feat: set attribute once for ssh folder recursively

This commit is contained in:
phoenix 2025-04-17 05:17:30 +01:00
parent 0a568393a9
commit 3bed4d88eb

View File

@ -23,10 +23,9 @@ buildah run "$ctr" -- mkdir -p /"$SECURE"/ssh
buildah copy "$ctr" ssh/config /"$SECURE"/ssh/config
buildah copy "$ctr" ssh/ssh_blocker.sh /"$SECURE"/ssh/ssh_blocker.sh
buildah run "$ctr" -- chmod 100 /"$SECURE"/ssh/ssh_blocker.sh
buildah run "$ctr" -- chattr +i /"$SECURE"/ssh/ssh_blocker.sh
buildah run "$ctr" -- chmod 000 /"$SECURE"/ssh/config
buildah run "$ctr" -- chattr +i /"$SECURE"/ssh/config
buildah run "$ctr" -- chown -R root:root ssh/config /"$SECURE"/ssh_blocker.sh
buildah run "$ctr" -- chattr -R +i /"$SECURE"/ssh
# Neovim config (immutable)
buildah copy "$ctr" config/nvim /home/devuser/.config/nvim