Preserve app gate TLS access through provisioning and certificate rotation

This commit is contained in:
archipelago
2026-10-06 15:19:38 -04:00
parent 719e723816
commit 9f0df2ac44
9 changed files with 200 additions and 2 deletions
+5 -1
View File
@@ -362,6 +362,10 @@ stage_tls() {
[ -s "$TLS_STAGE_KEY" ] && [ -s "$TLS_STAGE_CRT" ] || return 1
tls_pair_matches "$TLS_STAGE_KEY" "$TLS_STAGE_CRT" || return 1
chmod 600 "$TLS_STAGE_KEY"
if getent passwd archipelago >/dev/null 2>&1; then
chgrp "$(id -gn archipelago)" "$TLS_STAGE_KEY" || return 1
chmod 640 "$TLS_STAGE_KEY" || return 1
fi
return 0
}
@@ -376,7 +380,7 @@ stage_ssh() {
swap_tls() {
mv -f "$TLS_STAGE_KEY" "$TLS_KEY" || return 1
mv -f "$TLS_STAGE_CRT" "$TLS_CRT" || return 1
chmod 600 "$TLS_KEY"
# Preserve the staged daemon-readable mode through the atomic rename.
return 0
}