Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 919455212a | |||
| c00d5b4a16 | |||
| 4aacfaa0ee | |||
| 02ec8ba161 | |||
| fb0b664373 | |||
| 79a43dbadc | |||
| 466ff8e447 | |||
| d74f05c0d1 |
@@ -59,15 +59,10 @@ DB_MIGRATE_INDEXES_CONCURRENTLY=false
|
||||
# ====================================
|
||||
# SEARCH BACKEND
|
||||
|
||||
# recommended search backend sonic
|
||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.sonic.yml"
|
||||
# docker secret cannot be used due to distroless image, threfore add secret here
|
||||
#SONIC_PASSWORD=
|
||||
|
||||
# alternative search service
|
||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.meilisearch.yml"
|
||||
#SECRET_MEILI_MASTER_KEY_VERSION=v1
|
||||
|
||||
# ====================================
|
||||
# MAIL
|
||||
|
||||
|
||||
@@ -15,24 +15,38 @@ A [coop-cloud](https://coopcloud.tech) recipe for deploying [Bonfire](https://bo
|
||||
|
||||
## Basic usage
|
||||
|
||||
1. Set up Docker Swarm and [`abra`]
|
||||
2. Deploy [`coop-cloud/traefik`]
|
||||
3. `abra app new bonfire --secrets` (optionally with `--pass` if you'd like to save secrets in `pass`) and select your server from the list and enter the domain name you want Bonfire to be served from
|
||||
4. `abra app config YOUR_APP_DOMAIN_NAME` and check/edit the config keys
|
||||
5. `abra app deploy YOUR_APP_DOMAIN_NAME`
|
||||
6. Open the configured domain in your browser and sign up!
|
||||
1. `abra app new bonfire --secrets`
|
||||
2. `abra app config <app-name>`
|
||||
3. `abra app deploy <app-name>`
|
||||
4. Open the Elixir console: `abra app run <app-name> app bin/bonfire remote`
|
||||
5. Create admin account in Elixir console (the first account created this way will get admin rights): `Bonfire.Me.make_account_only("my@email.net", "my pw")`
|
||||
|
||||
## Upgrades
|
||||
`abra app deploy --force your-server.domain.name`
|
||||
## Use a custom Bonfire flavour
|
||||
|
||||
NOTE: we recommend switching to the new `sonic` search backend (instead of the deprecated `meilisearch`):
|
||||
1. comment the `COMPOSE_FILE` line that contains `compose.meilisearch.yml` in the `.env` file for your bonfire instancem and replace with a line like `COMPOSE_FILE="compose.yml:compose.sonic.yml"`
|
||||
By default, this recipe deploys the Bonfire `social` flavour. If you want a different one uncomment and define `APP_FLAVOUR` in you env file.
|
||||
|
||||
## Use a custom Bonfire version
|
||||
|
||||
Attention: This is not recommended for production deployment!
|
||||
|
||||
You can deploy another version of Bonfire by using `APP_VERSION` and `APP_PLATFORM`. Be aware that not all versions might be compatible with this recipe, especially the quite old ones.
|
||||
If you want to use bleeding edge releases try setting `APP_VERSION=latest-alpha`. When using this, every time you deploy with `abra app deploy --force <app-name>` the latest alpha replease will be used.
|
||||
|
||||
## Using a search backend
|
||||
|
||||
1. uncomment the `COMPOSE_FILE` line that contains `compose.sonic.yml` in the `.env` file for your bonfire instance.
|
||||
2. add `SONIC_PASSWORD=a-super-secret-password` to the same file (make sure to change the password after pasting!)
