mirror of
https://github.com/fscotto/infra.git
synced 2026-10-03 21:39:50 +00:00
Move Atlas Gitea Quadlet to admin with internal gitea user
This commit is contained in:
@@ -9,16 +9,18 @@
|
||||
- atlas_manage_storage | bool
|
||||
- atlas_gitea_dataset == atlas_zfs_pool ~ '/services/data/gitea'
|
||||
- atlas_gitea_mountpoint == atlas_app_data_mountpoint ~ '/gitea'
|
||||
- atlas_gitea_uid | int != atlas_admin_uid | int
|
||||
- atlas_gitea_uid | int != atlas_immich_uid | int
|
||||
- atlas_gitea_gid | int != atlas_admin_gid | int
|
||||
- atlas_gitea_gid | int != atlas_immich_gid | int
|
||||
- atlas_gitea_username == atlas_admin_username
|
||||
- atlas_gitea_group == atlas_admin_group
|
||||
- atlas_gitea_uid | int == atlas_admin_uid | int
|
||||
- atlas_gitea_gid | int == atlas_admin_gid | int
|
||||
- atlas_gitea_container_uid | int == 1000
|
||||
- atlas_gitea_container_gid | int == 1000
|
||||
- atlas_gitea_staging_bind_address == '127.0.0.1'
|
||||
- not (atlas_gitea_production_enabled | bool) or atlas_manage_firewall | bool
|
||||
- not (atlas_gitea_production_enabled | bool) or atlas_gitea_bind_address == ansible_host
|
||||
fail_msg: >-
|
||||
Rootless Gitea preparation requires Atlas storage, an isolated service
|
||||
identity and dataset, and loopback-only staging ports.
|
||||
Rootless Gitea requires Atlas storage, the admin user manager, the
|
||||
dedicated dataset, and loopback-only staging ports.
|
||||
|
||||
- name: Inspect the final-restore marker before production activation
|
||||
ansible.builtin.stat:
|
||||
@@ -33,43 +35,32 @@
|
||||
fail_msg: Restore the final stopped-source Gitea export before enabling production.
|
||||
when: atlas_gitea_production_enabled | bool
|
||||
|
||||
- name: Create the dedicated Gitea group
|
||||
ansible.builtin.group:
|
||||
name: "{{ atlas_gitea_group }}"
|
||||
gid: "{{ atlas_gitea_gid }}"
|
||||
system: true
|
||||
state: present
|
||||
- name: Verify the production Gitea dataset belongs to admin
|
||||
ansible.builtin.stat:
|
||||
path: "{{ atlas_gitea_mountpoint }}"
|
||||
register: atlas_gitea_dataset_owner
|
||||
when: atlas_gitea_production_enabled | bool
|
||||
|
||||
- name: Create the non-login Gitea service account
|
||||
ansible.builtin.user:
|
||||
name: "{{ atlas_gitea_username }}"
|
||||
uid: "{{ atlas_gitea_uid }}"
|
||||
group: "{{ atlas_gitea_group }}"
|
||||
home: "{{ atlas_gitea_home }}"
|
||||
shell: /sbin/nologin
|
||||
create_home: true
|
||||
system: true
|
||||
state: present
|
||||
- name: Refuse to overlap the legacy host-account service
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- atlas_gitea_dataset_owner.stat.uid | int == atlas_admin_uid | int
|
||||
- atlas_gitea_dataset_owner.stat.gid | int == atlas_admin_gid | int
|
||||
fail_msg: >-
|
||||
Run the explicit Gitea owner migration before enabling the admin
|
||||
Quadlet; never chown an active legacy service in a normal run.
