fix: harden owner bootstrap and auth persistence
This commit is contained in:
@@ -94,22 +94,12 @@ jobs:
|
||||
fi
|
||||
|
||||
# ═══════════════════════════════════════════════════
|
||||
# Step 3: Prepare .env from secrets + host .env (safe temp file)
|
||||
# Step 3: Prepare .env from secrets (safe temp file)
|
||||
# ═══════════════════════════════════════════════════
|
||||
- name: Prepare .env (secrets + host .env → temp file)
|
||||
- name: Prepare .env (secrets → temp file)
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
# Read OWNER_PASSWORD from the host's persistent .env
|
||||
HOST_OWNER_PASSWORD=""
|
||||
if [ -f "${DEPLOY_PATH}/.env" ]; then
|
||||
HOST_OWNER_PASSWORD=$(grep '^OWNER_PASSWORD=' "${DEPLOY_PATH}/.env" | cut -d= -f2- || true)
|
||||
fi
|
||||
if [ -z "${HOST_OWNER_PASSWORD}" ]; then
|
||||
echo "❌ OWNER_PASSWORD not found in ${DEPLOY_PATH}/.env"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
cat > "${ENV_TMPFILE}" <<EOF
|
||||
# Nexus Production Environment — auto-generated by CD pipeline
|
||||
POSTGRES_DB=nexus
|
||||
@@ -118,9 +108,7 @@ jobs:
|
||||
JWT_KEY=${ENV_JWT_KEY}
|
||||
JWT_ISSUER=nexus
|
||||
JWT_AUDIENCE=nexus-web
|
||||
OWNER_EMAIL=vmbao62@hotmail.de
|
||||
OWNER_PASSWORD=${HOST_OWNER_PASSWORD}
|
||||
OWNER_DISPLAY_NAME=
|
||||
BOOTSTRAP_OWNER_EMAIL=vmbao62@hotmail.de
|
||||
OPENCLAW_BASE_URL=http://host.docker.internal:18789
|
||||
OPENCLAW_GATEWAY_TOKEN=${ENV_OPENCLAW_TOKEN}
|
||||
OPENCLAW_GATEWAY_PASSWORD=
|
||||
|
||||
Reference in New Issue
Block a user