Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fe70100959 | ||
|
|
5ed2d33124 | ||
|
|
2fecad021b |
@@ -14,10 +14,13 @@ func GenerateConfigTOML(cv ConfigValues) (string, error) {
|
|||||||
sb.WriteString("# Server Configuration\n")
|
sb.WriteString("# Server Configuration\n")
|
||||||
sb.WriteString("[server]\n")
|
sb.WriteString("[server]\n")
|
||||||
// Always containerAppPort: the container listens on this port internally; the
|
// Always containerAppPort: the container listens on this port internally; the
|
||||||
// user's port is the host-side mapping (see RunAppClienteContainer).
|
// user's port is the host-side mapping (see RunAppClienteContainer). Persisted
|
||||||
|
// separately as host_port so it survives as the form default on a re-run.
|
||||||
sb.WriteString(fmt.Sprintf("port = %d\n", containerAppPort))
|
sb.WriteString(fmt.Sprintf("port = %d\n", containerAppPort))
|
||||||
|
sb.WriteString(fmt.Sprintf("host_port = %s\n", cv.Server["port"]))
|
||||||
sb.WriteString(fmt.Sprintf("timeout_seconds = %s\n", cv.Server["timeout"]))
|
sb.WriteString(fmt.Sprintf("timeout_seconds = %s\n", cv.Server["timeout"]))
|
||||||
sb.WriteString(fmt.Sprintf("environment = %q\n", cv.Server["environment"]))
|
sb.WriteString(fmt.Sprintf("environment = %q\n", cv.Server["environment"]))
|
||||||
|
sb.WriteString(fmt.Sprintf("seccomp_unconfined = %t\n", cv.Server["seccomp_unconfined"] == "Sim"))
|
||||||
sb.WriteString("\n")
|
sb.WriteString("\n")
|
||||||
|
|
||||||
// [database]
|
// [database]
|
||||||
|
|||||||
@@ -60,6 +60,12 @@ func TestGenerateConfigTOML_RoundTrip(t *testing.T) {
|
|||||||
if cfg.Server.Environment != "production" {
|
if cfg.Server.Environment != "production" {
|
||||||
t.Errorf("environment = %q, want %q", cfg.Server.Environment, "production")
|
t.Errorf("environment = %q, want %q", cfg.Server.Environment, "production")
|
||||||
}
|
}
|
||||||
|
if cfg.Server.HostPort != 9090 {
|
||||||
|
t.Errorf("host_port = %d, want 9090", cfg.Server.HostPort)
|
||||||
|
}
|
||||||
|
if cfg.Server.SeccompUnconfined {
|
||||||
|
t.Errorf("seccomp_unconfined = true, want false")
|
||||||
|
}
|
||||||
if cfg.Database.Type != "postgres" {
|
if cfg.Database.Type != "postgres" {
|
||||||
t.Errorf("database type = %q, want %q", cfg.Database.Type, "postgres")
|
t.Errorf("database type = %q, want %q", cfg.Database.Type, "postgres")
|
||||||
}
|
}
|
||||||
@@ -103,8 +109,8 @@ func TestGenerateConfigTOML_PortIsAlwaysContainerPort(t *testing.T) {
|
|||||||
if cfg.Server.Port != containerAppPort {
|
if cfg.Server.Port != containerAppPort {
|
||||||
t.Errorf("config port = %d, want fixed containerAppPort %d", cfg.Server.Port, containerAppPort)
|
t.Errorf("config port = %d, want fixed containerAppPort %d", cfg.Server.Port, containerAppPort)
|
||||||
}
|
}
|
||||||
if strings.Contains(out, "port = 9090") {
|
if cfg.Server.HostPort != 9090 {
|
||||||
t.Errorf("host port 9090 leaked into config.toml:\n%s", out)
|
t.Errorf("host_port = %d, want 9090", cfg.Server.HostPort)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+20
-2
@@ -182,6 +182,16 @@ func shellQuoteArgs(args []string) string {
|
|||||||
// app-cliente image.
|
// app-cliente image.
|
||||||
const updaterPollIntervalSeconds = 300
|
const updaterPollIntervalSeconds = 300
|
||||||
|
|
||||||
|
// buildRecreateCmd takes the app-cliente run argv (built with the wizard-time port) and
|
||||||
|
// swaps the baked-in port for a `$PORT` shell reference, so the poll script's recreate
|
||||||
|
// step uses whatever port it reads live from the container (see the PORT= line in
|
||||||
|
// RunUpdaterDockerContainer) instead of always replaying the port typed into the wizard.
