This commit is contained in:
@@ -0,0 +1,77 @@
|
|||||||
|
# Use an official PHP runtime as a parent image
|
||||||
|
FROM php:8.1-fpm
|
||||||
|
|
||||||
|
# Set the working directory
|
||||||
|
WORKDIR /workspace
|
||||||
|
|
||||||
|
# Install dependencies
|
||||||
|
RUN apt-get update && apt-get install -y \
|
||||||
|
git \
|
||||||
|
openssh-client \
|
||||||
|
unzip \
|
||||||
|
iputils-ping \
|
||||||
|
libpng-dev \
|
||||||
|
libjpeg-dev \
|
||||||
|
libfreetype6-dev \
|
||||||
|
libonig-dev \
|
||||||
|
libzip-dev \
|
||||||
|
libpq5 \
|
||||||
|
libpq-dev \
|
||||||
|
zip \
|
||||||
|
fish \
|
||||||
|
cron \
|
||||||
|
sudo \
|
||||||
|
&& docker-php-ext-configure gd --with-freetype --with-jpeg \
|
||||||
|
&& docker-php-ext-install gd mbstring zip pdo pdo_mysql pdo_pgsql pgsql
|
||||||
|
|
||||||
|
# Install Redis PHP extension via PECL
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends $PHPIZE_DEPS libssl-dev \
|
||||||
|
&& pecl install redis \
|
||||||
|
&& docker-php-ext-enable redis \
|
||||||
|
&& apt-get purge -y --auto-remove $PHPIZE_DEPS libssl-dev \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Install Composer
|
||||||
|
COPY --from=composer:latest /usr/bin/composer /usr/bin/composer
|
||||||
|
|
||||||
|
RUN git clone https://gitea.bramkelchtermans.be/Bram/linux-presets.git && \
|
||||||
|
cd linux-presets && \
|
||||||
|
chmod +x setup.sh && \
|
||||||
|
./setup.sh --terminal-icon && \
|
||||||
|
cd .. && \
|
||||||
|
rm -rf linux-presets
|
||||||
|
|
||||||
|
|
||||||
|
RUN usermod -aG sudo root
|
||||||
|
|
||||||
|
# Install Node.js and npm
|
||||||
|
RUN curl -sL https://deb.nodesource.com/setup_16.x | bash - && \
|
||||||
|
apt-get install -y nodejs
|
||||||
|
|
||||||
|
# Install PM2 globally
|
||||||
|
RUN npm install -g pm2
|
||||||
|
|
||||||
|
# # Switch to Fish shell
|
||||||
|
# SHELL [ "fish", "--command" ]
|
||||||
|
# RUN chsh -s /usr/bin/fish
|
||||||
|
# ENV SHELL /usr/bin/fish
|
||||||
|
# ENV LANG=C.UTF-8 LANGUAGE=C.UTF-8 LC_ALL=C.UTF-8
|
||||||
|
|
||||||
|
|
||||||
|
# Create a directory for the SSH keys
|
||||||
|
RUN mkdir -p /root/.ssh
|
||||||
|
|
||||||
|
# Copy the entrypoint script into the container
|
||||||
|
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||||
|
RUN chmod +x /usr/local/bin/entrypoint.sh
|
||||||
|
|
||||||
|
# Copy the crontab file into the container
|
||||||
|
COPY crontab /etc/cron.d/laravel-cron
|
||||||
|
RUN chmod 0644 /etc/cron.d/laravel-cron
|
||||||
|
RUN crontab /etc/cron.d/laravel-cron
|
||||||
|
|
||||||
|
# Expose ports
|
||||||
|
EXPOSE 8000
|
||||||
|
|
||||||
|
# Set the entrypoint
|
||||||
|
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
* * * * * root /usr/local/bin/php /workspace/artisan schedule:run >> /var/log/cron.log 2>&1
|
||||||
@@ -0,0 +1,182 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# Check if the SSH key exists
|
||||||
|
if [ ! -f /root/.ssh/id_rsa ]; then
|
||||||
|
echo "Error: SSH private key not found at /root/.ssh/id_rsa"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check if the required environment variables are set
|
||||||
|
if [ -z "$REPO_URL" ]; then
|
||||||
|
echo "Error: REPO_URL environment variable must be set."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -z "$GIT_USER" ]; then
|
||||||
|
