From 9c7f5cee2129d3ba786761b2ecf876ef7710ae8d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A2u=20Cao?= Date: Tue, 6 Oct 2026 17:22:09 +0200 Subject: [PATCH 1/2] Add Redis password to akkounts, liquor cabinet --- data_bags/credentials/redis.json | 6 +++--- site-cookbooks/kosmos-akkounts/CHANGELOG.md | 4 ++++ site-cookbooks/kosmos-akkounts/metadata.rb | 2 +- site-cookbooks/kosmos-akkounts/recipes/default.rb | 5 ++++- site-cookbooks/liquor_cabinet/CHANGELOG.md | 4 ++++ site-cookbooks/liquor_cabinet/metadata.rb | 2 +- site-cookbooks/liquor_cabinet/recipes/default.rb | 2 ++ site-cookbooks/liquor_cabinet/templates/config.yml.erb | 1 + 8 files changed, 20 insertions(+), 6 deletions(-) diff --git a/data_bags/credentials/redis.json b/data_bags/credentials/redis.json index 594a2e7..8325e52 100644 --- a/data_bags/credentials/redis.json +++ b/data_bags/credentials/redis.json @@ -1,9 +1,9 @@ { "id": "redis", "password": { - "encrypted_data": "M2Cr7oNhL735D3coHnMc9yLuUzYlhkl+TfyMx1ccplFOyVZ+fXRF9UdDqxJ2\nyFIDJ+Yg\n", - "iv": "nEQz0SCUuFAEmxMd\n", - "auth_tag": "uuwSJdMZfLcRs7yjVrRlAQ==\n", + "encrypted_data": "vboNGwFD8JtX4d6Y6lTN4L/BXy1K1GWziX5S28Pm2/anH6Zydyjh3dvlmz1F\nXgddVQ==\n", + "iv": "5YH4k07V3t6dDajR\n", + "auth_tag": "k8ISunt4kgQ/WDB9aPS8kg==\n", "version": 3, "cipher": "aes-256-gcm" } diff --git a/site-cookbooks/kosmos-akkounts/CHANGELOG.md b/site-cookbooks/kosmos-akkounts/CHANGELOG.md index 5365d00..0daf4f3 100644 --- a/site-cookbooks/kosmos-akkounts/CHANGELOG.md +++ b/site-cookbooks/kosmos-akkounts/CHANGELOG.md @@ -1,5 +1,9 @@ # kosmos-akkounts CHANGELOG +# 0.4.0 + +- Add Redis password support to the remoteStorage Redis URL. + # 0.1.0 Initial release. diff --git a/site-cookbooks/kosmos-akkounts/metadata.rb b/site-cookbooks/kosmos-akkounts/metadata.rb index 18ed462..6ea2610 100644 --- a/site-cookbooks/kosmos-akkounts/metadata.rb +++ b/site-cookbooks/kosmos-akkounts/metadata.rb @@ -4,7 +4,7 @@ maintainer_email 'mail@kosmos.org' license 'MIT' description 'Installs/configures kosmos-akkounts' long_description 'Installs/configures kosmos-akkounts' -version '0.3.0' +version '0.4.0' chef_version '>= 18.0' depends 'kosmos_openresty' diff --git a/site-cookbooks/kosmos-akkounts/recipes/default.rb b/site-cookbooks/kosmos-akkounts/recipes/default.rb index 6d04488..c673d9e 100644 --- a/site-cookbooks/kosmos-akkounts/recipes/default.rb +++ b/site-cookbooks/kosmos-akkounts/recipes/default.rb @@ -3,6 +3,7 @@ # Recipe:: default # require 'ipaddr' +require 'uri' app_name = "akkounts" deploy_user = "deploy" @@ -10,6 +11,7 @@ deploy_group = "deploy" deploy_path = "/opt/#{app_name}" credentials = Chef::EncryptedDataBagItem.load('credentials', app_name) smtp_credentials = Chef::EncryptedDataBagItem.load('credentials', 'smtp') +redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis') group deploy_group @@ -210,7 +212,8 @@ rs_redis_host = search(:node, "role:redis_server").first["knife_zero"]["host"] r rs_redis_port = node['liquor-cabinet']['redis_port'] rs_redis_db = node['liquor-cabinet']['redis_db'] if rs_redis_host - env[:rs_redis_url] = "redis://#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}" + rs_redis_password = URI.encode_www_form_component(redis_credentials['password']) + env[:rs_redis_url] = "redis://:#{rs_redis_password}@#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}" end # diff --git a/site-cookbooks/liquor_cabinet/CHANGELOG.md b/site-cookbooks/liquor_cabinet/CHANGELOG.md index feaf621..8191071 100644 --- a/site-cookbooks/liquor_cabinet/CHANGELOG.md +++ b/site-cookbooks/liquor_cabinet/CHANGELOG.md @@ -2,6 +2,10 @@ This file is used to list changes made in each version of the liquor_cabinet cookbook. +## 0.2.0 + +- Add Redis password support. + ## 0.1.0 Initial release. diff --git a/site-cookbooks/liquor_cabinet/metadata.rb b/site-cookbooks/liquor_cabinet/metadata.rb index