fix(systemd): ensure 0644 file permissions and document root execution for docker volumes

This commit is contained in:
2026-09-22 15:28:04 +02:00
parent 3a5633d92f
commit ea7356ba13
2 changed files with 14 additions and 6 deletions
+6 -1
View File
@@ -256,7 +256,12 @@ function atomicWriteFileSync(filePath, content) {
}
const tmpPath = `${resolvedPath}.tmp.${Date.now()}`
fs.writeFileSync(tmpPath, content, 'utf8')
fs.writeFileSync(tmpPath, content, { encoding: 'utf8', mode: 0o644 })
try {
fs.chmodSync(tmpPath, 0o644)
} catch {
// Ignore chmod errors if not supported or not owner
}
fs.renameSync(tmpPath, resolvedPath)
}
+8 -5
View File
@@ -5,10 +5,13 @@ Wants=network-online.target
[Service]
Type=oneshot
# Adjust user/paths if needed for your server environment:
User=caddy
Group=caddy
WorkingDirectory=/var/www/orario
ExecStart=/usr/bin/node /var/www/orario/scripts/update-semester-data.js --output /var/www/orario/semester-data.json --quiet
# NOTE: If your webroot (e.g. orario.volume) is created by Docker (owned by root:root),
# run this service as root by leaving User/Group unset (or User=root).
# The script automatically writes files with world-readable 0644 permissions so Caddy can read them.
# If you prefer running as caddy, ensure 'chown -R caddy:caddy <webroot>' is run after docker builds.
# User=caddy
# Group=caddy
WorkingDirectory=/srv/services/orario
ExecStart=/usr/bin/node /srv/services/orario/src/scripts/update-semester-data.js --output /srv/services/orario/orario.volume/semester-data.json --quiet
StandardOutput=journal
StandardError=journal