|
||||
3. redeploy with `abra app deploy --force your-server.domain.name`
|
||||
3. redeploy with `abra app deploy --force <app-name>`
|
||||
|
||||
## Protect the instance with basic auth
|
||||
|
||||
[`abra`]: https://docs.coopcloud.tech/abra/
|
||||
[`coop-cloud/traefik`]: https://git.coopcloud.tech/coop-cloud/traefik
|
||||
For e.g. a testing phase you can protect your Bonfire instance with basic auth:
|
||||
|
||||
1. uncomment the section `## BASIC_AUTH`
|
||||
2. create a username/password combination with `echo $(htpasswd -nB <username>)`
|
||||
3. add the combination as secret with `abra app secret insert <app-name> usersfile v1 '<the-user-password-combination>'`
|
||||
|
||||
##
|
||||
|
||||
## FAQ
|
||||
|
||||
@@ -44,3 +58,5 @@ Go into your app's Elixir console and enter something like `Bonfire.Me.make_acco
|
||||
|
||||
### How can I get to the app's Elixir console?
|
||||
`abra app run your-server.domain.name app bin/bonfire remote`
|
||||
|
||||
For more, see [docs.coopcloud.tech](https://docs.coopcloud.tech).
|
||||
@@ -1,51 +0,0 @@
|
||||
---
|
||||
version: "3.8"
|
||||
|
||||
services:
|
||||
app:
|
||||
depends_on:
|
||||
- search
|
||||
environment:
|
||||
- SEARCH_MEILI_INSTANCE=http://${STACK_NAME}_search:7700
|
||||
secrets:
|
||||
- meili_master_key
|
||||
|
||||
search:
|
||||
image: getmeili/meilisearch:v1.14 # WIP: upgrade from v1.11 to 1.14
|
||||
secrets:
|
||||
- meili_master_key
|
||||
volumes:
|
||||
- "search-data:/meili_data"
|
||||
- "dump-data:/meili_dumps"
|
||||
networks:
|
||||
- internal
|
||||
entrypoint: ["tini", "--", "/docker-entrypoint.sh", "/bin/meilisearch"]
|
||||
environment:
|
||||
- MEILI_DUMP_DIR=/meili_dumps
|
||||
configs:
|
||||
- source: app_entrypoint
|
||||
target: /docker-entrypoint.sh
|
||||
mode: 0555
|
||||
- source: meili_backup
|
||||
target: /meili_backup.sh
|
||||
mode: 0555
|
||||
labels:
|
||||
backupbot.backup: ${ENABLE_BACKUPS:-true}
|
||||
backupbot.backup.volumes.search-data: "false"
|
||||
backupbot.backup.volumes.dump-data.path: "/meili_dumps/meilisearch_latest.dump"
|
||||
backupbot.backup.pre-hook: "/meili_backup.sh backup"
|
||||
backupbot.restore.post-hook: '/meili_backup.sh restore'
|
||||
|
||||
volumes:
|
||||
search-data:
|
||||
dump-data:
|
||||
|
||||
configs:
|
||||
meili_backup:
|
||||
name: ${STACK_NAME}_meili_backup_${MEILI_BACKUP_VERSION:-v4}
|
||||
file: meili_backup.sh
|
||||
|
||||
secrets:
|
||||
meili_master_key:
|
||||
external: true
|
||||
name: ${STACK_NAME}_meili_master_key_${SECRET_MEILI_MASTER_KEY_VERSION:-v1}
|
||||
+1
-1
@@ -15,7 +15,7 @@ services:
|
||||
# - sonic_password
|
||||
|
||||
search:
|
||||
image: valeriansaliou/sonic:v1.5.1
|
||||
image: valeriansaliou/sonic:v1.7.4
|
||||
# secrets:
|
||||
# - sonic_password
|
||||
volumes:
|
||||
|
||||
@@ -86,6 +86,7 @@ services:
|
||||
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
|
||||
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
|
||||
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||
- "coop-cloud.${STACK_NAME}.version=1.0.0+1.0.5-social-amd64"
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:4000"]
|
||||
interval: 30s
|
||||
|
||||
-107
@@ -1,107 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
|
||||
backup() {
|
||||
SECRET=$(cat /run/secrets/meili_master_key)
|
||||
# Create dump
|
||||
echo "Creating new Meilisearch dump..."
|
||||
RESPONSE=$(curl -s -X POST 'http://localhost:7700/dumps' -H "Authorization: Bearer $SECRET")
|
||||
echo "Response: $RESPONSE"
|
||||
|
||||
# More robust extraction of task UID
|
||||
TASK_UID=$(echo "$RESPONSE" | sed -n 's/.*"taskUid":\([0-9]*\).*/\1/p')
|
||||
|
||||
if [ -z "$TASK_UID" ]; then
|
||||
echo "Failed to extract task UID from response. Aborting."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Waiting for dump creation (task $TASK_UID)..."
