Skip to content

Commit f60784e

Browse files
committed
Lock down database.yml
It should not be world-readable or writeable by the GitLab user.
1 parent 872bacd commit f60784e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

recipes/default.rb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -215,9 +215,9 @@ class file open;
215215
# Write the database.yml
216216
template "#{node['gitlab']['app_home']}/config/database.yml" do
217217
source 'database.yml.erb'
218-
owner node['gitlab']['user']
218+
owner 'root'
219219
group node['gitlab']['group']
220-
mode '0644'
220+
mode '0640'
221221
variables(
222222
adapter: node['gitlab']['database']['adapter'],
223223
encoding: node['gitlab']['database']['encoding'],

0 commit comments

Comments
 (0)