Bonjour,
Q/A 0.7.0-rc1 can be done with the following:
Using packages.securedrop.club
- wget -O install_files/ansible-base/roles/install-fpf-repo/files/securedrop-club.pub https://packages.securedrop.club/key.asc
- add the securedrop.club signing key at the beginning of
install_files/ansible-base/roles/install-fpf-repo/tasks/main.yml
- name: Install SecureDrop.club apt repo GPG signing key. apt_key: state: present data: "{{ lookup('file', 'securedrop-club.pub') }}" keyring: /etc/apt/trusted.gpg.d/securedrop-club-keyring.gpg tags: - apt - fpf_repo
Upgrading production VM
On a laptop:
- git clone -b release/0.6 http://lab.securedrop.club/main/securedrop
- git reset --hard 0.6
- ANSIBLE_ARGS="–skip-tags validate" vagrant up /prod/
- copied in paste2.org mon-ssh-aths app-ssh-aths
On a 3.6.2 tails run with kvm, followed the install process and:
- git clone -b release/0.7 https://lab.securedrop.club/main/securedrop
- cd securedrop
- git reset --hard 0.7.0-rc1
- pasted from the above mon-ssh-aths app-ssh-aths into install_files/ansible-base
- echo apt_repo_url: https://packages.securedrop.club/0.7.0-rc1 > install_files/ansible-base/groups_var/all//qa
Creating production VM
On a laptop
- git clone -b release/0.7 http://lab.securedrop.club/main/securedrop
- git reset --hard 0.7.0-rc1
- sed -i -e ‘s|^apt_repo_url|apt_repo_url: https://packages.securedrop.club/0.7.0-rc1|’ install_files/ansible-base/roles/install-fpf-repo/defaults/main.yml