Add Redis password to akkounts, liquor cabinet

This commit is contained in:
raucao committed 2026-10-06 17:22:09 +02:00
1 parent df36aff732
commit 9c7f5cee21
8 files changed
+20 -6

No files matched your search

+3 -3
View File
@@ -1,9 +1,9 @@
{
"id": "redis",
"password": {
"encrypted_data": "M2Cr7oNhL735D3coHnMc9yLuUzYlhkl+TfyMx1ccplFOyVZ+fXRF9UdDqxJ2\nyFIDJ+Yg\n",
"iv": "nEQz0SCUuFAEmxMd\n",
"auth_tag": "uuwSJdMZfLcRs7yjVrRlAQ==\n",
"encrypted_data": "vboNGwFD8JtX4d6Y6lTN4L/BXy1K1GWziX5S28Pm2/anH6Zydyjh3dvlmz1F\nXgddVQ==\n",
"iv": "5YH4k07V3t6dDajR\n",
"auth_tag": "k8ISunt4kgQ/WDB9aPS8kg==\n",
"version": 3,
"cipher": "aes-256-gcm"
}
@@ -1,5 +1,9 @@
# kosmos-akkounts CHANGELOG
# 0.4.0
- Add Redis password support to the remoteStorage Redis URL.
# 0.1.0
Initial release.
+1 -1
View File
@@ -4,7 +4,7 @@ maintainer_email 'mail@kosmos.org'
license 'MIT'
description 'Installs/configures kosmos-akkounts'
long_description 'Installs/configures kosmos-akkounts'
version '0.3.0'
version '0.4.0'
chef_version '>= 18.0'
depends 'kosmos_openresty'
@@ -3,6 +3,7 @@
# Recipe:: default
#
require 'ipaddr'
require 'uri'
app_name = "akkounts"
deploy_user = "deploy"
@@ -10,6 +11,7 @@ deploy_group = "deploy"
deploy_path = "/opt/#{app_name}"
credentials = Chef::EncryptedDataBagItem.load('credentials', app_name)
smtp_credentials = Chef::EncryptedDataBagItem.load('credentials', 'smtp')
redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis')
group deploy_group
@@ -210,7 +212,8 @@ rs_redis_host = search(:node, "role:redis_server").first["knife_zero"]["host"] r
rs_redis_port = node['liquor-cabinet']['redis_port']
rs_redis_db = node['liquor-cabinet']['redis_db']
if rs_redis_host
env[:rs_redis_url] = "redis://#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}"
rs_redis_password = URI.encode_www_form_component(redis_credentials['password'])
env[:rs_redis_url] = "redis://:#{rs_redis_password}@#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}"
end
#
@@ -2,6 +2,10 @@
This file is used to list changes made in each version of the liquor_cabinet cookbook.
## 0.2.0
- Add Redis password support.
## 0.1.0
Initial release.
+1 -1
View File
@@ -3,7 +3,7 @@ maintainer 'Kosmos Developers'
maintainer_email 'ops@kosmos.org'
license 'MIT'
description 'Installs/configures the Liquor Cabinet remoteStorage API server'
version '0.1.0'
version '0.2.0'
chef_version '>= 18.2'
issues_url 'https://gitea.kosmos.org/kosmos/chef/issues'
# source_url 'https://gitea.kosmos.org/kosmos/chef'
@@ -8,6 +8,7 @@ deploy_user = node[app_name]['user']
deploy_group = node[app_name]['group']
deploy_path = node[app_name]['deploy_path']
credentials = Chef::EncryptedDataBagItem.load('credentials', app_name)
redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis')
ruby_version = node[app_name]['ruby']['version']
ruby_path = "/opt/ruby_build/builds/#{ruby_version}"
@@ -70,6 +71,7 @@ template "#{deploy_path}/config.yml.erb" do
redis_host: redis_host,
redis_port: node[app_name]['redis_port'],
redis_db: node[app_name]['redis_db'],
redis_password: redis_credentials['password'],
s3_endpoint: node[app_name]['s3_endpoint'],
s3_region: node[app_name]['s3_region'],
s3_bucket: node[app_name]['s3_bucket'],
@@ -4,6 +4,7 @@
host: <%= @redis_host %>
port: <%= @redis_port %>
db: <%= @redis_db %>
password: <%= @redis_password.to_json %>
s3:
endpoint: <%= @s3_endpoint %>
region: <%= @s3_region %>