| #!/bin/sh | |
| set -e | |
| secret() { | |
| seed=$(cat /run/secrets/seed) | |
| printf "%s:%40s" "${seed}" "$*" | sha256sum | sed 's/[[:space:]].*//' | |
| } | |
| export GERRIT_MAIL_PASSWORD=$(secret mail:gerrit) | |
| export GERRIT_KC_PASSWORD=$(secret kc:gerrit) | |
| # Allows us to bind mount arbitrary owned files | |
| chown -R gerrit:gerrit /var/gerrit/{logs,etc,db,git,index,cache}/ | |
| # Drop privileges as we set `USER root` only to change file permissions | |
| exec setpriv --reuid=gerrit --regid=gerrit --init-groups --inh-caps=-all /unprivileged.sh "$@" |