docs: describe read-only workspace runtime configuration
This commit is contained in:
@@ -20,19 +20,16 @@ install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source
|
||||
install -d -o 10001 -g 20002 -m 2770 /srv/thothii/operator
|
||||
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/secrets
|
||||
install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry
|
||||
install -d -o 10001 -g 10001 -m 0700 /srv/thothii/data/workspace-secrets
|
||||
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts
|
||||
install -o 10001 -g 20002 -m 0750 /repository/scripts/build-thothctl.sh /srv/thothii/source/ThothII/scripts/build-thothctl.sh
|
||||
install -o 10001 -g 20002 -m 0750 /repository/scripts/generate-connector-secrets-override.sh /srv/thothii/source/ThothII/scripts/generate-connector-secrets-override.sh
|
||||
install -o 10001 -g 20002 -m 0750 /repository/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh
|
||||
/srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001
|
||||
|
||||
printf "%s\n" "PLACEHOLDER=replace-me" "THT_WS_TEST_DWH_PASSWORD_SOURCE=/srv/thothii/secrets/dwh-password" > /srv/thothii/operator/server.env
|
||||
printf "%s\n" "PLACEHOLDER=replace-me" > /srv/thothii/operator/server.env
|
||||
printf "%s\n" "projectDirectory: replace-me" > /srv/thothii/operator/thothii-installation.yaml
|
||||
printf "%s\n" "THT_WS_TEST_DWH_PASSWORD_FILE=/run/secrets/test-dwh-password" > /srv/thothii/operator/workspace-bindings.env
|
||||
printf "%s\n" "operator-readable-secret" > /srv/thothii/secrets/dwh-password
|
||||
chown 10001:20002 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml /srv/thothii/operator/workspace-bindings.env /srv/thothii/secrets/dwh-password
|
||||
chmod 0660 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml /srv/thothii/operator/workspace-bindings.env
|
||||
chmod 0640 /srv/thothii/secrets/dwh-password
|
||||
chown 10001:20002 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
|
||||
chmod 0660 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
|
||||
|
||||
printf "%s\n" \
|
||||
"#!/bin/bash" \
|
||||
@@ -40,7 +37,7 @@ printf "%s\n" \
|
||||
"if [[ \"\${1:-}\" == build ]]; then" \
|
||||
" destination=; for argument in \"\$@\"; do case \"\$argument\" in type=local,dest=*) destination=\"\${argument#type=local,dest=}\" ;; esac; done" \
|
||||
" test -n \"\$destination\"; mkdir -p \"\$destination\"" \
|
||||
" printf \"%s\\n\" \"#!/bin/bash\" \"set -euo pipefail\" \"test -r \\\"\\\$2\\\"\" \"test -r /srv/thothii/secrets/dwh-password\" \"docker compose up --detach\" > \"\$destination/thothctl-linux-amd64\"" \
|
||||
" printf \"%s\\n\" \"#!/bin/bash\" \"set -euo pipefail\" \"test -r \\\"\\\$2\\\"\" \"docker compose up --detach\" > \"\$destination/thothctl-linux-amd64\"" \
|
||||
" chmod 0750 \"\$destination/thothctl-linux-amd64\"; exit 0" \
|
||||
"fi" \
|
||||
"test \"\${1:-}\" = compose; : > /srv/thothii/operator/start.marker" \
|
||||
@@ -51,12 +48,6 @@ runuser --user operator -- /bin/bash -ceu '\''
|
||||
umask 0007
|
||||
sed -i "s/replace-me/ready/" /srv/thothii/operator/server.env
|
||||
sed -i "s#replace-me#/srv/thothii/source/ThothII#" /srv/thothii/operator/thothii-installation.yaml
|
||||
/srv/thothii/source/ThothII/scripts/generate-connector-secrets-override.sh \
|
||||
--bindings-env /srv/thothii/operator/workspace-bindings.env \
|
||||
--operator-env /srv/thothii/operator/server.env \
|
||||
--output /srv/thothii/operator/connector-secrets.server.yaml
|
||||
test -r /srv/thothii/secrets/dwh-password
|
||||
if (printf tamper >> /srv/thothii/secrets/dwh-password) 2>/dev/null; then exit 41; fi
|
||||
for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \
|
||||
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
|
||||
if touch "$protected/operator-must-not-write" 2>/dev/null; then exit 42; fi
|
||||
@@ -75,8 +66,6 @@ rm -f "$root_output_error"
|
||||
--installation /srv/thothii/operator/thothii-installation.yaml start
|
||||
'\''
|
||||
|
||||
test "$(stat -c %u:%g /srv/thothii/operator/connector-secrets.server.yaml)" = 20001:20002
|
||||
test "$(stat -c %a /srv/thothii/operator/connector-secrets.server.yaml)" = 660
|
||||
test "$(stat -c %u:%g /srv/thothii)" = 10001:20002
|
||||
test "$(stat -c %a /srv/thothii)" = 2750
|
||||
test "$(stat -c %u:%g /srv/thothii/pi-state/agent)" = 10001:10001
|
||||
@@ -92,7 +81,6 @@ for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \
|
||||
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
|
||||
test ! -e "$protected/operator-must-not-write"
|
||||
done
|
||||
test "$(cat /srv/thothii/secrets/dwh-password)" = operator-readable-secret
|
||||
'
|
||||
|
||||
echo "distinct server operator UID/GID fixture passed"
|
||||
|
||||
Reference in New Issue
Block a user