# limitations under the License.
#
+include_recipe "accounts"
include_recipe "git"
-include_recipe "awscli"
+include_recipe "planet::aws"
db_passwords = data_bag_item("db", "passwords")
systemd_service "planet-notes-dump" do
description "Create notes dump"
exec_start "/usr/local/bin/planet-notes-dump"
- user "www-data"
+ user "planet"
sandbox :enable_network => true
+ protect_home "tmpfs"
+ bind_paths "/home/planet"
read_write_paths "/store/planet/notes"
end
systemd_service "planet-notes-cleanup" do
description "Delete old notes dumps"
exec_start "/usr/local/bin/planet-notes-cleanup"
- user "www-data"
+ user "planet"
sandbox true
read_write_paths "/store/planet/notes"
end