Clone the private Mastodon repo with an SSH deploy key

The repository is private, so use git@gitea.kosmos.org with a read-only deploy key stored in credentials/mastodon (repo_deploy_key). The pinned gitea host key is an attribute.
This commit is contained in:
raucao committed 2026-10-07 19:41:43 +02:00
1 parent d05f00dae2
commit abfd654ae5
2 files changed
+47 -3

No files matched your search

@@ -1,4 +1,4 @@
node.default["kosmos-mastodon"]["repo"] = "https://gitea.kosmos.org/kosmos/mastodon.git"
node.default["kosmos-mastodon"]["repo"] = "git@gitea.kosmos.org:kosmos/mastodon.git"
node.default["kosmos-mastodon"]["revision"] = "production-4.7"
node.default["kosmos-mastodon"]["directory"] = "/opt/mastodon"
node.default["kosmos-mastodon"]["bind_ip"] = "127.0.0.1"
@@ -22,6 +22,12 @@ node.default["kosmos-mastodon"]["nodejs_version"] = "24.21.0"
node.default["kosmos-mastodon"]["ruby_version"] = "4.0.7"
node.default["kosmos-mastodon"]["ruby_build_version"] = "v20260924"
# SSH deploy key access to the (private) repository. The private key is stored
# in the credentials/mastodon data bag as `repo_deploy_key`; this is the pinned
# host key of gitea.kosmos.org.
node.default["kosmos-mastodon"]["gitea_ssh_host_key"] =
"gitea.kosmos.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJycWc3U9P/6BzE0HcPiTdmaDN8zKRx+0/jGXYuKiwx7"
# External Redis cluster (see the kosmos_redis cookbook)
node.default["kosmos-mastodon"]["redis_server_role"] = "redis_server"
node.default["kosmos-mastodon"]["redis_port"] = 6379
@@ -42,16 +42,54 @@ deploy_env = {
build_uptodate = "test -f #{mastodon_path}/tmp/built-revision && " \
"test \"$(cat #{mastodon_path}/tmp/built-revision)\" = \"$(git -C #{mastodon_path} rev-parse HEAD)\""
credentials = data_bag_item('credentials', 'mastodon')
# The repository is private; clone it with a read-only SSH deploy key.
directory "#{mastodon_path}/.ssh" do
owner mastodon_user
group mastodon_user
mode "0700"
end
file "#{mastodon_path}/.ssh/id_ed25519" do
content credentials["repo_deploy_key"]
owner mastodon_user
group mastodon_user
mode "0600"
sensitive true
end
file "#{mastodon_path}/.ssh/known_hosts" do
content "#{node['kosmos-mastodon']['gitea_ssh_host_key']}\n"
owner mastodon_user
group mastodon_user
mode "0644"
end
file "#{mastodon_path}/.ssh/config" do
content <<-EOF
Host gitea.kosmos.org
IdentityFile #{mastodon_path}/.ssh/id_ed25519
IdentitiesOnly yes
StrictHostKeyChecking yes
UserKnownHostsFile #{mastodon_path}/.ssh/known_hosts
EOF
owner mastodon_user
group mastodon_user
mode "0600"
end
git mastodon_path do
user mastodon_user
group mastodon_user
repository node["kosmos-mastodon"]["repo"]
revision node["kosmos-mastodon"]["revision"]
environment "GIT_SSH_COMMAND" =>
"ssh -i #{mastodon_path}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \
"-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_path}/.ssh/known_hosts"
end
credentials = data_bag_item('credentials', 'mastodon')
ldap_config = {
host: "ldap.kosmos.local",
port: 389,