risotto is started with a specific user

This commit is contained in:
Emmanuel Garette 2020-09-19 07:11:36 +02:00
parent 709538e4e4
commit 58ebb8e1ad
6 changed files with 31 additions and 42 deletions

View File

@ -3,7 +3,6 @@
<files> <files>
<service>risotto</service> <service>risotto</service>
<file filelist='risotto' name='/etc/risotto/risotto.conf' mkdir='True' rm='True'/> <file filelist='risotto' name='/etc/risotto/risotto.conf' mkdir='True' rm='True'/>
<file filelist='risotto' name='/etc/systemd/system/risotto.service' mkdir='True' rm='True'/>
<file filelist='risotto' name='/etc/eole/eole-db.d/risotto.yml' mkdir='True' rm='True'/> <file filelist='risotto' name='/etc/eole/eole-db.d/risotto.yml' mkdir='True' rm='True'/>
<file filelist='risotto' name='/etc/eole/eole-db.d/tiramisu.yml' mkdir='True' rm='True'/> <file filelist='risotto' name='/etc/eole/eole-db.d/tiramisu.yml' mkdir='True' rm='True'/>
</files> </files>
@ -37,30 +36,14 @@
<value>/usr/share/risotto-message/messages</value> <value>/usr/share/risotto-message/messages</value>
</variable> </variable>
<variable name='risotto_cache_dir' type='filename' description='Emplacement du cache' hidden='True'> <variable name='risotto_cache_dir' type='filename' description='Emplacement du cache' hidden='True'>
<value>/srv/risotto/cache/risotto</value> <value>/srv/risotto/cache</value>
</variable> </variable>
<variable name='risotto_seed_dir' type='filename' description='Emplacement des descriptions de services' hidden='True'> <variable name='risotto_seed_dir' type='filename' description='Emplacement des descriptions de services' hidden='True'>
<value>/srv/risotto/seed</value> <value>/srv/risotto/seed</value>
</variable> </variable>
<variable name='risotto_factory_configuration_dir' type='filename' description='Emplacement de la configuration du provider factory' hidden='True'> <variable name='risotto_images_dir' type='filename' description='Emplacement des images disques' hidden='True'>
<value>/srv/factory/</value> <value>/srv/risotto/images</value>
</variable> </variable>
</family> </family>
</variables> </variables>
<constraints>
</constraints>
<help>
<variable name='risotto_configuration_dir'>Aide pour la variable risotto_configuration_dir</variable>
<variable name='risotto_temp_dir'>Aide pour la variable risotto_temp_dir</variable>
<variable name='risotto_default_user'>Aide pour la variable risotto_default_user</variable>
<variable name='risotto_main_dbname'>Aide pour la variable risotto_main_dbname</variable>
<variable name='risotto_tiramisu_dbname'>Aide pour la variable risotto_tiramisu_dbname</variable>
<variable name='risotto_db_user'>Aide pour la variable risotto_db_user</variable>
<variable name='risotto_tiramisu_db_user'>Aide pour la variable risotto_tiramisu_db_user</variable>
<variable name='risotto_db_address'>Aide pour la variable risotto_db_address</variable>
<variable name='risotto_messages_dir'>Aide pour la variable risotto_messages_dir</variable>
<variable name='risotto_cache_dir'>Aide pour la variable risotto_cache_dir</variable>
<variable name='risotto_seed_dir'>Aide pour la variable risotto_seed_dir</variable>
<variable name='risotto_factory_configuration_dir'>Aide pour la variable risotto_factory_configuration_dir</variable>
</help>
</creole> </creole>

View File

@ -1,7 +1,8 @@
#!/bin/bash #!/bin/bash
for dir in risotto_messages_dir risotto_cache_dir risotto_seed_dir; do for dir in risotto_cache_dir risotto_seed_dir risotto_temp_dir risotto_configuration_dir risotto_images_dir; do
mkdir -p $(CreoleGet $dir) mkdir -p $(CreoleGet $dir)
chown risotto: $dir
done done
exit 0 exit 0

View File

@ -2,8 +2,9 @@
Description=risotto Description=risotto
[Service] [Service]
EnvironmentFile=/etc/risotto/risotto.conf
ExecStart=/usr/bin/risotto-server ExecStart=/usr/bin/risotto-server
User=risotto
Group=risotto
[Install] [Install]
WantedBy=multi-user.target WantedBy=multi-user.target

