docs: adopt clean PSD replacement model

This commit is contained in:
User
2026-08-21 16:05:11 +02:00
parent 9974fb4bc0
commit 042af932ee
10 changed files with 527 additions and 128 deletions
+10 -4
View File
@@ -1233,9 +1233,11 @@ verify_server_guide() {
"frontend" \
"core" \
"UID/GID 10001" \
"thothii-ops" \
"-m 2770 /srv/thothii/operator" \
"chmod 0660 /srv/thothii/operator/server.env" \
"does not require or permit creation" \
"getent passwd 10001" \
"getent group 10001" \
"-m 0750 /srv/thothii/operator" \
"chmod 0600 /srv/thothii/operator/server.env" \
"THT_THT_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output" \
"/srv/thothii" \
"example operator root" \
@@ -1268,10 +1270,14 @@ verify_server_guide() {
"docker compose down --volumes" \
"reverse-proxy-nginx.md" \
"reverse-proxy-caddy.md"
if ! grep -Eq '^sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii$' "$guide"; then
if ! grep -Fq 'sudo install -d -o "$operator_uid" -g 10001 -m 0750 /srv/thothii' "$guide"; then
echo "server installation guide does not set parent traversal boundary" >&2
return 1
fi
if grep -Eq '(^|[[:space:]])(sudo[[:space:]]+)?(useradd|groupadd|usermod)([[:space:]]|$)|sudo[[:space:]]+-u[[:space:]]+thothii|thothii-ops' "$guide"; then
echo "server installation guide creates or depends on a host identity" >&2
return 1
fi
node - "$guide" <<'NODE'
const fs = require("fs");
const source = fs.readFileSync(process.argv[2], "utf8");