forked from heavy-duty/rig
fix: bootstrap installs openssh-server — sshd_config.d does not exist on pristine images
Found by the Incus rehearsal (prod-migration Task 4): cloud images ship openssh-server, container/VM images do not; the hardening drop-in and 'systemctl restart ssh' both presume it. A rig box is SSH-managed by definition, so the dependency is explicit now. No-op on cloud images. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
9f079bff55
commit
5fb342d64d
1 changed files with 5 additions and 1 deletions
|
|
@ -66,7 +66,11 @@ fi
|
||||||
export DEBIAN_FRONTEND=noninteractive
|
export DEBIAN_FRONTEND=noninteractive
|
||||||
log "installing base packages"
|
log "installing base packages"
|
||||||
apt-get update -qq
|
apt-get update -qq
|
||||||
apt-get install -y -qq curl ca-certificates unattended-upgrades
|
# openssh-server: a rig box is managed over SSH (Coolify SSHes in as root),
|
||||||
|
# and the hardening drop-in below targets /etc/ssh/sshd_config.d/ — which
|
||||||
|
# only exists once the package is installed. Cloud images ship it; pristine
|
||||||
|
# container/VM images (the Incus rehearsal) do not.
|
||||||
|
apt-get install -y -qq curl ca-certificates unattended-upgrades openssh-server
|
||||||
|
|
||||||
# enable periodic unattended upgrades (canonical file; idempotent overwrite)
|
# enable periodic unattended upgrades (canonical file; idempotent overwrite)
|
||||||
cat > /etc/apt/apt.conf.d/20auto-upgrades <<'EOF'
|
cat > /etc/apt/apt.conf.d/20auto-upgrades <<'EOF'
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue