Make Hermes secret permissions idempotent
This commit is contained in:
@@ -18,9 +18,15 @@ install -d -m 0750 "$HERMES_DATA_DIR/workspace"
|
|||||||
[[ -s $SECRETS_DIR/hermes-api-key ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-api-key"
|
[[ -s $SECRETS_DIR/hermes-api-key ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-api-key"
|
||||||
[[ -s $SECRETS_DIR/hermes-dashboard-password ]] || openssl rand -base64 24 >"$SECRETS_DIR/hermes-dashboard-password"
|
[[ -s $SECRETS_DIR/hermes-dashboard-password ]] || openssl rand -base64 24 >"$SECRETS_DIR/hermes-dashboard-password"
|
||||||
[[ -s $SECRETS_DIR/hermes-dashboard-secret ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-dashboard-secret"
|
[[ -s $SECRETS_DIR/hermes-dashboard-secret ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-dashboard-secret"
|
||||||
chmod 0600 "$SECRETS_DIR/hermes-api-key" \
|
for secret in \
|
||||||
|
"$SECRETS_DIR/hermes-api-key" \
|
||||||
"$SECRETS_DIR/hermes-dashboard-password" \
|
"$SECRETS_DIR/hermes-dashboard-password" \
|
||||||
"$SECRETS_DIR/hermes-dashboard-secret"
|
"$SECRETS_DIR/hermes-dashboard-secret"; do
|
||||||
|
# The Athena operator receives /etc/mike-ai read-only. A managed secret that
|
||||||
|
# is already mode 0600 needs no write at all, which keeps this installer
|
||||||
|
# safely idempotent both interactively and through the operator.
|
||||||
|
[[ $(stat -c '%a' "$secret") == 600 ]] || chmod 0600 "$secret"
|
||||||
|
done
|
||||||
|
|
||||||
router_key=$(<"$SECRETS_DIR/router-api-key")
|
router_key=$(<"$SECRETS_DIR/router-api-key")
|
||||||
mua_url=http://127.0.0.1:9/mcp
|
mua_url=http://127.0.0.1:9/mcp
|
||||||
|
|||||||
Reference in New Issue
Block a user