53 lines
1.6 KiB
PHP
53 lines
1.6 KiB
PHP
<?php
|
|
|
|
namespace App\Provisioning\Steps\Customer;
|
|
|
|
use App\Models\ProvisioningRun;
|
|
use App\Provisioning\StepResult;
|
|
use App\Services\Proxmox\ProxmoxClient;
|
|
use Illuminate\Support\Facades\Crypt;
|
|
use Illuminate\Support\Str;
|
|
|
|
class CreateCustomerAdmin extends CustomerStep
|
|
{
|
|
public function __construct(private ProxmoxClient $pve) {}
|
|
|
|
public function key(): string
|
|
{
|
|
return 'create_customer_admin';
|
|
}
|
|
|
|
public function maxDuration(): int
|
|
{
|
|
return 120;
|
|
}
|
|
|
|
public function execute(ProvisioningRun $run): StepResult
|
|
{
|
|
// Idempotent: admin already created.
|
|
if ($this->hasResource($run, 'nc_admin')) {
|
|
return StepResult::advance();
|
|
}
|
|
|
|
$instance = $this->instance($run);
|
|
$pve = $this->pve->forHost($instance->host);
|
|
|
|
$username = 'admin';
|
|
$password = Str::random(20);
|
|
|
|
// Pass the password via env (OC_PASS), never on the argv/command line.
|
|
$this->guest($pve, $run,
|
|
'cd /opt/nextcloud && OC_PASS='.escapeshellarg($password).
|
|
' docker compose exec -T -e OC_PASS app php occ user:add --password-from-env --group=admin '.
|
|
escapeshellarg($username));
|
|
|
|
// Persist only the username (encrypted ref); hand the password to step 15
|
|
// encrypted-in-context for delivery, then it is scrubbed. Never plaintext.
|
|
$instance->update(['nc_admin_ref' => $username]);
|
|
$run->mergeContext(['admin_password' => Crypt::encryptString($password)]);
|
|
$this->recordResource($run, $instance->host, 'nc_admin', $username);
|
|
|
|
return StepResult::advance();
|
|
}
|
|
}
|