATH", - "HOME" => mastodon_path, + "HOME" => "/home/#{mastodon_user}", "RAILS_ENV" => rails_env, "NODE_ENV" => rails_env, "COREPACK_ENABLE_DOWNLOAD_PROMPT" => "0"