| author | |
| committer | |
| log | 21c7642b347997f1c6d3400bdc766e16d190414f |
| tree | 9f0f69aef26cd7baba1d084bc9acf96e5d6d9a89 |
| parent | db792ebc5ec23d7de27231d6584eeb01a89a5f78 |
| signature | Signed by SSH key SHA256:xbd+BjjhyBfwk7GVoURf9Yx0gzDerHbvYv7SddNWmAs |
three services silently crash-looping for five months, all casualties
of the jan 16 image/user changes:
- dawarich: rails 8 requires SECRET_KEY_BASE; new DAWARICH_SECRET_KEY_BASE
env var (added to generate-env.sh and the deployed .env)
- technitium: new image writes blocklists to /etc/dns, which was
root-owned in-container; mount a writable volume there
- openspeedtest: the image entrypoint rewrites nginx config as root;
drop the user override that broke it2 files changed, 6 insertions(+), 1 deletions(-)
compose.yaml+3-1| ... | ... | @@ -640,6 +640,7 @@ services: |
| 640 | 640 | user: "$USER_ID:$GROUP_ID" |
| 641 | 641 | environment: |
| 642 | 642 | RAILS_ENV: production |
| 643 | SECRET_KEY_BASE: "${DAWARICH_SECRET_KEY_BASE:?}" | |
| 643 | 644 | REDIS_URL: "redis://redis:6379" |
| 644 | 645 | DATABASE_HOST: postgres |
| 645 | 646 | DATABASE_USERNAME: dawarich |
| ... | ... | @@ -677,6 +678,7 @@ services: |
| 677 | 678 | user: "$USER_ID:$GROUP_ID" |
| 678 | 679 | environment: |
| 679 | 680 | RAILS_ENV: production |
| 681 | SECRET_KEY_BASE: "${DAWARICH_SECRET_KEY_BASE:?}" | |
| 680 | 682 | REDIS_URL: "redis://redis:6379" |
| 681 | 683 | DATABASE_HOST: postgres |
| 682 | 684 | DATABASE_USERNAME: dawarich |
| ... | ... | @@ -768,7 +770,6 @@ services: |
| 768 | 770 | restart: unless-stopped |
| 769 | 771 | container_name: openspeedtest |
| 770 | 772 | image: openspeedtest/latest |
| 771 | user: "$USER_ID:$GROUP_ID" | |
| 772 | 773 | labels: |
| 773 | 774 | net.paperclover.list.name: Open Speed Test |
| 774 | 775 | net.paperclover.list.domain: speedtest |
| ... | ... | @@ -785,6 +786,7 @@ services: |
| 785 | 786 | - 8053:8053/tcp # dns over http |
| 786 | 787 | volumes: |
| 787 | 788 | - "${APP_ROOT}/technitium/config:/app/config" |
| 789 | - "${APP_ROOT}/technitium/dns:/etc/dns" | |
| 788 | 790 | - "${APP_ROOT}/technitium/ssl:/etc/ssl" |
| 789 | 791 | - "${APP_ROOT}/technitium/logs:/app/config/logs" |
| 790 | 792 | restart: unless-stopped |
generate-env.sh+3| ... | ... | @@ -39,6 +39,9 @@ template() { |
| 39 | 39 | section "authentication" |
| 40 | 40 | add "KEYCLOAK_ADMIN_PASSWORD" "$(secret 12)" |
| 41 | 41 | |
| 42 | section "dawarich" | |
| 43 | add "DAWARICH_SECRET_KEY_BASE" "$(hex_secret 64)" | |
| 44 | ||
| 42 | 45 | section "postgres" |
| 43 | 46 | add "POSTGRES_PASSWORD" "$(secret 32)" |
| 44 | 47 | add "POSTGRES_PASSWORD_KEYCLOAK" "$(secret 32)" |