systemd files : 644 permissions and owner/group

This commit is contained in:
Jérémy Lecour 2021-09-16 17:25:24 +02:00 committed by Jérémy Lecour
parent c99ba0de82
commit 4275cab72a
10 changed files with 25 additions and 0 deletions

View file

@ -29,6 +29,7 @@ The **patch** part changes incrementally at each release.
* Use python3 modules for Debian 11 and later * Use python3 modules for Debian 11 and later
* Remove embedded GPG keys only if legacy keyring is present * Remove embedded GPG keys only if legacy keyring is present
* systemd files : 644 permissions and owner/group
* apt: remove workaround for Evolix public repositories with Debian 11 * apt: remove workaround for Evolix public repositories with Debian 11
* apt: use the new security repository for Bullseye * apt: use the new security repository for Bullseye
* certbot: silence letsencrypt deprecation warnings * certbot: silence letsencrypt deprecation warnings

View file

@ -70,6 +70,8 @@
copy: copy:
src: docker.conf src: docker.conf
dest: /etc/systemd/system/docker.service.d/ dest: /etc/systemd/system/docker.service.d/
owner: root
group: root
mode: "0644" mode: "0644"
notify: reload systemd notify: reload systemd

View file

@ -60,6 +60,9 @@
template: template:
src: elasticsearch-head.service.j2 src: elasticsearch-head.service.j2
dest: /etc/systemd/system/elasticsearch-head.service dest: /etc/systemd/system/elasticsearch-head.service
owner: root
group: root
mode: "0644"
tags: tags:
- elasticsearch - elasticsearch
- systemd - systemd

View file

@ -3,6 +3,8 @@
copy: copy:
src: log2mail.service src: log2mail.service
dest: /etc/systemd/system/log2mail.service dest: /etc/systemd/system/log2mail.service
owner: root
group: root
mode: "0644" mode: "0644"
- name: Remove log2mail sysvinit service - name: Remove log2mail sysvinit service

View file

@ -168,6 +168,8 @@
src: alert5.service src: alert5.service
dest: /etc/systemd/system/alert5.service dest: /etc/systemd/system/alert5.service
force: yes force: yes
owner: root
group: root
mode: "0644" mode: "0644"
when: when:
- evolinux_system_alert5_init | bool - evolinux_system_alert5_init | bool

View file

@ -28,6 +28,9 @@
copy: copy:
src: memcached@.service src: memcached@.service
dest: /etc/systemd/system/memcached@.service dest: /etc/systemd/system/memcached@.service
owner: root
group: root
mode: "0644"
tags: tags:
- memcached - memcached
when: memcached_instance_name | length > 0 when: memcached_instance_name | length > 0

View file

@ -35,6 +35,9 @@
src: mariadb.systemd.j2 src: mariadb.systemd.j2
dest: /etc/systemd/system/mariadb.service.d/evolinux.conf dest: /etc/systemd/system/mariadb.service.d/evolinux.conf
force: yes force: yes
owner: root
group: root
mode: "0644"
register: mariadb_systemd_override register: mariadb_systemd_override
- name: reload systemd and restart MariaDB - name: reload systemd and restart MariaDB

View file

@ -32,6 +32,9 @@
copy: copy:
src: systemd/spawn-fcgi-munin-graph.service src: systemd/spawn-fcgi-munin-graph.service
dest: /etc/systemd/system/spawn-fcgi-munin-graph.service dest: /etc/systemd/system/spawn-fcgi-munin-graph.service
owner: root
group: root
mode: "0644"
- name: Enable and start Munin-fcgi - name: Enable and start Munin-fcgi
systemd: systemd:

View file

@ -10,6 +10,9 @@
src: postgresql.service.override.conf src: postgresql.service.override.conf
dest: /etc/systemd/system/postgresql@.service.d/override.conf dest: /etc/systemd/system/postgresql@.service.d/override.conf
force: yes force: yes
owner: root
group: root
mode: "0644"
notify: notify:
- reload systemd - reload systemd
- restart postgresql - restart postgresql

View file

@ -19,6 +19,9 @@
template: template:
src: systemd-override.conf.j2 src: systemd-override.conf.j2
dest: /etc/systemd/system/squid.service.d/override.conf dest: /etc/systemd/system/squid.service.d/override.conf
owner: root
group: root
mode: "0644"
force: yes force: yes
register: _squid_systemd_override register: _squid_systemd_override