X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/23d8f4f4043479c3cbd43239bc2ab2e20dd87eb8..d6a7b1ff202f827f02addc259a5c9dbc3638d056:/cookbooks/planet/recipes/replication.rb diff --git a/cookbooks/planet/recipes/replication.rb b/cookbooks/planet/recipes/replication.rb index e09bbcbe6..d719d11ae 100644 --- a/cookbooks/planet/recipes/replication.rb +++ b/cookbooks/planet/recipes/replication.rb @@ -22,6 +22,7 @@ require "yaml" include_recipe "accounts" include_recipe "apt" include_recipe "osmosis" +include_recipe "planet::aws" include_recipe "ruby" include_recipe "tools" @@ -162,13 +163,8 @@ systemd_service "users-agreed" do user "planet" exec_start "/usr/local/bin/users-agreed" nice 10 - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true read_write_paths "/store/planet/users_agreed" - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "users-agreed" do @@ -181,13 +177,8 @@ systemd_service "users-deleted" do user "planet" exec_start "/usr/local/bin/users-deleted" nice 10 - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true read_write_paths "/store/planet/users_deleted" - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "users-deleted" do @@ -215,16 +206,13 @@ systemd_service "replication-changesets" do description "Changesets replication" user "planet" exec_start "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf" - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true + protect_home "tmpfs" + bind_paths "/home/planet" read_write_paths [ "/run/replication", "/store/planet/replication/changesets" ] - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "replication-changesets" do @@ -280,18 +268,14 @@ systemd_service "replication-minutely" do user "planet" working_directory "/etc/replication" exec_start "/usr/local/bin/replicate-minute" - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true + protect_home "tmpfs" + bind_paths "/home/planet" read_write_paths [ "/run/replication", - "/store/replication/minute", - "/store/planet/replication/minute", + "/store", "/var/lib/replication/minute" ] - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "replication-minutely" do @@ -330,22 +314,20 @@ end systemd_service "replication-hourly" do description "Hourly replication" user "planet" - exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/hour" + exec_start "/usr/local/bin/replicate-hour" environment "LD_PRELOAD" => "/opt/flush/flush.so" - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true + memory_deny_write_execute false + protect_home "tmpfs" + bind_paths "/home/planet" read_write_paths [ "/store/planet/replication/hour", "/var/lib/replication/hour" ] - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "replication-hourly" do - description "Daily replication" + description "Hourly replication" on_calendar "*-*-* *:02/15:00" end @@ -378,18 +360,16 @@ end systemd_service "replication-daily" do description "Daily replication" user "planet" - exec_start "/usr/local/bin/osmosis -q --merge-replication-files workingDirectory=/var/lib/replication/day" + exec_start "/usr/local/bin/replicate-day" environment "LD_PRELOAD" => "/opt/flush/flush.so" - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true + memory_deny_write_execute false + protect_home "tmpfs" + bind_paths "/home/planet" read_write_paths [ "/store/planet/replication/day", "/var/lib/replication/day" ] - restrict_address_families %w[AF_INET AF_INET6] - no_new_privileges true end systemd_timer "replication-daily" do @@ -403,13 +383,8 @@ systemd_service "replication-cleanup" do description "Cleanup replication" user "planet" exec_start "/usr/local/bin/replicate-cleanup" - private_tmp true - private_devices true - private_network true - protect_system "strict" - protect_home true + sandbox true read_write_paths "/var/lib/replication" - no_new_privileges true end systemd_timer "replication-cleanup" do