echo "Error: GIT_USER environment variable must be set."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -z "$GIT_EMAIL" ]; then
|
||||||
|
echo "Error: GIT_EMAIL environment variable must be set."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Set the git user and email
|
||||||
|
git config --global user.name $GIT_USER
|
||||||
|
git config --global user.email $GIT_EMAIL
|
||||||
|
|
||||||
|
# Ensure the SSH key has the correct permissions
|
||||||
|
chmod 600 /root/.ssh/id_rsa
|
||||||
|
|
||||||
|
# Extract the domain from the REPO_URL
|
||||||
|
DOMAIN=$(echo $REPO_URL | awk -F'[@:]' '{print $3}')
|
||||||
|
|
||||||
|
# Check if the repository directory already exists
|
||||||
|
if [ ! -d "/workspace/.git" ]; then
|
||||||
|
# Add the SSH configuration for the domain
|
||||||
|
echo "Host $DOMAIN
|
||||||
|
HostName $DOMAIN
|
||||||
|
IdentityFile /root/.ssh/id_rsa
|
||||||
|
StrictHostKeyChecking no
|
||||||
|
" >>/root/.ssh/config
|
||||||
|
# Clone the repository if it doesn't exist
|
||||||
|
git clone $REPO_URL /workspace
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Add the public SSH key to authorized_keys
|
||||||
|
if [ -f /root/.ssh/hostkey.pub ]; then
|
||||||
|
cat /root/.ssh/hostkey.pub >>/root/.ssh/authorized_keys
|
||||||
|
fi
|
||||||
|
|
||||||
|
# If no teleport edition is given, fallback to oss
|
||||||
|
if [ -z "$TELEPORT_EDITION" ]; then
|
||||||
|
TELEPORT_EDITION="oss"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Install Teleport if the environment variables are set
|
||||||
|
if [ -n "$TELEPORT_VERSION" ] && [ -n "$TELEPORT_URL" ]; then
|
||||||
|
echo "Installing Teleport version $TELEPORT_VERSION, edition $TELEPORT_EDITION..."
|
||||||
|
echo "Executing: curl https://goteleport.com/static/install.sh | bash -s $TELEPORT_VERSION $TELEPORT_EDITION"
|
||||||
|
curl https://goteleport.com/static/install.sh | bash -s ${TELEPORT_VERSION} ${TELEPORT_EDITION}
|
||||||
|
else
|
||||||
|
echo "Error: TELEPORT_VERSION and TELEPORT_EDITION environment variables must be set."
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Change to the repository directory
|
||||||
|
cd /workspace
|
||||||
|
|
||||||
|
# Install PHP dependencies
|
||||||
|
composer install
|
||||||
|
|
||||||
|
# Copy the environment file to the repository's environments directory
|
||||||
|
if [ -f /environment/.env ]; then
|
||||||
|
cp /environment/.env /workspace/.env
|
||||||
|
fi
|
||||||
|
|
||||||
|
## If teleport token is set and there is no teleport.yaml file, create one
|
||||||
|
if [ -n "$TELEPORT_TOKEN" ] && [ ! -f /etc/teleport.yaml ]; then
|
||||||
|
teleport configure --roles=node --token=$TELEPORT_TOKEN --proxy=$TELEPORT_URL --no-acme -o file
|
||||||
|
echo "Created teleport configuration file"
|
||||||
|
fi
|
||||||
|
|
||||||
|
HOSTNAME=$(hostname)
|
||||||
|
|
||||||
|
# File path
|
||||||
|
CONFIG_FILE="/etc/teleport.yaml"
|
||||||
|
|
||||||
|
# Edit the teleport.yaml file to update the nodename
|
||||||
|
sed -i "s/^ nodename:.*/ nodename: $HOSTNAME/" "$CONFIG_FILE"
|
||||||
|
|
||||||
|
# Function to add labels to teleport.yaml
|
||||||
|
# Function to add labels to teleport.yaml
|
||||||
|
add_teleport_labels() {
|
||||||
|
if [ -n "$TELEPORT_LABELS" ]; then
|
||||||
|
echo "Adding Teleport labels from TELEPORT_LABELS environment variable..."
