feat: AtroPIM image pipeline with secret-free build (AZ-NIX-ava.1)
- flake input atrocore-docker rev-pinned (e1e9bed) - pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage podman build (vendor pdf target + entrypoint wrapper) - entrypoint writes ATRO_DB_* to data/config.php at runtime, guarded by isInstalled (idempotent); no DB credentials in layers - devShell documents build/push commands and ENV variables
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
# Stage 2 of the AtroPIM image pipeline: takes the vendor-built base image
|
||||
# (atrocore/docker, target "pdf") and layers the secret-free entrypoint
|
||||
# wrapper on top. The base image reference is injected via BASE_IMAGE so the
|
||||
# vendor Dockerfile stays untouched (pinned flake input).
|
||||
ARG BASE_IMAGE
|
||||
FROM ${BASE_IMAGE}
|
||||
|
||||
COPY entrypoint.sh /entrypoint.sh
|
||||
COPY entrypoint-prepare-pim.php /entrypoint-prepare-pim.php
|
||||
|
||||
RUN chmod +x /entrypoint.sh
|
||||
|
||||
CMD ["/entrypoint.sh"]
|
||||
@@ -0,0 +1,32 @@
|
||||
<?php
|
||||
/* Runtime counterpart of the vendor's prepare-pim.php (atrocore/docker). */
|
||||
|
||||
if (empty($argv[5])) {
|
||||
exit("Usage: php entrypoint-prepare-pim.php <instance-dir> <db-host> <db-name> <db-user> <db-password>\n");
|
||||
}
|
||||
|
||||
$instanceDir = $argv[1];
|
||||
|
||||
chdir($instanceDir);
|
||||
set_include_path($instanceDir);
|
||||
|
||||
require_once 'vendor/autoload.php';
|
||||
|
||||
$app = new \Atro\Core\Application();
|
||||
$config = $app->getContainer()->get('config');
|
||||
|
||||
if ($config->get('isInstalled')) {
|
||||
exit("[entrypoint] instance already installed - keeping existing data/config.php\n");
|
||||
}
|
||||
|
||||
$config->set('database', [
|
||||
'driver' => 'pdo_pgsql',
|
||||
'host' => $argv[2],
|
||||
'port' => '',
|
||||
'charset' => 'utf8',
|
||||
'dbname' => $argv[3],
|
||||
'user' => $argv[4],
|
||||
'password' => $argv[5],
|
||||
]);
|
||||
$config->set('useChromeNoSandbox', true);
|
||||
$config->save();
|
||||
@@ -0,0 +1,24 @@
|
||||
#!/bin/sh
|
||||
# Secret-free AtroPIM image entrypoint.
|
||||
#
|
||||
# Before cron/apache start, the ATRO_DB_* environment variables are written
|
||||
# into data/config.php of the instance directory (same pattern as the vendor's
|
||||
# prepare-pim.php). The PHP side skips the write once the instance is
|
||||
# installed (isInstalled), which makes the wrapper idempotent: a config
|
||||
# completed by the web installer is never overwritten.
|
||||
|
||||
set -e
|
||||
|
||||
INSTANCE_DIR="/var/www/${ATRO_INSTANCE_DIR:-pim.l.az-gruppe.com}"
|
||||
|
||||
if [ -n "${ATRO_DB_HOST:-}" ] && [ -n "${ATRO_DB_NAME:-}" ] && [ -n "${ATRO_DB_USER:-}" ] && [ -n "${ATRO_DB_PASSWORD:-}" ]; then
|
||||
echo "[entrypoint] applying ATRO_DB_* variables to ${INSTANCE_DIR}/data/config.php"
|
||||
mkdir -p "${INSTANCE_DIR}/data"
|
||||
php /entrypoint-prepare-pim.php "${INSTANCE_DIR}" "${ATRO_DB_HOST}" "${ATRO_DB_NAME}" "${ATRO_DB_USER}" "${ATRO_DB_PASSWORD}"
|
||||
# The web installer (running as www-data) must stay able to update the config later.
|
||||
chown www-data:www-data "${INSTANCE_DIR}/data/config.php"
|
||||
else
|
||||
echo "[entrypoint] no ATRO_DB_* variables set - starting web installer"
|
||||
fi
|
||||
|
||||
exec /startup.sh
|
||||
Reference in New Issue
Block a user