fix(deploy): prepare server auth root before configure

This commit is contained in:
2026-08-25 23:46:32 +02:00
parent 66f9fa2821
commit d49c644b61
2 changed files with 25 additions and 0 deletions
+14
View File
@@ -80,6 +80,20 @@ else
TASK13_SESSION_PASSWORD="fixture-private-token-$profile" TASK13_SESSION_PASSWORD="fixture-private-token-$profile"
TASK13_SESSION_MIGRATOR_PASSWORD="fixture-migrator-token-$profile" TASK13_SESSION_MIGRATOR_PASSWORD="fixture-migrator-token-$profile"
task13_write_server_fixture_files task13_write_server_fixture_files
original_task13_run_logged="$(declare -f task13_run_logged)"
ownership_calls="$fixture/server-auth-ownership.calls"
task13_run_logged() {
printf '%s\n' "$*" >"$ownership_calls"
}
task13_prepare_server_auth_canonical_root
grep -Fxq -- \
"prepare server authentication canonical root sudo -n -- install -d -o 0 -g 0 -m 0700 -- $TASK13_AUTH_ROOT" \
"$ownership_calls" || {
echo "server auth fixture does not prepare a root-owned private canonical directory" >&2
exit 1
}
unset -f task13_run_logged
eval "$original_task13_run_logged"
compose_files=( compose_files=(
-f "$root/compose.yaml" -f "$root/compose.yaml"
-f "$root/deploy/compose.server.yaml" -f "$root/deploy/compose.server.yaml"
+11
View File
@@ -944,6 +944,16 @@ task13_configure_server_oidc_authentication() {
--authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins --authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins
} }
task13_prepare_server_auth_canonical_root() {
[[ "${TASK13_PROFILE:-}" == server \
&& "$TASK13_AUTH_ROOT" == "$TASK13_TMP/auth" \
&& ! -L "$TASK13_AUTH_ROOT" \
&& ( ! -e "$TASK13_AUTH_ROOT" || -d "$TASK13_AUTH_ROOT" ) ]] \
|| task13_fail "refusing to prepare an unexpected server authentication root"
task13_run_logged "prepare server authentication canonical root" sudo -n -- \
install -d -o 0 -g 0 -m 0700 -- "$TASK13_AUTH_ROOT"
}
task13_prepare_local_auth_runtime() { task13_prepare_local_auth_runtime() {
local owner_label local owner_label
owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \ owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \
@@ -2844,6 +2854,7 @@ task13_server_smoke_main() {
task13_write_server_fixture_files task13_write_server_fixture_files
task13_seed_registry task13_seed_registry
task13_build_tht task13_build_tht
task13_prepare_server_auth_canonical_root
task13_configure_server_oidc_authentication task13_configure_server_oidc_authentication
task13_start_server_stack task13_start_server_stack
task13_record_project_image_evidence task13_record_project_image_evidence