|
||||||
|
|
||||||
|
# Check if ssh_service section exists
|
||||||
|
if ! grep -q "ssh_service:" "$CONFIG_FILE"; then
|
||||||
|
echo "Error: ssh_service section not found in teleport.yaml"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Create a backup
|
||||||
|
cp "$CONFIG_FILE" "$CONFIG_FILE.backup"
|
||||||
|
|
||||||
|
# Build the new ssh_service section
|
||||||
|
NEW_SSH_SECTION="ssh_service:"
|
||||||
|
NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" labels:"
|
||||||
|
|
||||||
|
# Parse TELEPORT_LABELS and add each label
|
||||||
|
IFS=',' read -ra LABELS <<< "$TELEPORT_LABELS"
|
||||||
|
for label in "${LABELS[@]}"; do
|
||||||
|
# Trim whitespace
|
||||||
|
label=$(echo "$label" | xargs)
|
||||||
|
|
||||||
|
# Check if label contains colon
|
||||||
|
if [[ "$label" == *":"* ]]; then
|
||||||
|
key=$(echo "$label" | cut -d':' -f1 | xargs)
|
||||||
|
value=$(echo "$label" | cut -d':' -f2- | xargs)
|
||||||
|
|
||||||
|
if [ -n "$key" ] && [ -n "$value" ]; then
|
||||||
|
NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" $key: $value"
|
||||||
|
echo "Added label: $key = $value"
|
||||||
|
else
|
||||||
|
echo "Warning: Invalid label format '$label'. Expected format: key:value"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "Warning: Label '$label' does not contain colon separator. Expected format: key:value"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
NEW_SSH_SECTION="$NEW_SSH_SECTION"$'\n'" enabled: \"yes\""
|
||||||
|
|
||||||
|
# Replace the ssh_service section
|
||||||
|
awk -v new_section="$NEW_SSH_SECTION" '
|
||||||
|
BEGIN {
|
||||||
|
in_ssh_service = 0
|
||||||
|
section_replaced = 0
|
||||||
|
}
|
||||||
|
/^ssh_service:/ {
|
||||||
|
in_ssh_service = 1
|
||||||
|
if (!section_replaced) {
|
||||||
|
print new_section
|
||||||
|
section_replaced = 1
|
||||||
|
}
|
||||||
|
next
|
||||||
|
}
|
||||||
|
in_ssh_service && /^[a-zA-Z_][a-zA-Z0-9_]*:/ {
|
||||||
|
in_ssh_service = 0
|
||||||
|
}
|
||||||
|
in_ssh_service {
|
||||||
|
next
|
||||||
|
}
|
||||||
|
{
|
||||||
|
print $0
|
||||||
|
}
|
||||||
|
' "$CONFIG_FILE" > "$CONFIG_FILE.tmp"
|
||||||
|
|
||||||
|
# Replace the original file
|
||||||
|
mv "$CONFIG_FILE.tmp" "$CONFIG_FILE"
|
||||||
|
|
||||||
|
echo "Teleport labels added successfully"
|
||||||
|
else
|
||||||
|
echo "No TELEPORT_LABELS environment variable set, skipping label configuration"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Add labels to teleport configuration
|
||||||
|
add_teleport_labels
|
||||||
|
|
||||||
|
# Start the cron service
|
||||||
|
service cron start
|
||||||
|
nohup teleport start &
|
||||||
|
|
||||||
|
# If no custom app command is provided, use a simple PHP built-in server
|
||||||
|
if [ -z "$START_COMMAND" ]; then
|
||||||
|
START_COMMAND='php -S 0.0.0.0:8000'
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Always run the app under pm2-runtime
|
||||||
|
exec pm2-runtime "$START_COMMAND"
|
||||||
@@ -0,0 +1,202 @@
|
|||||||
|
usage: teleport start [<flags>]
|
||||||
|
|
||||||
|
Starts the Teleport service.
|
||||||
|
|
||||||
|
Flags:
|
||||||
|
-d, --[no-]debug Enable verbose logging to stderr
|
||||||
|
--[no-]insecure-no-tls Disable TLS for the web socket
|
||||||
|
-r, --roles Comma-separated list of roles to start with
|
||||||
|
[proxy,node,auth,app,db]
|
||||||
|
--pid-file Full path to the PID file. By default no PID
|
||||||
|
file will be created
|
||||||
|
--advertise-ip IP to advertise to clients if running behind
|
||||||
|
NAT
|
||||||
|
-l, --listen-ip IP address to bind to [0.0.0.0]
|
||||||
|
--auth-server Address of the auth server [127.0.0.1:3025]
|
||||||
|
--token Invitation token or path to file with token
|
||||||
|
value. Used to register with an auth server
|
||||||
|
[none]
|
||||||
|
--ca-pin CA pin to validate the Auth Server (can be
|
||||||
|
repeated for multiple pins)
|
||||||
|
--nodename Name of this node, defaults to hostname
|
||||||
|
-c, --config Path to a configuration file
|
||||||
|
[/etc/teleport.yaml]
|
||||||
|
--apply-on-startup Path to a non-empty YAML file containing
|
||||||
|
resources to apply on startup. Works on
|
||||||
|
initialized clusters, unlike --bootstrap.
