justfile: harden and normalize move to _helper scripts #304
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!304
Loading…
Reference in a new issue
No description provided.
Delete branch "refactor/justfile-scripts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
hardenandnormalizewere most of the justfile: two long bash bodies with guards, loops and the comments that explain the permission model, sitting in a file whose job is to be scannable. Nothing said where recipe logic should live, so the file grew that way.Fix
Both move to
_helper/harden.shand_helper/normalize.sh, bodies and guards unchanged, and the recipes wrap them the waydeploywrapsdeploy.py. One comment in normalize now states the constraint (a general chmod sweep reaches acme.json, grafana.db and PGDATA) instead of the incident. CONTRIBUTING gains a Justfile section: a recipe is its comment line and an invocation; logic beyond a few lines is a script under_helper/.Verification
just hardenunprivileged: the root guard fires with the same message, exit 1.just normalizeandsudo just hardenon the live tree: both print their summary line, no errors.just --listunchanged. Justfile 172 lines, from ~250.