diff --git a/README.md b/README.md index 90ee105..71adfe0 100644 --- a/README.md +++ b/README.md @@ -25,7 +25,7 @@ included files, so it reloads them without a container restart. ```sh podman build -t localhost/glance-updater:latest /var/lib/glance/webhook - podman compose up -d glance-updater + podman compose up -d updater ``` 5. In Tangled, open **Settings > Hooks** and create an active push webhook: @@ -36,7 +36,7 @@ The Glance route can keep its Authentik middleware. The more-specific webhook route intentionally has no Authentik middleware because Tangled authenticates with its HMAC signature instead. -The updater uses `git pull --ff-only`. If the server checkout has local changes -or has diverged, the update fails rather than discarding anything. For a private -repository, also mount read-only Git credentials into `glance-updater`; a public -HTTPS remote needs no credentials. +The updater fetches `origin/main` and resets the checkout to that commit. This +overwrites tracked local changes and divergent local commits, but preserves +untracked files. For a private repository, also mount read-only Git credentials +into `updater`; a public HTTPS remote needs no credentials. diff --git a/webhook/compose.yml b/webhook/compose.yml index e919aed..2104a0a 100644 --- a/webhook/compose.yml +++ b/webhook/compose.yml @@ -1,20 +1,25 @@ services: - glance-updater: - image: localhost/glance-updater:latest - pull_policy: never - hostname: glance-updater - restart: unless-stopped + updater: + image: "localhost/glance-updater:latest" + pull_policy: "never" + hostname: "updater" + restart: "unless-stopped" user: "1000:1000" - read_only: true - tmpfs: - - /tmp:size=1m,mode=1777 - environment: - WEBHOOK_SECRET: "${GLANCE_WEBHOOK_SECRET:?GLANCE_WEBHOOK_SECRET must be set}" - volumes: - - /var/lib/glance:/repo + read_only: "true" labels: traefik.enable: "true" traefik.http.routers.glance-updater.rule: "Host(`${GROUND_DOMAIN}`) && Path(`/hooks/glance`)" traefik.http.routers.glance-updater.entrypoints: "websecure" traefik.http.routers.glance-updater.tls.certresolver: "myresolver" traefik.http.services.glance-updater.loadbalancer.server.port: "9000" + environment: + WEBHOOK_SECRET: "${GLANCE_WEBHOOK_SECRET}" + volumes: + - "/var/lib/glance:/repo" + - "updater-cache:/etc/webhook" + +volumes: + updater-cache: + driver_opts: + type: "tmpfs" + device: "tmpfs" diff --git a/webhook/update.sh b/webhook/update.sh index 49a858f..1a51a69 100644 --- a/webhook/update.sh +++ b/webhook/update.sh @@ -1,11 +1,12 @@ #!/bin/sh set -eu -lock=/tmp/glance-update.lock +lock=/etc/webhook/glance-update.lock if ! mkdir "$lock" 2>/dev/null; then echo "An update is already running" exit 0 fi trap 'rmdir "$lock"' EXIT -git -C /repo pull --ff-only +git -C /repo fetch origin main +git -C /repo reset --hard FETCH_HEAD