93 lines
4.8 KiB
Bash
Executable File
93 lines
4.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Execute the documented server ownership model with distinct runtime and human operator IDs.
|
|
set -euo pipefail
|
|
|
|
root="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651'
|
|
|
|
docker run --rm --volume "$root:/repository:ro" "$image" /bin/bash -ceu '
|
|
groupadd --gid 20001 operator-primary
|
|
groupadd --gid 20003 docker
|
|
useradd --uid 20001 --gid 20001 --groups 20003 --create-home --shell /bin/bash operator
|
|
|
|
install -d -o 20001 -g 10001 -m 0750 /srv/thothii
|
|
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/source
|
|
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/operator
|
|
install -d -o 10001 -g 20001 -m 0750 /srv/thothii/secrets
|
|
install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry
|
|
install -d -o 10001 -g 10001 -m 0700 /srv/thothii/data/workspace-secrets
|
|
install -d -o 20001 -g 20001 -m 0750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts
|
|
install -o 20001 -g 20001 -m 0750 /repository/scripts/build-tht.sh /srv/thothii/source/ThothII/scripts/build-tht.sh
|
|
install -o 20001 -g 20001 -m 0750 /repository/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh
|
|
/srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001
|
|
|
|
printf "%s\n" "PLACEHOLDER=replace-me" > /srv/thothii/operator/server.env
|
|
printf "%s\n" "projectDirectory: replace-me" > /srv/thothii/operator/thothii-installation.yaml
|
|
chown 20001:20001 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
|
|
chmod 0600 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml
|
|
|
|
printf "%s\n" \
|
|
"#!/bin/bash" \
|
|
"set -euo pipefail" \
|
|
"if [[ \"\${1:-}\" == build ]]; then" \
|
|
" destination=; for argument in \"\$@\"; do case \"\$argument\" in type=local,dest=*) destination=\"\${argument#type=local,dest=}\" ;; esac; done" \
|
|
" test -n \"\$destination\"; mkdir -p \"\$destination\"" \
|
|
" printf \"%s\\n\" \"#!/bin/bash\" \"set -euo pipefail\" \"test -r \\\"\\\$2\\\"\" \"docker compose up --detach\" > \"\$destination/tht-linux-amd64\"" \
|
|
" chmod 0750 \"\$destination/tht-linux-amd64\"; exit 0" \
|
|
"fi" \
|
|
"test \"\${1:-}\" = compose; : > /srv/thothii/operator/start.marker" \
|
|
> /usr/local/bin/docker
|
|
chmod 0755 /usr/local/bin/docker
|
|
|
|
runuser --user operator -- /bin/bash -ceu '\''
|
|
umask 0077
|
|
sed -i "s/replace-me/ready/" /srv/thothii/operator/server.env
|
|
sed -i "s#replace-me#/srv/thothii/source/ThothII#" /srv/thothii/operator/thothii-installation.yaml
|
|
for protected in /srv/thothii/secrets \
|
|
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
|
|
if touch "$protected/operator-must-not-write" 2>/dev/null; then exit 42; fi
|
|
done
|
|
THT_THT_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output \
|
|
/srv/thothii/source/ThothII/scripts/build-tht.sh
|
|
if THT_THT_OUTPUT_DIRECTORY=relative-output \
|
|
/srv/thothii/source/ThothII/scripts/build-tht.sh 2>/dev/null; then exit 44; fi
|
|
root_output_error=/srv/thothii/operator/root-output.error
|
|
if THT_THT_OUTPUT_DIRECTORY=/ \
|
|
/srv/thothii/source/ThothII/scripts/build-tht.sh 2>"$root_output_error"; then exit 45; fi
|
|
grep -Fq "THT_THT_OUTPUT_DIRECTORY must be an absolute canonical path" \
|
|
"$root_output_error" || exit 46
|
|
rm -f "$root_output_error"
|
|
/srv/thothii/operator/build-output/tht-linux-amd64 \
|
|
--installation /srv/thothii/operator/thothii-installation.yaml start
|
|
'\''
|
|
|
|
test "$(stat -c %u:%g /srv/thothii)" = 20001:10001
|
|
test "$(stat -c %a /srv/thothii)" = 750
|
|
test "$(stat -c %u:%g /srv/thothii/pi-state/agent)" = 10001:10001
|
|
test "$(stat -c %a /srv/thothii/pi-state/agent)" = 700
|
|
for target in auth.json models.json settings.json; do
|
|
test "$(stat -c %u:%g /srv/thothii/pi-state/agent/$target)" = 10001:10001
|
|
test "$(stat -c %a /srv/thothii/pi-state/agent/$target)" = 600
|
|
done
|
|
test "$(stat -c %u:%g /srv/thothii/operator/build-output/tht-linux-amd64)" = 20001:20001
|
|
if getent passwd 10001 >/dev/null || getent group 10001 >/dev/null; then
|
|
printf "%s\n" "numeric runtime identity unexpectedly mapped on host fixture" >&2
|
|
exit 47
|
|
fi
|
|
test "$(stat -c %u:%g /srv/thothii)" = 20001:10001
|
|
test "$(stat -c %a /srv/thothii)" = 750
|
|
test "$(stat -c %u:%g /srv/thothii/source)" = 20001:20001
|
|
test "$(stat -c %u:%g /srv/thothii/operator)" = 20001:20001
|
|
test "$(stat -c %u:%g /srv/thothii/secrets)" = 10001:20001
|
|
test "$(stat -c %a /srv/thothii/operator/server.env)" = 600
|
|
test "$(stat -c %a /srv/thothii/operator/thothii-installation.yaml)" = 600
|
|
test "$(stat -c %a /srv/thothii/operator/build-output/tht-linux-amd64)" = 750
|
|
test -f /srv/thothii/operator/start.marker
|
|
for protected in /srv/thothii/secrets \
|
|
/srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do
|
|
test ! -e "$protected/operator-must-not-write"
|
|
done
|
|
'
|
|
|
|
echo "distinct server operator UID/GID fixture passed"
|