From f44471b85e8cd0a36b9c900b04d871faf8e29f7d Mon Sep 17 00:00:00 2001 From: "anil.recoil.org" Date: Mon, 5 May 2025 18:43:25 +0000 Subject: [PATCH] docker: make docker-compose serve https and fix permissions This fixes two issues I had when deploying the eeg.cl.cam.ac.uk knot: 1) The permissions on the volumes are currently set at build time, which means that when a fresh volume is mounted it has the wrong permissions. This fixes it to run the chmods on the volumes dynamically at entrypoint time, which lets a fresh volume work with a knotserver. The error before was: ``` knot-1 | time=2025-05-04T13:58:36.054Z level=ERROR msg="failed to setup db" error="unable to open database file: no such file or directory" ``` 2) It's a little odd for the default setup to expose 5555 and insecure http to the Internet, given that the appview will try to connect to the knot over https. This adds a standalone Caddy server as the default and removes port 5555 from being directly explosed. A more advanced user with an existing proxy can easily remove this from the compose file and hook in their own. The only remaining footgun my users have encountered is that of port 2222 being the default. Almost all the users have forgotten to add the `port 2222` directive in their ssh_config, and the _host_ sshd rejects them. In my local setup, I've swapped the host and knot ports around so that the knot runs on 2222, but a really elegant solution would be for some sort of ssh proxy on the host ssh to redirect the `git` user to the knotserver sshd. I haven't done that yet though! --- docker/Dockerfile | 6 ++---- docker/docker-compose.yml | 18 +++++++++++++++++- 2 files changed, 19 insertions(+), 5 deletions(-) diff --git a/docker/Dockerfile b/docker/Dockerfile index f7c7604..2c9c1a2 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -42,11 +42,9 @@ COPY --from=build /usr/local/bin/repoguard /home/git/repoguard COPY docker/rootfs/ . RUN chown root:root /usr/local/libexec/tangled-keyfetch && \ - chmod 755 /usr/local/libexec/tangled-keyfetch && \ - chown git:git /home/git/repoguard && \ - chown git:git /app && chown git:git /home/git/repositories + chmod 755 /usr/local/libexec/tangled-keyfetch EXPOSE 22 EXPOSE 5555 -ENTRYPOINT ["/init"] +ENTRYPOINT ["/bin/sh", "-c", "chown git:git /home/git/repoguard && chown git:git /app && chown git:git /home/git/repositories && /init"] diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index 04a5793..7a1ad94 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -13,5 +13,21 @@ services: - "./repositories:/home/git/repositories" - "./server:/app" ports: - - "5555:5555" - "2222:22" + frontend: + image: caddy:2-alpine + command: > + caddy + reverse-proxy + --from ${KNOT_SERVER_HOSTNAME} + --to knot:5555 + depends_on: + - knot + ports: + - "443:443" + - "443:443/udp" + volumes: + - caddy_data:/data + restart: always +volumes: + caddy_data: -- 2.51.2