fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
Build containers / fedora-cosmic (44) (push) Successful in 13m9s
Build containers / fedora-cosmic (rawhide) (push) Successful in 17m18s

build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the
secret is set, via a generated add-files include. Without the secret the image
is built unchanged and the token must be provisioned on the host.
This commit is contained in:
2026-09-21 19:24:15 +02:00
parent d7ca0cae6e
commit 7693e22b08
5 changed files with 39 additions and 0 deletions
+9
View File
@@ -93,3 +93,12 @@ postprocess:
#!/usr/bin/env bash
set -xeuo pipefail
semanage permissive -a unconfined_service_t || true
# Lock down the Kanidm service account token if it was seeded at build time.
- |
#!/usr/bin/env bash
set -xeuo pipefail
if [[ -f /etc/kanidm/unixd_token ]]; then
chown root:root /etc/kanidm/unixd_token
chmod 0600 /etc/kanidm/unixd_token
fi
+2
View File
@@ -30,3 +30,5 @@ include:
- custom.yaml
# Generated by build.sh from upstream-exclude.txt (exclude-packages list).
- hardware-exclude.yaml
# Generated by build.sh; adds the Kanidm unixd token when provided.
- kanidm-token.yaml