fix: close server bypass edge cases
This commit is contained in:
@@ -60,9 +60,12 @@ write access to runtime bind trees.
|
||||
|
||||
Create explicit directories. `source` contains the clone; `operator` contains untracked path-only
|
||||
configuration; the three writable trees are bind-mounted into `core`; `secrets` contains regular
|
||||
files only. Backups are separate from live data.
|
||||
files only. Backups are separate from live data. Reset the account home explicitly because
|
||||
distribution `useradd` defaults may otherwise leave `/srv/thothii` non-traversable by
|
||||
`thothii-ops`.
|
||||
|
||||
```sh
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/source
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2770 /srv/thothii/operator
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/secrets
|
||||
@@ -72,7 +75,8 @@ sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/workspace-registry
|
||||
sudo install -d -o root -g root -m 0700 /srv/thothii-backups
|
||||
```
|
||||
|
||||
The human operator can write only `operator`; setgid keeps generated files in `thothii-ops`.
|
||||
Verify `/srv/thothii` is owned by `10001:thothii-ops` with mode `2750`. The human operator can
|
||||
traverse the parent but can write only `operator`; setgid keeps generated files in `thothii-ops`.
|
||||
`source`, `secrets`, and all runtime bind trees remain non-group-writable. Do not make
|
||||
`/srv/thothii` a shared application directory.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user