From 81809160f41aed1161070148d8cf60a1ed24a6f3 Mon Sep 17 00:00:00 2001 From: Luke Hoersten Date: Thu, 30 Jul 2026 18:19:43 -0500 Subject: bitcoind-prometheus-exporter: grant read access to bitcoin.conf The exporter reads rpc credentials from bitcoin.conf but the bitcoind role writes it 0600 bitcoin:bitcoin, so the prometheus user could never read it (only long-lived processes predating the tightened mode kept working). Make the conf group-readable and add prometheus to the bitcoin group. --- bitcoind-prometheus-exporter/tasks/main.yaml | 10 ++++++++++ bitcoind/tasks/main.yaml | 4 +++- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/bitcoind-prometheus-exporter/tasks/main.yaml b/bitcoind-prometheus-exporter/tasks/main.yaml index 59eed2f..5792252 100644 --- a/bitcoind-prometheus-exporter/tasks/main.yaml +++ b/bitcoind-prometheus-exporter/tasks/main.yaml @@ -12,6 +12,16 @@ - "prometheus_client" - "python-bitcoinlib" +# The exporter reads rpc credentials from bitcoin.conf, which the bitcoind +# role keeps at 0640 bitcoin:bitcoin. +- name: add prometheus user to the bitcoin group + become: yes + user: + name: "prometheus" + groups: "{{bitcoind_user | default('bitcoin')}}" + append: yes + notify: restart service + - name: unarchive bitcoind-prometheus-exporter become: yes unarchive: diff --git a/bitcoind/tasks/main.yaml b/bitcoind/tasks/main.yaml index a11dbbf..f99256c 100644 --- a/bitcoind/tasks/main.yaml +++ b/bitcoind/tasks/main.yaml @@ -49,7 +49,9 @@ dest: "{{bitcoind_conf_dir}}/bitcoin.conf" owner: "{{bitcoind_user}}" group: "{{bitcoind_user}}" - mode: "0600" + # group-readable: the prometheus exporter reads rpc credentials from this + # file (its role adds the prometheus user to the bitcoin group) + mode: "0640" notify: restart bitcoind no_log: true -- cgit v1.2.3