From 797087c66f62cc5f6205534a606d498124cda3a8 Mon Sep 17 00:00:00 2001 From: Fabio Scotto di Santolo Date: Wed, 30 Sep 2026 08:56:01 +0200 Subject: [PATCH] Fix Atlas Borg runtime permissions --- .../roles/profile_atlas/templates/atlas-borg-backup.sh.j2 | 5 ++++- .../templates/atlas-monitor-failure@.service.j2 | 4 ++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/ansible/roles/profile_atlas/templates/atlas-borg-backup.sh.j2 b/ansible/roles/profile_atlas/templates/atlas-borg-backup.sh.j2 index 5720a52..8f048fe 100644 --- a/ansible/roles/profile_atlas/templates/atlas-borg-backup.sh.j2 +++ b/ansible/roles/profile_atlas/templates/atlas-borg-backup.sh.j2 @@ -87,7 +87,10 @@ exec 9>/run/lock/atlas-zfs-snapshot.lock zpool list -H -o name "$pool" >/dev/null rm -rf "$stage" mkdir -p "$stage" -chown root:"$borg_group" /run/atlas-borg "$stage" +# Keep systemd's root:root ownership of RuntimeDirectory: changing it makes +# ExecStopPost re-chown its contents, which SELinux denies for the marker. +setfacl -m "u:${borg_user}:rx" /run/atlas-borg +chown root:"$borg_group" "$stage" chmod 0750 /run/atlas-borg "$stage" flock 9 diff --git a/ansible/roles/profile_atlas/templates/atlas-monitor-failure@.service.j2 b/ansible/roles/profile_atlas/templates/atlas-monitor-failure@.service.j2 index 6c746c4..66d671c 100644 --- a/ansible/roles/profile_atlas/templates/atlas-monitor-failure@.service.j2 +++ b/ansible/roles/profile_atlas/templates/atlas-monitor-failure@.service.j2 @@ -1,12 +1,12 @@ [Unit] -Description=Submit a 45Drives Alert for failed Atlas job %I +Description=Submit a 45Drives Alert for failed Atlas job %i Requires=houston-dbus.service After=houston-dbus.service ConditionFileIsExecutable=/usr/local/libexec/atlas-health-monitor [Service] Type=oneshot -ExecStart=/usr/local/libexec/atlas-health-monitor --job-failed %I +ExecStart=/usr/local/libexec/atlas-health-monitor --job-failed %i User=root Group=root UMask=0077