abra app run escaping and environment issues #790
Open
opened 2026-02-25 16:11:20 +00:00 by fauno
·
4 comments
No Branch/Tag Specified
main
local-integration-testing
renovate/otel-weaver-0.x
renovate/codespell-2.x
renovate/github.com-charmbracelet-lipgloss-2.x
renovate/github.com-charmbracelet-bubbletea-2.x
renovate/tonistiigi-xx-1.x
renovate/alpine-3.x
renovate/github.com-charmbracelet-log-2.x
chore-deps
fix/492
fix/deps
fix/613
0.13.0-beta
0.13.0-rc2-beta
0.13.0-rc1-beta
0.12.0-beta
0.11.0-beta
0.10.1-beta
0.10.0-beta
0.10.0-rc2-beta
0.10.0-rc1-beta
0.9.0-beta
0.8.1-beta
0.8.0-beta
0.8.0-rc2-beta
0.8.0-rc1-beta
0.7.0-beta
0.7.0-rc3-beta
0.7.0-rc2-beta
0.6.0-beta
0.5.1-beta
0.5.0-alpha
0.4.1-alpha
0.4.0-alpha
0.4.0-alpha-rc8
0.4.0-alpha-rc7
0.4.0-alpha-rc6
0.4.0-alpha-rc5
0.4.0-alpha-rc4
0.4.0-alpha-rc3
0.4.0-alpha-rc2
0.4.0-alpha-rc1
0.3.1-alpha-rc2
0.3.1-alpha-rc1
0.3.1-rc1
0.3.0-alpha
0.2.2-alpha
0.2.1-alpha
0.2.0-alpha
0.1.8-alpha
0.1.7-alpha
0.1.6-alpha
0.1.5-alpha
0.1.4-alpha
0.1.3-alpha
0.1.2-alpha
0.1.1-alpha
0.1.0-alpha
10.0.5
10.0.3
10.0.2
10.0.1
10.0.0
9.0.0
8.0.1
8.0.0
0.7.4
0.7.3
0.7.2
0.7.1
0.7.0
checkout
0.6.0
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
0.1.2
0.1.1
0.1.0
Labels
Clear labels
bug
build
ci/cd
critical fix
design
documentation
duplicate
easy-first-issue
enhancement
help wanted
i10n
i18n
installer
invalid
question
release
release-candidate
security
tech-debt
test
wontfix
Something is not working
go build related issues
Building things with CI/CD
https://docs.coopcloud.tech/federation/resolutions/passed/010/
UI/UX
Documenting all the things
This issue or pull request already exists
Something for new people to get stuck into. We hope it's easy!
New feature
Need some help
Everything to do with localisation
Everything to do with internationalisation
Everything to do with the install script.
Something is wrong
More information is needed
Release management
Related to the new release candidate
Security related
Unit/integration testing
This won't be fixed
No Label
enhancement
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
3wordchant
aadil (Aadil Ayub)
abra-bot (Abra Bot)
ammaratef45
amras (Sarma)
Apfelwurm
BornDeleuze
Brooke
carla
cas (Cassowary)
coopcloud
cyrnel
decentral1se (d1)
dede
devydave
fauno (fauno)
iexos
jade (Jade Ambrose)
jjsfunhouse
jmakdah2 (Jackie Makdah)
joe-irving (Joe Irving)
kawaiipunk (KawaiiPunk)
knoflook
kolaente
lambdabundesverband
linnealovespie (April)
moosemower
moritz
notplants
oxaliq (sorrel)
p4u1
pharaohgraphy (Andrew 🐦🔥❤️🔥✴️)
renovate-bot (Comrade Renovate Bot)
ripclap
simon
sixsmith (Sixsmith)
stevensting
trav
val (val (he/him))
yksflip
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: toolshed/abra#790
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
related to coop-cloud/peertube#21 coop-cloud/nextcloud#58
we're running into issues with
abra app runbecause it's inconsistent on escaping shell commands, specially flags (see related issues), but we just ran (!) into an issue where peertube npm run needed access to an environmental secret that was set by the custom entrypoint, butabra app rundoesn't use it by default, so with everything combined the command to reset admin password became:That
-- --is killing me 😆This is usually solved by migrated the env vars into the
abra.sh👇Uhm, I don't know how to reproduce this issue as it currently stands without deploying peertube which I'm not going to do 😛 Do you have a simple reproduction of this issue that can be run locally? You could re-use https://git.coopcloud.tech/toolshed/abra-test-recipe for this.
It's not exactly clear how we want to improve the situation specifically. Can you go a bit more into detail on how you think this can be made better? Obviously the command you had to run is hilariously wild but it's not obvious to me how to improve it 🙃
ah that's nice to know thanks. some ideas:
abra app runsets default user as dockerfile'sUSERUSERisrootsu -c "$@" usercommands that are currently breaking escaping (i'm assuming they're nested sometimes)docker exechas a--userflagabra app runstops parsing flags after the domain or service name--(the second one on my example was required bynpm)abra app runorabra.shreceive env vars by default according to serviceabra.sh'senvironmentfunction but we already set env vars on.envand several.compose.ymlso it feels a bit repetitive / prone to forgetfulnessalso, somewhere here, maybe at yunoesque discussion? mentioned rootless containers, so maybe
abra app runis a complete sidecar in the future?so ideally it would've been like this:
as in "prefix anything the official docs say with abra app run"
i saw this yesterday for further inspiration: https://github.com/bibendi/dip