Init this thing too

This commit is contained in:
decentral1se 2021-06-11 13:40:49 +02:00
parent ed92960c47
commit 7defc326ff
No known key found for this signature in database
GPG Key ID: 92DAD76BD9567B8A
4 changed files with 114 additions and 29 deletions

View File

@ -3,14 +3,16 @@
Community Keycloak SSO user management.
<!-- metadata -->
* **Category**:
* **Status**:
* **Image**: [`keycloak-collective-portal`](https://hub.docker.com/r/keycloak-collective-portal/keycloak-collective-portal)
* **Healthcheck**:
* **Backups**:
* **Email**:
* **Tests**:
* **SSO**:
- **Category**:
- **Status**:
- **Image**: [`decentral1se/keycloak-collective-portal`](https://hub.docker.com/r/decentral1se/keycloak-collective-portal)
- **Healthcheck**:
- **Backups**:
- **Email**:
- **Tests**:
- **SSO**:
<!-- endmetadata -->
## Basic usage

View File

@ -2,30 +2,50 @@
version: "3.8"
services:
web:
image: nginx:1.21.0
environment:
- STACK_NAME=${STACK_NAME}
- DOMAIN=${DOMAIN}
configs:
- source: nginx_conf
target: /etc/nginx/nginx.conf
networks:
- proxy
- internal
deploy:
update_config:
failure_action: rollback
labels:
- "traefik.enable=true"
- "traefik.http.services.wiki.loadbalancer.server.port=80"
- "traefik.http.routers.wiki.rule=Host(`${DOMAIN}`)"
- "traefik.http.routers.wiki.entrypoints=web-secure"
- "traefik.http.routers.wiki.tls.certresolver=production"
app:
image: nginx:1.19.2
image: "decentral1se/keycloak-collective-portal:latest"
networks:
- proxy
deploy:
restart_policy:
condition: on-failure
labels:
- "traefik.enable=true"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=80"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
## Redirect from EXTRA_DOMAINS to DOMAIN
#- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
- internal
configs:
- source: entrypoint_sh
target: /usr/local/bin/entrypoint.sh
mode: 0555
entrypoint: /usr/local/bin/entrypoint.sh
command: uvivorn --host 0.0.0.0 keycloak_collective_portal:app
networks:
proxy:
external: true
internal:
internal: true
configs:
nginx_conf:
name: ${STACK_NAME}_nginx_conf_${NGINX_CONF_VERSION}
file: nginx.conf.tmpl
template_driver: golang
entrypoint_sh:
name: ${STACK_NAME}_entrypoint_conf_${ENTRYPOINT_CONF_VERSION}
file: entrypoint.sh.tmpl
template_driver: golang

27
entrypoint.sh.tmpl Normal file
View File

@ -0,0 +1,27 @@
#! /bin/bash
set -eu
file_env() {
local var="$1"
local fileVar="${var}_FILE"
local def="${2:-}"
if [ "${!var:-}" ] && [ "${!fileVar:-}" ]; then
echo >&2 "error: both $var and $fileVar are set (but are exclusive)"
exit 1
fi
local val="$def"
if [ "${!var:-}" ]; then
val="${!var}"
elif [ "${!fileVar:-}" ]; then
val="$(< "${!fileVar}")"
fi
export "$var"="$val"
unset "$fileVar"
}
echo "Passing it back to the upstream ENTRYPOINT/CMD..."
exec "$@"

36
nginx.conf.tmpl Normal file
View File

@ -0,0 +1,36 @@
user www-data;
events {
worker_connections 768;
}
http {
upstream backend {
server {{ env "STACK_NAME" }}_app:8000;
}
include /etc/nginx/mime.types;
client_max_body_size 25M;
charset utf-8;
server {
listen 80 default;
server_name {{ env "DOMAIN" }};
location / {
try_files $uri @proxy_to_app;
}
location @proxy_to_app {
proxy_pass http://backend;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_redirect off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $server_name;
}
}
}