adapt role: the image should not be run as root, but with user with id 82.

This commit is contained in:
2026-05-15 15:15:24 +02:00
parent 8ccb88503a
commit 0dcd51b601
5 changed files with 12 additions and 23 deletions
+1 -1
View File
@@ -54,5 +54,5 @@ default_chill:
# jwt_public_key: '1234'
rabbitmq_user: 'chilldev'
# rabbitmq_password:
editor_server: 'https://collabora.samusocial.be'
editor_server: 'https://collabora.champs-libres.be'
ovhcloud_dsn: 'null://null'
+4 -4
View File
@@ -42,15 +42,15 @@
ansible.builtin.file:
path: "{{ install_dir }}/{{ chill['chill_environment'] }}/config/prod"
state: directory
owner: "{{ as_user }}"
mode: '0400'
owner: "82"
mode: '0500'
- name: Copy configuration files
ansible.builtin.template:
src: "config/prod/{{ file }}"
dest: "{{ install_dir }}/{{ chill['chill_environment'] }}/config/prod/{{ file }}"
owner: "{{ as_user }}"
mode: '0444'
owner: "82"
mode: '0400'
loop:
- lexik_jwt_authentication.yaml
- messenger.yaml
+1 -1
View File
@@ -73,7 +73,7 @@ services:
sleep 3 && bin/console cache:clear &&
while ! [ -f /tmp/kill_me ];
do
su -p -s /bin/bash -c 'php -d memory_limit=2G bin/console messenger:consume priority async --limit=20 --time-limit=600 -v' "www-data";
php -d memory_limit=2G bin/console messenger:consume priority async --limit=40 --time-limit=600 -v;
done;
pre_stop:
- command:
+2 -4
View File
@@ -29,11 +29,9 @@ monolog:
type: stream
path: "%kernel.logs_dir%/default-%log_prefix%.log"
level: info
channels: [ '!event', '!doctrine', '!console', '!chill' ]
channels: [ '!event', '!doctrine', '!console', '!chill', '!deprecation']
deprecation_log:
type: stream
path: "%kernel.logs_dir%/deprecation-%log_prefix%.log"
level: info
type: 'null'
channels: [ 'deprecation' ]
console:
type: console
+4 -13
View File
@@ -1,26 +1,17 @@
/var/log/chill/default-*.log {
/var/log/chill/*.log {
su php-fpm php-fpm
rotate 90
daily
compress
missingok
notifempty
copytruncate
rotate 90
}
/var/log/chill/privacy-*.log {
su php-fpm php-fpm
rotate 180
daily
compress
missingok
notifempty
}
/var/log/chill/notifier-*.log {
su php-fpm php-fpm
rotate 800
daily
compress
missingok
notifempty
}
}