Add dedicated operator Git identity

This commit is contained in:
Mikei386
2026-08-23 21:18:06 +02:00
parent ed4d5e3315
commit 4287236777
4 changed files with 26 additions and 1 deletions
+13 -1
View File
@@ -14,6 +14,7 @@ import hashlib
import json
import os
import re
import shlex
import shutil
import socketserver
import subprocess
@@ -70,8 +71,19 @@ def compact(text: str) -> str:
def run(argv: list[str], *, cwd: Path = STACK, timeout: int = 900, check: bool = False) -> dict[str, Any]:
environment = {
"PATH": "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
"LANG": "C.UTF-8",
"HOME": "/root",
}
git_key = Path(os.environ.get("ATHENA_OPERATOR_GIT_SSH_KEY", "/etc/mike-ai/athena-operator-git"))
if git_key.is_file():
environment["GIT_SSH_COMMAND"] = (
f"ssh -i {shlex.quote(str(git_key))} -o IdentitiesOnly=yes "
"-o StrictHostKeyChecking=yes"
)
completed = subprocess.run(
argv, cwd=cwd, env={"PATH": "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", "LANG": "C.UTF-8", "HOME": "/root"},
argv, cwd=cwd, env=environment,
stdin=subprocess.DEVNULL, stdout=subprocess.PIPE, stderr=subprocess.STDOUT,
text=True, errors="replace", timeout=timeout, check=False,
)
+6
View File
@@ -6,6 +6,12 @@ install -d -m 0700 /etc/mike-ai
if [[ ! -e /etc/mike-ai/athena-operator.env ]]; then
install -m 0600 "$ROOT/config/athena-operator.env.example" /etc/mike-ai/athena-operator.env
fi
if [[ ! -e /etc/mike-ai/athena-operator-git ]]; then
ssh-keygen -q -t ed25519 -N '' -C athena-operator \
-f /etc/mike-ai/athena-operator-git
fi
chmod 0600 /etc/mike-ai/athena-operator-git
chmod 0644 /etc/mike-ai/athena-operator-git.pub
install -d -m 0750 -o root -g 10003 /run/mike-ai-operator
install -d -m 0700 /data/mike-ai-operator/state /data/mike-ai-operator/repository
install -m 0755 "$ROOT/platform/operator/athena_operatord.py" /usr/local/libexec/mike-ai-athena-operatord