View File

@ -1,15 +1,19 @@
CONFIGURATION_DIR=%%getVar('risotto_configuration_dir') CONFIGURATION_DIR=%%risotto_configuration_dir
PROVIDER_FACTORY_CONFIG_DIR=%%getVar('risotto_factory_configuration_dir') TMP_DIR=%%risotto_temp_dir
TMP_DIR=%%getVar('risotto_temp_dir') DEFAULT_USER=%%risotto_default_user
DEFAULT_USER=%%getVar('risotto_default_user') RISOTTO_DB_NAME=%%risotto_main_dbname
RISOTTO_DB_NAME=%%getVar('risotto_main_dbname') RISOTTO_DB_USER=%%risotto_db_user
RISOTTO_DB_USER=%%getVar('risotto_db_user')
RISOTTO_DB_PASSWORD=replace_me RISOTTO_DB_PASSWORD=replace_me
TIRAMISU_DB_NAME=%%getVar('risotto_tiramisu_dbname') TIRAMISU_DB_NAME=%%risotto_tiramisu_dbname
TIRAMISU_DB_USER=%%getVar('risotto_tiramisu_db_user') TIRAMISU_DB_USER=%%risotto_tiramisu_db_user
TIRAMISU_DB_PASSWORD=replace_me TIRAMISU_DB_PASSWORD=replace_me
DB_ADDRESS=%%getVar('risotto_db_address') DB_ADDRESS=%%risotto_db_address
MESSAGE_PATH=%%getVar('risotto_messages_dir') MESSAGE_PATH=%%risotto_messages_dir
CACHE_ROOT_PATH=%%getVar('risotto_cache_dir') CACHE_ROOT_PATH=%%risotto_cache_dir
SRV_SEED_PATH=%%getVar('risotto_seed_dir') SRV_SEED_PATH=%%risotto_seed_dir
PYTHONPATH="/usr/lib/python3.6/dist-packages:$PYTHONPATH" %set %%var = %%getVar('celeryrisotto_db_user', None)
%if not %%is_empty(%%var)
CELERYRISOTTO_DB_NAME=%%celeryrisotto_main_dbname
CELERYRISOTTO_DB_USER=%%var
CELERYRISOTTO_DB_PASSWORD=replace_me
%end if

View File

@ -1,14 +1,14 @@
%from os import listdir %from os import listdir
%set %%dbname = %%getVar('risotto_main_dbname') %set %%dbname = %%risotto_main_dbname
--- ---
dbuser: %%getVar('risotto_db_user') dbuser: %%risotto_db_user
dbuser_options: dbuser_options:
- LOGIN - LOGIN
privileges: privileges:
%%{dbname}.public.*: 'ALL' %%{dbname}.public.*: 'ALL'
%%{dbname}.public: 'ALL' %%{dbname}.public: 'ALL'
%%{dbname}: 'ALL' %%{dbname}: 'ALL'
dbhost: %%getVar('risotto_db_address') dbhost: %%risotto_db_address
dbport: 5432 dbport: 5432
dbtype: postgres dbtype: postgres
dbname: %%dbname dbname: %%dbname

View File

@ -1,16 +1,16 @@
%set %%dbname = %%getVar('risotto_tiramisu_dbname') %set %%dbname = %%risotto_tiramisu_dbname
--- ---
dbuser: %%getVar('risotto_tiramisu_db_user') dbuser: %%risotto_tiramisu_db_user
dbuser_options: dbuser_options:
- LOGIN - LOGIN
privileges: privileges:
%%{dbname}.public.*: 'ALL' %%{dbname}.public.*: 'ALL'
%%{dbname}.public: 'ALL' %%{dbname}.public: 'ALL'
%%{dbname}: 'ALL' %%{dbname}: 'ALL'
dbhost: %%getVar('risotto_db_address') dbhost: %%risotto_db_address
dbport: 5432 dbport: 5432
dbtype: postgres dbtype: postgres
dbname: %%getVar('risotto_tiramisu_dbname') dbname: %%risotto_tiramisu_dbname
template: 'template0' template: 'template0'
pwd_files: pwd_files:
- {'file': '/etc/risotto/risotto.conf', 'pattern': 'TIRAMISU_DB_PASSWORD='} - {'file': '/etc/risotto/risotto.conf', 'pattern': 'TIRAMISU_DB_PASSWORD='}