generated from coop-cloud/example
Compare commits
3 Commits
main
...
keycloak-s
Author | SHA1 | Date | |
---|---|---|---|
20067dbe93 | |||
3d447a72c8 | |||
0a04bae1f5 |
22
.drone.yml
22
.drone.yml
@ -3,37 +3,27 @@ kind: pipeline
|
|||||||
name: deploy to swarm-test.autonomic.zone
|
name: deploy to swarm-test.autonomic.zone
|
||||||
steps:
|
steps:
|
||||||
- name: deployment
|
- name: deployment
|
||||||
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
|
image: decentral1se/stack-ssh-deploy:latest
|
||||||
settings:
|
settings:
|
||||||
host: swarm-test.autonomic.zone
|
host: swarm-test.autonomic.zone
|
||||||
stack: custom_html
|
stack: custom_html
|
||||||
purge: true
|
purge: true
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
deploy_key:
|
deploy_key:
|
||||||
from_secret: drone_ssh_swarm_test
|
from_secret: drone_ssh_swarm_test
|
||||||
environment:
|
environment:
|
||||||
DOMAIN: custom-html.swarm-test.autonomic.zone
|
DOMAIN: custom-html.swarm-test.autonomic.zone
|
||||||
STACK_NAME: custom_html
|
STACK_NAME: custom_html
|
||||||
LETS_ENCRYPT_ENV: production
|
LETS_ENCRYPT_ENV: production
|
||||||
NGINX_DEFAULT_CONF_VERSION: v1
|
|
||||||
ENTRYPOINT_CONF_VERSION: v1
|
|
||||||
trigger:
|
trigger:
|
||||||
branch:
|
branch:
|
||||||
- main
|
- main
|
||||||
---
|
---
|
||||||
kind: pipeline
|
kind: pipeline
|
||||||
name: generate recipe catalogue
|
name: recipe release
|
||||||
steps:
|
steps:
|
||||||
- name: release a new version
|
- name: release a new version
|
||||||
image: plugins/downstream
|
image: thecoopcloud/drone-abra:latest
|
||||||
settings:
|
settings:
|
||||||
server: https://build.coopcloud.tech
|
command: recipe custom-html release
|
||||||
token:
|
deploy_key:
|
||||||
from_secret: drone_abra-bot_token
|
from_secret: abra_bot_deploy_key
|
||||||
fork: true
|
|
||||||
repositories:
|
|
||||||
- toolshed/auto-recipes-catalogue-json
|
|
||||||
|
|
||||||
trigger:
|
|
||||||
event: tag
|
|
||||||
|
21
.env.sample
21
.env.sample
@ -9,24 +9,3 @@ COMPOSE_FILE="compose.yml"
|
|||||||
|
|
||||||
# Single Sign On via Traefik "file provider"
|
# Single Sign On via Traefik "file provider"
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.sso.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.sso.yml"
|
||||||
|
|
||||||
# Git-pull regularly
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.git-pull.yml"
|
|
||||||
#GIT_REPO_URL="https://git.coopcloud.tech/dalmationer/hexbomb.gay"
|
|
||||||
#CRON_SCHEDULE="*/1 * * * *"
|
|
||||||
|
|
||||||
# Optionally redirect the entire domain or a sub-path:
|
|
||||||
# path under which you want to redirect all URLs (with trailing slash):
|
|
||||||
#REDIRECT_FROM_PATH=/
|
|
||||||
# full URL of target domain (and optionally path) with trailing slash:
|
|
||||||
#REDIRECT_TO_URL=https://coopcloud.tech/
|
|
||||||
# temporary or permanent redirect? (uncomment one)
|
|
||||||
#REDIRECT_TYPE=redirect
|
|
||||||
#REDIRECT_TYPE=permanent
|
|
||||||
|
|
||||||
# Optionally handle all URL requests using a single file (commonly index.html)
|
|
||||||
#SINGLE_PAGE_SITE_HANDLER=/index.html
|
|
||||||
|
|
||||||
# Enable an SSH server to allow SFTP uploads to the web root
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.sftp.yml"
|
|
||||||
#PUBLIC_KEY="ssh-ed25519 AAAAC3NzaJ1lZDI1NTE5AAAAIXqf4nxUxuGmLOaxXXXXXXXXoM/GwhcrAgmtbgXToaYmCJ user@host" # Replace with a public key you generate
|
|
25
README.md
25
README.md
@ -1,11 +1,9 @@
|
|||||||
# Custom HTML
|
# Custom HTML
|
||||||
|
|
||||||
[](https://build.coopcloud.tech/coop-cloud/custom-html)
|
|
||||||
|
|
||||||
Custom HTML website, served using Nginx.
|
Custom HTML website, served using Nginx.
