diff --git a/README.md b/README.md index 28a3d32..2e3dfc5 100644 --- a/README.md +++ b/README.md @@ -125,13 +125,24 @@ if [ ! -s /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && [ ! -s /var/lib/forgej exit 1 fi systemctl stop forgejo -[ -d /var/lib/forgejo/.restore/data ] && cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/ +if [ -d /var/lib/forgejo/.restore/data ]; then + cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/ +fi rm -rf /var/lib/forgejo/data/repositories mkdir -p /var/lib/forgejo/data/repositories -[ -d /var/lib/forgejo/.restore/repos ] && cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/ -[ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db -[ -d /var/lib/forgejo/.restore/lfs ] && mkdir -p /var/lib/forgejo/data/lfs && cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/ -[ -d /var/lib/forgejo/.restore/custom ] && cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/ +if [ -d /var/lib/forgejo/.restore/repos ]; then + cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/ +fi +if [ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ]; then + cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db +fi +if [ -d /var/lib/forgejo/.restore/lfs ]; then + mkdir -p /var/lib/forgejo/data/lfs + cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/ +fi +if [ -d /var/lib/forgejo/.restore/custom ]; then + cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/ +fi if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2 exit 1 @@ -156,13 +167,24 @@ if [ ! -s /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && [ ! -s /var/lib/forgej exit 1 fi systemctl stop forgejo -[ -d /var/lib/forgejo/.restore/data ] && cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/ +if [ -d /var/lib/forgejo/.restore/data ]; then + cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/ +fi rm -rf /var/lib/forgejo/data/repositories mkdir -p /var/lib/forgejo/data/repositories -[ -d /var/lib/forgejo/.restore/repos ] && cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/ -[ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db -[ -d /var/lib/forgejo/.restore/lfs ] && mkdir -p /var/lib/forgejo/data/lfs && cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/ -[ -d /var/lib/forgejo/.restore/custom ] && cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/ +if [ -d /var/lib/forgejo/.restore/repos ]; then + cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/ +fi +if [ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ]; then + cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db +fi +if [ -d /var/lib/forgejo/.restore/lfs ]; then + mkdir -p /var/lib/forgejo/data/lfs + cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/ +fi +if [ -d /var/lib/forgejo/.restore/custom ]; then + cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/ +fi if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2 exit 1 diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index ca243ce..11fb618 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -13,9 +13,10 @@ # 4. Point TFC_AWS_* at hcptf-forgejo / hcptf-forgejo-plan. # 5. Re-run the script without --allow-workspace. # 6. Second Manual apply creates the instance, buckets, ALB, and Lambda. -# Later edits to these hcptf-* inline policies need the same window. -# DenySelfMutation blocks PutRolePolicy on hcptf-* from the scoped role. -# Do not add StringLike on bootstrap trust. CreatePolicy stays on hcptf-bootstrap. +# Later edits to hcptf-* inline policies and to policy/tf-managed/forgejo-services +# need the org-account role. The scoped role cannot PutRolePolicy or +# CreatePolicyVersion. Do not add StringLike on bootstrap trust. +# CreatePolicy stays on hcptf-bootstrap. data "aws_iam_policy_document" "hcptf_apply_trust" { statement {