diff --git a/.env.sample b/.env.sample index c7fc131..d4daf3c 100644 --- a/.env.sample +++ b/.env.sample @@ -9,3 +9,5 @@ LETS_ENCRYPT_ENV=production SECRET_KEY_BASE=replace-me DISABLE_AUTH=replace-me # true or false DISABLE_REGISTRATION=replace-me # true or false + +SECRET_TOTP_VAULT_KEY_VERSION=v1 diff --git a/README.md b/README.md index b7b4e28..a9be24e 100644 --- a/README.md +++ b/README.md @@ -19,6 +19,11 @@ 2. Deploy [`coop-cloud/traefik`] 3. `abra app new ${REPO_NAME} --secrets` (optionally with `--pass` if you'd like to save secrets in `pass`) + IMPORTANT: The TOTP secret needs to be 32 bytes or the container does not start. + ```sh + openssl rand -base64 32 > totp.txt + abra app secret insert zammad.klasse-methode.it totp_secret v1 -f -t totp.txt + ``` 4. `abra app config YOURAPPDOMAIN` - be sure to change `$DOMAIN` to something that resolves to your Docker swarm box 5. `abra app deploy YOURAPPDOMAIN` diff --git a/abra.sh b/abra.sh index 60974a7..fb179b1 100644 --- a/abra.sh +++ b/abra.sh @@ -3,3 +3,4 @@ export CLICKHOUSE_USER_CONF_VERSION=v2 export CLICKHOUSE_ENTRYPOINT_VERSION=v6 export PG_BACKUP_VERSION=v1 export CLICKHOUSE_BACKUP_SCRIPT_VERSION=v1 +export PLAUSIBLE_ENTRYPOINT_VERSION=v1 diff --git a/compose.yml b/compose.yml index ca1e152..89b5c71 100644 --- a/compose.yml +++ b/compose.yml @@ -3,8 +3,8 @@ version: "3.8" services: app: - image: plausible/analytics:v2.0.0 - command: sh -c "sleep 10 && /entrypoint.sh db createdb && /entrypoint.sh db migrate && /entrypoint.sh run" + image: ghcr.io/plausible/community-edition:v2.1.0 + entrypoint: /plausible_entrypoint.sh depends_on: - db - plausible_events_db @@ -21,6 +21,12 @@ services: - SMTP_HOST_SSL_ENABLED - DISABLE_REGISTRATION - DISABLE_AUTH + secrets: + - totp_secret + configs: + - source: plausible_entrypoint + target: /plausible_entrypoint.sh + mode: 0555 networks: - proxy - internal @@ -67,7 +73,7 @@ services: backupbot.restore.post-hook: "/pg_backup.sh restore" plausible_events_db: - image: clickhouse/clickhouse-server:23.4.2.11-alpine + image: clickhouse/clickhouse-server:24.3.3.102-alpine volumes: - event-data:/var/lib/clickhouse entrypoint: /custom-entrypoint.sh @@ -103,6 +109,9 @@ networks: internal: configs: + plausible_entrypoint: + name: ${STACK_NAME}_plausible_entrypoint_${PLAUSIBLE_ENTRYPOINT_VERSION} + file: plausible_entrypoint.sh clickhouse-config: name: ${STACK_NAME}_clickhouse_config_${CLICKHOUSE_CONF_VERSION} file: clickhouse-config.xml @@ -118,3 +127,8 @@ configs: clickhouse_backup: name: ${STACK_NAME}_clickhouse_backup_${CLICKHOUSE_BACKUP_SCRIPT_VERSION} file: clickhouse_backup.sh + +secrets: + totp_secret: + name: ${STACK_NAME}_totp_secret_${SECRET_TOTP_VAULT_KEY_VERSION} + external: true diff --git a/plausible_entrypoint.sh b/plausible_entrypoint.sh new file mode 100644 index 0000000..e87b9d8 --- /dev/null +++ b/plausible_entrypoint.sh @@ -0,0 +1,7 @@ +#!/bin/sh + +set -e + +[ -f /run/secrets/totp_secret ] && export TOTP_VAULT_KEY="$(cat /run/secrets/totp_secret)" + +sh -c "sleep 10 && /entrypoint.sh db createdb && /entrypoint.sh db migrate && /entrypoint.sh run"