From f97e0374fbdaff7cf200ba47858e4e6fc25cda43 Mon Sep 17 00:00:00 2001 From: patkarcarasent <143094465+patkarcarasent@users.noreply.github.com> Date: Thu, 2 May 2024 11:41:52 +0200 Subject: Update cloud-init.rst Added additional documentation regarding the need to use "exec sg vyattacfg" to run script as the correct group, to avoid configuration pitfalls. --- docs/automation/cloud-init.rst | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'docs') diff --git a/docs/automation/cloud-init.rst b/docs/automation/cloud-init.rst index bbc8967c..354abd05 100644 --- a/docs/automation/cloud-init.rst +++ b/docs/automation/cloud-init.rst @@ -156,6 +156,12 @@ can execute commands and then configure VyOS in the same script. The following example sets the hostname based on the instance identifier obtained from the EC2 metadata service. +Please observe that the same configuration pitfall described in :ref:`command-scripting` +exists here when running ``configure`` in any context as without user group +'vyattacfg' will cause the error message ``Set failed`` to appear. +We therefor need to wrap it and have the script re-execute itself with the correct +group permissions. + .. code-block:: yaml @@ -166,6 +172,9 @@ obtained from the EC2 metadata service. permissions: '0775' content: | #!/bin/vbash + if [ "$(id -g -n)" != 'vyattacfg' ] ; then + exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) $@" + fi source /opt/vyatta/etc/functions/script-template hostname=`curl -s http://169.254.169.254/latest/meta-data/instance-id` configure -- cgit v1.2.3 From a60de82f58745375b697f190c02135fea433bd76 Mon Sep 17 00:00:00 2001 From: patkarcarasent <143094465+patkarcarasent@users.noreply.github.com> Date: Mon, 6 May 2024 08:31:31 +0200 Subject: Update cloud-init.rst fixed spelling error --- docs/automation/cloud-init.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/automation/cloud-init.rst b/docs/automation/cloud-init.rst index 354abd05..20b6dc49 100644 --- a/docs/automation/cloud-init.rst +++ b/docs/automation/cloud-init.rst @@ -159,7 +159,7 @@ obtained from the EC2 metadata service. Please observe that the same configuration pitfall described in :ref:`command-scripting` exists here when running ``configure`` in any context as without user group 'vyattacfg' will cause the error message ``Set failed`` to appear. -We therefor need to wrap it and have the script re-execute itself with the correct +We therefore need to wrap it and have the script re-execute itself with the correct group permissions. .. code-block:: yaml -- cgit v1.2.3