|
||||
when: atlas_gitea_production_enabled | bool
|
||||
|
||||
- name: Restrict the Gitea service home
|
||||
ansible.builtin.file:
|
||||
path: "{{ atlas_gitea_home }}"
|
||||
state: directory
|
||||
owner: "{{ atlas_gitea_username }}"
|
||||
group: "{{ atlas_gitea_group }}"
|
||||
mode: "0700"
|
||||
|
||||
- name: Reserve dedicated rootless UID and GID ranges for Gitea
|
||||
ansible.builtin.lineinfile:
|
||||
- name: Remove the retired account's parent-dataset traverse ACL
|
||||
ansible.posix.acl:
|
||||
path: "{{ item }}"
|
||||
regexp: '^{{ atlas_gitea_username }}:'
|
||||
line: >-
|
||||
{{ atlas_gitea_username }}:{{ atlas_gitea_subid_start }}:{{ atlas_gitea_subid_count }}
|
||||
create: false
|
||||
mode: "0644"
|
||||
etype: user
|
||||
entity: "{{ atlas_gitea_legacy_username }}"
|
||||
state: absent
|
||||
loop:
|
||||
- /etc/subuid
|
||||
- /etc/subgid
|
||||
- "{{ atlas_services_mountpoint }}"
|
||||
- "{{ atlas_app_data_mountpoint }}"
|
||||
when: atlas_gitea_production_enabled | bool
|
||||
|
||||
- name: Enable POSIX ACLs only on the service-namespace parents
|
||||
community.general.zfs:
|
||||
@@ -81,17 +72,6 @@
|
||||
- "{{ atlas_zfs_pool }}/{{ atlas_zfs_dataset_services }}"
|
||||
- "{{ atlas_zfs_pool }}/{{ atlas_zfs_dataset_app_data }}"
|
||||
|
||||
- name: Permit Gitea to traverse only the application-data parents
|
||||
ansible.posix.acl:
|
||||
path: "{{ item }}"
|
||||
entity: "{{ atlas_gitea_username }}"
|
||||
etype: user
|
||||
permissions: x
|
||||
state: present
|
||||
loop:
|
||||
- "{{ atlas_services_mountpoint }}"
|
||||
- "{{ atlas_app_data_mountpoint }}"
|
||||
|
||||
- name: Create the dedicated Gitea ZFS dataset
|
||||
community.general.zfs:
|
||||
name: "{{ atlas_gitea_dataset }}"
|
||||
@@ -115,7 +95,7 @@
|
||||
- "{{ atlas_gitea_home }}/.config/containers"
|
||||
- "{{ atlas_gitea_quadlet_dir }}"
|
||||
|
||||
- name: Enable lingering for the dedicated rootless account
|
||||
- name: Ensure lingering for the admin rootless account
|
||||
ansible.builtin.command:
|
||||
argv:
|
||||
- loginctl
|
||||
@@ -123,12 +103,15 @@
|
||||
- "{{ atlas_gitea_username }}"
|
||||
creates: "/var/lib/systemd/linger/{{ atlas_gitea_username }}"
|
||||
|
||||
- name: Start the dedicated rootless user manager
|
||||
- name: Start the admin rootless user manager
|
||||
ansible.builtin.systemd:
|
||||
name: "user@{{ atlas_gitea_uid }}.service"
|
||||
state: started
|
||||
when: not ansible_check_mode
|
||||
|
||||
- name: Prepare the admin-owned Gitea image
|
||||
ansible.builtin.import_tasks: gitea_image.yml
|
||||
|
||||
- name: Render the rootless Gitea Quadlet
|
||||
ansible.builtin.template:
|
||||
src: atlas-gitea.container.j2
|
||||
|
||||
51
ansible/roles/profile_atlas/tasks/gitea_image.yml
Normal file
51
ansible/roles/profile_atlas/tasks/gitea_image.yml
Normal file
@@ -0,0 +1,51 @@
|
||||
---
|
||||
- name: Create the admin-owned Gitea image build directory
|
||||
ansible.builtin.file:
|
||||
path: "{{ atlas_gitea_image_build_dir }}"
|
||||
state: directory
|
||||
owner: "{{ atlas_admin_username }}"
|
||||
group: "{{ atlas_admin_group }}"
|
||||
mode: "0700"
|
||||
|
||||
- name: Install the pinned rootless Gitea Containerfile
|
||||
ansible.builtin.copy:
|
||||
src: Containerfile.gitea-rootless
|
||||
dest: "{{ atlas_gitea_image_build_dir }}/Containerfile"
|
||||
owner: "{{ atlas_admin_username }}"
|
||||
group: "{{ atlas_admin_group }}"
|
||||
mode: "0644"
|
||||
|
||||
- name: Check the admin-owned Gitea image
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.command:
|
||||
argv: [podman, image, exists, "{{ atlas_gitea_image }}"]
|
||||
args:
|
||||
chdir: "{{ atlas_gitea_image_build_dir }}"
|
||||
environment:
|
||||
HOME: "{{ atlas_admin_home }}"
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
register: atlas_gitea_image_present
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
check_mode: false
|
||||
|
||||
- name: Build the pinned Gitea image with the internal gitea identity
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.command:
|
||||
argv:
|
||||
- podman
|
||||
- build
|
||||
- --pull=always
|
||||
- --tag
|
||||
- "{{ atlas_gitea_image }}"
|
||||
- --file
|
||||
- Containerfile
|
||||
- .
