46 lines
2.2 KiB
YAML
46 lines
2.2 KiB
YAML
# Host preparation for albok-service on nh3-docker (2026-10-02). Idempotent.
|
|
# scripts/elway infra-ops@10.100.50.40 --playbook playbooks/albok-service-host.yaml
|
|
# Creates the service identity and read groups with FIXED numeric ids (the contract requires them),
|
|
# and the two local roots owned by uid 1500. The config file itself (it carries the embedder key)
|
|
# is uploaded separately to /srv/albok/etc/albok.yaml: see stacks/albok-service/README.md.
|
|
steps:
|
|
- name: group albok (gid 1500)
|
|
sudo: true
|
|
shell: groupadd --gid 1500 albok
|
|
when: "! getent group albok >/dev/null"
|
|
- name: user albok (uid 1500, no login, no home)
|
|
sudo: true
|
|
shell: useradd --system --uid 1500 --gid 1500 --no-create-home --home-dir /nonexistent --shell /usr/sbin/nologin albok
|
|
when: "! getent passwd albok >/dev/null"
|
|
- name: read group albok-read (gid 1510) — building `fleet`
|
|
sudo: true
|
|
shell: groupadd --gid 1510 albok-read
|
|
when: "! getent group albok-read >/dev/null"
|
|
- name: read group albok-personal (gid 1511) — building `personal`
|
|
sudo: true
|
|
shell: groupadd --gid 1511 albok-personal
|
|
when: "! getent group albok-personal >/dev/null"
|
|
- name: read group albok-feedback (gid 1512) — restricted wing personal/agent-feedback
|
|
sudo: true
|
|
shell: groupadd --gid 1512 albok-feedback
|
|
when: "! getent group albok-feedback >/dev/null"
|
|
- name: store root, private root and config dir (local ext4, never NFS)
|
|
sudo: true
|
|
shell: |
|
|
set -e
|
|
install -d -o 1500 -g 1500 -m 0711 /srv/albok/store
|
|
install -d -o 1500 -g 1500 -m 0700 /srv/albok/private
|
|
install -d -o root -g 1500 -m 0750 /srv/albok/etc
|
|
changed_when: "false"
|
|
|
|
verify:
|
|
- name: ids are the fixed numbers
|
|
shell: |
|
|
test "$(getent passwd albok | cut -d: -f3,4)" = "1500:1500" && test "$(getent group albok-read | cut -d: -f3)" = 1510 && test "$(getent group albok-personal | cut -d: -f3)" = 1511 && test "$(getent group albok-feedback | cut -d: -f3)" = 1512
|
|
changed_when: "false"
|
|
- name: roots are local (not NFS) and owned by 1500
|
|
sudo: true
|
|
shell: |
|
|
test "$(findmnt -T /srv/albok/store -no FSTYPE)" = ext4 && test "$(stat -c %u /srv/albok/store)" = 1500 && test "$(stat -c %u /srv/albok/private)" = 1500
|
|
changed_when: "false"
|