From bec4e93d84e14156a50c9731d5ecce903045e510 Mon Sep 17 00:00:00 2001 From: Seongmin Lee Date: Wed, 2 Sep 2026 15:17:27 +0900 Subject: [PATCH] localinfra: remove legacy knot from docker-compose Signed-off-by: Seongmin Lee --- docker-compose.mill.yml | 2 +- docker-compose.yml | 50 +------------- localinfra/Caddyfile | 10 +-- localinfra/knot.Dockerfile | 102 ---------------------------- localinfra/readme.md | 2 +- localinfra/scripts/init-accounts.sh | 1 - localinfra/scripts/init-data.sh | 2 - 7 files changed, 4 insertions(+), 165 deletions(-) delete mode 100644 localinfra/knot.Dockerfile diff --git a/docker-compose.mill.yml b/docker-compose.mill.yml index bc9bc4202..bef93e461 100644 --- a/docker-compose.mill.yml +++ b/docker-compose.mill.yml @@ -21,7 +21,7 @@ x-mill-executor: &mill-executor SPINDLE_SERVER_PLC_URL: https://plc.tngl.boltless.dev SPINDLE_SERVER_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe SPINDLE_SERVER_DEV: "true" - SPINDLE_SERVER_DEV_EXTRA_HOSTS: knot.tngl.boltless.dev,mirror.tngl.boltless.dev + SPINDLE_SERVER_DEV_EXTRA_HOSTS: knot2.tngl.boltless.dev,mirror.tngl.boltless.dev SPINDLE_SERVER_TAP_DB_PATH: /var/lib/spindle/tap.db SPINDLE_SERVER_TAP_RELAY_URL: https://pds.tngl.boltless.dev SPINDLE_MICROVM_PIPELINES_IMAGE_DIR: /var/lib/spindle/images diff --git a/docker-compose.yml b/docker-compose.yml index 6046fe172..2b54b8715 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -49,7 +49,6 @@ services: environment: PDS_URL: http://pds:3000 OWNER_USER: alice - GO_KNOT_HOSTNAME: knot.tngl.boltless.dev KNOT_HOSTNAME: knot2.tngl.boltless.dev SPINDLE_HOSTNAME: spindle.tngl.boltless.dev volumes: @@ -67,8 +66,6 @@ services: env_file: localinfra/pds.env environment: PDS_URL: http://pds:3000 - GO_KNOT_URL: http://knot:5555 - GO_KNOT_HOSTNAME: knot.tngl.boltless.dev KNOT_URL: http://knot2:5555 KNOT_HOSTNAME: knot2.tngl.boltless.dev volumes: @@ -76,8 +73,6 @@ services: - init-state:/shared:ro command: sh -c "apk add --no-cache curl jq >/dev/null && sh /scripts/init-data.sh" depends_on: - knot: - condition: service_healthy knot2: condition: service_healthy networks: [tngl] @@ -157,46 +152,6 @@ services: condition: service_completed_successfully networks: [tngl] - knot: - build: - context: . - dockerfile: localinfra/knot.Dockerfile - restart: unless-stopped - environment: - KNOT_SERVER_HOSTNAME: knot.tngl.boltless.dev - KNOT_SERVER_LISTEN_ADDR: 0.0.0.0:5555 - KNOT_SERVER_INTERNAL_LISTEN_ADDR: 127.0.0.1:5444 - KNOT_SERVER_DB_PATH: /home/git/knotserver.db - KNOT_SERVER_PLC_URL: https://plc.tngl.boltless.dev - KNOT_SERVER_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe - KNOT_SERVER_DEV: "false" - KNOT_REPO_SCAN_PATH: /home/git/repositories - APPVIEW_ENDPOINT: https://tangled.org - KNOT_MIRRORS: https://mirror.tngl.boltless.dev - ports: - - "2222:22" - volumes: - - knot-data:/home/git - - knot-ssh-keys:/etc/ssh/keys - - init-state:/shared:ro - - ./localinfra/certs/root.crt:/usr/local/share/ca-certificates/caddy.crt:ro - healthcheck: - test: ["CMD", "wget", "-qO-", "http://localhost:5555/"] - interval: 2s - timeout: 2s - retries: 60 - start_period: 30s - depends_on: - plc: - condition: service_started - jetstream: - condition: service_started - knotmirror: - condition: service_healthy - init-accounts: - condition: service_completed_successfully - networks: [tngl] - ncps-migrate: image: &ncps-image ghcr.io/kalbasit/ncps:v0.9.4 profiles: ["linux"] @@ -241,7 +196,7 @@ services: SPINDLE_SERVER_PLC_URL: https://plc.tngl.boltless.dev SPINDLE_SERVER_JETSTREAM_ENDPOINT: wss://jetstream.tngl.boltless.dev/subscribe SPINDLE_SERVER_DEV: "true" - SPINDLE_SERVER_DEV_EXTRA_HOSTS: knot.tngl.boltless.dev,mirror.tngl.boltless.dev + SPINDLE_SERVER_DEV_EXTRA_HOSTS: knot2.tngl.boltless.dev,mirror.tngl.boltless.dev SPINDLE_SERVER_TAP_DB_PATH: /var/lib/spindle/tap.db SPINDLE_SERVER_TAP_RELAY_URL: https://pds.tngl.boltless.dev SPINDLE_MICROVM_PIPELINES_IMAGE_DIR: /var/lib/spindle/images @@ -697,7 +652,6 @@ services: - charlie.pds.tngl.boltless.dev - david.pds.tngl.boltless.dev - jetstream.tngl.boltless.dev - - knot.tngl.boltless.dev - knot2.tngl.boltless.dev - spindle.tngl.boltless.dev - tngl.boltless.dev @@ -771,8 +725,6 @@ volumes: postgres-data: pds-data: jetstream-data: - knot-data: - knot-ssh-keys: knot2-data: knotmirror-data: zoekt-index: diff --git a/localinfra/Caddyfile b/localinfra/Caddyfile index 69a32041e..e8ce9dcfb 100644 --- a/localinfra/Caddyfile +++ b/localinfra/Caddyfile @@ -52,15 +52,7 @@ jetstream.tngl.boltless.dev { reverse_proxy jetstream:6008 } -# knot. no cors import: the go knot sets its own headers (knotserver/middleware.go), -# and a second set here would send duplicates, which browsers reject outright. -knot.tngl.boltless.dev { - tls internal - reverse_proxy knot:5555 -} - -# knot2 serves no cors headers of its own, and web/ posts sh.tangled.git.keepCommit to -# whichever knot hosts the repo, straight from the browser. +# knot2 serves no cors headers of its own. knot2.tngl.boltless.dev { tls internal import cors knot2:5555 diff --git a/localinfra/knot.Dockerfile b/localinfra/knot.Dockerfile deleted file mode 100644 index 3d3b13316..000000000 --- a/localinfra/knot.Dockerfile +++ /dev/null @@ -1,102 +0,0 @@ -# Development only. Not for production use. - -FROM golang:1.25-alpine AS builder - -RUN apk add --no-cache git build-base sqlite-dev - -ENV CGO_ENABLED=1 -ENV GOCACHE=/go/cache -ENV GOMODCACHE=/go/mod - -WORKDIR /src - -COPY go.mod go.sum ./ -RUN --mount=type=cache,target=/go/cache \ - --mount=type=cache,target=/go/mod \ - go mod download - -COPY . . -RUN --mount=type=cache,target=/go/cache \ - --mount=type=cache,target=/go/mod \ - go build -tags libsqlite3 -o /out/knot ./cmd/knot - -FROM alpine:3.20 - -RUN apk add --no-cache git openssh-server tini sqlite-libs su-exec ca-certificates shadow openssl bash - -RUN groupadd -g 1000 -f git && \ - useradd -u 1000 -g 1000 -d /home/git -s /bin/sh -m git && \ - echo "git:$(openssl rand -hex 16)" | chpasswd - -COPY --from=builder /out/knot /usr/local/bin/knot -RUN chmod 0755 /usr/local/bin/knot - -COPY <<'EOF' /usr/local/bin/knot-keys-wrapper -#!