#cloud-config # The always-on controller droplet (smallest size is fine). Clones the repo # for ci/controller.sh, installs the unit and timer, and starts polling. # # Substitute before use: # __REPO_URL__ https://github.com/omacom/omarchy-pkgs.git # __BRANCH__ branch carrying ci/ (master once merged) # __ENV_B64__ base64 of a filled-in controller.env.example # __SSH_KEYS_JSON__ JSON array of public keys authorized for root package_update: true packages: [curl, jq, git] # Root stays reachable by key so the journal can be read. Two things stand # in the way on DO images: disable_root rewrites root's keys into a stub, and # with no account ssh key attached DO expires root's password, which makes # sshd refuse every non-interactive session with "password change required". disable_root: false chpasswd: expire: false ssh_authorized_keys: __SSH_KEYS_JSON__ users: - name: controller shell: /bin/bash write_files: # defer: write after the users module has created the controller group, # otherwise chown to root:controller fails and the unit cannot read this. - path: /etc/omarchy-controller.env permissions: "0640" owner: root:controller encoding: b64 defer: true content: __ENV_B64__ runcmd: - chage -d "$(date +%F)" -M -1 root - chown root:controller /etc/omarchy-controller.env && chmod 0640 /etc/omarchy-controller.env - git clone --depth 1 --branch __BRANCH__ __REPO_URL__ /opt/omarchy-pkgs - mkdir -p /run/omarchy-controller && chown controller:controller /run/omarchy-controller - echo "d /run/omarchy-controller 0755 controller controller -" > /etc/tmpfiles.d/omarchy-controller.conf # runcmd is executed by /bin/sh: no brace expansion. - cp /opt/omarchy-pkgs/ci/controller-box/omarchy-controller.service /opt/omarchy-pkgs/ci/controller-box/omarchy-controller.timer /etc/systemd/system/ - systemctl daemon-reload - systemctl enable --now omarchy-controller.timer