mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Production deployment previously depended on an illustrative Docker snippet and did not define which state or identity must survive replacement. Add a non-root runtime image, loopback-only Compose service, optional Caddy TLS overlay, shared /data layout, bounded public verifier, and an identity-persistence container test. Document backup, proxy, single-writer, upgrade, and rollback requirements as the contract for every environment. This assumes one ngit-grasp writer per state directory and a reverse proxy or platform edge for public TLS. Image publication and provider-specific control-plane setup are deliberately left to separate changes. Validated with sh -n, ShellCheck 0.11.0, locked Cargo metadata, YAML parsing, Docker Hub tag lookups, local input-failure checks, and git diff --check. Docker/Podman is unavailable in this VM, so the included end-to-end container test was not run here.
39 lines
1.0 KiB
Bash
Executable File
39 lines
1.0 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
data_root=/data
|
|
git_data_path=${NGIT_GIT_DATA_PATH:-${data_root}/git}
|
|
relay_data_path=${NGIT_RELAY_DATA_PATH:-${data_root}/relay}
|
|
|
|
if [ -z "${NGIT_BIND_ADDRESS:-}" ]; then
|
|
public_port=${PORT:-7334}
|
|
case "${public_port}" in
|
|
''|*[!0-9]*)
|
|
echo "PORT must be an integer" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
if [ "${public_port}" -lt 1 ] || [ "${public_port}" -gt 65535 ]; then
|
|
echo "PORT must be between 1 and 65535" >&2
|
|
exit 2
|
|
fi
|
|
export NGIT_BIND_ADDRESS="0.0.0.0:${public_port}"
|
|
fi
|
|
|
|
export NGIT_GIT_DATA_PATH="${git_data_path}"
|
|
export NGIT_RELAY_DATA_PATH="${relay_data_path}"
|
|
|
|
if [ "$(id -u)" -eq 0 ]; then
|
|
install -d -m 0750 -o ngit-grasp -g ngit-grasp \
|
|
"${data_root}" "${git_data_path}" "${relay_data_path}"
|
|
|
|
if [ -e "${data_root}/.relay-owner.nsec" ]; then
|
|
chown ngit-grasp:ngit-grasp "${data_root}/.relay-owner.nsec"
|
|
chmod 0600 "${data_root}/.relay-owner.nsec"
|
|
fi
|
|
|
|
exec gosu ngit-grasp:ngit-grasp ngit-grasp "$@"
|
|
fi
|
|
|
|
exec ngit-grasp "$@"
|