forked from heavy-duty/rig
A users file naming zero users is a valid instruction to revoke every operator on the box, and it is indistinguishable from the file a stray '>' produces. The per-user warnings apply already emitted arrive after the decision and scale wrong: twenty operators is twenty lines of scrollback, so the signal was loudest exactly where it read as noise. The /etc/rig/users ledger draws the line apply needs. An empty file against an empty ledger is an unambiguous no-op; against a populated one it closes every named door. Only the second now stops, states how many operators are at risk, and requires explicit consent: --yes, RIG_YES=1 (the installer-family variable bin/rig's uninstall_confirm already reads), or a y on a TTY. Without a terminal and without consent it exits 2 in that same refusal's words, rather than assume a yes it cannot ask for or hang on a prompt nothing can answer. A confirmation, not bootstrap's flat refusal of the same file (#57/#59): bootstrap asserts who lives on a box, apply converges, and converging to zero stays a legitimate de-provisioning. Ledger entries already marked revoked do not count toward the number, so a second identical run stays the silent no-op convergence promises. Mass revocation below the empty-file bright line is deliberately still ungated — that needs a threshold someone has to justify. Refs #65 |
||
|---|---|---|
| .. | ||
| lib | ||
| bootstrap-tenant.sh | ||
| bootstrap.sh | ||
| coolify-backup-install.sh | ||
| coolify-install.sh | ||
| db.sh | ||
| runner-install.sh | ||
| runner-remove.sh | ||
| runner-repoint.sh | ||
| runner-status.sh | ||
| users-apply.sh | ||
| users-close-root.sh | ||
| users-status.sh | ||