|
||||
args:
|
||||
chdir: "{{ atlas_gitea_image_build_dir }}"
|
||||
environment:
|
||||
HOME: "{{ atlas_admin_home }}"
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
when:
|
||||
- atlas_gitea_image_present.rc != 0
|
||||
- not ansible_check_mode
|
||||
275
ansible/roles/profile_atlas/tasks/gitea_owner_migration.yml
Normal file
275
ansible/roles/profile_atlas/tasks/gitea_owner_migration.yml
Normal file
@@ -0,0 +1,275 @@
|
||||
---
|
||||
# Run only in an approved outage with -e atlas_gitea_owner_migration=true.
|
||||
- name: Move live Gitea from the legacy host account to admin
|
||||
tags: [atlas, gitea_owner_migration]
|
||||
when: atlas_gitea_owner_migration | bool
|
||||
block:
|
||||
- name: Refuse a check-mode owner migration
|
||||
ansible.builtin.assert:
|
||||
that: not ansible_check_mode
|
||||
fail_msg: The owner migration requires an explicit live outage.
|
||||
|
||||
- name: Inspect the Gitea dataset owner
|
||||
ansible.builtin.stat:
|
||||
path: "{{ atlas_gitea_mountpoint }}"
|
||||
register: atlas_gitea_migration_owner
|
||||
|
||||
- name: Require either the legacy owner or an already migrated dataset
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- atlas_gitea_migration_owner.stat.isdir | default(false)
|
||||
- atlas_gitea_migration_owner.stat.uid | int in [atlas_gitea_legacy_uid | int, atlas_admin_uid | int]
|
||||
fail_msg: Refusing to modify a Gitea dataset with an unexpected owner.
|
||||
|
||||
- name: Migrate only a legacy-owned Gitea dataset
|
||||
when: atlas_gitea_migration_owner.stat.uid | int == atlas_gitea_legacy_uid | int
|
||||
block:
|
||||
- name: Require the final cutover marker and configuration
|
||||
ansible.builtin.stat:
|
||||
path: "{{ item }}"
|
||||
loop:
|
||||
- "{{ atlas_gitea_mountpoint }}/.final-sha256"
|
||||
- "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
||||
register: atlas_gitea_migration_files
|
||||
|
||||
- name: Refuse migration without both final data and configuration
|
||||
ansible.builtin.assert:
|
||||
that: atlas_gitea_migration_files.results | map(attribute='stat.isreg') | min
|
||||
|
||||
- name: Check that admin has no existing Gitea Quadlet
|
||||
ansible.builtin.stat:
|
||||
path: "{{ atlas_gitea_quadlet_dir }}/atlas-gitea.container"
|
||||
register: atlas_gitea_admin_quadlet
|
||||
|
||||
- name: Refuse to overwrite an existing admin Quadlet
|
||||
ansible.builtin.assert:
|
||||
that: not atlas_gitea_admin_quadlet.stat.exists
|
||||
|
||||
- name: Check pool health before the outage
|
||||
ansible.builtin.command:
|
||||
argv: [zpool, status, -x, "{{ atlas_zfs_pool }}"]
|
||||
register: atlas_gitea_pool_before
|
||||
changed_when: false
|
||||
failed_when: "'is healthy' not in atlas_gitea_pool_before.stdout"
|
||||
|
||||
- name: Ensure the admin Gitea image is available before stopping the source
|
||||
ansible.builtin.import_tasks: gitea_image.yml
|
||||
|
||||
- name: Stop, snapshot and test the admin-owned staging service
|
||||
block:
|
||||
- name: Stop and disable the legacy Gitea user service
|
||||
become_user: "{{ atlas_gitea_legacy_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: stopped
|
||||
enabled: false
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_gitea_legacy_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_gitea_legacy_uid }}/bus"
|
||||
|
||||
- name: Record the migration snapshot name
|
||||
ansible.builtin.set_fact:
|
||||
atlas_gitea_migration_snapshot: >-
|
||||
{{ atlas_gitea_dataset }}@gitea-owner-migration-{{ ansible_facts.date_time.iso8601_basic_short }}
|
||||
|
||||
- name: Snapshot the stopped Gitea dataset for manual recovery
|
||||
ansible.builtin.command:
|
||||
argv: [zfs, snapshot, "{{ atlas_gitea_migration_snapshot }}"]
|
||||
|
||||
- name: Transfer only the Gitea dataset to admin
|
||||
ansible.builtin.file:
|
||||
path: "{{ atlas_gitea_mountpoint }}"
|
||||
state: directory
|
||||
owner: "{{ atlas_admin_username }}"
|
||||
group: "{{ atlas_admin_group }}"
|
||||
recurse: true
|
||||
|
||||
- name: Set the actual internal Unix process user
|
||||
ansible.builtin.lineinfile:
|
||||
path: "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
||||
regexp: '^RUN_USER\s*='
|
||||
line: RUN_USER = gitea
|
||||
mode: "0600"
|
||||
no_log: true
|
||||
diff: false
|
||||
|
||||
- name: Preserve public git clone URLs independently of the Unix user
|
||||
community.general.ini_file:
|
||||
path: "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
||||
section: server
|
||||
option: "{{ item }}"
|
||||
value: git
|
||||
mode: "0600"
|
||||
no_extra_spaces: false
|
||||
loop: [BUILTIN_SSH_SERVER_USER, SSH_USER]
|
||||
no_log: true
|
||||
diff: false
|
||||
|
||||
- name: Render admin's loopback-only staging Quadlet
|
||||
ansible.builtin.template:
|
||||
src: atlas-gitea.container.j2
|
||||
dest: "{{ atlas_gitea_quadlet_dir }}/atlas-gitea.container"
|
||||
owner: "{{ atlas_admin_username }}"
|
||||
group: "{{ atlas_admin_group }}"
|
||||
mode: "0644"
|
||||
vars:
|
||||
atlas_gitea_production_enabled: false
|
||||
|
||||
- name: Reload the admin user manager for staging
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
scope: user
|
||||
daemon_reload: true
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
|
||||
- name: Start admin's loopback-only staging service
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: started
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
|
||||
- name: Verify staging HTTP before promotion
|
||||
ansible.builtin.uri:
|
||||
url: "http://127.0.0.1:{{ atlas_gitea_staging_http_port }}/"
|
||||
status_code: 200
|
||||
register: atlas_gitea_staging_http
|
||||
retries: 30
|
||||
delay: 2
|
||||
until: atlas_gitea_staging_http is succeeded
|
||||
|
||||
- name: Verify the container really runs as internal gitea
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.command:
|
||||
argv: [podman, exec, atlas-gitea, id, -un]
|
||||
environment:
|
||||
HOME: "{{ atlas_admin_home }}"
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
register: atlas_gitea_internal_user
|
||||
changed_when: false
|
||||
failed_when: atlas_gitea_internal_user.stdout != 'gitea'
|
||||
|
||||
- name: Verify the migrated SQLite database
|
||||
ansible.builtin.command:
|
||||
argv:
|
||||
- sqlite3
|
||||
- "{{ atlas_gitea_mountpoint }}/data/gitea/gitea.db"
|
||||
- PRAGMA quick_check;
|
||||
register: atlas_gitea_migration_sqlite
|
||||
changed_when: false
|
||||
failed_when: atlas_gitea_migration_sqlite.stdout != 'ok'
|
||||
|
||||
rescue:
|
||||
- name: Stop admin's failed staging service
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: stopped
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
failed_when: false
|
||||
|
||||
- name: Restore the original Gitea configuration from the safety snapshot
|
||||
ansible.builtin.command:
|
||||
argv:
|
||||
- cp
|
||||
- -a
|
||||
- "{{ atlas_gitea_mountpoint }}/.zfs/snapshot/{{ atlas_gitea_migration_snapshot.split('@')[1] }}/config/app.ini"