|
||||||
|
Only supports the following types: token.
|
||||||
|
--bootstrap Path to a non-empty YAML file containing
|
||||||
|
bootstrap resources (ignored if already
|
||||||
|
initialized)
|
||||||
|
--labels Comma-separated list of labels for this node,
|
||||||
|
for example env=dev,app=web
|
||||||
|
--diag-addr Start diagnostic prometheus and healthz
|
||||||
|
endpoint.
|
||||||
|
--[no-]permit-user-env Enables reading of ~/.tsh/environment when
|
||||||
|
creating a session
|
||||||
|
--[no-]insecure Insecure mode disables certificate validation
|
||||||
|
--[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode.
|
||||||
|
--[no-]skip-version-check Skip version checking between server and
|
||||||
|
client.
|
||||||
|
|
||||||
|
Aliases:
|
||||||
|
Notes:
|
||||||
|
--roles=node,proxy,auth,app
|
||||||
|
|
||||||
|
This flag tells Teleport which services to run. By default it runs auth,
|
||||||
|
proxy, and node. In a production environment you may want to separate them.
|
||||||
|
|
||||||
|
--token=xyz or --token=/tmp/token
|
||||||
|
|
||||||
|
This token is needed to connect a node or web app to an auth server. Get it
|
||||||
|
by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to
|
||||||
|
join an SSH server or web app to your cluster respectively. It's used once
|
||||||
|
and ignored afterwards.
|
||||||
|
|
||||||
|
Examples:
|
||||||
|
|
||||||
|
> teleport start
|
||||||
|
By default without any configuration, teleport starts running as a single-node
|
||||||
|
cluster. It's the equivalent of running with --roles=node,proxy,auth
|
||||||
|
|
||||||
|
> teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db
|
||||||
|
Starts a node named 'db' running in strictly SSH mode role, joining the cluster
|
||||||
|
serviced by the auth server running on 10.1.0.1
|
||||||
|
|
||||||
|
> teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master
|
||||||
|
Same as the above, but the node runs with db=master label and can be connected
|
||||||
|
to using that label in addition to its name.
|
||||||
|
|
||||||
|
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-app" \
|
||||||
|
--uri="http://localhost:8080"
|
||||||
|
Starts an app server that proxies the application "example-app" running at
|
||||||
|
http://localhost:8080.
|
||||||
|
|
||||||
|
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-app" \
|
||||||
|
--uri="http://localhost:8080" \
|
||||||
|
--labels=group=dev
|
||||||
|
Same as the above, but the app server runs with "group=dev" label which only
|
||||||
|
allows access to users with the role "group=dev".
|
||||||
|
|
||||||
|
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-db" \
|
||||||
|
--protocol="postgres" \
|
||||||
|
--uri="localhost:5432"
|
||||||
|
Starts a database server that proxies PostgreSQL database "example-db" running
|
||||||
|
at localhost:5432. The database must be configured with Teleport CA and key
|
||||||
|
pair issued by "tctl auth sign --format=db".
|
||||||
|
|
||||||
|
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="aurora-db" \
|
||||||
|
--protocol="mysql" \
|
||||||
|
--uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \
|
||||||
|
--aws-region=us-west-1 \
|
||||||
|
--labels=env=aws
|
||||||
|
Starts a database server that proxies Aurora MySQL database running in AWS
|
||||||
|
region us-west-1 which only allows access to users with the role "env=aws".
|
||||||
|
|
||||||
|
[31mERROR: [0mpath '/etc/teleport.yaml' does not exist
|
||||||
|
|
||||||
|
usage: teleport start [<flags>]
|
||||||
|
|
||||||
|
Starts the Teleport service.
