fix: atrocore-env ownership for atrocore-db-init (AZ-NIX-ava.2)
First deploy failed: atrocore-db-init (User=postgres) could not read /run/agenix/atrocore-env because agenix defaults to root:root:0400. Follow the pg-cert/pg-key precedent: owner/group postgres, mode 0400. Podman still reads the env-file and registry token as root (root bypasses DAC), container pull/run unaffected. Agenix applies ownership at activation time - no rekey needed. Validated on AZ-PRM-1.
This commit is contained in:
@@ -7,6 +7,9 @@ in {
|
||||
{
|
||||
atrocore-env = {
|
||||
file = ../../secrets/atrocore-env.age;
|
||||
owner = "postgres";
|
||||
group = "postgres";
|
||||
mode = "0400";
|
||||
};
|
||||
atrocore-registry-token = {
|
||||
file = ../../secrets/atrocore-registry-token.age;
|
||||
|
||||
Reference in New Issue
Block a user