Skip to content

Commit

Permalink
Allow to run services with custom user
Browse files Browse the repository at this point in the history
In some envs, archivematica needs to run with an user different than
"archivematica"

This pr adds two configuration default to allow so:
  - archivematica_src_am_system_user
  - archivematica_src_am_system_group
  - archivematica_src_ss_system_user
  - archivematica_src_ss_system_group
  • Loading branch information
scollazo committed Apr 5, 2022
1 parent 63079c7 commit fda8517
Show file tree
Hide file tree
Showing 15 changed files with 51 additions and 46 deletions.
5 changes: 5 additions & 0 deletions defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,11 @@ archivematica_src_install_fixity: "no"
archivematica_src_search_enabled: "yes"
archivematica_src_am_mcpclient_instances: 1

# System Users
archivematica_src_am_system_user: "archivematica"
archivematica_src_am_system_group: "archivematica"
archivematica_src_ss_system_user: "archivematica"
archivematica_src_ss_system_group: "archivematica"
#Components to configure
archivematica_src_configure_dashboard: "no"
archivematica_src_configure_ss: "no"
Expand Down
4 changes: 2 additions & 2 deletions tasks/automation-tools.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@
file:
dest: "{{ item }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_user }}"
with_items:
- "/var/log/archivematica/automation-tools"
- "/var/archivematica/automation-tools"
Expand Down
8 changes: 4 additions & 4 deletions tasks/configure-gpg.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@
executable: "/bin/bash"
register: "gpg_key_already_exist"
become: "yes"
become_user: "archivematica"
become_user: "{{ archivematica_src_ss_system_user }}"
ignore_errors: "yes"

- name: "Create GPG key when doesn't exist"
Expand All @@ -63,7 +63,7 @@
print(key)
register: "gpg_fingerprint"
become: "yes"
become_user: "archivematica"
become_user: "{{ archivematica_src_ss_system_user }}"
when: gpg_key_already_exist.rc != 0

- name: "Create GPG Space (new key)"
Expand Down Expand Up @@ -119,8 +119,8 @@
- name: "Create directories for GPG locations"
file:
path: "{{ item }}"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
mode: "0755"
state: "directory"
become: "yes"
Expand Down
6 changes: 3 additions & 3 deletions tasks/configure.yml
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@

- name: "Create ssh key"
user:
name: "archivematica"
name: "{{ archivematica_src_am_system_user }}"
generate_ssh_key: "yes"
ssh_key_file: ".ssh/id_rsa"
when: archivematica_src_configure_dashboardsettings is defined
Expand All @@ -161,8 +161,8 @@
lineinfile:
create: "yes"
path: "/var/lib/archivematica/.ssh/config"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
mode: "0600"
line: "StrictHostKeyChecking no"
when: archivematica_src_configure_dashboardsettings is defined
Expand Down
16 changes: 8 additions & 8 deletions tasks/fixity.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,25 +28,25 @@
file:
path: "{{ archivematica_src_fixity_virtualenv }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
recurse: "yes"

- name: "Create config file"
template:
src: "etc/sysconfig/fixity.j2"
dest: "{{ systemd_environment_path }}/fixity"
mode: 0640
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"

- name: "Create log dir"
file:
path: "/var/log/archivematica/fixity/"
state: "directory"
mode: 0750
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"

- name: "Create fixity script"
template:
Expand All @@ -66,7 +66,7 @@
hour: "3"
day: "1"
month: "*/3"
user: "archivematica"
user: "{{ archivematica_src_ss_system_user }}"
cron_file: "fixity"
state: "present"

Expand All @@ -76,5 +76,5 @@
env: yes
value: "/bin/bash"
cron_file: "fixity"
user: "archivematica"
user: "{{ archivematica_src_ss_system_user }}"
state: "present"
4 changes: 2 additions & 2 deletions tasks/pipeline-environment.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,8 @@
file:
dest: "{{ archivematica_src_shareddir }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
mode: "0755"
when: "archivematica_src_reset_shareddir|bool or archivematica_src_reset_am_all|bool"

Expand Down
6 changes: 3 additions & 3 deletions tasks/pipeline-instcode.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,16 +44,16 @@
file:
dest: "{{ archivematica_src_dir }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
recurse: "yes"
with_items:
- "{{ archivematica_src_dir }}/archivematica/src/dashboard/src/media"
- "{{ archivematica_src_dir }}/archivematica/src/dashboard/frontend"