|
||||
- "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
||||
when: atlas_gitea_migration_snapshot is defined
|
||||
|
||||
- name: Return the Gitea dataset to the legacy account
|
||||
ansible.builtin.file:
|
||||
path: "{{ atlas_gitea_mountpoint }}"
|
||||
state: directory
|
||||
owner: "{{ atlas_gitea_legacy_username }}"
|
||||
group: "{{ atlas_gitea_legacy_username }}"
|
||||
recurse: true
|
||||
|
||||
- name: Restart the legacy Gitea service
|
||||
become_user: "{{ atlas_gitea_legacy_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: started
|
||||
enabled: true
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_gitea_legacy_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_gitea_legacy_uid }}/bus"
|
||||
|
||||
- name: Report the failed migration and preserved snapshot
|
||||
ansible.builtin.fail:
|
||||
msg: >-
|
||||
Admin staging failed; legacy Gitea was restarted. Inspect
|
||||
{{ atlas_gitea_migration_snapshot | default('the host journal') }}.
|
||||
|
||||
- name: Stop admin's validated staging service
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: stopped
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
|
||||
- name: Render admin's production Gitea Quadlet
|
||||
ansible.builtin.template:
|
||||
src: atlas-gitea.container.j2
|
||||
dest: "{{ atlas_gitea_quadlet_dir }}/atlas-gitea.container"
|
||||
owner: "{{ atlas_admin_username }}"
|
||||
group: "{{ atlas_admin_group }}"
|
||||
mode: "0644"
|
||||
vars:
|
||||
atlas_gitea_production_enabled: true
|
||||
|
||||
- name: Reload admin's production user manager
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
scope: user
|
||||
daemon_reload: true
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
|
||||
- name: Enable and start admin's production Gitea
|
||||
become_user: "{{ atlas_admin_username }}"
|
||||
ansible.builtin.systemd:
|
||||
name: atlas-gitea.service
|
||||
scope: user
|
||||
state: started
|
||||
enabled: true
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_admin_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_admin_uid }}/bus"
|
||||
|
||||
- name: Verify production HTTP before retiring the old Quadlet
|
||||
ansible.builtin.uri:
|
||||
url: "http://{{ atlas_gitea_bind_address }}:{{ atlas_gitea_http_port }}/"
|
||||
status_code: 200
|
||||
register: atlas_gitea_production_http
|
||||
retries: 30
|
||||
delay: 2
|
||||
until: atlas_gitea_production_http is succeeded
|
||||
|
||||
- name: Remove only the disabled legacy Quadlet
|
||||
ansible.builtin.file:
|
||||
path: "{{ atlas_gitea_legacy_home }}/.config/containers/systemd/atlas-gitea.container"
|
||||
state: absent
|
||||
|
||||
- name: Reload the legacy user manager after Quadlet removal
|
||||
become_user: "{{ atlas_gitea_legacy_username }}"
|
||||
ansible.builtin.systemd:
|
||||
scope: user
|
||||
daemon_reload: true
|
||||
environment:
|
||||
XDG_RUNTIME_DIR: "/run/user/{{ atlas_gitea_legacy_uid }}"
|
||||
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_gitea_legacy_uid }}/bus"
|
||||
@@ -14,6 +14,9 @@
|
||||
- name: Import Atlas storage tasks
|
||||
ansible.builtin.import_tasks: storage.yml
|
||||
|
||||
- name: Import explicit Atlas Gitea owner migration
|
||||
ansible.builtin.import_tasks: gitea_owner_migration.yml
|
||||
|
||||
- name: Import staged Atlas rootless Gitea tasks
|
||||
ansible.builtin.import_tasks: gitea.yml
|
||||
|
||||
|
||||
Reference in New Issue
Block a user