chore: Update Dockerfile to remove unnecessary SSH server configuration

This commit is contained in:
Bram Kelchtermans
2024-07-31 13:54:28 +02:00
parent af829e8693
commit 8ae00048c8
10 changed files with 1 additions and 0 deletions
@@ -0,0 +1,63 @@
# Use an official PHP runtime as a parent image
FROM php:8.1-fpm
# Set the working directory
WORKDIR /workspace
# Install dependencies
RUN apt-get update && apt-get install -y \
git \
openssh-client \
unzip \
libpng-dev \
libjpeg-dev \
libfreetype6-dev \
libonig-dev \
libzip-dev \
libpq-dev \
zip \
fish \
cron \
sudo \
&& docker-php-ext-configure gd --with-freetype --with-jpeg \
&& docker-php-ext-install gd mbstring zip pdo pdo_mysql pdo_pgsql
# Install Composer
COPY --from=composer:latest /usr/bin/composer /usr/bin/composer
RUN usermod -aG sudo root
# Install Node.js and npm
RUN curl -sL https://deb.nodesource.com/setup_16.x | bash - && \
apt-get install -y nodejs
# Install PM2 globally
RUN npm install -g pm2
# # Switch to Fish shell
# SHELL [ "fish", "--command" ]
# RUN chsh -s /usr/bin/fish
# ENV SHELL /usr/bin/fish
# ENV LANG=C.UTF-8 LANGUAGE=C.UTF-8 LC_ALL=C.UTF-8
# Create a directory for the SSH keys
RUN mkdir -p /root/.ssh
RUN git clone https://gitea.bramkelchtermans.be/Bram/linux-presets.git && cd linux-presets && chmod +x setup.sh && ./setup.sh --terminal-icon 
RUN rm -r linux-presets/
# Copy the entrypoint script into the container
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh
# Copy the crontab file into the container
COPY crontab /etc/cron.d/laravel-cron
RUN chmod 0644 /etc/cron.d/laravel-cron
RUN crontab /etc/cron.d/laravel-cron
# Expose ports
EXPOSE 8000
# Set the entrypoint
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
+1
View File
@@ -0,0 +1 @@
* * * * * root /usr/local/bin/php /workspace/artisan schedule:run >> /var/log/cron.log 2>&1
@@ -0,0 +1,77 @@
#!/bin/bash
set -e
# Check if the required environment variables are set
if [ -z "$REPO_URL" ]; then
echo "Error: REPO_URL environment variable must be set."
exit 1
fi
# Check if the SSH key exists
if [ ! -f /root/.ssh/id_rsa ]; then
echo "Error: SSH private key not found at /root/.ssh/id_rsa"
exit 1
fi
if [ -z $GIT_USER ]; then
echo "Error: GIT_USER environment variable must be set."
exit 1
fi
if [ -z $GIT_EMAIL ]; then
echo "Error: GIT_EMAIL environment variable must be set."
exit 1
fi
# Set the git user and email
git config --global user.name $GIT_USER
git config --global user.email $GIT_EMAIL
# Ensure the SSH key has the correct permissions
chmod 600 /root/.ssh/id_rsa
# Extract the domain from the REPO_URL
DOMAIN=$(echo $REPO_URL | awk -F'[@:]' '{print $3}')
# Check if the repository directory already exists
if [ ! -d "/workspace/.git" ]; then
# Add the SSH configuration for the domain
echo "Host $DOMAIN
HostName $DOMAIN
IdentityFile /root/.ssh/id_rsa
StrictHostKeyChecking no
" >> /root/.ssh/config
# Clone the repository if it doesn't exist
git clone $REPO_URL /workspace
fi
# Add the public SSH key to authorized_keys
if [ -f /root/.ssh/hostkey.pub ]; then
cat /root/.ssh/hostkey.pub >> /root/.ssh/authorized_keys
fi
# Change to the repository directory
cd /workspace
# Install PHP dependencies
composer install
# Copy the environment file to the repository's environments directory
if [ -f /environment/.env ]; then
cp /environment/.env /workspace/.env
fi
HOSTNAME=$(hostname)
# File path
CONFIG_FILE="/etc/teleport.yaml"
# Edit the teleport.yaml file to update the nodename
sed -i "s/^ nodename:.*/ nodename: $HOSTNAME/" "$CONFIG_FILE"
# Start the cron service
service cron start
nohup teleport start &
# Start the application with pm2
exec pm2-runtime "php artisan serve --host=0.0.0.0 --port=8000"
File diff suppressed because it is too large Load Diff
+202
View File
@@ -0,0 +1,202 @@
usage: teleport start [<flags>]
Starts the Teleport service.
Flags:
-d, --[no-]debug Enable verbose logging to stderr
--[no-]insecure-no-tls Disable TLS for the web socket
-r, --roles Comma-separated list of roles to start with
[proxy,node,auth,app,db]
--pid-file Full path to the PID file. By default no PID
file will be created
--advertise-ip IP to advertise to clients if running behind
NAT
-l, --listen-ip IP address to bind to [0.0.0.0]
--auth-server Address of the auth server [127.0.0.1:3025]
--token Invitation token or path to file with token
value. Used to register with an auth server
[none]
--ca-pin CA pin to validate the Auth Server (can be
repeated for multiple pins)
--nodename Name of this node, defaults to hostname
-c, --config Path to a configuration file
[/etc/teleport.yaml]
--apply-on-startup Path to a non-empty YAML file containing
resources to apply on startup. Works on
initialized clusters, unlike --bootstrap.
Only supports the following types: token.
--bootstrap Path to a non-empty YAML file containing
bootstrap resources (ignored if already
initialized)
--labels Comma-separated list of labels for this node,
for example env=dev,app=web
--diag-addr Start diagnostic prometheus and healthz
endpoint.
--[no-]permit-user-env Enables reading of ~/.tsh/environment when
creating a session
--[no-]insecure Insecure mode disables certificate validation
--[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode.
--[no-]skip-version-check Skip version checking between server and
client.
Aliases:
Notes:
--roles=node,proxy,auth,app
This flag tells Teleport which services to run. By default it runs auth,
proxy, and node. In a production environment you may want to separate them.
--token=xyz or --token=/tmp/token
This token is needed to connect a node or web app to an auth server. Get it
by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to
join an SSH server or web app to your cluster respectively. It's used once
and ignored afterwards.
Examples:
> teleport start
By default without any configuration, teleport starts running as a single-node
cluster. It's the equivalent of running with --roles=node,proxy,auth
> teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db
Starts a node named 'db' running in strictly SSH mode role, joining the cluster
serviced by the auth server running on 10.1.0.1
> teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master
Same as the above, but the node runs with db=master label and can be connected
to using that label in addition to its name.
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-app" \
--uri="http://localhost:8080"
Starts an app server that proxies the application "example-app" running at
http://localhost:8080.
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-app" \
--uri="http://localhost:8080" \
--labels=group=dev
Same as the above, but the app server runs with "group=dev" label which only
allows access to users with the role "group=dev".
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-db" \
--protocol="postgres" \
--uri="localhost:5432"
Starts a database server that proxies PostgreSQL database "example-db" running
at localhost:5432. The database must be configured with Teleport CA and key
pair issued by "tctl auth sign --format=db".
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
--name="aurora-db" \
--protocol="mysql" \
--uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \
--aws-region=us-west-1 \
--labels=env=aws
Starts a database server that proxies Aurora MySQL database running in AWS
region us-west-1 which only allows access to users with the role "env=aws".
ERROR: path '/etc/teleport.yaml' does not exist
usage: teleport start [<flags>]
Starts the Teleport service.
Flags:
-d, --[no-]debug Enable verbose logging to stderr
--[no-]insecure-no-tls Disable TLS for the web socket
-r, --roles Comma-separated list of roles to start with
[proxy,node,auth,app,db]
--pid-file Full path to the PID file. By default no PID
file will be created
--advertise-ip IP to advertise to clients if running behind
NAT
-l, --listen-ip IP address to bind to [0.0.0.0]
--auth-server Address of the auth server [127.0.0.1:3025]
--token Invitation token or path to file with token
value. Used to register with an auth server
[none]
--ca-pin CA pin to validate the Auth Server (can be
repeated for multiple pins)
--nodename Name of this node, defaults to hostname
-c, --config Path to a configuration file
[/etc/teleport.yaml]
--apply-on-startup Path to a non-empty YAML file containing
resources to apply on startup. Works on
initialized clusters, unlike --bootstrap.
Only supports the following types: token.
--bootstrap Path to a non-empty YAML file containing
bootstrap resources (ignored if already
initialized)
--labels Comma-separated list of labels for this node,
for example env=dev,app=web
--diag-addr Start diagnostic prometheus and healthz
endpoint.
--[no-]permit-user-env Enables reading of ~/.tsh/environment when
creating a session
--[no-]insecure Insecure mode disables certificate validation
--[no-]fips Start Teleport in FedRAMP/FIPS 140-2 mode.
--[no-]skip-version-check Skip version checking between server and
client.
Aliases:
Notes:
--roles=node,proxy,auth,app
This flag tells Teleport which services to run. By default it runs auth,
proxy, and node. In a production environment you may want to separate them.
--token=xyz or --token=/tmp/token
This token is needed to connect a node or web app to an auth server. Get it
by running "tctl tokens add --type=node" or "tctl tokens add --type=app" to
join an SSH server or web app to your cluster respectively. It's used once
and ignored afterwards.
Examples:
> teleport start
By default without any configuration, teleport starts running as a single-node
cluster. It's the equivalent of running with --roles=node,proxy,auth
> teleport start --roles=node --auth-server=10.1.0.1 --token=xyz --nodename=db
Starts a node named 'db' running in strictly SSH mode role, joining the cluster
serviced by the auth server running on 10.1.0.1
> teleport start --roles=node --auth-server=10.1.0.1 --labels=db=master
Same as the above, but the node runs with db=master label and can be connected
to using that label in addition to its name.
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-app" \
--uri="http://localhost:8080"
Starts an app server that proxies the application "example-app" running at
http://localhost:8080.
> teleport app start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-app" \
--uri="http://localhost:8080" \
--labels=group=dev
Same as the above, but the app server runs with "group=dev" label which only
allows access to users with the role "group=dev".
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
--name="example-db" \
--protocol="postgres" \
--uri="localhost:5432"
Starts a database server that proxies PostgreSQL database "example-db" running
at localhost:5432. The database must be configured with Teleport CA and key
pair issued by "tctl auth sign --format=db".
> teleport db start --token=xyz --auth-server=proxy.example.com:3080 \
--name="aurora-db" \
--protocol="mysql" \
--uri="example.cluster-abcdefghij.us-west-1.rds.amazonaws.com:3306" \
--aws-region=us-west-1 \
--labels=env=aws
Starts a database server that proxies Aurora MySQL database running in AWS
region us-west-1 which only allows access to users with the role "env=aws".
ERROR: path '/etc/teleport.yaml' does not exist
+1
View File
@@ -0,0 +1 @@
1.0