mastodon: Adjust directory permissions

This patch reduces the permissions on the install directory to just the root user and also fixes the ansible-lint issue by specifying the `mode`.
For all container mounted volumes, the ansible-lint rule is disabled, as the container takes care of the permissions etc.
This commit is contained in:
saibotk 2020-09-26 21:36:25 +02:00
parent 22302117fa
commit 1d7d56814e
No known key found for this signature in database
GPG key ID: A3299C587D5DF523

View file

@ -36,12 +36,15 @@
file:
path: "{{ item }}"
state: directory
mode: '0700'
owner: 'root'
group: 'root'
with_items:
- "{{ mastodon_install_location }}"
become: true
- name: Create data directories
file:
file: # noqa 208 # Container manages permissions on its own
path: "{{ item }}"
state: directory
setype: "container_file_t"
@ -56,8 +59,9 @@
- name: Create public data directory
file:
path: "{{ mastodon_public_location }}/system"
owner: "991"
group: "991"
mode: '0755'
owner: '991'
group: '991'
state: directory
setype: "container_file_t"
become: true