- name: "Install front-end dependencies"
become: "yes"
become_user: "archivematica"
become_user: "{{ archivematica_src_am_system_user }}"
command: npm install
args:
chdir: "{{ item }}"
Expand Down
14 changes: 7 additions & 7 deletions tasks/pipeline-osconf.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,8 +44,8 @@
file:
dest: "{{ archivematica_src_shareddir }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
when: "create_shareddir"

# (this is required because some hardcoding of the shared dir remains in archivematica code)
Expand Down Expand Up @@ -77,8 +77,8 @@
file:
dest: "{{ item }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
mode: "g+s"
with_items:
- "{{ archivematica_src_dashboard_logdir }}"
Expand All @@ -90,7 +90,7 @@
file:
dest: "{{ item }}"
state: "directory"
owner: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "syslog"
mode: "g+w"
with_items:
Expand All @@ -100,8 +100,8 @@
- name: "Touch log files"
file:
path: "{{ item }}"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_am_system_user }}"
group: "{{ archivematica_src_am_system_group }}"
state: "touch"
with_items:
- "{{ archivematica_src_dashboard_logdir }}/dashboard.log"
Expand Down
4 changes: 2 additions & 2 deletions tasks/ss-db.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,8 @@
- name: "Fix DB permissions"
file:
dest: "{{ archivematica_src_ss_environment['SS_DB_NAME'] }}"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
mode: "u=rwX,g=rwX,o=rX"
when: "archivematica_src_ss_environment['SS_DB_URL'] is not defined"

Expand Down
12 changes: 6 additions & 6 deletions tasks/ss-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -97,8 +97,8 @@
file:
dest: "{{ item }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
with_items:
- "/var/archivematica/storage-service"
tags: "amsrc-ss-osconf"
Expand All @@ -115,17 +115,17 @@
file:
dest: "{{ archivematica_src_ss_logdir }}"
state: "directory"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
mode: "g+s"
tags: "amsrc-ss-osconf"
when: "archivematica_src_logging_backward_compatible|bool"

- name: "Touch SS log files"
file:
path: "{{ archivematica_src_ss_logdir }}/{{ item }}"
owner: "archivematica"
group: "archivematica"
owner: "{{ archivematica_src_ss_system_user }}"
group: "{{ archivematica_src_ss_system_group }}"
state: "touch"
with_items:
- "storage_service.log"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,8 @@ StartLimitBurst=5

[Service]
PIDFile=/run/archivematica-dashboard_gunicorn.pid
User=archivematica
Group=archivematica
User={{ archivematica_src_am_system_user }}
Group={{ archivematica_src_am_system_group }}
EnvironmentFile=-{{ systemd_environment_path }}/archivematica-dashboard
{% if archivematica_src_syslog_enabled|bool %}
StandardOutput=syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ After=syslog.target network.target

[Service]
Type=simple
User=archivematica
Group=archivematica
User={{ archivematica_src_am_system_user }}
Group={{ archivematica_src_am_system_group }}
{% if archivematica_src_am_mcpclient_instances == 1 %}
EnvironmentFile=-{{ systemd_environment_path }}/archivematica-mcp-client
{% else %}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ After=syslog.target network.target mysql.service

[Service]
Type=simple
User=archivematica
Group=archivematica
User={{ archivematica_src_am_system_user }}
Group={{ archivematica_src_am_system_group }}
EnvironmentFile=-{{ systemd_environment_path }}/archivematica-mcp-server
{% if archivematica_src_syslog_enabled|bool %}
StandardOutput=syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ After=network.target

[Service]
PIDFile=/run/archivematica-storage-service_gunicorn.pid
User=archivematica
Group=archivematica
User={{ archivematica_src_ss_system_user }}
Group={{ archivematica_src_ss_system_group }}
EnvironmentFile=-{{ systemd_environment_path }}/archivematica-storage-service
{% if archivematica_src_syslog_enabled|bool %}
StandardOutput=syslog
Expand Down
2 changes: 1 addition & 1 deletion templates/etc/systemd/system/fits-nailgun.service.j2
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ Description=FITS Nailgun server
After=syslog.target network.target

[Service]
User=archivematica
User={{ archivematica_src_am_system_user }}
ExecStart=/usr/bin/fits-ngserver.sh /usr/share/maven-repo/com/martiansoftware/nailgun-server/debian/nailgun-server-debian.jar
Restart=always
RestartSec=3
Expand Down

0 comments on commit fda8517

Please sign in to comment.