|
||||||
|
func buildRecreateCmd(recreateArgs []string, wizardPort string) string {
|
||||||
|
wizardPortArg := shellQuote(fmt.Sprintf("%s:%d", wizardPort, containerAppPort))
|
||||||
|
livePortArg := fmt.Sprintf(`"$PORT:%d"`, containerAppPort)
|
||||||
|
return strings.Replace("docker "+shellQuoteArgs(recreateArgs), wizardPortArg, livePortArg, 1)
|
||||||
|
}
|
||||||
|
|
||||||
// RunUpdaterDockerContainer starts a tiny self-contained auto-updater for the
|
// RunUpdaterDockerContainer starts a tiny self-contained auto-updater for the
|
||||||
// app-dono-cliente container: no third-party updater project, just the official
|
// app-dono-cliente container: no third-party updater project, just the official
|
||||||
// `docker:cli` image running a poll loop (docker pull, compare image IDs, recreate on
|
// `docker:cli` image running a poll loop (docker pull, compare image IDs, recreate on
|
||||||
@@ -192,6 +202,11 @@ const updaterPollIntervalSeconds = 300
|
|||||||
// It mounts the docker socket (to pull/recreate) and the host's docker config.json
|
// It mounts the docker socket (to pull/recreate) and the host's docker config.json
|
||||||
// (written by the StepDockerLogin `docker login`) so `docker pull` can authenticate
|
// (written by the StepDockerLogin `docker login`) so `docker pull` can authenticate
|
||||||
// against the private registry.
|
// against the private registry.
|
||||||
|
//
|
||||||
|
// The recreate command reuses appClienteRunArgs' host port only as a fallback: at
|
||||||
|
// recreate time the script re-reads the live container's actual published port via
|
||||||
|
// `docker inspect`, so a port changed by hand after install survives an auto-update
|
||||||
|
// instead of being silently reverted to whatever was typed into the wizard.
|
||||||
func RunUpdaterDockerContainer(appImage, appContainerName, configPath, configDestinationPath string, cv ConfigValues) error {
|
func RunUpdaterDockerContainer(appImage, appContainerName, configPath, configDestinationPath string, cv ConfigValues) error {
|
||||||
updaterName := "app-dono-updater"
|
updaterName := "app-dono-updater"
|
||||||
|
|
||||||
@@ -211,7 +226,7 @@ func RunUpdaterDockerContainer(appImage, appContainerName, configPath, configDes
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
recreateCmd := "docker " + shellQuoteArgs(recreateArgs)
|
recreateCmd := buildRecreateCmd(recreateArgs, cv.Server["port"])
|
||||||
|
|
||||||
script := fmt.Sprintf(`set -e
|
script := fmt.Sprintf(`set -e
|
||||||
IMAGE=%s
|
IMAGE=%s
|
||||||
@@ -221,13 +236,15 @@ while true; do
|
|||||||
CURRENT=$(docker inspect --format '{{.Image}}' "$NAME" 2>/dev/null || true)
|
CURRENT=$(docker inspect --format '{{.Image}}' "$NAME" 2>/dev/null || true)
|
||||||
LATEST=$(docker inspect --format '{{.Id}}' "$IMAGE" 2>/dev/null || true)
|
LATEST=$(docker inspect --format '{{.Id}}' "$IMAGE" 2>/dev/null || true)
|
||||||
if [ -n "$LATEST" ] && [ "$CURRENT" != "$LATEST" ]; then
|
