-
Notifications
You must be signed in to change notification settings - Fork 0
How to grant galaxy web admin access
Galaxy admin access is normally configured with the setting "admin_users" in the "galaxy.yml" configuration file. In the Galaxy Ansible playbook, these settings are included in the file env/common/group_vars/galaxy.yml, but the "admin_users" setting here refers to a variable which is defined in the file env/common/group_vars/global.yml. Note that this same file is used for both test and production, since it is symlinked from both env/test/group_vars/global.yml and env/main/group_vars/global.yml. The recipe below describes how to update the test server. To update the production server instead, just replace every instance of test in path-names with main.
- Clone the infrastructure playbook to your local computer.
git clone https://github.com/usegalaxy-no/infrastructure-playbook If you already have a clone of the repository, you can just git pull to get the latest changes.
-
Make sure you have added the Ansible vault password to the file
env/test/vault_password(not included in the repo). You can get this password by asking another administrator. -
Locate the variable
galaxy_adminin the fileenv/test/group_vars/global.ymland find its decrypted value. This can for instance be done by executing the following command within theenv/testdirectory:
ansible galaxyserver -m debug -a var='galaxy_admin' -e "@group_vars/global.yml"- The value of the
galaxy_adminvariable should be a comma-separated list of Galaxy user IDs (email addresses). Add the ID of the new admin user to this list and run the command below to encrypt the new value again (replace the "XXXXXX" string with the list of user IDs). The result will be output to STDOUT where you can copy it.
(Note: since the same configuration file is used by both test and production Galaxy, you should add separate IDs for both test and prod if they are not the same. In our setup, the production ID will usually be a FEIDE ID and the test ID will be a "test-NeLS" ID. If the new admin does not have a test-NeLS account, they can apply for one by going to https://test.usegalaxy.no, select "Login with NeLS Identity" and then "Apply for a NeLS Account".)
ansible-vault encrypt_string --name "galaxy_admin" "XXXXXX"- Open the file
env/test/group_vars/global.ymlin a text editor and replace the old encrypted value ofgalaxy_adminwith the new encrypted value that you got from the previous step. (Run the command from step 3 again to check that the value in the playbook is now correct.) - Run the
galaxy.ymlplaybook from inside the directoryenv/test. This will update the test stack.
ansible-playbook galaxy.yml- Commit your modified file(s) back to the git repo. NB!: Do not commit the "vault_password" file! (This is included in
.gitignoreand will be ignored by default.)
git add ../common/group_vars/global.yml
git commit -m "Added new Galaxy web admin user"
git push origin master