Use 0700 perms for backup-everything script

just in case it has secrets
This commit is contained in:
Lance Edgar 2018-09-06 11:39:36 -05:00
parent 12a29f2088
commit a920eebc4c

View file

@ -43,7 +43,7 @@ def deploy_backup_everything(**context):
""" """
context.setdefault('envname', 'backup') context.setdefault('envname', 'backup')
context.setdefault('user', 'rattail') context.setdefault('user', 'rattail')
deploy_generic('backup/backup-everything.mako', '/usr/local/bin/backup-everything', mode='0755', deploy_generic('backup/backup-everything.mako', '/usr/local/bin/backup-everything', mode='0700',
context=context) context=context)
@ -91,7 +91,7 @@ def deploy_backup_app(deploy, envname, mkvirtualenv=True, user='rattail',
'user': user, 'user': user,
} }
if everything: if everything:
deploy(everything, '/usr/local/bin/backup-everything', mode='0755', context=everything_context) deploy(everything, '/usr/local/bin/backup-everything', mode='0700', context=everything_context)
else: else:
deploy_backup_everything(**everything_context) deploy_backup_everything(**everything_context)