fix(systemd): ensure 0644 file permissions and document root execution for docker volumes
This commit is contained in:
@@ -256,7 +256,12 @@ function atomicWriteFileSync(filePath, content) {
|
||||
}
|
||||
|
||||
const tmpPath = `${resolvedPath}.tmp.${Date.now()}`
|
||||
fs.writeFileSync(tmpPath, content, 'utf8')
|
||||
fs.writeFileSync(tmpPath, content, { encoding: 'utf8', mode: 0o644 })
|
||||
try {
|
||||
fs.chmodSync(tmpPath, 0o644)
|
||||
} catch {
|
||||
// Ignore chmod errors if not supported or not owner
|
||||
}
|
||||
fs.renameSync(tmpPath, resolvedPath)
|
||||
}
|
||||
|
||||
|
||||
@@ -5,10 +5,13 @@ Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
# Adjust user/paths if needed for your server environment:
|
||||
User=caddy
|
||||
Group=caddy
|
||||
WorkingDirectory=/var/www/orario
|
||||
ExecStart=/usr/bin/node /var/www/orario/scripts/update-semester-data.js --output /var/www/orario/semester-data.json --quiet
|
||||
# NOTE: If your webroot (e.g. orario.volume) is created by Docker (owned by root:root),
|
||||
# run this service as root by leaving User/Group unset (or User=root).
|
||||
# The script automatically writes files with world-readable 0644 permissions so Caddy can read them.
|
||||
# If you prefer running as caddy, ensure 'chown -R caddy:caddy <webroot>' is run after docker builds.
|
||||
# User=caddy
|
||||
# Group=caddy
|
||||
WorkingDirectory=/srv/services/orario
|
||||
ExecStart=/usr/bin/node /srv/services/orario/src/scripts/update-semester-data.js --output /srv/services/orario/orario.volume/semester-data.json --quiet
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
|
||||
Reference in New Issue
Block a user