hive-gateway: chmod cert parent dir so nginx worker can traverse
Parent /var/lib/hive-gateway came out 0700, blocking the nginx-user worker from reaching the 0755 tls/ subdir and surfacing as a generic cert-load failure at nginx start.
This commit is contained in:
parent
b0495c5167
commit
d10f7d4c13
1 changed files with 12 additions and 4 deletions
|
|
@ -441,10 +441,18 @@ in
|
||||||
''
|
''
|
||||||
set -eu
|
set -eu
|
||||||
mkdir -p ${tlsDir}
|
mkdir -p ${tlsDir}
|
||||||
# 0755 dir so nginx (master starts as root but workers
|
# 0755 on BOTH the cert dir and its parent so nginx
|
||||||
# drop to the nginx user) can traverse to read the cert
|
# (master starts as root but workers drop to the nginx
|
||||||
# path. Re-applied every boot in case a prior run left
|
# user) can traverse the whole path to read the cert.
|
||||||
# a tighter mode behind. Key stays 0600 below.
|
# The parent `/var/lib/hive-gateway` lands at 0700 by
|
||||||
|
# default (systemd-nspawn StateDirectory / mkdir umask
|
||||||
|
# depending on which service created it first), which
|
||||||
|
# blocks the nginx-user worker from even reaching
|
||||||
|
# `${tlsDir}` and surfaces as a generic "cannot load
|
||||||
|
# certificate" at nginx start. Re-applied every boot
|
||||||
|
# in case a prior run left a tighter mode behind. Key
|
||||||
|
# stays 0600 below.
|
||||||
|
chmod 0755 ${builtins.dirOf tlsDir}
|
||||||
chmod 0755 ${tlsDir}
|
chmod 0755 ${tlsDir}
|
||||||
# Generate the cert when EITHER the cert or key is
|
# Generate the cert when EITHER the cert or key is
|
||||||
# missing/empty, OR the cert fails an openssl parse —
|
# missing/empty, OR the cert fails an openssl parse —
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue