Make Hermes secret permissions idempotent

This commit is contained in:
Mikei386
2026-08-25 10:25:52 +02:00
parent 221f88c939
commit 4a260ae7d7
+8 -2
View File
@@ -18,9 +18,15 @@ install -d -m 0750 "$HERMES_DATA_DIR/workspace"
[[ -s $SECRETS_DIR/hermes-api-key ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-api-key" [[ -s $SECRETS_DIR/hermes-api-key ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-api-key"
[[ -s $SECRETS_DIR/hermes-dashboard-password ]] || openssl rand -base64 24 >"$SECRETS_DIR/hermes-dashboard-password" [[ -s $SECRETS_DIR/hermes-dashboard-password ]] || openssl rand -base64 24 >"$SECRETS_DIR/hermes-dashboard-password"
[[ -s $SECRETS_DIR/hermes-dashboard-secret ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-dashboard-secret" [[ -s $SECRETS_DIR/hermes-dashboard-secret ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-dashboard-secret"
chmod 0600 "$SECRETS_DIR/hermes-api-key" \ for secret in \
"$SECRETS_DIR/hermes-api-key" \
"$SECRETS_DIR/hermes-dashboard-password" \ "$SECRETS_DIR/hermes-dashboard-password" \
"$SECRETS_DIR/hermes-dashboard-secret" "$SECRETS_DIR/hermes-dashboard-secret"; do
# The Athena operator receives /etc/mike-ai read-only. A managed secret that
# is already mode 0600 needs no write at all, which keeps this installer
# safely idempotent both interactively and through the operator.
[[ $(stat -c '%a' "$secret") == 600 ]] || chmod 0600 "$secret"
done
router_key=$(<"$SECRETS_DIR/router-api-key") router_key=$(<"$SECRETS_DIR/router-api-key")
mua_url=http://127.0.0.1:9/mcp mua_url=http://127.0.0.1:9/mcp