Compare commits
13 Commits
1.4.1+2024
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
57b2b21353
|
|||
| 8b48069197 | |||
| 3e25010062 | |||
| 93b40b1e29 | |||
| f277fe7070 | |||
| 13077bb2a4 | |||
| 0dc4c7f70f | |||
| d67f375d47 | |||
| 2590fd1343 | |||
| 1347ac8984 | |||
| fffc1c1459 | |||
| 292619f299 | |||
| bf442edf8e |
@ -24,6 +24,7 @@ steps:
|
||||
SECRET_SMTP_PASSWORD_VERSION: v1
|
||||
PRETIX_CONFIG_VERSION: v1
|
||||
PG_BACKUP_VERSION: v1
|
||||
SECRET_ADMIN_PASS_VERSION: v1
|
||||
trigger:
|
||||
branch:
|
||||
- main
|
||||
@ -39,7 +40,7 @@ steps:
|
||||
from_secret: drone_abra-bot_token
|
||||
fork: true
|
||||
repositories:
|
||||
- coop-cloud/auto-recipes-catalogue-json
|
||||
- toolshed/auto-recipes-catalogue-json
|
||||
|
||||
trigger:
|
||||
event: tag
|
||||
|
||||
@ -7,9 +7,11 @@ DOMAIN=pretix.example.com
|
||||
|
||||
LETS_ENCRYPT_ENV=production
|
||||
ENABLE_BACKUPS=true
|
||||
POST_DEPLOY_CMDS="app change_admin_pass"
|
||||
|
||||
SECRET_DB_PASSWORD_VERSION=v1
|
||||
SECRET_DJANGO_SECRET_KEY_VERSION=v1
|
||||
SECRET_ADMIN_PASS_VERSION=v1
|
||||
|
||||
SECRET_SMTP_PASSWORD_VERSION=v1
|
||||
SMTP_FROM=hello@localhost
|
||||
|
||||
16
abra.sh
16
abra.sh
@ -1,8 +1,16 @@
|
||||
export PRETIX_CONFIG_VERSION=v1
|
||||
export CRON_ENTRYPOINT_VERSION=v1
|
||||
export DB_ENTRYPOINT_VERSION=v1
|
||||
export PRETIX_CONFIG_VERSION=v2
|
||||
export CRON_ENTRYPOINT_VERSION=v2
|
||||
export DB_ENTRYPOINT_VERSION=v2
|
||||
export PG_BACKUP_VERSION=v1
|
||||
|
||||
change_adminpass(){
|
||||
python -m django changepassword admin@localhost
|
||||
password=$(cat /run/secrets/admin_pass)
|
||||
~/src/manage.py shell -c """
|
||||
from django.contrib.auth import get_user_model
|
||||
UserModel = get_user_model()
|
||||
u = UserModel.objects.get(email='admin@localhost')
|
||||
u.set_password('$password')
|
||||
u.save()
|
||||
"""
|
||||
echo "Changed admin password"
|
||||
}
|
||||
|
||||
36
compose.yml
36
compose.yml
@ -3,7 +3,7 @@ version: "3.8"
|
||||
|
||||
services:
|
||||
app:
|
||||
image: 'pretix/standalone:2024.11.0'
|
||||
image: "pretix/standalone:2025.10.0"
|
||||
networks:
|
||||
- proxy
|
||||
- internal
|
||||
@ -16,6 +16,7 @@ services:
|
||||
- db_password
|
||||
- smtp_password
|
||||
- django_secret_key
|
||||
- admin_pass
|
||||
deploy:
|
||||
restart_policy:
|
||||
condition: on-failure
|
||||
@ -25,16 +26,16 @@ services:
|
||||
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
|
||||
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
|
||||
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||
- "coop-cloud.${STACK_NAME}.version=1.4.1+2024.11.0"
|
||||
- "coop-cloud.${STACK_NAME}.version=2.3.0+2025.10.0"
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost/healthcheck"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 10
|
||||
retries: 30
|
||||
start_period: 1m
|
||||
|
||||
db:
|
||||
image: postgres:12
|
||||
image: postgres:16
|
||||
volumes:
|
||||
- "postgres:/var/lib/postgresql/data"
|
||||
networks:
|
||||
@ -54,26 +55,32 @@ services:
|
||||
mode: 0555
|
||||
entrypoint: /docker-entrypoint.sh
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "[ -f $${HEALTHCHECK_MARKER} ] || pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
|
||||
interval: 10s
|
||||
test:
|
||||
[
|
||||
"CMD-SHELL",
|
||||
"[ -f $${HEALTHCHECK_MARKER} ] || pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}",
|
||||
]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
retries: 20
|
||||
start_period: 1m
|
||||
deploy:
|
||||
labels:
|
||||
