From abfd654ae57d8f87203dc92973935837bd48387a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A2u=20Cao?= Date: Wed, 7 Oct 2026 19:41:43 +0200 Subject: [PATCH] Clone the private Mastodon repo with an SSH deploy key The repository is private, so use git@gitea.kosmos.org with a read-only deploy key stored in credentials/mastodon (repo_deploy_key). The pinned gitea host key is an attribute. --- .../kosmos-mastodon/attributes/default.rb | 8 +++- .../kosmos-mastodon/recipes/build.rb | 42 ++++++++++++++++++- 2 files changed, 47 insertions(+), 3 deletions(-) diff --git a/site-cookbooks/kosmos-mastodon/attributes/default.rb b/site-cookbooks/kosmos-mastodon/attributes/default.rb index 5b18556..31f88e3 100644 --- a/site-cookbooks/kosmos-mastodon/attributes/default.rb +++ b/site-cookbooks/kosmos-mastodon/attributes/default.rb @@ -1,4 +1,4 @@ -node.default["kosmos-mastodon"]["repo"] = "https://gitea.kosmos.org/kosmos/mastodon.git" +node.default["kosmos-mastodon"]["repo"] = "git@gitea.kosmos.org:kosmos/mastodon.git" node.default["kosmos-mastodon"]["revision"] = "production-4.7" node.default["kosmos-mastodon"]["directory"] = "/opt/mastodon" node.default["kosmos-mastodon"]["bind_ip"] = "127.0.0.1" @@ -22,6 +22,12 @@ node.default["kosmos-mastodon"]["nodejs_version"] = "24.21.0" node.default["kosmos-mastodon"]["ruby_version"] = "4.0.7" node.default["kosmos-mastodon"]["ruby_build_version"] = "v20260924" +# SSH deploy key access to the (private) repository. The private key is stored +# in the credentials/mastodon data bag as `repo_deploy_key`; this is the pinned +# host key of gitea.kosmos.org. +node.default["kosmos-mastodon"]["gitea_ssh_host_key"] = + "gitea.kosmos.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJycWc3U9P/6BzE0HcPiTdmaDN8zKRx+0/jGXYuKiwx7" + # External Redis cluster (see the kosmos_redis cookbook) node.default["kosmos-mastodon"]["redis_server_role"] = "redis_server" node.default["kosmos-mastodon"]["redis_port"] = 6379 diff --git a/site-cookbooks/kosmos-mastodon/recipes/build.rb b/site-cookbooks/kosmos-mastodon/recipes/build.rb index 95b6b99..3c85ccd 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/build.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/build.rb @@ -42,16 +42,54 @@ deploy_env = { build_uptodate = "test -f #{mastodon_path}/tmp/built-revision && " \ "test \"$(cat #{mastodon_path}/tmp/built-revision)\" = \"$(git -C #{mastodon_path} rev-parse HEAD)\"" +credentials = data_bag_item('credentials', 'mastodon') + +# The repository is private; clone it with a read-only SSH deploy key. +directory "#{mastodon_path}/.ssh" do + owner mastodon_user + group mastodon_user + mode "0700" +end + +file "#{mastodon_path}/.ssh/id_ed25519" do + content credentials["repo_deploy_key"] + owner mastodon_user + group mastodon_user + mode "0600" + sensitive true +end + +file "#{mastodon_path}/.ssh/known_hosts" do + content "#{node['kosmos-mastodon']['gitea_ssh_host_key']}\n" + owner mastodon_user + group mastodon_user + mode "0644" +end + +file "#{mastodon_path}/.ssh/config" do + content <<-EOF +Host gitea.kosmos.org + IdentityFile #{mastodon_path}/.ssh/id_ed25519 + IdentitiesOnly yes + StrictHostKeyChecking yes + UserKnownHostsFile #{mastodon_path}/.ssh/known_hosts + EOF + owner mastodon_user + group mastodon_user + mode "0600" +end + git mastodon_path do user mastodon_user group mastodon_user repository node["kosmos-mastodon"]["repo"] revision node["kosmos-mastodon"]["revision"] + environment "GIT_SSH_COMMAND" => + "ssh -i #{mastodon_path}/.ssh/id_ed25519 -o IdentitiesOnly=yes " \ + "-o StrictHostKeyChecking=yes -o UserKnownHostsFile=#{mastodon_path}/.ssh/known_hosts" end -credentials = data_bag_item('credentials', 'mastodon') - ldap_config = { host: "ldap.kosmos.local", port: 389,