mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-06 23:56:37 +08:00
fix(agent): unify agent and openresty runtime user as openflare
Introduce the shared openflare service account for the agent process and OpenResty workers, normalize data_dir ownership on startup, and ensure managed paths are chowned with 0755/0644 during sync and apply. Docker entrypoint fixes volume ownership before dropping privileges; local systemd install runs the service as openflare with CAP_NET_BIND_SERVICE.
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
package nginx
|
||||
|
||||
import (
|
||||
openrestyrender "github.com/Rain-kl/Wavelet/pkg/render/openresty"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
|
||||
)
|
||||
|
||||
// OpenFlareRuntimeUser is the shared OS account for the agent process and
|
||||
// OpenResty worker processes.
|
||||
const OpenFlareRuntimeUser = openrestyrender.OpenFlareRuntimeUser
|
||||
|
||||
// OpenRestyWorkerUser is an alias kept for internal call sites.
|
||||
const OpenRestyWorkerUser = OpenFlareRuntimeUser
|
||||
|
||||
// EnsureWorldTraversablePath makes targetDir and its ancestors world-traversable.
|
||||
func EnsureWorldTraversablePath(targetDir string) error {
|
||||
return runtimeuser.EnsurePathOwnership(targetDir, nginxDirPerm, nginxConfigFilePerm)
|
||||
}
|
||||
|
||||
// EnsureWorkerReadableTree normalizes ownership and modes under root for the
|
||||
// shared runtime user.
|
||||
func EnsureWorkerReadableTree(rootDir string) error {
|
||||
return runtimeuser.EnsurePathOwnership(rootDir, nginxDirPerm, nginxConfigFilePerm)
|
||||
}
|
||||
|
||||
// EnsureWorkerReadAccess makes agent-managed runtime paths accessible to the
|
||||
// shared runtime user.
|
||||
func (m *Manager) EnsureWorkerReadAccess() error {
|
||||
return m.ensureOpenRestyWorkerReadAccess()
|
||||
}
|
||||
Reference in New Issue
Block a user