/bin/sh -exec /usr/local/bin/knot keys -output authorized-keys \ - -internal-api "http://${KNOT_SERVER_INTERNAL_LISTEN_ADDR:-127.0.0.1:5444}" \ - -git-dir "${KNOT_REPO_SCAN_PATH:-/home/git/repositories}" \ - -log-path "/tmp/knotguard.log" -EOF -RUN chmod +x /usr/local/bin/knot-keys-wrapper - -# sshd config -COPY <<'EOF' /etc/ssh/sshd_config.d/knot.conf -PermitRootLogin no -PasswordAuthentication no -ChallengeResponseAuthentication no - -Match User git - AuthorizedKeysCommand /usr/local/bin/knot-keys-wrapper - AuthorizedKeysCommandUser nobody -EOF - -RUN echo 'Include /etc/ssh/sshd_config.d/*.conf' >> /etc/ssh/sshd_config - -COPY <<'EOF' /etc/ssh/sshd_config.d/host-keys.conf -HostKey /etc/ssh/keys/ssh_host_rsa_key -HostKey /etc/ssh/keys/ssh_host_ecdsa_key -HostKey /etc/ssh/keys/ssh_host_ed25519_key -EOF - -RUN mkdir -p /home/git/.config/git -COPY <<'EOF' /home/git/.config/git/config -[user] - name = Tangled - email = noreply@tangled.org -[receive] - advertisePushOptions = true -[uploadpack] - allowFilter = true - allowReachableSHA1InWant = true -EOF -RUN mkdir -p /home/git/repositories && chown -R git:git /home/git - -COPY <<'EOF' /usr/local/bin/knot-entrypoint.sh -#!/bin/sh -set -eu -[ -z "${KNOT_SERVER_OWNER:-}" ] && [ -r /shared/owner-did ] && \ - export KNOT_SERVER_OWNER="$(cat /shared/owner-did)" -: "${KNOT_SERVER_OWNER:?set via env or /shared/owner-did}" - -mkdir -p /etc/ssh/keys -[ -f /etc/ssh/keys/ssh_host_rsa_key ] || ssh-keygen -t rsa -f /etc/ssh/keys/ssh_host_rsa_key -q -N "" -[ -f /etc/ssh/keys/ssh_host_ecdsa_key ] || ssh-keygen -t ecdsa -f /etc/ssh/keys/ssh_host_ecdsa_key -q -N "" -[ -f /etc/ssh/keys/ssh_host_ed25519_key ] || ssh-keygen -t ed25519 -f /etc/ssh/keys/ssh_host_ed25519_key -q -N "" - -if [ -f /usr/local/share/ca-certificates/caddy.crt ]; then - update-ca-certificates -fi - -/usr/sbin/sshd -D -e & -exec su-exec git /usr/local/bin/knot server -EOF -RUN chmod +x /usr/local/bin/knot-entrypoint.sh - -VOLUME /home/git -EXPOSE 22 5555 - -WORKDIR /home/git - -ENTRYPOINT ["/sbin/tini", "--"] -CMD ["/usr/local/bin/knot-entrypoint.sh"] diff --git a/localinfra/readme.md b/localinfra/readme.md index 9c7d5fe0e..ebee64d40 100644 --- a/localinfra/readme.md +++ b/localinfra/readme.md @@ -13,7 +13,7 @@ To make that work: - [did-method-plc](https://github.com/did-method-plc/did-method-plc) () - atproto_pds () - jetstream () -- knot () +- knot () - spindle () - knotmirror () - appview () (live reloading) diff --git a/localinfra/scripts/init-accounts.sh b/localinfra/scripts/init-accounts.sh index 69f8c8fe3..1b4c778d0 100644 --- a/localinfra/scripts/init-accounts.sh +++ b/localinfra/scripts/init-accounts.sh @@ -138,7 +138,6 @@ printf '%s' "$LABEL_DEFAULTS" > "${SHARED_DIR}/label-defaults" printf '[env] wrote label-defaults, label-gfi\n' >&2 # service definitions (under OWNER_DID) -put_record "at://$OWNER_DID/sh.tangled.knot/$GO_KNOT_HOSTNAME" "{\"createdAt\": \"${CREATED_AT}\"}" >/dev/null put_record "at://$OWNER_DID/sh.tangled.knot/$KNOT_HOSTNAME" "{\"createdAt\": \"${CREATED_AT}\"}" >/dev/null put_record "at://$OWNER_DID/sh.tangled.spindle/$SPINDLE_HOSTNAME" "{\"createdAt\": \"${CREATED_AT}\"}" >/dev/null diff --git a/localinfra/scripts/init-data.sh b/localinfra/scripts/init-data.sh index c68174ecf..175f1cf4f 100644 --- a/localinfra/scripts/init-data.sh +++ b/localinfra/scripts/init-data.sh @@ -1,8 +1,6 @@ #!/bin/sh set -eu -: "${GO_KNOT_URL:?GO_KNOT_URL must be set}" -: "${GO_KNOT_HOSTNAME:?GO_KNOT_HOSTNAME must be set}" : "${KNOT_URL:?KNOT_URL must be set}" : "${KNOT_HOSTNAME:?KNOT_HOSTNAME must be set}" : "${PDS_HOSTNAME:?PDS_HOSTNAME must be set}" -- 2.51.2