fix(agent): unify agent and openresty runtime user as openflare

Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
This commit is contained in:
ryan
2026-06-21 14:25:20 +08:00
parent ee047cb351
commit d3777eac2d
17 changed files with 505 additions and 55 deletions
+9
View File
@@ -16,6 +16,7 @@ import (
"github.com/Rain-kl/Wavelet/internal/apps/agent/httpclient"
"github.com/Rain-kl/Wavelet/internal/apps/agent/logging"
"github.com/Rain-kl/Wavelet/internal/apps/agent/nginx"
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
"github.com/Rain-kl/Wavelet/internal/apps/agent/state"
syncservice "github.com/Rain-kl/Wavelet/internal/apps/agent/sync"
"github.com/Rain-kl/Wavelet/internal/apps/agent/updater"
@@ -33,6 +34,14 @@ func main() {
slog.Error("load agent config failed", "error", err)
os.Exit(1)
}
if err = runtimeuser.EnsureProcessUser(); err != nil {
slog.Error("ensure runtime user failed", "error", err)
os.Exit(1)
}
if err = runtimeuser.EnsurePathOwnership(cfg.DataDir, runtimeuser.DefaultDirPerm, runtimeuser.DefaultFilePerm); err != nil {
slog.Error("ensure data dir ownership failed", "error", err, "data_dir", cfg.DataDir)
os.Exit(1)
}
cfg.ExtVersion = nginx.DetectVersion(
context.Background(),
nginx.ExecutorOptions{