fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
This commit is contained in:
@@ -93,3 +93,12 @@ postprocess:
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
semanage permissive -a unconfined_service_t || true
|
||||
|
||||
# Lock down the Kanidm service account token if it was seeded at build time.
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
if [[ -f /etc/kanidm/unixd_token ]]; then
|
||||
chown root:root /etc/kanidm/unixd_token
|
||||
chmod 0600 /etc/kanidm/unixd_token
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user