|
||||||
|
|
||||||
<!-- metadata -->
|
<!-- metadata -->
|
||||||
* **Category**: Development
|
* **Category**: Apps
|
||||||
* **Status**: 2, beta
|
* **Status**: 2, beta
|
||||||
* **Image**: [`nginx`](https://hub.docker.com/_/nginx), 4, upstream
|
* **Image**: [`nginx`](https://hub.docker.com/_/nginx), 4, upstream
|
||||||
* **Healthcheck**: No
|
* **Healthcheck**: No
|
||||||
@ -20,28 +18,13 @@ Custom HTML website, served using Nginx.
|
|||||||
1. Set up Docker Swarm and [`abra`]
|
1. Set up Docker Swarm and [`abra`]
|
||||||
2. Deploy [`coop-cloud/traefik`]
|
2. Deploy [`coop-cloud/traefik`]
|
||||||
3. `abra app new custom-html`
|
3. `abra app new custom-html`
|
||||||
4. `abra app config YOURAPPDOMAIN` - be sure to change `$DOMAIN` to something that resolves to
|
4. `abra app YOURAPPDOMAIN config` - be sure to change `$DOMAIN` to something that resolves to
|
||||||
your Docker swarm box
|
your Docker swarm box
|
||||||
5. `abra app deploy YOURAPPDOMAIN`
|
5. `abra app YOURAPPDOMAIN deploy`
|
||||||
6. Copy your files to the container, using something like
|
6. Copy your files to the container, using something like
|
||||||
```
|
```
|
||||||
abra app cp YOURAPPDOMAIN index.html app:/usr/share/nginx/html
|
abra app YOURAPPDOMAIN cp index.html app:/usr/share/nginx/html
|
||||||
```
|
```
|
||||||
|
|
||||||
## Allowing upload via SSH/SFTP
|
|
||||||
To allow management of your site's files using scp, rsync or other SSH-based tools:
|
|
||||||
1. If you don't already have one, generate an SSH keypair using `ssh-keygen`
|
|
||||||
1. `abra app config YOURAPPDOMAIN`
|
|
||||||
2. Uncomment these lines and add your public key:
|
|
||||||
```
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.sftp.yml"
|
|
||||||
#PUBLIC_KEY="ssh-ed25519 AAAAC3NzaJ1lZDI1NTE5AAAAIXqf4nxUxuGmLOaxXXXXXXXXoM/GwhcrAgmtbgXToaYmCJ user@host" # Replace with a public key you generate
|
|
||||||
```
|
|
||||||
3. `abra app undeploy YOURAPPDOMAIN`
|
|
||||||
3. `abra app deploy YOURAPPDOMAIN`
|
|
||||||
4. Test the SSH connection: `ssh -p 2220 sftp@YOURAPPDOMAIN`
|
|
||||||
5. You can copy local files into the server's web root with a command like: `scp -r -P 2220 * sftp@YOURAPPDOMAIN:/content`
|
|
||||||
|
|
||||||
|
|
||||||
[`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra
|
[`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra
|
||||||
[`coop-cloud/traefik`]: https://git.autonomic.zone/coop-cloud/traefik
|
[`coop-cloud/traefik`]: https://git.autonomic.zone/coop-cloud/traefik
|
||||||
|
3
abra.sh
3
abra.sh
@ -1,2 +1 @@
|
|||||||
export NGINX_DEFAULT_CONF_VERSION=v6
|
export NGINX_DEFAULT_CONF_VERSION=v1
|
||||||
export ENTRYPOINT_CONF_VERSION=v3
|
|
||||||
|
@ -1,26 +0,0 @@
|
|||||||
version: "3.8"
|
|
||||||
services:
|
|
||||||
git:
|
|
||||||
environment:
|
|
||||||
- GIT_REPO_URL
|
|
||||||
image: alpine/git:v2.47.2
|
|
||||||
entrypoint: /docker-entrypoint.sh
|
|
||||||
volumes:
|
|
||||||
- content:/git
|
|
||||||
configs:
|
|
||||||
- source: entrypoint_conf
|
|
||||||
target: /docker-entrypoint.sh
|
|
||||||
mode: 0555
|
|
||||||
deploy:
|
|
||||||
mode: replicated
|
|
||||||
replicas: 0
|
|
||||||
labels:
|
|
||||||
- "swarm.cronjob.enable=true"
|
|
||||||
- "swarm.cronjob.schedule=${CRON_SCHEDULE:-*/5 * * * *}"
|
|
||||||
restart_policy:
|
|
||||||
condition: none
|
|
||||||
|
|
||||||
configs:
|
|
||||||
entrypoint_conf:
|
|
||||||
name: ${STACK_NAME}_entrypoint_conf_${ENTRYPOINT_CONF_VERSION}
|
|
||||||
file: entrypoint.git-pull.sh
|
|
@ -1,41 +0,0 @@
|
|||||||
version: "3.8"
|
|
||||||
services:
|
|
||||||
ssh:
|
|
||||||
image: lscr.io/linuxserver/openssh-server:latest
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
environment:
|
|
||||||
- PUID=1000
|
|
||||||
- PGID=1000
|
|
||||||
- TZ=Etc/UTC
|
|
||||||
- USER_NAME=sftp
|
|
||||||
- PUBLIC_KEY
|
|
||||||
volumes:
|
|
||||||
- content:/content:rw
|
|
||||||
ports:
|
|
||||||
- 2220:2222
|
|
||||||
deploy:
|
|
||||||
restart_policy:
