X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/68e068818d559ef35bdf2a138a93596337828ef9..f7628dac50cd43cd44bb4f7e5c343fe990b5af3f:/cookbooks/planet/recipes/notes.rb diff --git a/cookbooks/planet/recipes/notes.rb b/cookbooks/planet/recipes/notes.rb index 3f0e2c996..e63297081 100644 --- a/cookbooks/planet/recipes/notes.rb +++ b/cookbooks/planet/recipes/notes.rb @@ -17,7 +17,9 @@ # limitations under the License. # +include_recipe "accounts" include_recipe "git" +include_recipe "planet::aws" db_passwords = data_bag_item("db", "passwords") @@ -53,8 +55,10 @@ end systemd_service "planet-notes-dump" do description "Create notes dump" exec_start "/usr/local/bin/planet-notes-dump" - user "www-data" + user "planet" sandbox :enable_network => true + protect_home "tmpfs" + bind_paths "/home/planet" read_write_paths "/store/planet/notes" end @@ -77,7 +81,7 @@ end systemd_service "planet-notes-cleanup" do description "Delete old notes dumps" exec_start "/usr/local/bin/planet-notes-cleanup" - user "www-data" + user "planet" sandbox true read_write_paths "/store/planet/notes" end