From 83fd2be145e3278b29a56c5b44483dddabdf9521 Mon Sep 17 00:00:00 2001 From: Sam Date: Mon, 20 Jul 2026 15:46:53 -0700 Subject: [PATCH] setup.sh: don't chmod -R 777 the postgres tree -- breaks re-deploys Blanket 777 over an existing PGDATA makes psql_server.key world-accessible; postgres refuses to boot (FATAL: private key file has group or world access) and the whole core cascades down. Fresh installs were unaffected since the key is generated after the chmod. Skip postgres/ (the image entrypoint owns its perms) and re-tighten the key/cert if a prior run already clobbered them. Co-Authored-By: Claude Fable 5 --- setup.sh | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/setup.sh b/setup.sh index 650cfdc..bdcb5f9 100755 --- a/setup.sh +++ b/setup.sh @@ -107,7 +107,24 @@ for d in config grafana grafana/provisioning kafka-data zk-data zk-log \ $SUDO mkdir -p "$OBMP_DATA_ROOT/$d" done # Container processes run as assorted UIDs; lab-permissive perms. -$SUDO chmod -R 777 "$OBMP_DATA_ROOT" 2>/dev/null || true +# EXCEPT postgres/: postgres enforces its own perms and refuses to start if +# its SSL key is group/world-accessible. A blanket 777 over an EXISTING data +# tree makes psql_server.key 0777 -> FATAL on every re-deploy (fresh installs +# are unaffected because the key is generated after this runs). Leave the +# postgres tree alone; the image entrypoint owns it. +for _p in "$OBMP_DATA_ROOT"/*; do + [ "$(basename "$_p")" = "postgres" ] && continue + $SUDO chmod -R 777 "$_p" 2>/dev/null || true +done +# Postgres bind dirs just need to exist and be reachable; the container +# entrypoint chowns/chmods PGDATA itself on init. +$SUDO chmod 777 "$OBMP_DATA_ROOT" "$OBMP_DATA_ROOT/postgres" 2>/dev/null || true +# Repair the re-deploy damage if a previous setup.sh already clobbered an +# initialized data dir: re-tighten the SSL key/cert so postgres will boot. +if [ -f "$OBMP_DATA_ROOT/postgres/data/psql_server.key" ]; then + $SUDO chmod 600 "$OBMP_DATA_ROOT/postgres/data/psql_server.key" \ + "$OBMP_DATA_ROOT/postgres/data/psql_server.crt" 2>/dev/null || true +fi # --- Grafana provisioning + dashboards -------------------------------------- # Provisioning YAML points Grafana at /var/lib/grafana/dashboards/... (bind-