docker-distribution: Run service as docker instead of root
This commit is contained in:
parent
82a4c66575
commit
08d395078d
1 changed files with 33 additions and 0 deletions
|
@ -4,6 +4,39 @@
|
||||||
name: docker-distribution
|
name: docker-distribution
|
||||||
state: installed
|
state: installed
|
||||||
|
|
||||||
|
- name: create docker group
|
||||||
|
group:
|
||||||
|
name: docker
|
||||||
|
gid: 1004
|
||||||
|
|
||||||
|
- name: create docker user
|
||||||
|
user:
|
||||||
|
name: docker
|
||||||
|
comment: Service Docker-Registry
|
||||||
|
createhome: false
|
||||||
|
group: docker
|
||||||
|
groups: hostkey
|
||||||
|
home: /var/empty
|
||||||
|
shell: /sbin/nologin
|
||||||
|
uid: 1004
|
||||||
|
|
||||||
|
- name: create unit file drop-in directory
|
||||||
|
file:
|
||||||
|
path: /etc/systemd/system/docker-distribution.service.d
|
||||||
|
state: directory
|
||||||
|
mode: 0755
|
||||||
|
owner: root
|
||||||
|
group: "{{ ansible_wheel }}"
|
||||||
|
|
||||||
|
- name: create unit file drop-in
|
||||||
|
copy:
|
||||||
|
dest: /etc/systemd/system/docker-distribution.service.d/user.conf
|
||||||
|
src: user.conf
|
||||||
|
mode: 0644
|
||||||
|
owner: root
|
||||||
|
group: "{{ ansible_wheel }}"
|
||||||
|
notify: restart docker-distribution
|
||||||
|
|
||||||
- name: create config file
|
- name: create config file
|
||||||
template:
|
template:
|
||||||
dest: /etc/docker-distribution/registry/config.yml
|
dest: /etc/docker-distribution/registry/config.yml
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue