diff --git a/hive-c0re/src/forge.rs b/hive-c0re/src/forge.rs index 3014dce2..d9697763 100644 --- a/hive-c0re/src/forge.rs +++ b/hive-c0re/src/forge.rs @@ -66,7 +66,26 @@ async fn forge_admin(args: &[&str]) -> Result { // `runuser` (util-linux, always present in a NixOS container) // beats `sudo` here — sudo isn't installed unless `security.sudo` // is enabled, and we don't want to depend on that. - cmd.args(["run", FORGE_CONTAINER, "--", "runuser", "-u", "forgejo", "--", "forgejo", "admin"]); + // + // `--work-path` is mandatory: without it, the admin CLI defaults + // WorkPath to `dirname(executable)` (a RO nix-store path), then + // looks for `/custom/conf/app.ini` which doesn't + // exist, falls back to defaults, and F3 init tries to mkdir + // under the nix store and fatals. The systemd unit sets + // WORK_PATH for the daemon; we mirror it here for the CLI. + cmd.args([ + "run", + FORGE_CONTAINER, + "--", + "runuser", + "-u", + "forgejo", + "--", + "forgejo", + "--work-path", + "/var/lib/forgejo", + "admin", + ]); cmd.args(args); let out = cmd .output() diff --git a/scripts/forge-create-user.sh b/scripts/forge-create-user.sh new file mode 100755 index 00000000..827f6fad --- /dev/null +++ b/scripts/forge-create-user.sh @@ -0,0 +1,35 @@ +#!/usr/bin/env bash +# Create a Forgejo user in the hive-forge container. +# +# Usage: forge-create-user.sh [--admin] [--email ] [--password ] +# +# Defaults: --random-password, --must-change-password=false, email = @hive.local. +# Requires: sudo, the hive-forge nixos-container running. +set -euo pipefail + +if [ $# -lt 1 ]; then + echo "usage: $0 [--admin] [--email ] [--password ]" >&2 + exit 2 +fi + +username="$1"; shift +email="${username}@hive.local" +admin=() +password_args=(--random-password) + +while [ $# -gt 0 ]; do + case "$1" in + --admin) admin=(--admin); shift ;; + --email) email="$2"; shift 2 ;; + --password) password_args=(--password "$2"); shift 2 ;; + *) echo "unknown arg: $1" >&2; exit 2 ;; + esac +done + +sudo nixos-container run hive-forge -- runuser -u forgejo -- \ + forgejo --work-path /var/lib/forgejo admin user create \ + --username "$username" \ + --email "$email" \ + --must-change-password=false \ + "${password_args[@]}" \ + "${admin[@]}"