diff --git a/configs/nsenter_iptables.sh b/configs/nsenter_iptables.sh index 2f3b6c82..621ceb99 100755 --- a/configs/nsenter_iptables.sh +++ b/configs/nsenter_iptables.sh @@ -1,11 +1,11 @@ #!/bin/sh -if [ -d /containers/onboot/004-admin-ip-setup ]; then - LOWER=/containers/onboot/004-admin-ip-setup/lower +if [ -d /containers/onboot/004-synchro-ip-setup ]; then + LOWER=/containers/onboot/004-synchro-ip-setup/lower elif [ -d /containers/onboot/004-frontal-ip-setup ]; then LOWER=/containers/onboot/004-frontal-ip-setup/lower else - nsenter -t 1 -a "$0" $@ + nsenter -t 1 -m -u -i -p -- "$0" $@ exit $? fi diff --git a/configs/nsenter_mysql.sh b/configs/nsenter_mysql.sh index e387b86a..961107d4 100755 --- a/configs/nsenter_mysql.sh +++ b/configs/nsenter_mysql.sh @@ -1,3 +1,3 @@ #!/bin/sh -nsenter -t $(pgrep mysql | head -1) -a mysql $@ +nsenter -t $(pgrep mysql | head -1) -m -u -i -n -p -- mysql $@ diff --git a/fickit-backend.yml b/fickit-backend.yml index 60e0a2be..dbdcd5fc 100644 --- a/fickit-backend.yml +++ b/fickit-backend.yml @@ -23,10 +23,13 @@ onboot: # Filesystem - name: swap image: linuxkit/swap:v0.7 - command: ["/sbin/swapon", "/dev/sda2", "/dev/sdb2"] + command: ["/sbin/swapon", "/dev/md1"] + - name: dm-crypt + image: linuxkit/dm-crypt:v0.7 + command: ["/usr/bin/crypto", "-l", "crypt_fic", "/dev/md0"] - name: mount image: linuxkit/mount:v0.7 - command: ["/usr/bin/mountie", "-device", "/dev/md0", "/var/lib/fic" ] + command: ["/usr/bin/mountie", "-device", "/dev/mapper/crypt_fic", "/var/lib/fic" ] # Network # - name: dhcpcd @@ -373,6 +376,10 @@ files: COMMIT mode: "0440" + - path: etc/dm-crypt/key + source: configs/dm-crypt.key + mode: "0440" + trust: org: - linuxkit diff --git a/fickit-frontend.yml b/fickit-frontend.yml index 71f0ac64..1c47d702 100644 --- a/fickit-frontend.yml +++ b/fickit-frontend.yml @@ -23,10 +23,13 @@ onboot: # Filesystem - name: swap image: linuxkit/swap:v0.7 - command: ["/sbin/swapon", "/dev/sda2", "/dev/sdb2"] + command: ["/sbin/swapon", "/dev/md1"] + - name: dm-crypt + image: linuxkit/dm-crypt:v0.7 + command: ["/usr/bin/crypto", "-l", "crypt_fic", "/dev/md0"] - name: mount image: linuxkit/mount:v0.7 - command: ["/usr/bin/mountie", "-device", "/dev/md0", "/var/lib/fic" ] + command: ["/usr/bin/mountie", "-device", "/dev/mapper/crypt_fic", "/var/lib/fic" ] # Network # - name: ntp @@ -512,6 +515,10 @@ files: COMMIT mode: "0440" + - path: etc/dm-crypt/key + source: configs/dm-crypt.key + mode: "0440" + trust: org: - linuxkit