#!/bin/sh set -e # disable bubblewrap sandbox — not supported inside Docker rm -f /usr/bin/bwrap # install runtime dependencies apk add --no-cache bash git-daemon openssh-keygen > /dev/null 2>&1 || true # set git identity for auto-commit if command -v git > /dev/null 2>&1; then git config --global user.email "lichen@${LM_DASHBOARD_DOMAIN:-localhost}" git config --global user.name "lichen" fi # write lichen.toml if it doesn't exist yet if [ ! -f /data/lichen.toml ]; then TOML_PROVIDERS=$(echo "${AUTH_PROVIDERS:-file,atproto}" | sed 's/[^,][^,]*/\"&\"/g') echo "auth_providers = [$TOML_PROVIDERS]" > /data/lichen.toml if [ -n "$DEFAULT_STORAGE_LIMIT" ]; then echo "default_storage_limit = \"$DEFAULT_STORAGE_LIMIT\"" >> /data/lichen.toml fi fi # choose one executable for both administration and serving LICHEN_BIN=lichen if [ -x /opt/lichen-bin/lichen ]; then LICHEN_BIN=/opt/lichen-bin/lichen echo "++ using custom binary from $LICHEN_BIN" fi # create or update admin user on every startup if [ -n "$ADMIN_PASSWORD" ]; then if [ -f "/data/users/${ADMIN_USER:-admin}.toml" ]; then "$LICHEN_BIN" server --multi users set-password "${ADMIN_USER:-admin}" \ --password "$ADMIN_PASSWORD" --root-dir /data else "$LICHEN_BIN" server --multi users add "${ADMIN_USER:-admin}" \ --password "$ADMIN_PASSWORD" --root-dir /data fi fi # start hosted mode explicitly; the bare server command is the local manager exec "$LICHEN_BIN" server --multi --root-dir /data run