backupbot.backup: "${ENABLE_BACKUPS:-true}"
|
||||
backupbot.backup.pre-hook: "/pg_backup.sh backup"
|
||||
backupbot.backup.pre-hook: "/pg_backup.sh backup"
|
||||
backupbot.backup.volumes.postgres.path: "backup.sql"
|
||||
backupbot.restore.post-hook: '/pg_backup.sh restore'
|
||||
backupbot.restore.post-hook: "/pg_backup.sh restore"
|
||||
|
||||
redis:
|
||||
image: redis:7.0.10-alpine
|
||||
image: redis:8.0.2-alpine
|
||||
volumes:
|
||||
- "redis:/data"
|
||||
healthcheck:
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
interval: 3s
|
||||
interval: 20s
|
||||
timeout: 5s
|
||||
retries: 20
|
||||
start_period: 1m
|
||||
networks:
|
||||
- internal
|
||||
|
||||
@ -83,8 +90,7 @@ services:
|
||||
- STACK_NAME=${STACK_NAME}
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
entrypoint:
|
||||
/entrypoint.sh
|
||||
entrypoint: /entrypoint.sh
|
||||
configs:
|
||||
- source: cron_entrypoint
|
||||
target: /entrypoint.sh
|
||||
@ -116,7 +122,6 @@ networks:
|
||||
external: true
|
||||
internal:
|
||||
|
||||
|
||||
secrets:
|
||||
db_password:
|
||||
external: true
|
||||
@ -127,3 +132,6 @@ secrets:
|
||||
django_secret_key:
|
||||
external: true
|
||||
name: ${STACK_NAME}_django_secret_key_${SECRET_DJANGO_SECRET_KEY_VERSION}
|
||||
admin_pass:
|
||||
external: true
|
||||
name: ${STACK_NAME}_admin_pass_${SECRET_ADMIN_PASS_VERSION}
|
||||
|
||||
@ -1,3 +1,3 @@
|
||||
#!/bin/sh
|
||||
|
||||
echo '15,45 * * * * docker exec $(docker ps -qf 'name=${STACK_NAME}_app') pretix runperiodic' | crontab - && crond -f -d 8
|
||||
echo '15,45 * * * * docker exec $(docker ps -qf 'name=^${STACK_NAME}_app') pretix runperiodic' | crontab - && crond -f -d 8
|
||||
@ -21,7 +21,6 @@ install_old_postgres_debian() {
|
||||
pgenv check
|
||||
LATEST_OLD_VERSION=$(pgenv available $DATA_VERSION | grep -oE "$DATA_VERSION\.[0-9]+" | tail -n 1)
|
||||
pgenv build $LATEST_OLD_VERSION
|
||||
export PATH="/tmp/pgenv/pgsql-$LATEST_OLD_VERSION/bin:$PATH"
|
||||
}
|
||||
|
||||
install_old_postgres_alpine() {
|
||||
@ -35,7 +34,6 @@ install_old_postgres_alpine() {
|
||||
pgenv check
|
||||
LATEST_OLD_VERSION=$(pgenv available $DATA_VERSION | grep -oE "$DATA_VERSION\.[0-9]+" | tail -n 1)
|
||||
pgenv build $LATEST_OLD_VERSION
|
||||
export PATH="/tmp/pgenv/pgsql-$LATEST_OLD_VERSION/bin:$PATH"
|
||||
}
|
||||
|
||||
if [ -e $MIGRATION_MARKER ]; then
|
||||
@ -55,9 +53,11 @@ if [ -f $PGDATA/PG_VERSION ]; then
|
||||
install_old_postgres_debian
|
||||
fi
|
||||
echo "shuffling around"
|
||||
gosu postgres mkdir $OLDDATA $NEWDATA
|
||||
chmod 700 $OLDDATA $NEWDATA
|
||||
gosu postgres mkdir $OLDDATA
|
||||
chmod 700 $OLDDATA
|
||||
mv $PGDATA/* $OLDDATA/ || true
|
||||
gosu postgres mkdir $NEWDATA
|
||||
chmod 700 $NEWDATA
|
||||
touch $MIGRATION_MARKER
|
||||
echo "running initdb"
|
||||
# abuse entrypoint script for initdb by making server error out
|
||||
|
||||
@ -42,9 +42,6 @@ debug=off
|
||||
location=redis://redis:6379/1
|
||||
sessions=true
|
||||
|
||||
[languages]
|
||||
enabled=en,de
|
||||
|
||||
[celery]
|
||||
backend=redis://redis:6379/1
|
||||
broker=redis://redis:6379/2
|
||||
|
||||
1
release/1.5.0+2024.11.0
Normal file
1
release/1.5.0+2024.11.0
Normal file
@ -0,0 +1 @@
|
||||
New major postgres version with automated update script! Make sure to backup your database before.
|
||||
1
release/2.0.0+2025.1.0
Normal file
1
release/2.0.0+2025.1.0
Normal file
@ -0,0 +1 @@
|
||||
New secret ADMIN_PASS which will be used to automatically replace the insecure default password
|
||||
Reference in New Issue
Block a user