|
||||
|
||||
MAX_ATTEMPTS=600
|
||||
ATTEMPT=0
|
||||
while [ $ATTEMPT -lt $MAX_ATTEMPTS ]; do
|
||||
RESPONSE=$(curl -s "http://localhost:7700/tasks/$TASK_UID" -H "Authorization: Bearer $SECRET")
|
||||
echo "Task status response: $RESPONSE"
|
||||
|
||||
TASK_STATUS=$(echo "$RESPONSE" | sed -n 's/.*"status":"\([^"]*\)".*/\1/p')
|
||||
|
||||
if [ -z "$TASK_STATUS" ]; then
|
||||
echo "Failed to extract task status. Retrying..."
|
||||
ATTEMPT=$((ATTEMPT+1))
|
||||
sleep 5
|
||||
continue
|
||||
fi
|
||||
|
||||
echo "Current status: $TASK_STATUS"
|
||||
|
||||
if [ "$TASK_STATUS" = "succeeded" ]; then
|
||||
echo "Dump creation succeeded"
|
||||
break
|
||||
elif [ "$TASK_STATUS" = "enqueued" ] || [ "$TASK_STATUS" = "processing" ]; then
|
||||
echo "Dump creation in progress... ($TASK_STATUS)"
|
||||
ATTEMPT=$((ATTEMPT+1))
|
||||
sleep 5
|
||||
else
|
||||
echo "Dump creation in unexpected state: $TASK_STATUS. Giving up."
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
if [ $ATTEMPT -eq $MAX_ATTEMPTS ]; then
|
||||
echo "Timed out waiting for dump creation"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Extract dump UID more reliably
|
||||
DUMP_UID=$(echo "$RESPONSE" | sed -n 's/.*"dumpUid":"\([^"]*\)".*/\1/p')
|
||||
|
||||
if [ -z "$DUMP_UID" ]; then
|
||||
echo "Failed to extract dump UID. Aborting."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Using dump $DUMP_UID"
|
||||
|
||||
# Check if file exists before copying
|
||||
if [ ! -f "/meili_dumps/$DUMP_UID.dump" ]; then
|
||||
echo "Dump file /meili_dumps/$DUMP_UID.dump not found!"
|
||||
ls -la /meili_dumps/
|
||||
exit 1
|
||||
fi
|
||||
|
||||
cp -f "/meili_dumps/$DUMP_UID.dump" "/meili_dumps/meilisearch_latest.dump"
|
||||
echo "Dump created and copied successfully. You can find it at /meili_dumps/meilisearch_latest.dump"
|
||||
}
|
||||
|
||||
restore() {
|
||||
echo 'Restarting Meilisearch with imported dump, may take a while to become available...'
|
||||
|
||||
# Check if dump file exists
|
||||
if [ ! -f "/meili_dumps/meilisearch_latest.dump" ]; then
|
||||
echo "Error: Dump file not found at /meili_dumps/meilisearch_latest.dump"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
pkill meilisearch || echo "No Meilisearch process found to kill"
|
||||
|
||||
echo "Starting Meilisearch with import dump option..."
|
||||
MEILI_NO_ANALYTICS=true /bin/meilisearch --import-dump /meili_dumps/meilisearch_latest.dump &
|
||||
|
||||
echo "Meilisearch restore process initiated..."
|
||||
}
|
||||
|
||||
# Handle command line argument
|
||||
case "$1" in
|
||||
backup)
|
||||
backup
|
||||
;;
|
||||
restore)
|
||||
restore
|
||||
;;
|
||||
*)
|
||||
echo "Usage: $0 {backup|restore}"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1 @@
|
||||
ATTENTION: this is the first release and contains a couple of breaking changes in comparison to the previously unreleased recipe. There are a lot of secrets, keys and passwords moved to docker secrets, and the .env.sample was completly restructured. It is recommended to start your env file from scratch from the new template to make sure nothing is missing.
|
||||
Reference in New Issue
Block a user