fix(terraform): restore the dump app.ini with the database

INTERNAL_TOKEN, JWT_SECRET, and LFS_JWT_SECRET live in that file. A restore that keeps the generated file cannot decrypt the dumped secrets.
This commit is contained in:
Adam Moussa 2026-09-29 19:59:54 -04:00
parent 494b63439f
commit dd23f08878
No known key found for this signature in database
2 changed files with 16 additions and 0 deletions

View file

@ -147,6 +147,11 @@ if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then
echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2
exit 1
fi
if [ -f /var/lib/forgejo/.restore/app.ini ]; then
cp /var/lib/forgejo/.restore/app.ini /etc/forgejo/app.ini
chown root:forgejo /etc/forgejo/app.ini
chmod 660 /etc/forgejo/app.ini
fi
chown -R forgejo:forgejo /var/lib/forgejo
systemctl start forgejo
rm -rf /var/lib/forgejo/.restore
@ -189,6 +194,11 @@ if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then
echo "Restore did not produce /var/lib/forgejo/data/forgejo.db" >&2
exit 1
fi
if [ -f /var/lib/forgejo/.restore/app.ini ]; then
cp /var/lib/forgejo/.restore/app.ini /etc/forgejo/app.ini
chown root:forgejo /etc/forgejo/app.ini
chmod 660 /etc/forgejo/app.ini
fi
chown -R forgejo:forgejo /var/lib/forgejo
systemctl start forgejo
rm -rf /var/lib/forgejo/.restore

View file

@ -136,6 +136,12 @@ if [ ! -f /var/lib/forgejo/data/forgejo.db ]; then
if [ -d "$RESTORE_DIR/custom" ]; then
cp -a "$RESTORE_DIR"/custom/. /var/lib/forgejo/custom/
fi
# The dump's app.ini carries INTERNAL_TOKEN, JWT_SECRET, and LFS_JWT_SECRET.
if [ -f "$RESTORE_DIR/app.ini" ]; then
cp "$RESTORE_DIR/app.ini" /etc/forgejo/app.ini
chown root:forgejo /etc/forgejo/app.ini
chmod 660 /etc/forgejo/app.ini
fi
chown -R forgejo:forgejo /var/lib/forgejo
rm -rf "$RESTORE_DIR"
if [ ! -s /var/lib/forgejo/data/forgejo.db ]; then