7d91337447
The file permissions for {{ gitea_home }} especially in conjunction with the recurse: true flag are on closer inspection very open to all and also have a +x set on files. This should be done better. And I have done here now. By the way: To improve the -x on normal files in his gitea installation this shell command was useful for me ``` find . -type f -exec chmod a-x {} \+; find . -type f -exec chmod u=rwX {} \+; ```
79 lines
1.7 KiB
YAML
79 lines
1.7 KiB
YAML
---
|
|
|
|
- name: "Check gitea version"
|
|
shell: "set -eo pipefail; /usr/local/bin/gitea -v | cut -d' ' -f 3"
|
|
args:
|
|
executable: /bin/bash
|
|
register: gitea_active_version
|
|
changed_when: false
|
|
failed_when: false
|
|
when: gitea_version_check|bool
|
|
|
|
- name: "Download the binary"
|
|
get_url:
|
|
url: "{{ gitea_dl_url }}"
|
|
dest: /usr/local/bin/gitea
|
|
owner: root
|
|
group: root
|
|
mode: 0755
|
|
force: true
|
|
notify: "Restart gitea"
|
|
when: (not gitea_version_check|bool) or (not ansible_check_mode and (gitea_active_version.stdout != gitea_version))
|
|
|
|
- include: create_user.yml
|
|
|
|
- name: "Create config directory"
|
|
file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
owner: "{{ gitea_user }}"
|
|
group: "{{ gitea_group }}"
|
|
mode: '0755'
|
|
with_items:
|
|
- "/etc/gitea"
|
|
|
|
- name: "Create data directory"
|
|
file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
owner: "{{ gitea_user }}"
|
|
group: "{{ gitea_group }}"
|
|
mode: 'u=rwX,g=rX,o='
|
|
recurse: true
|
|
with_items:
|
|
- "{{ gitea_home }}"
|
|
- "{{ gitea_home }}/data"
|
|
- "{{ gitea_home }}/custom"
|
|
- "{{ gitea_home }}/custom/https"
|
|
- "{{ gitea_home }}/custom/mailer"
|
|
- "{{ gitea_home }}/indexers"
|
|
- "{{ gitea_home }}/log"
|
|
|
|
- include: install_systemd.yml
|
|
when: ansible_service_mgr == "systemd"
|
|
|
|
- name: 'Install git'
|
|
package:
|
|
name: 'git'
|
|
state: 'present'
|
|
|
|
- include_tasks: jwt_secrets.yml
|
|
|
|
- name: "Configure gitea"
|
|
template:
|
|
src: gitea.ini.j2
|
|
dest: /etc/gitea/gitea.ini
|
|
owner: "{{ gitea_user }}"
|
|
group: "{{ gitea_group }}"
|
|
mode: 0600
|
|
notify: "Restart gitea"
|
|
|
|
- name: "Service gitea"
|
|
service:
|
|
name: gitea
|
|
state: started
|
|
enabled: true
|
|
when: ansible_service_mgr == "systemd"
|
|
|
|
- include: fail2ban.yml
|
|
when: gitea_fail2ban_enabled|bool
|