|
||||||
|
|
||||||
|
Flags:
|
||||||
|
-d, --[no-]debug Enable verbose logging to stderr
|
||||||
|
--[no-]insecure-no-tls Disable TLS for the web socket
|
||||||
|
-r, --roles Comma-separated list of roles to start with
|
||||||
|
[proxy,node,auth,app,db]
|
||||||
|
--pid-file Full path to the PID file. By default no PID
|
||||||
|
file will be created
|
||||||
|
--advertise-ip IP to advertise to clients if running behind
|
||||||
|
NAT
|
||||||
|
-l, --listen-ip IP address to bind to [0.0.0.0]
|
||||||
|
--auth-server Address of the auth server [127.0.0.1:3025]
|
||||||
|
--token Invitation token or path to file with token
|
||||||
|
value. Used to register with an auth server
|
||||||
|
[none]
|
||||||
|
--ca-pin CA pin to validate the Auth Server (can be
|
||||||
|
repeated for multiple pins)
|
||||||
|
--nodename Name of this node, defaults to hostname
|
||||||
|
-c, --config Path to a configuration file
|
||||||
|
[/etc/teleport.yaml]
|
||||||
|
--apply-on-startup Path to a non-empty YAML file containing
|
||||||
|
resources to apply on startup. Works on
|
||||||
|
initialized clusters, unlike --bootstrap.
|
||||||
|
Only supports the following types: token.
|
||||||
|
--bootstrap Path to a non-empty YAML file containing
|
||||||
|
bootstrap resources (ignored if already
|
||||||
|
initialized)
|
||||||
|
--labels Comma-separated list of labels for this node,
|
||||||
|
for example env=dev,app=web
|
||||||
|
--diag-addr Start diagnostic prometheus and healthz
|
||||||
|
endpoint.
|
||||||
|
--[no-]permit-user-env Enables reading of ~/.tsh/environment when
|
||||||
|
creating a session
|
||||||
|
--[no-]insecure Insecure mode disables certificate validation
|
||||||
|
--[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode.
|
||||||
|
--[no-]skip-version-check Skip version checking between server and
|
||||||
|
client.
|
||||||
|
|
||||||
|
Aliases:
|
||||||
|
Notes:
|
||||||
|
--roles=node,proxy,auth,app
|
||||||
|
|
||||||
|
This flag tells Teleport which services to run. By default it runs auth,
|
||||||
|
proxy, and node. In a production environment you may want to separate them.
|
||||||
|
|
||||||
|
--token=xyz or --token=/tmp/token
|
||||||
|
|
||||||
|
This token is needed to connect a node or web app to an auth server. Get it
|
||||||
|
by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to
|
||||||
|
join an SSH server or web app to your cluster respectively. It's used once
|
||||||
|
and ignored afterwards.
|
||||||
|
|
||||||
|
Examples:
|
||||||
|
|
||||||
|
> teleport start
|
||||||
|
By default without any configuration, teleport starts running as a single-node
|
||||||
|
cluster. It's the equivalent of running with --roles=node,proxy,auth
|
||||||
|
|
||||||
|
> teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db
|
||||||
|
Starts a node named 'db' running in strictly SSH mode role, joining the cluster
|
||||||
|
serviced by the auth server running on 10.1.0.1
|
||||||
|
|
||||||
|
> teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master
|
||||||
|
Same as the above, but the node runs with db=master label and can be connected
|
||||||
|
to using that label in addition to its name.
|
||||||
|
|
||||||
|
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-app" \
|
||||||
|
--uri="http://localhost:8080"
|
||||||
|
Starts an app server that proxies the application "example-app" running at
|
||||||
|
http://localhost:8080.
|
||||||
|
|
||||||
|
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-app" \
|
||||||
|
--uri="http://localhost:8080" \
|
||||||
|
--labels=group=dev
|
||||||
|
Same as the above, but the app server runs with "group=dev" label which only
|
||||||
|
allows access to users with the role "group=dev".
|
||||||
|
|
||||||
|
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="example-db" \
|
||||||
|
--protocol="postgres" \
|
||||||
|
--uri="localhost:5432"
|
||||||
|
Starts a database server that proxies PostgreSQL database "example-db" running
|
||||||
|
at localhost:5432. The database must be configured with Teleport CA and key
|
||||||
|
pair issued by "tctl auth sign --format=db".
|
||||||
|
|
||||||
|
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
|
||||||
|
--name="aurora-db" \
|
||||||
|
--protocol="mysql" \
|
||||||
|
--uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \
|
||||||
|
--aws-region=us-west-1 \
|
||||||
|
--labels=env=aws
|
||||||
|
Starts a database server that proxies Aurora MySQL database running in AWS
|
||||||
|
region us-west-1 which only allows access to users with the role "env=aws".
|
||||||
|
|
||||||
|
[31mERROR: [0mpath '/etc/teleport.yaml' does not exist
|
||||||
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
1.0
|
||||||
Reference in New Issue
Block a user