|
|
||||||
condition: on-failure
|
|
||||||
# The following is an admittedly hacky way of setting the owner
|
|
||||||
# of the `content` volume to the unprivileged `sftp` user, so
|
|
||||||
# that content can be transferred through the unprivileged sshd process
|
|
||||||
# using `scp` etc.
|
|
||||||
sshstart:
|
|
||||||
image: lscr.io/linuxserver/openssh-server:latest
|
|
||||||
user: root
|
|
||||||
depends_on:
|
|
||||||
- ssh
|
|
||||||
deploy:
|
|
||||||
restart_policy:
|
|
||||||
condition: none
|
|
||||||
volumes:
|
|
||||||
- content:/content:rw
|
|
||||||
entrypoint: [ "bash", "-c", "sleep 10 && chown -R 1000:1000 /content"]
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
content:
|
|
||||||
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
14
compose.yml
14
compose.yml
@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: nginx:1.28.0
|
image: nginx:1.21.3
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
deploy:
|
deploy:
|
||||||
@ -19,14 +19,9 @@ services:
|
|||||||
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
|
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
|
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
|
||||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
|
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
|
||||||
- "coop-cloud.${STACK_NAME}.version=1.10.0+1.28.0"
|
- "coop-cloud.${STACK_NAME}.version=1.1.0+1.21.3"
|
||||||
- "backupbot.backup=true"
|
|
||||||
- "backupbot.backup.path=/usr/share/nginx/html"
|
|
||||||
environment:
|
environment:
|
||||||
- DEFAULT_CONF_FILE=/etc/nginx/conf.d/default.conf
|
DEFAULT_CONF_FILE: /etc/nginx/conf.d/default.conf
|
||||||
- REDIRECT_FROM_PATH
|
|
||||||
- REDIRECT_TO_URL
|
|
||||||
- REDIRECT_TYPE
|
|
||||||
volumes:
|
volumes:
|
||||||
- content:/usr/share/nginx/html
|
- content:/usr/share/nginx/html
|
||||||
configs:
|
configs:
|
||||||
@ -45,8 +40,7 @@ volumes:
|
|||||||
configs:
|
configs:
|
||||||
nginx_default_conf:
|
nginx_default_conf:
|
||||||
name: ${STACK_NAME}_nginx_default_conf_${NGINX_DEFAULT_CONF_VERSION}
|
name: ${STACK_NAME}_nginx_default_conf_${NGINX_DEFAULT_CONF_VERSION}
|
||||||
file: default.conf.tmpl
|
file: default.conf
|
||||||
template_driver: golang
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
|
@ -10,22 +10,10 @@ server {
|
|||||||
location / {
|
location / {
|
||||||
root /usr/share/nginx/html;
|
root /usr/share/nginx/html;
|
||||||
index index.html index.htm;
|
index index.html index.htm;
|
||||||
|
try_files $uri $uri/ $uri.html;
|
||||||
{{ if env "REDIRECT_TO_URL" }}
|
|
||||||
rewrite ^{{ env "REDIRECT_FROM_PATH" }}(.*)$ {{ env "REDIRECT_TO_URL" }}$1 {{ env "REDIRECT_TYPE" }};
|
|
||||||
{{ end }}
|
|
||||||
|
|
||||||
{{ if env "SINGLE_PAGE_SITE_HANDLER" }}
|
|
||||||
try_files $uri $uri/ {{ env "SINGLE_PAGE_SITE_HANDLER" }} =404;
|
|
||||||
{{ else }}
|
|
||||||
try_files $uri $uri/ $uri.html =404;
|
|
||||||
{{ end }}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
error_page 404 /404.html;
|
#error_page 404 /404.html;
|
||||||
location = /404.html {
|
|
||||||
root /usr/share/nginx/html;
|
|
||||||
}
|
|
||||||
|
|
||||||
# redirect server error pages to the static page /50x.html
|
# redirect server error pages to the static page /50x.html
|
||||||
#
|
#
|
@ -1,11 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
|
|
||||||
if [ ! -d /git/.git ]; then
|
|
||||||
echo "No repo found, emptying /git/ directory"
|
|
||||||
rm -r /git/*
|
|
||||||
echo "Cloning $GIT_REPO_URL into /git"
|
|
||||||
git clone "$GIT_REPO_URL" /git
|
|
||||||
else
|
|
||||||
echo "Updating /git"
|
|
||||||
git pull
|
|
||||||
fi
|
|
@ -1 +0,0 @@
|
|||||||
Adds optional sftp support
|
|
Loading…
x
Reference in New Issue
Block a user