Fixed some file permission issues
This commit is contained in:
1
ansible/roles/gitea/files/ssh_shim.sh
Normal file
1
ansible/roles/gitea/files/ssh_shim.sh
Normal file
@@ -0,0 +1 @@
|
||||
ssh -p 2222 -o StrictHostKeyChecking=no git@127.0.0.1 "SSH_ORIGINAL_COMMAND=\"$SSH_ORIGINAL_COMMAND\" $0 $@"
|
@@ -1,10 +1,27 @@
|
||||
- name: Create service user
|
||||
user:
|
||||
name: "{{ role_name }}"
|
||||
system: true
|
||||
name: git
|
||||
password_lock: yes
|
||||
generate_ssh_key: yes
|
||||
ssh_key_comment: Gitea Host Key
|
||||
register: service_user
|
||||
become: true
|
||||
|
||||
- name: Add user git's ssh key to its own authorized_key file
|
||||
ansible.posix.authorized_key:
|
||||
user: git
|
||||
key: "{{ service_user.ssh_public_key }}"
|
||||
become: true
|
||||
|
||||
- name: Install SSH shim script
|
||||
copy:
|
||||
src: ssh_shim.sh
|
||||
dest: /usr/local/bin/gitea
|
||||
owner: "{{ service_user.uid }}"
|
||||
group: "{{ service_user.group }}"
|
||||
mode: 711
|
||||
become: true
|
||||
|
||||
- name: Create install directory
|
||||
file:
|
||||
path: "{{ install_directory }}/{{ role_name }}"
|
||||
@@ -13,15 +30,6 @@
|
||||
mode: "{{ docker_compose_directory_mask }}"
|
||||
become: true
|
||||
|
||||
- name: Create config directory
|
||||
file:
|
||||
path: "{{ data_dir }}/{{ role_name }}"
|
||||
state: directory
|
||||
owner: "{{ service_user.uid }}"
|
||||
group: "{{ service_user.uid }}"
|
||||
mode: "{{ docker_compose_directory_mask }}"
|
||||
become: true
|
||||
|
||||
- name: Copy docker-compose file to destination
|
||||
template:
|
||||
src: docker-compose.yml
|
||||
|
@@ -16,18 +16,24 @@ services:
|
||||
networks:
|
||||
- traefik
|
||||
- default
|
||||
ports:
|
||||
- "127.0.0.1:2222:2222"
|
||||
environment:
|
||||
- "USER_UID={{ service_user.uid }}"
|
||||
- "USER_GID={{ service_user.uid }}"
|
||||
- GITEA_database__DB_TYPE=postgres
|
||||
- GITEA_database__HOST=db:5432
|
||||
- GITEA_database__NAME=gitea
|
||||
- GITEA_database__USER=gitea
|
||||
- GITEA_database__PASSWD=gitea
|
||||
- "USER_GID={{ service_user.group }}"
|
||||
- GITEA__database__DB_TYPE=postgres
|
||||
- GITEA__database__HOST=db:5432
|
||||
- GITEA__database__NAME=gitea
|
||||
- GITEA__database__USER=gitea
|
||||
- GITEA__database__PASSWD=gitea
|
||||
- GITEA__server__START_SSH_SERVER=true
|
||||
- GITEA__server__BUILTIN_SSH_SERVER_USER=git
|
||||
- GITEA__server__SSH_LISTEN_PORT=2222
|
||||
volumes:
|
||||
- "{{ data_dir }}/gitea:/data"
|
||||
- /etc/localtime:/etc/localtime:ro
|
||||
- /etc/timezone:/etc/timezone:ro
|
||||
- /home/git/.ssh:/data/git/.ssh # For SSH passthrough
|
||||
labels:
|
||||
traefik.enable: true
|
||||
traefik.http.routers.gitea.rule: "Host(`git.{{ personal_domain }}`)"
|
||||
|
@@ -15,6 +15,7 @@ services:
|
||||
- "PUID={{ service_user.uid }}"
|
||||
- "PGID={{ media_gid }}"
|
||||
- "TZ={{ timezone }}"
|
||||
- "UMASK=002"
|
||||
volumes:
|
||||
- "{{ data_dir }}/{{ role_name }}:/config"
|
||||
- "{{ media_storage_mnt }}/data:/data"
|
||||
|
@@ -15,6 +15,7 @@ services:
|
||||
- "PUID={{ service_user.uid }}"
|
||||
- "PGID={{ media_gid }}"
|
||||
- "TZ={{ timezone }}"
|
||||
- "UMASK=002"
|
||||
volumes:
|
||||
- "{{ data_dir }}/{{ role_name }}:/config"
|
||||
- "{{ media_storage_mnt }}/data:/data"
|
||||
|
@@ -8,9 +8,7 @@
|
||||
- name: Set media directory permissions
|
||||
ansible.builtin.file:
|
||||
path: "{{ media_storage_mnt }}/data"
|
||||
state: directory
|
||||
owner: "{{ primary_gid }}"
|
||||
group: media
|
||||
mode: 0775
|
||||
mode: "a=,a+rX,u+w,g+w"
|
||||
recurse: yes
|
||||
become: true
|
||||
|
@@ -10,6 +10,7 @@ services:
|
||||
- "PUID={{ service_user.uid }}"
|
||||
- "PGID={{ media_gid }}"
|
||||
- "TZ={{ timezone }}"
|
||||
- "UMASK=002"
|
||||
#- DOCKER_MODS=arafatamim/linuxserver-io-mod-vuetorrent
|
||||
volumes:
|
||||
- "{{ data_dir }}/{{ role_name }}:/config"
|
||||
|
@@ -18,6 +18,7 @@ services:
|
||||
- "PUID={{ service_user.uid }}"
|
||||
- "PGID={{ media_gid }}"
|
||||
- "TZ={{ timezone }}"
|
||||
- "UMASK=002"
|
||||
volumes:
|
||||
- "{{ data_dir }}/{{ role_name }}:/config"
|
||||
- "{{ media_storage_mnt }}/data:/data"
|
||||
|
@@ -18,6 +18,7 @@ services:
|
||||
- "PUID={{ service_user.uid }}"
|
||||
- "PGID={{ media_gid }}"
|
||||
- "TZ={{ timezone }}"
|
||||
- "UMASK=002"
|
||||
volumes:
|
||||
- "{{ data_dir }}/{{ role_name }}:/config"
|
||||
- "{{ media_storage_mnt }}/data:/data"
|
||||
|
Reference in New Issue
Block a user