Compare commits

...
Author SHA1 Message Date
müde
d8b05a9eb9 scripts: forge-create-user.sh wrapper
one-liner-as-a-script: `forge-create-user.sh mara --admin`. wraps
the nixos-container run + runuser + --work-path dance + sensible
defaults (random password, no force-change, email = <user>@hive.local)
so copy-paste line-continuations don't bite.
2026-05-17 00:43:02 +02:00
müde
2b076f8ce4 forge: pass --work-path to admin CLI so app.ini is found
without --work-path, forgejo's admin CLI defaults WorkPath to the
binary's directory (RO nix store), can't find custom/conf/app.ini
there, falls back to defaults, and F3 init mkdir-fails inside the
store. systemd unit sets WORK_PATH for the daemon; mirror it here
for every nixos-container-driven 'forgejo admin' invocation.
2026-05-17 00:42:03 +02:00
2 changed files with 55 additions and 1 deletions

View file

@ -66,7 +66,26 @@ async fn forge_admin(args: &[&str]) -> Result<String> {
// `runuser` (util-linux, always present in a NixOS container)
// beats `sudo` here — sudo isn't installed unless `security.sudo`
// is enabled, and we don't want to depend on that.
cmd.args(["run", FORGE_CONTAINER, "--", "runuser", "-u", "forgejo", "--", "forgejo", "admin"]);
//
// `--work-path` is mandatory: without it, the admin CLI defaults
// WorkPath to `dirname(executable)` (a RO nix-store path), then
// looks for `<WorkPath>/custom/conf/app.ini` which doesn't
// exist, falls back to defaults, and F3 init tries to mkdir
// under the nix store and fatals. The systemd unit sets
// WORK_PATH for the daemon; we mirror it here for the CLI.
cmd.args([
"run",
FORGE_CONTAINER,
"--",
"runuser",
"-u",
"forgejo",
"--",
"forgejo",
"--work-path",
"/var/lib/forgejo",
"admin",
]);
cmd.args(args);
let out = cmd
.output()

35
scripts/forge-create-user.sh Executable file
View file

@ -0,0 +1,35 @@
#!/usr/bin/env bash
# Create a Forgejo user in the hive-forge container.
#
# Usage: forge-create-user.sh <username> [--admin] [--email <addr>] [--password <pw>]
#
# Defaults: --random-password, --must-change-password=false, email = <user>@hive.local.
# Requires: sudo, the hive-forge nixos-container running.
set -euo pipefail
if [ $# -lt 1 ]; then
echo "usage: $0 <username> [--admin] [--email <addr>] [--password <pw>]" >&2
exit 2
fi
username="$1"; shift
email="${username}@hive.local"
admin=()
password_args=(--random-password)
while [ $# -gt 0 ]; do
case "$1" in
--admin) admin=(--admin); shift ;;
--email) email="$2"; shift 2 ;;
--password) password_args=(--password "$2"); shift 2 ;;
*) echo "unknown arg: $1" >&2; exit 2 ;;
esac
done
sudo nixos-container run hive-forge -- runuser -u forgejo -- \
forgejo --work-path /var/lib/forgejo admin user create \
--username "$username" \
--email "$email" \
--must-change-password=false \
"${password_args[@]}" \
"${admin[@]}"