if [ -n "$LATEST" ] && [ "$CURRENT" != "$LATEST" ]; then
|
||||||
|
PORT=$(docker inspect --format '{{(index (index .NetworkSettings.Ports "%d/tcp") 0).HostPort}}' "$NAME" 2>/dev/null || true)
|
||||||
|
if [ -z "$PORT" ]; then PORT=%s; fi
|
||||||
docker stop "$NAME" >/dev/null 2>&1 || true
|
docker stop "$NAME" >/dev/null 2>&1 || true
|
||||||
docker rm "$NAME" >/dev/null 2>&1 || true
|
docker rm "$NAME" >/dev/null 2>&1 || true
|
||||||
%s
|
%s
|
||||||
fi
|
fi
|
||||||
sleep %d
|
sleep %d
|
||||||
done
|
done
|
||||||
`, shellQuote(appImage), shellQuote(appContainerName), recreateCmd, updaterPollIntervalSeconds)
|
`, shellQuote(appImage), shellQuote(appContainerName), containerAppPort, shellQuote(cv.Server["port"]), recreateCmd, updaterPollIntervalSeconds)
|
||||||
|
|
||||||
args := []string{
|
args := []string{
|
||||||
"run", "-d",
|
"run", "-d",
|
||||||
@@ -235,6 +252,7 @@ done
|
|||||||
"--restart", "unless-stopped",
|
"--restart", "unless-stopped",
|
||||||
"-v", "/var/run/docker.sock:/var/run/docker.sock",
|
"-v", "/var/run/docker.sock:/var/run/docker.sock",
|
||||||
"-v", fmt.Sprintf("%s:/config.json", dockerConfigPath),
|
"-v", fmt.Sprintf("%s:/config.json", dockerConfigPath),
|
||||||
|
"-e", "DOCKER_CONFIG=/",
|
||||||
"--log-opt", "max-size=5m",
|
"--log-opt", "max-size=5m",
|
||||||
"--log-opt", "max-file=1",
|
"--log-opt", "max-file=1",
|
||||||
"--entrypoint", "sh",
|
"--entrypoint", "sh",
|
||||||
|
|||||||
@@ -39,3 +39,35 @@ func TestShellQuoteArgsRoundTrip(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestBuildRecreateCmdUsesLivePort guards against the updater silently reverting a host
|
||||||
|
// port that was changed by hand after install: the recreate command must reference the
|
||||||
|
// live $PORT read at recreate time, not replay the port typed into the wizard.
|
||||||
|
func TestBuildRecreateCmdUsesLivePort(t *testing.T) {
|
||||||
|
if _, err := exec.LookPath("sh"); err != nil {
|
||||||
|
t.Skip("sh not available")
|
||||||
|
}
|
||||||
|
|
||||||
|
args := []string{"run", "-d", "-p", "9999:8080", "--name", "app-dono-cliente"}
|
||||||
|
cmd := buildRecreateCmd(args, "9999")
|
||||||
|
|
||||||
|
if strings.Contains(cmd, "9999:8080") {
|
||||||
|
t.Fatalf("recreate command still contains the wizard-time port literal: %s", cmd)
|
||||||
|
}
|
||||||
|
if !strings.Contains(cmd, `"$PORT:8080"`) {
|
||||||
|
t.Fatalf("recreate command missing live $PORT reference: %s", cmd)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Swap the leading `docker` for `printf` so we can inspect the argv sh would have
|
||||||
|
// passed to docker, with PORT set as the poll script would set it live.
|
||||||
|
script := "PORT=8081\n" + strings.Replace(cmd, "docker ", "printf '%s\\n' ", 1)
|
||||||
|
out, err := exec.Command("sh", "-c", script).Output()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("sh failed: %v", err)
|
||||||
|
}
|
||||||
|
got := strings.Split(strings.TrimRight(string(out), "\n"), "\n")
|
||||||
|
