瀏覽代碼

Merge pull request #115 from Plailect/master

Start appservice-irc as non-root
pull/116/head
Slavi Pantaleev 7 年之前
committed by GitHub
父節點
當前提交
70bc532285
沒有發現已知的金鑰在資料庫的簽署中 GPG 金鑰 ID: 4AEE18F83AFDEB23
共有 2 個檔案被更改,包括 13 行新增1 行删除
  1. +11
    -0
      roles/matrix-synapse/tasks/ext/appservice-irc/setup.yml
  2. +2
    -1
      roles/matrix-synapse/templates/ext/appservice-irc/systemd/matrix-appservice-irc.service.j2

+ 11
- 0
roles/matrix-synapse/tasks/ext/appservice-irc/setup.yml 查看文件

@@ -54,6 +54,8 @@
- name: Generate matrix-appservice-irc registration.yaml if it doesn't exist - name: Generate matrix-appservice-irc registration.yaml if it doesn't exist
shell: >- shell: >-
/usr/bin/docker run --rm --name matrix-appservice-irc-gen /usr/bin/docker run --rm --name matrix-appservice-irc-gen
--user={{ matrix_user_uid }}:{{ matrix_user_gid }} \
--cap-drop=ALL \
-v {{ matrix_appservice_irc_base_path }}:/data:z -v {{ matrix_appservice_irc_base_path }}:/data:z
{{ matrix_appservice_irc_docker_image }} {{ matrix_appservice_irc_docker_image }}
node app.js node app.js
@@ -82,6 +84,15 @@
{{ ["{{ matrix_synapse_app_service_config_file_appservice_irc }}"] | to_nice_json }} {{ ["{{ matrix_synapse_app_service_config_file_appservice_irc }}"] | to_nice_json }}
when: "matrix_appservice_irc_enabled" when: "matrix_appservice_irc_enabled"


- name: Ensure IRC configuration directory permissions are correct
file:
path: "{{ matrix_appservice_irc_base_path }}"
state: directory
owner: "{{ matrix_user_username }}"
group: "{{ matrix_user_username }}"
recurse: true
when: "matrix_appservice_irc_enabled"

# #
# Tasks related to getting rid of matrix-appservice-irc (if it was previously enabled) # Tasks related to getting rid of matrix-appservice-irc (if it was previously enabled)
# #


+ 2
- 1
roles/matrix-synapse/templates/ext/appservice-irc/systemd/matrix-appservice-irc.service.j2 查看文件

@@ -11,7 +11,8 @@ ExecStartPre=-/usr/bin/docker kill matrix-appservice-irc
ExecStartPre=-/usr/bin/docker rm matrix-appservice-irc ExecStartPre=-/usr/bin/docker rm matrix-appservice-irc
ExecStart=/usr/bin/docker run --rm --name matrix-appservice-irc \ ExecStart=/usr/bin/docker run --rm --name matrix-appservice-irc \
--log-driver=none \ --log-driver=none \
-e "UID={{ matrix_user_uid }}" -e "GID={{ matrix_user_gid }}" \
--user={{ matrix_user_uid }}:{{ matrix_user_gid }} \
--cap-drop=ALL \
--network={{ matrix_docker_network }} \ --network={{ matrix_docker_network }} \
{% if matrix_appservice_irc_container_expose_client_server_api_port %} {% if matrix_appservice_irc_container_expose_client_server_api_port %}
-p 127.0.0.1:9999:9999 \ -p 127.0.0.1:9999:9999 \


Loading…
取消
儲存