Re: non-root install of plone
Steve McMahon <[email protected]> Thu, 1 Oct 2015 10:09:37 -0700
| Newsgroups | gmane.comp.web.zope.plone.user |
|---|---|
| Message-ID | <CAOqzbggvpHZU47XZRKWSauXJ3+gv7_3sbtvwMp+QfGof=2ny0A@mail.gmail.com> |
--===============4738187127094948162== Content-Type: multipart/alternative; boundary=089e01160002cc96b905210e1d22 --089e01160002cc96b905210e1d22 Content-Type: text/plain; charset=UTF-8 The "special sauce" is to make both plone_buildout and plone_daemon members of a common group. I use plone_group. Give that group read/write permissions for ./var, then set the group sticky bit so that new items created there will keep the group. That allows the buildout user to create ./var subdirectories for new parts when needed. Also, don't forget a precompiler step to compile all the .po and .mo files during buildout. Doing that during buildout allows you to block the daemon component from writing into the code space. On Thu, Oct 1, 2015 at 3:57 AM, Jens W. Klein <jens-/[email protected]> wrote: > Hi Ralf, > > I dont know unified installer very well. But the base idea is to split > service and buildout user. Buildout user needs r/w access for all files, > while service user has no write access to files were read is enough - > for security reasons. > > I know several setups where only one user "zope" (or "plone") exists for > both roles - with r/w for the whole buildout. The service user is > defined in the buildout section(s) for the instance(s). Using the same > user is - afaik - officially not recommended. My personal opinion is, in > fact it does not matter that much. > > Anyway, with separate service user, it needs (in a standard buildout) > only write access for the ./var directory. Here are the zodb and blob > data, logging and pid files. This assumes precompiled python files > (pyc/pyo) and precompiled gettext translations files (po/mo). > Precompiling happens in buildout at buildout-time. > > hth > Jens > > On 2015-10-01 12:14, Ralf Hemmecke wrote: > > Hello, > > > > due to some restrictions I don't have root access to a linux box, but > > would like to install plone 5 in a similar way as it is done when > > running install.sh zeo (as root user) from the unified installer. > > In other words the plone maintainer is not the system administrator of > > the machine. > > > > The users plone_daemon and plone_buildout as well as the group > > plone_group exist in the system and the user 'plone' who is ower of the > > unified installer files and who is supposed to install Plone5 has sudo > > rights for plone_daemon and plone_buildout. > > > > What is the way to install Plone in such a case? > > Note that I would like the distinction between the daemon and buildout > user. > > > > It's probably easiest to simply do the install as user plone and > > afterwards change the user of the respective files. My problem, however > > is: which files should belong to plone_daemon and which to > > plone_buildout? Is there already a script that I can simply run? > > > > Thank you > > Ralf > > > > > ------------------------------------------------------------------------------ > > > > > -- > Klein & Partner KG, member of BlueDynamics Alliance > > > > ------------------------------------------------------------------------------ > _______________________________________________ > Plone-Users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/plone-users > --089e01160002cc96b905210e1d22 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">The "special sauce" is to make both plone_buildo= ut and plone_daemon members of a common group. I use plone_group. Give that= group read/write permissions for ./var, then set the group sticky bit so t= hat new items created there will keep the group.<div><br></div><div>That al= lows the buildout user to create ./var subdirectories for new parts when ne= eded.</div><div><br></div><div>Also, don't forget a precompiler step to= compile all the .po and .mo files during buildout. Doing that during build= out allows you to block the daemon component from writing into the code spa= ce.</div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On= Thu, Oct 1, 2015 at 3:57 AM, Jens W. Klein <span dir=3D"ltr"><<a href= =3D"mailto:jens-/[email protected]" target=3D"_blank">jens-/[email protected]</= a>></span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0= 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Ralf,<br> <br> I dont know unified installer very well. But the base idea is to split<br> service and buildout user. Buildout user needs r/w access for all files,<br= > while service user has no write access to files were read is enough -<br> for security reasons.<br> <br> I know several setups where only one user "zope" (or "plone&= quot;) exists for<br> both roles - with r/w for the whole buildout. The service user is<br> defined in the buildout section(s) for the instance(s). Using the same<br> user is - afaik - officially not recommended. My personal opinion is, in<br= > fact it does not matter that much.<br> <br> Anyway, with separate service user, it needs (in a standard buildout)<br> only write access for the ./var directory. Here are the zodb and blob<br> data, logging and pid files. This assumes precompiled python files<br> (pyc/pyo) and precompiled gettext translations files (po/mo).<br> Precompiling happens in buildout at buildout-time.<br> <br> hth<br> Jens<br> <span class=3D"im HOEnZb"><br> On 2015-10-01 12:14, Ralf Hemmecke wrote:<br> > Hello,<br> ><br> > due to some restrictions I don't have root access to a linux box, = but<br> > would like to install plone 5 in a similar way as it is done when<br> > running install.sh zeo (as root user) from the unified installer.<br> > In other words the plone maintainer is not the system administrator of= <br> > the machine.<br> ><br> > The users plone_daemon and plone_buildout as well as the group<br> > plone_group exist in the system and the user 'plone' who is ow= er of the<br> > unified installer files and who is supposed to install Plone5 has sudo= <br> > rights for plone_daemon and plone_buildout.<br> ><br> > What is the way to install Plone in such a case?<br> > Note that I would like the distinction between the daemon and buildout= user.<br> ><br> > It's probably easiest to simply do the install as user plone and<b= r> > afterwards change the user of the respective files. My problem, howeve= r<br> > is: which files should belong to plone_daemon and which to<br> > plone_buildout? Is there already a script that I can simply run?<br> ><br> > Thank you<br> > Ralf<br> ><br> > ----------------------------------------------------------------------= --------<br> ><br> <br> <br> </span><span class=3D"HOEnZb"><font color=3D"#888888">--<br> Klein & Partner KG, member of BlueDynamics Alliance<br> </font></span><div class=3D"HOEnZb"><div class=3D"h5"><br> <br> ---------------------------------------------------------------------------= ---<br> _______________________________________________<br> Plone-Users mailing list<br> <a href=3D"mailto:[email protected]">[email protected]= ceforge.net</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/plone-users" rel=3D= "noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/listinfo= /plone-users</a><br> </div></div></blockquote></div><br></div> --089e01160002cc96b905210e1d22-- --===============4738187127094948162== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ --===============4738187127094948162== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Plone-Users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/plone-users --===============4738187127094948162==--