From 61fe314bb1790ab69e7ee43a77c6664f600e0bc9 Mon Sep 17 00:00:00 2001 From: Natalie Rose Date: Thu, 10 Sep 2026 13:42:11 +1000 Subject: [PATCH] Check formatting --- .prettierignore | 1 + CLAUDE.md | 49 ++++++++++--------- docker-compose.yml | 3 +- tailscale/phpmyadmin/phpmyadmin.json | 1 - .../portainer-agent/portainer-agent.json | 1 - 5 files changed, 29 insertions(+), 26 deletions(-) create mode 100644 .prettierignore diff --git a/.prettierignore b/.prettierignore new file mode 100644 index 0000000..72e8cca --- /dev/null +++ b/.prettierignore @@ -0,0 +1 @@ +deploy-trigger/hooks.json diff --git a/CLAUDE.md b/CLAUDE.md index 1eb938a..7fbc133 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -74,9 +74,9 @@ if one exists and otherwise reverse-proxies to `server:5000`. **Data + infra.** None of these publish host ports (only `caddy` does). `mysql` 5.5 (root password from `LACUNA_MYSQL_ROOT_PASSWORD`; compose healthcheck via `mysqladmin ping`), with `mysql-dump.sh` bind-mounted in and nightly logical dumps written to `./data/backups` (7-day retention, driven by -the Ofelia `mysql-dump` job). `memcached` for sessions/cache -— currently ephemeral; the file-persistence `command`/`volumes` in `docker-compose.yml` are -commented out. `beanstalk` job queue (schickling/beanstalkd) with `beanstalk-console`. +the Ofelia `mysql-dump` job). `memcached` for sessions/cache — currently ephemeral; the +file-persistence `command`/`volumes` in `docker-compose.yml` are commented out. `beanstalk` job +queue (schickling/beanstalkd) with `beanstalk-console`. **Schedulers** — all reuse the `tlecommunity/server` image: @@ -98,20 +98,23 @@ them). Each follows the same two-container pattern: a `-tailscale` sidecar `net_admin`/`sys_module` caps, tsnet state under `./data/tailscale-`, and a Tailscale Serve config at `./tailscale//.json` (`AllowFunnel: false` — tailnet-only) — while the real service container joins it via `network_mode: service:-tailscale` with no ports/caps of its -own. `phpmyadmin` proxies to its own apache on `:80`; `portainer-agent` (`EDGE`-mode, `/var/run/docker.sock` -+ `/:/host` mounted) proxies to `:9001`. -`deploy-trigger` is an HMAC-gated webhook (`adnanh/webhook`, built via `Dockerfile.deploy-trigger`, -config in `./tailscale/deploy-trigger/hooks.json`) that CI POSTs to in order to trigger a deploy. It -deliberately does **not** run `deploy.sh` or touch docker itself — `deploy.sh` needs root, and giving -a network-reachable container that power (whether via `sudo` or a mounted docker socket) would just -relocate the same risk. Instead `hooks.json` runs `./tailscale/deploy-trigger/receive-deploy.sh`, -which records the request (with CI-supplied `actor`/`ref`/`commit`/`ci_run_url`) into -`./data/deploy-requests/` and appends a line to `./log/deploy/deploy-audit.log`. A host-level systemd -`.path`/`.service` pair (`./systemd/deploy-trigger.path`, `./systemd/deploy-trigger.service`, -`./systemd/run-queued-deploy.sh` — see `./systemd/README.md` for the one-time install) is the only -thing outside Docker Compose in this repo: it watches that directory and, running as root, actually -executes `deploy.sh`, logging full output to `./log/deploy/deploy-.log` and appending the -outcome (`succeeded`/`failed`, exit code, duration) to the audit log. +own. `phpmyadmin` proxies to its own apache on `:80`; `portainer-agent` (`EDGE`-mode, +`/var/run/docker.sock` + +- `/:/host` mounted) proxies to `:9001`. `deploy-trigger` is an HMAC-gated webhook + (`adnanh/webhook`, built via `Dockerfile.deploy-trigger`, config in + `./tailscale/deploy-trigger/hooks.json`) that CI POSTs to in order to trigger a deploy. It + deliberately does **not** run `deploy.sh` or touch