Pin Athena operator Gitea transport
This commit is contained in:
@@ -0,0 +1 @@
|
|||||||
|
[192.168.1.2]:33 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBMz8WHIg09GxMuqmeGoGs4lV2lT+vntgarPwoecQHhJ
|
||||||
@@ -4,7 +4,8 @@ ATHENA_OPERATOR_STATE=/data/mike-ai-operator/state
|
|||||||
ATHENA_OPERATOR_MODELS=/data/models
|
ATHENA_OPERATOR_MODELS=/data/models
|
||||||
ATHENA_OPERATOR_SOCKET=/run/mike-ai-operator/operator.sock
|
ATHENA_OPERATOR_SOCKET=/run/mike-ai-operator/operator.sock
|
||||||
ATHENA_OPERATOR_GID=10003
|
ATHENA_OPERATOR_GID=10003
|
||||||
ATHENA_OPERATOR_GIT_REMOTE=git@192.168.1.2:michael/AI-Profile-Router.git
|
ATHENA_OPERATOR_GIT_REMOTE=ssh://git@192.168.1.2:33/michael/AI-Profile-Router.git
|
||||||
ATHENA_OPERATOR_GIT_SSH_KEY=/etc/mike-ai/athena-operator-git
|
ATHENA_OPERATOR_GIT_SSH_KEY=/etc/mike-ai/athena-operator-git
|
||||||
|
ATHENA_OPERATOR_GIT_KNOWN_HOSTS=/etc/mike-ai/athena-operator-known-hosts
|
||||||
ATHENA_OPERATOR_GIT_NAME=Athena Operator
|
ATHENA_OPERATOR_GIT_NAME=Athena Operator
|
||||||
ATHENA_OPERATOR_GIT_EMAIL=athena-operator@localhost
|
ATHENA_OPERATOR_GIT_EMAIL=athena-operator@localhost
|
||||||
|
|||||||
@@ -49,6 +49,10 @@ Für Git-Publishing besitzt Athena ein eigenes Schlüsselpaar unter
|
|||||||
in Gitea als schreibberechtigter Deploy-Key für `AI-Profile-Router` hinterlegt.
|
in Gitea als schreibberechtigter Deploy-Key für `AI-Profile-Router` hinterlegt.
|
||||||
Der private Schlüssel verlässt Athena nicht und wird weder an den MCP-Container
|
Der private Schlüssel verlässt Athena nicht und wird weder an den MCP-Container
|
||||||
noch an das Modell ausgegeben.
|
noch an das Modell ausgegeben.
|
||||||
|
Der Gitea-Endpunkt ist als `ssh://...:33/...` konfiguriert; sein auf dem
|
||||||
|
Administrator-Mac verifizierter Ed25519-Hostschlüssel ist in
|
||||||
|
`config/athena-operator-known-hosts` fest gebunden. Ein unerwarteter
|
||||||
|
Hostschlüsselwechsel stoppt Git-Zugriffe, statt ihn still zu akzeptieren.
|
||||||
|
|
||||||
TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis
|
TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis
|
||||||
`/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen
|
`/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen
|
||||||
|
|||||||
@@ -77,9 +77,11 @@ def run(argv: list[str], *, cwd: Path = STACK, timeout: int = 900, check: bool =
|
|||||||
"HOME": "/root",
|
"HOME": "/root",
|
||||||
}
|
}
|
||||||
git_key = Path(os.environ.get("ATHENA_OPERATOR_GIT_SSH_KEY", "/etc/mike-ai/athena-operator-git"))
|
git_key = Path(os.environ.get("ATHENA_OPERATOR_GIT_SSH_KEY", "/etc/mike-ai/athena-operator-git"))
|
||||||
|
known_hosts = Path(os.environ.get("ATHENA_OPERATOR_GIT_KNOWN_HOSTS", "/etc/mike-ai/athena-operator-known-hosts"))
|
||||||
if git_key.is_file():
|
if git_key.is_file():
|
||||||
environment["GIT_SSH_COMMAND"] = (
|
environment["GIT_SSH_COMMAND"] = (
|
||||||
f"ssh -i {shlex.quote(str(git_key))} -o IdentitiesOnly=yes "
|
f"ssh -i {shlex.quote(str(git_key))} -o IdentitiesOnly=yes "
|
||||||
|
f"-o UserKnownHostsFile={shlex.quote(str(known_hosts))} "
|
||||||
"-o StrictHostKeyChecking=yes"
|
"-o StrictHostKeyChecking=yes"
|
||||||
)
|
)
|
||||||
completed = subprocess.run(
|
completed = subprocess.run(
|
||||||
|
|||||||
@@ -12,6 +12,8 @@ if [[ ! -e /etc/mike-ai/athena-operator-git ]]; then
|
|||||||
fi
|
fi
|
||||||
chmod 0600 /etc/mike-ai/athena-operator-git
|
chmod 0600 /etc/mike-ai/athena-operator-git
|
||||||
chmod 0644 /etc/mike-ai/athena-operator-git.pub
|
chmod 0644 /etc/mike-ai/athena-operator-git.pub
|
||||||
|
install -m 0644 "$ROOT/config/athena-operator-known-hosts" \
|
||||||
|
/etc/mike-ai/athena-operator-known-hosts
|
||||||
install -d -m 0750 -o root -g 10003 /run/mike-ai-operator
|
install -d -m 0750 -o root -g 10003 /run/mike-ai-operator
|
||||||
install -d -m 0700 /data/mike-ai-operator/state /data/mike-ai-operator/repository
|
install -d -m 0700 /data/mike-ai-operator/state /data/mike-ai-operator/repository
|
||||||
install -m 0755 "$ROOT/platform/operator/athena_operatord.py" /usr/local/libexec/mike-ai-athena-operatord
|
install -m 0755 "$ROOT/platform/operator/athena_operatord.py" /usr/local/libexec/mike-ai-athena-operatord
|
||||||
|
|||||||
Reference in New Issue
Block a user