bd24a4c..20eecaa 100644 --- a/site-cookbooks/liquor_cabinet/metadata.rb +++ b/site-cookbooks/liquor_cabinet/metadata.rb @@ -3,7 +3,7 @@ maintainer 'Kosmos Developers' maintainer_email 'ops@kosmos.org' license 'MIT' description 'Installs/configures the Liquor Cabinet remoteStorage API server' -version '0.1.0' +version '0.2.0' chef_version '>= 18.2' issues_url 'https://gitea.kosmos.org/kosmos/chef/issues' # source_url 'https://gitea.kosmos.org/kosmos/chef' diff --git a/site-cookbooks/liquor_cabinet/recipes/default.rb b/site-cookbooks/liquor_cabinet/recipes/default.rb index 39687cd..f333f69 100644 --- a/site-cookbooks/liquor_cabinet/recipes/default.rb +++ b/site-cookbooks/liquor_cabinet/recipes/default.rb @@ -8,6 +8,7 @@ deploy_user = node[app_name]['user'] deploy_group = node[app_name]['group'] deploy_path = node[app_name]['deploy_path'] credentials = Chef::EncryptedDataBagItem.load('credentials', app_name) +redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis') ruby_version = node[app_name]['ruby']['version'] ruby_path = "/opt/ruby_build/builds/#{ruby_version}" @@ -70,6 +71,7 @@ template "#{deploy_path}/config.yml.erb" do redis_host: redis_host, redis_port: node[app_name]['redis_port'], redis_db: node[app_name]['redis_db'], + redis_password: redis_credentials['password'], s3_endpoint: node[app_name]['s3_endpoint'], s3_region: node[app_name]['s3_region'], s3_bucket: node[app_name]['s3_bucket'], diff --git a/site-cookbooks/liquor_cabinet/templates/config.yml.erb b/site-cookbooks/liquor_cabinet/templates/config.yml.erb index 615d28d..810dea2 100644 --- a/site-cookbooks/liquor_cabinet/templates/config.yml.erb +++ b/site-cookbooks/liquor_cabinet/templates/config.yml.erb @@ -4,6 +4,7 @@ host: <%= @redis_host %> port: <%= @redis_port %> db: <%= @redis_db %> + password: <%= @redis_password.to_json %> s3: endpoint: <%= @s3_endpoint %> region: <%= @s3_region %> -- 2.50.1 From 103ce389de82f0358d662d6387be6b0f91c028d4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A2u=20Cao?= Date: Tue, 6 Oct 2026 17:26:54 +0200 Subject: [PATCH 2/2] Updated nodes (Redis migration) --- clients/redis-1.json | 4 ---- clients/redis-2.json | 4 ---- nodes | 2 +- 3 files changed, 1 insertion(+), 9 deletions(-) delete mode 100644 clients/redis-1.json delete mode 100644 clients/redis-2.json diff --git a/clients/redis-1.json b/clients/redis-1.json deleted file mode 100644 index d3bc445..0000000 --- a/clients/redis-1.json +++ /dev/null @@ -1,4 +0,0 @@ -{ - "name": "redis-1", - "public_key": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7J/jWx6xCoz3ECDA9gr6\nAVVjd3MhE9LmE/bFLdQLariJjyNxJ1qLp/SN1P/H/aBS9YP6HEGkkTekRkWrHkDr\n5pliR9lmdS7c1W2pRKOaBm8r3pl98fBcFtxrkEhlULX5XMUCeGqANjDYeswaKYGb\nYF/OPsL2ZyIzUiejIVoPR9kuCWA8DNa1whgO84r2gMkBSzGu8hAhBoAlXQAoZWWj\nem3sNNwA9X+0WVGuG0X+RxdzNnZ6o28f5UZuDTCuMjJubKM4qg5uuwFtSXHoW8nU\nGl6Y7Owmqsdkh8ZCM8gA4lPu5Kh6XatqQ6Gzq0PXFyCykuXzJRwW4ZVCKC+UyhA0\nQQIDAQAB\n-----END PUBLIC KEY-----\n" -} \ No newline at end of file diff --git a/clients/redis-2.json b/clients/redis-2.json deleted file mode 100644 index 64ca777..0000000 --- a/clients/redis-2.json +++ /dev/null @@ -1,4 +0,0 @@ -{ - "name": "redis-2", - "public_key": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzjHtl5iChC5+uxr9YrQu\n3x4zihlVZGk+fYlpbHg2hV880NslRb1MJYFTaKcJrYmgVAnMaKZjfA4fGsWQ3tDl\n/2JcA95U0Soj9BMwr1EUfvna587xS5DnYNCd+OkVtNwqujdoU8Use13UcpwnaN4V\n/9bslQdw2qDeVmeqx7bfTvsATIedWt9eseMR/qnsMd9Rkz/Q3xJ9NgIdQL6cC7uf\nN6H/B+Y+qV5Kv84nwrkTGPyzNOt21mfzeYOiAMGUTUoS+l38hA4ehfVxb8dWTmNa\n8QENbx6DKP5xUEyCiluzFp5jiGJu9xSDngndLVsQ7de5+KvxTjfipczmrWSjPuYB\nXQIDAQAB\n-----END PUBLIC KEY-----\n" -} \ No newline at end of file diff --git a/nodes b/nodes index a0396e9..b3b5042 160000 --- a/nodes +++ b/nodes @@ -1 +1 @@ -Subproject commit a0396e959b4b65ea720c977cf345b412d7242e76 +Subproject commit b3b5042655b1f9f6c41e4ec46da1ed574200e05b -- 2.50.1