docker itself — `deploy.sh` needs root, and + giving a network-reachable container that power (whether via `sudo` or a mounted docker socket) + would just relocate the same risk. Instead `hooks.json` runs + `./tailscale/deploy-trigger/receive-deploy.sh`, which records the request (with CI-supplied + `actor`/`ref`/`commit`/`ci_run_url`) into `./data/deploy-requests/` and appends a line to + `./log/deploy/deploy-audit.log`. A host-level systemd `.path`/`.service` pair + (`./systemd/deploy-trigger.path`, `./systemd/deploy-trigger.service`, + `./systemd/run-queued-deploy.sh` — see `./systemd/README.md` for the one-time install) is the only + thing outside Docker Compose in this repo: it watches that directory and, running as root, + actually executes `deploy.sh`, logging full output to `./log/deploy/deploy-.log` and + appending the outcome (`succeeded`/`failed`, exit code, duration) to the audit log. ## Configuration @@ -130,10 +133,10 @@ Tracked config and scripts: `etc/log4perl.conf` (Perl logging — INFO to stderr bootstrap), `mysql-dump.sh` (nightly db backup, bind-mounted into `mysql`), `Dockerfile.logrotate` + `entrypoint-logrotate.sh` + `lacuna.logrotate` (the logrotate sidecar), `deploy.sh` (pull → `up -d --remove-orphans` → `image prune`), `./tailscale//` (Serve configs for the Management -services, see Architecture), `Dockerfile.deploy-trigger` + `./tailscale/deploy-trigger/{hooks.json, -receive-deploy.sh}`, and `./systemd/` (the host-installed deploy-trigger units — the one thing here -Compose doesn't manage). Repo files are Prettier-formatted: `npm run format:check` / -`npm run format:fix` (config in `.prettierrc`). +services, see Architecture), `Dockerfile.deploy-trigger` + +`./tailscale/deploy-trigger/{hooks.json, receive-deploy.sh}`, and `./systemd/` (the host-installed +deploy-trigger units — the one thing here Compose doesn't manage). Repo files are +Prettier-formatted: `npm run format:check` / `npm run format:fix` (config in `.prettierrc`). ## Host-mounted trees @@ -155,5 +158,5 @@ Created on the deploy host, mostly not in git: persistence is re-enabled.) `tailscale-phpmyadmin` / `tailscale-portainer-agent` / `tailscale-deploy-trigger` hold each Management sidecar's tsnet state. `deploy-requests` is not persistent state but a transient work queue: `deploy-trigger` writes one JSON file per triggered - deploy there, and the host `deploy-trigger.service` (see Architecture → Management) deletes it once - `deploy.sh` has run. + deploy there, and the host `deploy-trigger.service` (see Architecture → Management) deletes it + once `deploy.sh` has run. diff --git a/docker-compose.yml b/docker-compose.yml index 4680d04..33aa282 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -146,7 +146,8 @@ services: server-building-scheduler: image: ${CONTAINER_REGISTRY_URL:?error}/tlecommunity/server:latest - command: '/bin/bash bin/run_scheduler.sh schedule_building.pl --noquiet --nodaemonize --initialize' + command: + '/bin/bash bin/run_scheduler.sh schedule_building.pl --noquiet --nodaemonize --initialize' container_name: server-building-scheduler restart: unless-stopped depends_on: diff --git a/tailscale/phpmyadmin/phpmyadmin.json b/tailscale/phpmyadmin/phpmyadmin.json index f006eda..088f152 100644 --- a/tailscale/phpmyadmin/phpmyadmin.json +++ b/tailscale/phpmyadmin/phpmyadmin.json @@ -17,4 +17,3 @@ "${TS_CERT_DOMAIN}:443": false } } - diff --git a/tailscale/portainer-agent/portainer-agent.json b/tailscale/portainer-agent/portainer-agent.json index 251dfd5..47b64fd 100644 --- a/tailscale/portainer-agent/portainer-agent.json +++ b/tailscale/portainer-agent/portainer-agent.json @@ -17,4 +17,3 @@ "${TS_CERT_DOMAIN}:443": false } } - -- 2.51.2