Unrelax configuration file permissions

This commit is contained in:
Guido Grazioli 2024-04-17 10:46:23 +02:00
parent 4ba9014edb
commit 1229a0b023
4 changed files with 10 additions and 10 deletions

View file

@ -31,7 +31,7 @@
state: directory state: directory
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0750 mode: '0750'
## check remote archive ## check remote archive
- name: Set download archive path - name: Set download archive path
@ -56,7 +56,7 @@
ansible.builtin.get_url: # noqa risky-file-permissions delegated, uses controller host user ansible.builtin.get_url: # noqa risky-file-permissions delegated, uses controller host user
url: "{{ keycloak_quarkus_download_url }}" url: "{{ keycloak_quarkus_download_url }}"
dest: "{{ local_path.stat.path }}/{{ keycloak.bundle }}" dest: "{{ local_path.stat.path }}/{{ keycloak.bundle }}"
mode: 0640 mode: '0640'
delegate_to: localhost delegate_to: localhost
become: false become: false
run_once: true run_once: true
@ -118,7 +118,7 @@
dest: "{{ archive }}" dest: "{{ archive }}"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0640 mode: '0640'
register: new_version_downloaded register: new_version_downloaded
when: when:
- not archive_path.stat.exists - not archive_path.stat.exists

View file

@ -6,7 +6,7 @@
dest: "{{ keycloak.home }}/providers" dest: "{{ keycloak.home }}/providers"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0640 mode: '0640'
become: true become: true
notify: notify:
- restart keycloak - restart keycloak

View file

@ -27,7 +27,7 @@
dest: "{{ keycloak.home }}/conf/keycloak.conf" dest: "{{ keycloak.home }}/conf/keycloak.conf"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0644 mode: '0640'
become: true become: true
notify: notify:
- rebuild keycloak config - rebuild keycloak config
@ -39,7 +39,7 @@
dest: "{{ keycloak.home }}/conf/quarkus.properties" dest: "{{ keycloak.home }}/conf/quarkus.properties"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0644 mode: '0640'
become: true become: true
notify: notify:
- restart keycloak - restart keycloak
@ -64,7 +64,7 @@
dest: "{{ keycloak.home }}/conf/cache-ispn.xml" dest: "{{ keycloak.home }}/conf/cache-ispn.xml"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0644 mode: '0640'
become: true become: true
notify: notify:
- rebuild keycloak config - rebuild keycloak config
@ -76,7 +76,7 @@
path: "{{ keycloak.log.file | dirname }}" path: "{{ keycloak.log.file | dirname }}"
owner: "{{ keycloak.service_user }}" owner: "{{ keycloak.service_user }}"
group: "{{ keycloak.service_group }}" group: "{{ keycloak.service_group }}"
mode: 0775 mode: '0775'
become: true become: true
- name: Flush pending handlers - name: Flush pending handlers

View file

@ -6,7 +6,7 @@
dest: "{{ keycloak_quarkus_sysconf_file }}" dest: "{{ keycloak_quarkus_sysconf_file }}"
owner: root owner: root
group: root group: root
mode: 0644 mode: '0640'
vars: vars:
keycloak_pkg_java_home: "{{ keycloak_quarkus_pkg_java_home }}" keycloak_pkg_java_home: "{{ keycloak_quarkus_pkg_java_home }}"
notify: notify:
@ -18,7 +18,7 @@
dest: /etc/systemd/system/keycloak.service dest: /etc/systemd/system/keycloak.service
owner: root owner: root
group: root group: root
mode: 0644 mode: '0644'
become: true become: true
register: systemdunit register: systemdunit
notify: notify: