Skip to content

How to grant galaxy web admin access

Kjetil Klepper edited this page Aug 26, 2022 · 11 revisions

Galaxy admin access is normally configured with the setting "admin_users" in the "galaxy.yml" configuration file. In the Galaxy Ansible playbook, these settings are included in the file env/common/group_vars/galaxy.yml, but the "admin_users" setting here refers to a variable which is defined in the file env/common/group_vars/global.yml. Note that this same file is used for both test and production, since it is symlinked from both env/test/group_vars/global.yml and env/main/group_vars/global.yml. The recipe below describes how to update the test server. To update the production server instead, just replace every instance of test in path-names with main.

  1. Clone the infrastructure playbook to your local computer.
git clone https://github.com/usegalaxy-no/infrastructure-playbook 

If you already have a clone of the repository, you can just git pull to get the latest changes.

  1. Make sure you have added the Ansible vault password to the file env/test/vault_password (not included in the repo). You can get this password by asking another administrator.

  2. Locate the variable galaxy_admin in the file env/test/group_vars/global.yml and find its decrypted value. This can for instance be done by executing the following command within the env/test directory:

ansible galaxyserver -m debug -a var='galaxy_admin' -e "@group_vars/global.yml"
  1. The value of the galaxy_admin variable should be a comma-separated list of Galaxy user IDs (email addresses). Add the ID of the new admin user to this list and run the command below to encrypt the new value again (replace the "XXXXXX" string with the list of user IDs). The result will be output to STDOUT where you can copy it.

(Note: since the same configuration file is used by both test and production Galaxy, you should add separate IDs for both test and prod if they are not the same. In our setup, the production ID will usually be a FEIDE ID and the test ID will be a "test-NeLS" ID. If the new admin does not have a test-NeLS account, they can apply for one by going to https://test.usegalaxy.no, select "Login with NeLS Identity" and then "Apply for a NeLS Account".)

ansible-vault encrypt_string --name "galaxy_admin" "XXXXXX"
  1. Open the file env/test/group_vars/global.yml in a text editor and replace the old encrypted value of galaxy_admin with the new encrypted value that you got from the previous step. (Run the command from step 3 again to check that the value in the playbook is now correct.)
  2. Run the galaxy.yml playbook from inside the directory env/test. This will update the test stack.
ansible-playbook galaxy.yml
  1. Commit your modified file(s) back to the git repo. NB!: Do not commit the "vault_password" file! (This is included in .gitignore and will be ignored by default.)
git add ../common/group_vars/global.yml
git commit -m "Added new Galaxy web admin user"
git push origin master

Clone this wiki locally