fix(agent): unify agent and openresty runtime user as openflare

Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
This commit is contained in:
ryan
2026-06-21 14:25:20 +08:00
parent ee047cb351
commit d3777eac2d
17 changed files with 505 additions and 55 deletions
+13 -43
View File
@@ -25,6 +25,7 @@ import (
"github.com/Rain-kl/Wavelet/pkg/utils"
"github.com/Rain-kl/Wavelet/internal/apps/agent/protocol"
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
)
// RuntimeConfigDirPlaceholder is substituted into generated configs at apply time.
@@ -187,6 +188,7 @@ const (
)
const safeDefaultFallbackMainConfig = `# This file is generated by OpenFlare safe default fallback.
user ` + OpenFlareRuntimeUser + `;
worker_processes auto;
pid logs/nginx.pid;
@@ -278,64 +280,32 @@ func (m *Manager) writeTargetFiles(mainConfig string, routeConfig string, suppor
return m.ensureOpenRestyWorkerReadAccess()
}
// ensureOpenRestyWorkerReadAccess makes runtime config and Lua paths traversable by the
// unprivileged OpenResty worker user (typically nobody). Volume mounts may create parent
// directories as 0700 root-owned; MkdirAll does not fix existing modes.
// ensureOpenRestyWorkerReadAccess assigns runtime ownership and normalized modes
// on agent-managed paths so the agent and OpenResty workers share access.
func (m *Manager) ensureOpenRestyWorkerReadAccess() error {
targets := []string{
m.RuntimeConfigDir,
m.LuaDir,
m.PagesDir,
filepath.Dir(m.MainConfigPath),
filepath.Dir(m.RouteConfigPath),
}
if m.AccessLogPath != "" {
targets = append(targets, filepath.Dir(m.AccessLogPath))
}
seen := make(map[string]struct{}, len(targets))
for _, target := range targets {
if err := ensureWorldTraversablePath(target); err != nil {
return err
}
}
if strings.TrimSpace(m.RuntimeConfigDir) == "" {
return nil
}
entries, err := os.ReadDir(m.RuntimeConfigDir)
if err != nil {
if os.IsNotExist(err) {
return nil
}
return err
}
for _, entry := range entries {
if entry.IsDir() {
cleaned := filepath.Clean(strings.TrimSpace(target))
if cleaned == "" || cleaned == "." {
continue
}
path := filepath.Join(m.RuntimeConfigDir, entry.Name())
if chmodErr := os.Chmod(path, nginxConfigFilePerm); chmodErr != nil && !os.IsNotExist(chmodErr) {
return chmodErr
if _, ok := seen[cleaned]; ok {
continue
}
}
return nil
}
func ensureWorldTraversablePath(targetDir string) error {
const maxDepth = 12
current := filepath.Clean(strings.TrimSpace(targetDir))
if current == "" || current == "." {
return nil
}
for depth := 0; depth < maxDepth; depth++ {
if err := os.Chmod(current, nginxDirPerm); err != nil {
if os.IsNotExist(err) || os.IsPermission(err) {
break
}
return fmt.Errorf("chmod %s: %w", current, err)
seen[cleaned] = struct{}{}
if err := runtimeuser.EnsurePathOwnership(cleaned, nginxDirPerm, nginxConfigFilePerm); err != nil {
return err
}
parent := filepath.Dir(current)
if parent == current {
break
}
current = parent
}
return nil
}