Merge pull request #882 from nazarewk/push-qqvmsowmnqtx

sops-install-secrets: create /run/secrets link before chowning it
This commit is contained in:
Jörg Thalheim 2026-01-10 08:40:03 +01:00 committed by GitHub
commit 57e2d9ef84
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1410,12 +1410,12 @@ func installSecrets(args []string) error {
if isDry {
return nil
}
if err := symlinkSecretsAndTemplates(manifest.SymlinkPath, manifest.Secrets, manifest.Templates, manifest.UserMode); err != nil {
return fmt.Errorf("failed to prepare symlinks to secret store: %w", err)
}
if err := atomicSymlink(*secretDir, manifest.SymlinkPath); err != nil {
return fmt.Errorf("cannot update secrets symlink: %w", err)
}
if err := symlinkSecretsAndTemplates(manifest.SymlinkPath, manifest.Secrets, manifest.Templates, manifest.UserMode); err != nil {
return fmt.Errorf("failed to prepare symlinks to secret store: %w", err)
}
if err := pruneGenerations(manifest.SecretsMountPoint, *secretDir, manifest.KeepGenerations); err != nil {
return fmt.Errorf("cannot prune old secrets generations: %w", err)
}