fix: make server operations executable
This commit is contained in:
@@ -14,8 +14,8 @@ first startup. Keep storage separated:
|
||||
```text
|
||||
/srv/thothii/data/ # settings, session data, Pi state as applicable
|
||||
/srv/thothii/workspace-registry/ # repo/, snapshots/, state/, locks/
|
||||
/srv/thothii/secrets/ # Git and connector secret files, mode 0700
|
||||
/srv/thothii/operator/ # untracked Compose/.env, mode 0700
|
||||
/srv/thothii/secrets/ # Git and connector secret files, setgid mode 2750
|
||||
/srv/thothii/operator/ # untracked Compose/.env, setgid mode 2750
|
||||
```
|
||||
|
||||
Permit outbound TCP only to approved Git/Gitea, DWH, vector, embedding, and bastion endpoints.
|
||||
@@ -41,8 +41,10 @@ authoring environment for migration.
|
||||
## Git credentials, CA, SSH key, and known-hosts mounts
|
||||
|
||||
Use the secret manager or a protected host-only procedure to create independent regular files under
|
||||
`/srv/thothii/secrets`. Set individual mode `0600`, directory mode `0700`, and ownership readable
|
||||
by the service account. These path-only variables are mounted read-only by Compose:
|
||||
`/srv/thothii/secrets`. As established in the server guide, use owner UID 10001, group
|
||||
`thothii-ops`, file mode `0640`, and setgid directory mode `2750`. This lets the UID 10001
|
||||
container and the reviewed Docker operator running `thothctl` read the files without making them
|
||||
public. These path-only variables are mounted read-only by Compose:
|
||||
|
||||
```dotenv
|
||||
THT_WORKSPACE_GIT_CREDENTIALS_FILE=/srv/thothii/secrets/git-credentials
|
||||
|
||||
Reference in New Issue
Block a user