fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
This commit is contained in:
@@ -128,6 +128,28 @@ generate_exclude_yaml() {
|
||||
} > "${out}"
|
||||
}
|
||||
|
||||
# Seed the Kanidm unixd service account token from the KANIDM_UNIXD_TOKEN
|
||||
# environment variable (a CI secret). The token is added to the image, so treat
|
||||
# the image as sensitive: anyone who can pull it can read the token.
|
||||
seed_kanidm_token() {
|
||||
local dir="$1"
|
||||
local out="${dir}/kanidm-token.yaml"
|
||||
if [[ -n "${KANIDM_UNIXD_TOKEN:-}" ]]; then
|
||||
printf '%s\n' "${KANIDM_UNIXD_TOKEN}" > "${dir}/kanidm-unixd-token"
|
||||
chmod 0600 "${dir}/kanidm-unixd-token"
|
||||
cat > "${out}" <<'EOF'
|
||||
# Generated by build.sh from the KANIDM_UNIXD_TOKEN secret.
|
||||
add-files:
|
||||
- ["kanidm-unixd-token", "/etc/kanidm/unixd_token"]
|
||||
EOF
|
||||
else
|
||||
cat > "${out}" <<'EOF'
|
||||
# Generated by build.sh: no Kanidm token seeded (KANIDM_UNIXD_TOKEN unset).
|
||||
add-files: []
|
||||
EOF
|
||||
fi
|
||||
}
|
||||
|
||||
case "${BUILD_MODE}" in
|
||||
upstream)
|
||||
[[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; }
|
||||
@@ -160,6 +182,8 @@ case "${BUILD_MODE}" in
|
||||
"${BUILD_DIR}/upstream/hardware-exclude.yaml"
|
||||
fi
|
||||
|
||||
seed_kanidm_token "${BUILD_DIR}/upstream"
|
||||
|
||||
MANIFEST="${BUILD_DIR}/upstream/manifest.yaml"
|
||||
;;
|
||||
standalone)
|
||||
@@ -188,6 +212,7 @@ ref: ${REF}
|
||||
include:
|
||||
- manifest.yaml
|
||||
EOF
|
||||
seed_kanidm_token "${local_dir}"
|
||||
MANIFEST="${local_dir}/.build-manifest.yaml"
|
||||
;;
|
||||
*)
|
||||
|
||||
Reference in New Issue
Block a user