want := []string{"run", "-d", "-p", "8081:8080", "--name", "app-dono-cliente"}
|
||||||
|
if !reflect.DeepEqual(got, want) {
|
||||||
|
t.Errorf("got %v, want %v", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+14
-6
@@ -61,9 +61,11 @@ type ConfigValues struct {
|
|||||||
|
|
||||||
type AppConfig struct {
|
type AppConfig struct {
|
||||||
Server struct {
|
Server struct {
|
||||||
Port int64 `toml:"port"`
|
Port int64 `toml:"port"`
|
||||||
Timeout int64 `toml:"timeout_seconds"`
|
HostPort int64 `toml:"host_port"`
|
||||||
Environment string `toml:"environment"`
|
Timeout int64 `toml:"timeout_seconds"`
|
||||||
|
Environment string `toml:"environment"`
|
||||||
|
SeccompUnconfined bool `toml:"seccomp_unconfined"`
|
||||||
} `toml:"server"`
|
} `toml:"server"`
|
||||||
Database struct {
|
Database struct {
|
||||||
Type string `toml:"type"`
|
Type string `toml:"type"`
|
||||||
@@ -83,7 +85,8 @@ type AppConfig struct {
|
|||||||
func loadConfig() AppConfig {
|
func loadConfig() AppConfig {
|
||||||
var config AppConfig
|
var config AppConfig
|
||||||
|
|
||||||
config.Server.Port = 8081
|
config.Server.Port = containerAppPort
|
||||||
|
config.Server.HostPort = 8081
|
||||||
config.Server.Timeout = 30
|
config.Server.Timeout = 30
|
||||||
config.Server.Environment = "production"
|
config.Server.Environment = "production"
|
||||||
|
|
||||||
@@ -113,6 +116,11 @@ func InitialModel() Model {
|
|||||||
s.Spinner = spinner.Dot
|
s.Spinner = spinner.Dot
|
||||||
s.Style = SpinnerStyle
|
s.Style = SpinnerStyle
|
||||||
|
|
||||||
|
seccompDefault := "Não"
|
||||||
|
if cfg.Server.SeccompUnconfined {
|
||||||
|
seccompDefault = "Sim"
|
||||||
|
}
|
||||||
|
|
||||||
return Model{
|
return Model{
|
||||||
currentStep: StepCheckDocker,
|
currentStep: StepCheckDocker,
|
||||||
loginForm: NewFormStep("Login no Repositório Docker", []FormField{
|
loginForm: NewFormStep("Login no Repositório Docker", []FormField{
|
||||||
@@ -175,7 +183,7 @@ func InitialModel() Model {
|
|||||||
Id: "port",
|
Id: "port",
|
||||||
Label: "Porta (host)",
|
Label: "Porta (host)",
|
||||||
Placeholder: "8081",
|
Placeholder: "8081",
|
||||||
Default: strconv.FormatInt(cfg.Server.Port, 10),
|
Default: strconv.FormatInt(cfg.Server.HostPort, 10),
|
||||||
Type: FieldTypeNumber,
|
Type: FieldTypeNumber,
|
||||||
CharLimit: 4,
|
CharLimit: 4,
|
||||||
},
|
},
|
||||||
@@ -197,7 +205,7 @@ func InitialModel() Model {
|
|||||||
{
|
{
|
||||||
Id: "seccomp_unconfined",
|
Id: "seccomp_unconfined",
|
||||||
Label: "Modo Compatibilidade (máquinas antigas)",
|
Label: "Modo Compatibilidade (máquinas antigas)",
|
||||||
Default: "Não",
|
Default: seccompDefault,
|
||||||
Type: FieldTypeSelect,
|
Type: FieldTypeSelect,
|
||||||
Options: []string{"Não", "Sim"},
|
Options: []string{"Não", "Sim"},
|
||||||
},
|
},
|
||||||
|
|||||||
Executable
+76
@@ -0,0 +1,76 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Manual fallback for tenants where the tuio installer's "run updater" step can't be
