docs(terraform): keep optional restore copies from aborting under set -e

if/fi matches user_data.sh. The file comment now says forgejo-services versions also go through the org-account role.
This commit is contained in:
Adam Moussa 2026-09-29 19:53:28 -04:00
parent 2541cd934c
commit 494b63439f
No known key found for this signature in database
2 changed files with 36 additions and 13 deletions

View file

@ -125,13 +125,24 @@ if [ ! -s /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && [ ! -s /var/lib/forgej
exit 1
fi
systemctl stop forgejo
[ -d /var/lib/forgejo/.restore/data ] && cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/
if [ -d /var/lib/forgejo/.restore/data ]; then
cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/
fi
rm -rf /var/lib/forgejo/data/repositories
mkdir -p /var/lib/forgejo/data/repositories
[ -d /var/lib/forgejo/.restore/repos ] && cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/
[ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db
[ -d /var/lib/forgejo/.restore/lfs ] && mkdir -p /var/lib/forgejo/data/lfs && cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/
[ -d /var/lib/forgejo/.restore/custom ] && cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/
if [ -d /var/lib/forgejo/.restore/repos ]; then
cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/
fi
if [ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ]; then
cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db
fi
if [ -d /var/lib/forgejo/.restore/lfs ]; then
mkdir -p /var/lib/forgejo/data/lfs
cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/
fi
if [ -d /var/lib/forgejo/.restore/custom ]; then
cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/
fi
if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then
echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2
exit 1
@ -156,13 +167,24 @@ if [ ! -s /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && [ ! -s /var/lib/forgej
exit 1
fi
systemctl stop forgejo
[ -d /var/lib/forgejo/.restore/data ] && cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/
if [ -d /var/lib/forgejo/.restore/data ]; then
cp -a /var/lib/forgejo/.restore/data/. /var/lib/forgejo/data/
fi
rm -rf /var/lib/forgejo/data/repositories
mkdir -p /var/lib/forgejo/data/repositories
[ -d /var/lib/forgejo/.restore/repos ] && cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/
[ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ] && cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db
[ -d /var/lib/forgejo/.restore/lfs ] && mkdir -p /var/lib/forgejo/data/lfs && cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/
[ -d /var/lib/forgejo/.restore/custom ] && cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/
if [ -d /var/lib/forgejo/.restore/repos ]; then
cp -a /var/lib/forgejo/.restore/repos/. /var/lib/forgejo/data/repositories/
fi
if [ -f /var/lib/forgejo/.restore/gitea-db.sqlite3 ]; then
cp /var/lib/forgejo/.restore/gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db
fi
if [ -d /var/lib/forgejo/.restore/lfs ]; then
mkdir -p /var/lib/forgejo/data/lfs
cp -a /var/lib/forgejo/.restore/lfs/. /var/lib/forgejo/data/lfs/
fi
if [ -d /var/lib/forgejo/.restore/custom ]; then
cp -a /var/lib/forgejo/.restore/custom/. /var/lib/forgejo/custom/
fi
if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then
echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2
exit 1

View file

@ -13,9 +13,10 @@
# 4. Point TFC_AWS_* at hcptf-forgejo / hcptf-forgejo-plan.
# 5. Re-run the script without --allow-workspace.
# 6. Second Manual apply creates the instance, buckets, ALB, and Lambda.
# Later edits to these hcptf-* inline policies need the same window.
# DenySelfMutation blocks PutRolePolicy on hcptf-* from the scoped role.
# Do not add StringLike on bootstrap trust. CreatePolicy stays on hcptf-bootstrap.
# Later edits to hcptf-* inline policies and to policy/tf-managed/forgejo-services
# need the org-account role. The scoped role cannot PutRolePolicy or
# CreatePolicyVersion. Do not add StringLike on bootstrap trust.
# CreatePolicy stays on hcptf-bootstrap.
data "aws_iam_policy_document" "hcptf_apply_trust" {
statement {