docs: adopt clean PSD replacement model

This commit is contained in:
User
2026-08-21 16:05:11 +02:00
parent 9974fb4bc0
commit 042af932ee
10 changed files with 527 additions and 128 deletions
+27 -21
View File
@@ -6,30 +6,25 @@ root="$(cd "$(dirname "$0")/.." && pwd -P)"
image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651'
docker run --rm --volume "$root:/repository:ro" "$image" /bin/bash -ceu '
groupadd --gid 10001 thothii
useradd --uid 10001 --gid 10001 --home-dir /srv/thothii --create-home --shell /usr/sbin/nologin thothii
# Reproduce the conservative home mode permitted by the documented useradd sequence.
chmod 0700 /srv/thothii
groupadd --gid 20001 operator-primary
groupadd --gid 20002 thothii-ops
groupadd --gid 20003 docker
useradd --uid 20001 --gid 20001 --groups 20002,20003 --create-home --shell /bin/bash operator
useradd --uid 20001 --gid 20001 --groups 20003 --create-home --shell /bin/bash operator
install -d -o 10001 -g 20002 -m 2750 /srv/thothii
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source
install -d -o 10001 -g 20002 -m 2770 /srv/thothii/operator
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/secrets
install -d -o 20001 -g 10001 -m 0750 /srv/thothii
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/source
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/operator
install -d -o 10001 -g 20001 -m 0750 /srv/thothii/secrets
install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry
install -d -o 10001 -g 10001 -m 0700 /srv/thothii/data/workspace-secrets
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts
install -o 10001 -g 20002 -m 0750 /repository/scripts/build-tht.sh /srv/thothii/source/ThothII/scripts/build-tht.sh
install -o 10001 -g 20002 -m 0750 /repository/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts
install -o 20001 -g 20001 -m 0750 /repository/scripts/build-tht.sh /srv/thothii/source/ThothII/scripts/build-tht.sh
install -o 20001 -g 20001 -m 0750 /repository/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh
/srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001
printf "%s\n" "PLACEHOLDER=replace-me" > /srv/thothii/operator/server.env
printf "%s\n" "projectDirectory: replace-me" > /srv/thothii/operator/thothii-installation.yaml
chown 10001:20002 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
chmod 0660 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
chown 20001:20001 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
chmod 0600 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
printf "%s\n" \
"#!/bin/bash" \
@@ -45,10 +40,10 @@ printf "%s\n" \
chmod 0755 /usr/local/bin/docker
runuser --user operator -- /bin/bash -ceu '\''
umask 0007
umask 0077
sed -i "s/replace-me/ready/" /srv/thothii/operator/server.env
sed -i "s#replace-me#/srv/thothii/source/ThothII#" /srv/thothii/operator/thothii-installation.yaml
for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \
for protected in /srv/thothii/secrets \
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
if touch "$protected/operator-must-not-write" 2>/dev/null; then exit 42; fi
done
@@ -66,18 +61,29 @@ rm -f "$root_output_error"
--installation /srv/thothii/operator/thothii-installation.yaml start
'\''
test "$(stat -c %u:%g /srv/thothii)" = 10001:20002
test "$(stat -c %a /srv/thothii)" = 2750
test "$(stat -c %u:%g /srv/thothii)" = 20001:10001
test "$(stat -c %a /srv/thothii)" = 750
test "$(stat -c %u:%g /srv/thothii/pi-state/agent)" = 10001:10001
test "$(stat -c %a /srv/thothii/pi-state/agent)" = 700
for target in auth.json models.json settings.json; do
test "$(stat -c %u:%g /srv/thothii/pi-state/agent/$target)" = 10001:10001
test "$(stat -c %a /srv/thothii/pi-state/agent/$target)" = 600
done
test "$(stat -c %u:%g /srv/thothii/operator/build-output/tht-linux-amd64)" = 20001:20002
test "$(stat -c %u:%g /srv/thothii/operator/build-output/tht-linux-amd64)" = 20001:20001
if getent passwd 10001 >/dev/null || getent group 10001 >/dev/null; then
printf "%s\n" "numeric runtime identity unexpectedly mapped on host fixture" >&2
exit 47
fi
test "$(stat -c %u:%g /srv/thothii)" = 20001:10001
test "$(stat -c %a /srv/thothii)" = 750
test "$(stat -c %u:%g /srv/thothii/source)" = 20001:20001
test "$(stat -c %u:%g /srv/thothii/operator)" = 20001:20001
test "$(stat -c %u:%g /srv/thothii/secrets)" = 10001:20001
test "$(stat -c %a /srv/thothii/operator/server.env)" = 600
test "$(stat -c %a /srv/thothii/operator/thothii-installation.yaml)" = 600
test "$(stat -c %a /srv/thothii/operator/build-output/tht-linux-amd64)" = 750
test -f /srv/thothii/operator/start.marker
for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \
for protected in /srv/thothii/secrets \
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
test ! -e "$protected/operator-must-not-write"
done