|
||||||
|
# used. Creates/recreates app-dono-updater: a poll loop (docker:cli, no third-party
|
||||||
|
# updater) that pulls app-dono-cliente's :latest image every 5 minutes and recreates the
|
||||||
|
# container when the image changes. Mirrors tuio's RunUpdaterDockerContainer /
|
||||||
|
# appClienteRunArgs (internal/tui/docker.go) -- keep the two in sync if either changes.
|
||||||
|
#
|
||||||
|
# Run this ON the tenant host, with app-dono-cliente already running. All of its run
|
||||||
|
# args (port, uid:gid, mounts, network, seccomp) are read live from the running
|
||||||
|
# container -- both now and every time the updater recreates it -- so nothing needs
|
||||||
|
# hand-editing per tenant and nothing baked-in goes stale if the container is ever
|
||||||
|
# changed by hand later (e.g. a manually remapped host port survives an auto-update).
|
||||||
|
set -e
|
||||||
|
|
||||||
|
APP_IMAGE="hub.davinti.com.br:443/app-dono/app-cliente:latest"
|
||||||
|
APP_NAME="app-dono-cliente"
|
||||||
|
UPDATER_NAME="app-dono-updater"
|
||||||
|
UPDATER_IMAGE="docker:cli"
|
||||||
|
POLL_INTERVAL="${POLL_INTERVAL:-300}"
|
||||||
|
DOCKER_CONFIG_HOST="${DOCKER_CONFIG_HOST:-$HOME/.docker/config.json}"
|
||||||
|
|
||||||
|
if ! docker inspect "$APP_NAME" >/dev/null 2>&1; then
|
||||||
|
echo "error: $APP_NAME is not running here -- start it first" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f "$DOCKER_CONFIG_HOST" ]; then
|
||||||
|
echo "error: $DOCKER_CONFIG_HOST not found -- run 'docker login' for the registry first" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker rm -f "$UPDATER_NAME" >/dev/null 2>&1 || true
|
||||||
|
docker pull "$UPDATER_IMAGE" >/dev/null
|
||||||
|
|
||||||
|
# The container is inspected again inside the poll loop on every recreate (not just
|
||||||
|
# here), so this whole block runs live in the updater container, not just once now.
|
||||||
|
POLL_SCRIPT=$(cat <<SCRIPT
|
||||||
|
set -e
|
||||||
|
IMAGE='$APP_IMAGE'
|
||||||
|
NAME='$APP_NAME'
|
||||||
|
while true; do
|
||||||
|
docker pull "\$IMAGE" >/dev/null 2>&1 || true
|
||||||
|
CURRENT=\$(docker inspect --format '{{.Image}}' "\$NAME" 2>/dev/null || true)
|
||||||
|
LATEST=\$(docker inspect --format '{{.Id}}' "\$IMAGE" 2>/dev/null || true)
|
||||||
|
if [ -n "\$LATEST" ] && [ "\$CURRENT" != "\$LATEST" ]; then
|
||||||
|
PORT=\$(docker inspect --format '{{(index (index .NetworkSettings.Ports "8080/tcp") 0).HostPort}}' "\$NAME")
|
||||||
|
UIDGID=\$(docker inspect --format '{{.Config.User}}' "\$NAME")
|
||||||
|
NET=\$(docker inspect --format '{{range \$k, \$v := .NetworkSettings.Networks}}{{\$k}}{{end}}' "\$NAME")
|
||||||
|
CONFMNT=\$(docker inspect --format '{{range .Mounts}}{{if eq .Destination "/app/config.toml"}}{{.Source}}{{end}}{{end}}' "\$NAME")
|
||||||
|
CERTMNT=\$(docker inspect --format '{{range .Mounts}}{{if eq .Destination "/app/certs"}}{{.Source}}{{end}}{{end}}' "\$NAME")
|
||||||
|
SECFLAG=""
|
||||||
|
case \$(docker inspect --format '{{json .HostConfig.SecurityOpt}}' "\$NAME") in
|
||||||
|
*seccomp=unconfined*) SECFLAG="--security-opt seccomp=unconfined" ;;
|
||||||
|
esac
|
||||||
|
docker stop "\$NAME" >/dev/null 2>&1 || true
|
||||||
|
docker rm "\$NAME" >/dev/null 2>&1 || true
|
||||||
|
docker run -d -u "\$UIDGID" -p "\$PORT:8080" --name "\$NAME" --network "\$NET" --restart unless-stopped -v "\$CONFMNT:/app/config.toml" -v "\$CERTMNT:/app/certs" \$SECFLAG "\$IMAGE"
|
||||||
|
fi
|
||||||
|
sleep $POLL_INTERVAL
|
||||||
|
done
|
||||||
|
SCRIPT
|
||||||
|
)
|
||||||
|
|
||||||
|
docker run -d \
|
||||||
|
--name "$UPDATER_NAME" \
|
||||||
|
--restart unless-stopped \
|
||||||
|
-v /var/run/docker.sock:/var/run/docker.sock \
|
||||||
|
-v "$DOCKER_CONFIG_HOST:/config.json" \
|
||||||
|
-e DOCKER_CONFIG=/ \
|
||||||
|
--log-opt max-size=5m \
|
||||||
|
--log-opt max-file=1 \
|
||||||
|
--entrypoint sh \
|
||||||
|
"$UPDATER_IMAGE" \
|
||||||
|
-c "$POLL_SCRIPT"
|
||||||
|
|
||||||
|
echo "app-dono-updater created for $APP_NAME."
|
||||||
Reference in New Issue
Block a user