Add security warning for cron token storage
This commit is contained in:
+31
-1
@@ -49,13 +49,43 @@ crontab -e
|
||||
0 0 * * * GH_TOKEN=ghp_your_token_here /home/youruser/.local/bin/ghrel check --since 1d >> /opt/nicible/ghrel.log 2>&1
|
||||
```
|
||||
|
||||
> [!WARNING]
|
||||
> **Never store your GitHub token as plaintext in crontab.** Crontab files may be readable by other users on the system. Use one of these alternatives instead:
|
||||
>
|
||||
> **Option 1: Environment file (recommended)**
|
||||
> Create a restricted environment file and source it from cron:
|
||||
> ```bash
|
||||
> echo 'GH_TOKEN=ghp_your_token_here' | sudo tee /etc/ghrel/token.env
|
||||
> sudo chmod 600 /etc/ghrel/token.env
|
||||
> ```
|
||||
> Then in crontab:
|
||||
> ```cron
|
||||
> 0 */6 * * * . /etc/ghrel/token.env && /home/youruser/.local/bin/ghrel check --since 6h >> /opt/nicible/ghrel.log 2>&1
|
||||
> ```
|
||||
>
|
||||
> **Option 2: Wrapper script**
|
||||
> Create a script with restricted permissions:
|
||||
> ```bash
|
||||
> cat > /opt/nicible/ghrel-check.sh << 'EOF'
|
||||
> #!/bin/bash
|
||||
> export GH_TOKEN="ghp_your_token_here"
|
||||
> exec /home/youruser/.local/bin/ghrel check --since 6h
|
||||
> EOF
|
||||
> chmod 700 /opt/nicible/ghrel-check.sh
|
||||
> ```
|
||||
> Then in crontab:
|
||||
> ```cron
|
||||
> 0 */6 * * * /opt/nicible/ghrel-check.sh >> /opt/nicible/ghrel.log 2>&1
|
||||
> ```
|
||||
>
|
||||
> **Option 3: Use systemd timer instead** (see below — preferred over cron)
|
||||
|
||||
### Notes
|
||||
|
||||
- Always use the **full path** to `ghrel` — cron runs with a minimal `$PATH`
|
||||
- Use `2>&1` to capture both stdout and stderr in the log file
|
||||
- Ensure the log directory exists and is writable: `sudo mkdir -p /opt/nicible && sudo chown $USER /opt/nicible`
|
||||
- The `--since` flag should match or slightly exceed your cron interval to avoid missing entries
|
||||
- Consider storing `GH_TOKEN` in a separate file and sourcing it from cron to avoid plaintext exposure
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user