Commit Graph
2 Commits
Author SHA1 Message Date
m3ta-chiron 6c9cb7b0e7 fix: atrocore-env ownership for atrocore-db-init (AZ-NIX-ava.2)
First deploy failed: atrocore-db-init (User=postgres) could not read
/run/agenix/atrocore-env because agenix defaults to root:root:0400.
Follow the pg-cert/pg-key precedent: owner/group postgres, mode 0400.
Podman still reads the env-file and registry token as root (root
bypasses DAC), container pull/run unaffected. Agenix applies
ownership at activation time - no rekey needed. Validated on AZ-PRM-1.
2026-08-17 14:16:09 +02:00
m3ta-chiron f1481dc256 feat: AtroPIM deployment config for AZ-PRM-1 (AZ-NIX-ava.2)
- port registry: atrocore = 3058
- oci-container atrocore: Gitea-registry image, 127.0.0.1:3058:80,
  web network, static ip 10.89.0.16, db alias to host pg, env-file
  from agenix, named volume for instance data, registry login via
  token secret
- agenix secrets: atrocore-env (ATRO_DB_*) + atrocore-registry-token,
  age-encrypted to AZ-PRM-1 + user, non-interactive creation
- host postgres 17: idempotent atrocore-db-init oneshot (psql peer,
  secret only at runtime), pg_hba 10.89.0.0/24 scram-sha-256,
  atrocore in 03:10 backup list
- traefik: pim.l.az-gruppe.com -> localhost:3058 (ionos, websecure)
2026-08-17 13:45:21 +02:00