Files
AI-Profile-Router/platform/operator/install-operator.sh
T

36 lines
1.7 KiB
Bash
Executable File

#!/usr/bin/env bash
set -Eeuo pipefail
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
ROOT=$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)
install -d -m 0700 /etc/mike-ai
if [[ ! -e /etc/mike-ai/athena-operator.env ]]; then
install -m 0600 "$ROOT/config/athena-operator.env.example" /etc/mike-ai/athena-operator.env
fi
if [[ ! -e /etc/mike-ai/athena-operator-git ]]; then
ssh-keygen -q -t ed25519 -N '' -C athena-operator \
-f /etc/mike-ai/athena-operator-git
fi
chmod 0600 /etc/mike-ai/athena-operator-git
chmod 0644 /etc/mike-ai/athena-operator-git.pub
install -m 0644 "$ROOT/config/athena-operator-known-hosts" \
/etc/mike-ai/athena-operator-known-hosts
install -d -m 0750 -o root -g 10003 /run/mike-ai-operator
install -d -m 0700 /data/mike-ai-operator/state /data/mike-ai-operator/staging
[[ -d "$ROOT/.git" ]] || {
echo "Der laufende Stack muss ein Git-Checkout sein: $ROOT" >&2
exit 1
}
# Read-only MCP containers need to traverse the stack directory. Secrets are
# stored separately in /etc/mike-ai and are not exposed by this permission.
chmod 0755 "$ROOT"
install -m 0755 "$ROOT/platform/operator/athena_operatord.py" /usr/local/libexec/mike-ai-athena-operatord
install -m 0644 "$ROOT/platform/operator/athena-operator.service" /etc/systemd/system/mike-ai-athena-operator.service
systemctl daemon-reload
systemctl enable mike-ai-athena-operator.service
# The unit may already be active during an in-place upgrade. `enable --now`
# does not reload a running process after its executable was replaced, which
# would leave the MCP facade and executor on different protocol versions.
systemctl restart mike-ai-athena-operator.service
systemctl is-active --quiet mike-ai-athena-operator.service
echo ATHENA_OPERATOR_EXECUTOR_OK