fix(agent): unify agent and openresty runtime user as openflare

Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
This commit is contained in:
ryan
2026-06-21 14:25:20 +08:00
parent ee047cb351
commit d3777eac2d
17 changed files with 505 additions and 55 deletions
+8
View File
@@ -25,7 +25,15 @@ const (
anubisAPIPrefix = "/.within.website/x/cmd/anubis/api/"
)
// OpenFlareRuntimeUser is the dedicated service account shared by the agent
// process and OpenResty worker processes.
const OpenFlareRuntimeUser = "openflare"
// OpenRestyWorkerUser is kept as an alias for existing call sites.
const OpenRestyWorkerUser = OpenFlareRuntimeUser
const defaultMainConfigTemplate = `# This file is generated by OpenFlare. Do not edit manually.
user ` + OpenFlareRuntimeUser + `;
worker_processes {{OpenRestyWorkerProcesses}};
worker_rlimit_nofile {{OpenRestyWorkerRlimitNofile}};
pid logs/nginx.pid;