Author SHA1 Message Date
Daniel-Garmig 236cfe44e9 Generate Nightly Build - 202405132248 2024-05-13 22:47:54 +02:00
Daniel-Garmig 2fae2fb37f Setup - Create new setup endpoint to init DB and instance config. 2024-05-13 22:43:19 +02:00
Daniel-Garmig 901454df3c Docs - Add deploy docs. 2024-05-13 22:37:39 +02:00
Daniel-Garmig 4abe778657 Generate Nightly Build - 202405131843 2024-05-13 18:43:29 +02:00
Daniel-Garmig d6ad52c044 Update .gitea/workflows/pub-on-tag.yaml
Fix error on variable "repository_owner" being uppercase for docker image tag.
2024-05-13 18:40:37 +02:00
Daniel-Garmig 72a9f69799 Generate Nightly Build - 202405131822 2024-05-13 18:22:21 +02:00
Daniel-Garmig faea267b1f Add Gitea Actions Support. 2024-05-13 18:14:32 +02:00
4 changed files with 259 additions and 21 deletions
+1 -1
View File
@@ -38,7 +38,7 @@ jobs:
with:
context: .
push: true
tags: ${{vars.REGISTRY_INSTANCE}}/daniel-garmig/somniarooms:devbuild
tags: ${{vars.REGISTRY_INSTANCE}}/somnia/somniarooms:devbuild
target: frankenphp_prod
platforms: linux/amd64,linux/arm64
secrets: |
+14
View File
@@ -23,3 +23,17 @@ Stop containers
```
docker compose down --remove-orphans
```
### Prod:
You can use docker compose for prod or build and deploy a prod image.
**Build Prod image**
```
docker build -t somniarooms:prod --target frankenphp_prod .
```
**Deploy prod image**
```
docker run -d -it -p 80:80 -p 443:443 --name somniarooms --env-file ./env.prod.local somniarooms:prod
```
+198
View File
@@ -0,0 +1,198 @@
# SomniaRooms - How to deploy.
SomniaRooms is designed to be easy to deploy and use.
Production images for Docker Containers are available from Gitea Registry.
Documentation on how to deploy them as containers can be found at [Readme](../README.md).
## Docker compose examples.
Here are some deploy examples using docker compose:
SomniaRooms back-end and front-end can run on the same machine, but some config is needed to work.
### Deploy back-end and front-end on different servers (different ip address).
If your servers have different IP addresses everything is a little bit easier. You can set-up subdomains for each one.
Use the following docker compose files for back-end and front-end.
Back-end:
```yml
services:
somniarooms-back:
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
restart: unless-stopped
environment:
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&ch> MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
APP_SECRET: ChangeMySecret
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
volumes:
- caddy_data:/data
- caddy_config:/config
ports:
# HTTP
- target: 80
published: 80
protocol: tcp
# HTTPS
- target: 443
published: 443
protocol: tcp
# HTTP/3
- target: 443
published: 443
protocol: udp
depends_on:
- database
database:
image: postgres:16-alpine
environment:
POSTGRES_DB: somniarooms
# You should definitely change the password in production
POSTGRES_PASSWORD: ChangeMe!
POSTGRES_USER: somnia
healthcheck:
test: ["CMD", "pg_isready"]
timeout: 5s
retries: 5
start_period: 60s
volumes:
- database_data:/var/lib/postgresql/data:rw
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
volumes:
caddy_data:
caddy_config:
database_data:
```
Config details
- SERVER_NAME -> if set to https a SSL cert will be obtained. If you set http, SSL will be disabled.
Front-end:
```yml
services:
somniarooms-front:
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
restart: unless-stopped
environment:
# You should set your public IP/hostname to back-end.
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
ports:
# HTTP
- target: 80
published: 80
# HTTPS
- target: 443
published: 443
```
### Deploy on the same server.
Right now, it's quite difficult to set back-end app on a port different from 80/443. Back-end uses Caddy as webserver and automatically try to get SSL certs from let's encrypt.
My go-to option will be using some reverse-proxy to redirect requests to back or front by domain name.
This is an example of deployment using Traefik.
```yml
services:
reverse-proxy:
# The official v3 Traefik docker image
image: traefik:v3.0
restart: unless-stopped
# Enables the web UI and tells Traefik to listen to docker
command:
- --api.insecure=true
- --providers.docker
- --entrypoints.web.address=:80
- --entrypoints.websecure.address=:443
- --entrypoints.web.http.redirections.entryPoint.to=websecure
- --entrypoints.web.http.redirections.entryPoint.scheme=https
- --certificatesresolvers.lets-encrypt.acme.tlschallenge=true
- --certificatesresolvers.lets-encrypt.acme.email=your_email # <-- Your email here!
- --certificatesresolvers.lets-encrypt.acme.storage=/letsencrypt/acme.json
ports:
# The HTTP port
- "80:80"
# The HTTPS port
- "443:443"
# The Web UI (enabled by --api.insecure=true)
- "8080:8080"
volumes:
# So that Traefik can listen to the Docker events
- /var/run/docker.sock:/var/run/docker.sock
# acme.json should be created on host instance
- .certs/:/letsencrypt/
somniarooms-back:
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
restart: unless-stopped
environment:
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&charset=utf8
MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
APP_SECRET: ChangeMySecret
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
volumes:
- caddy_data:/data
- caddy_config:/config
depends_on:
- database
labels:
# HTTPS YOUR APP
- "traefik.enable=true"
- "traefik.http.routers.somniarooms-back.rule=Host(`api.somnia.dev`)" # <-- Your back-end hostname here!
- "traefik.http.routers.somniarooms-back.entrypoints=websecure"
- "traefik.http.routers.somniarooms-back.tls=true"
- "traefik.http.routers.somniarooms-back.tls.certresolver=lets-encrypt"
somniarooms-front:
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
restart: unless-stopped
environment:
# You should set your public IP/hostname to back-end.
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
depends_on:
- somniarooms-back
labels:
- "traefik.http.routers.somniarooms-front.rule=Host(`app.somnia.dev`)" # <-- Your front-end hostname here!
database:
image: postgres:16-alpine
environment:
POSTGRES_DB: somniarooms
# You should definitely change the password in production
POSTGRES_PASSWORD: ChangeMe!
POSTGRES_USER: somnia
healthcheck:
test: ["CMD", "pg_isready"]
timeout: 5s
retries: 5
start_period: 60s
volumes:
- database_data:/var/lib/postgresql/data:rw
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
volumes:
caddy_data:
caddy_config:
database_data:
```
## What's next?
Remember you can run your docker compose files using:
```
docker compose up -d --wait
```
+35 -9
View File
@@ -2,15 +2,14 @@
namespace App\Controller;
use App\Entity\User;
use App\Entity\ConfigVariable;
use Doctrine\ORM\EntityManagerInterface;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
use Symfony\Component\Routing\Attribute\Route;
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
use Doctrine\ORM\EntityManagerInterface;
use App\Entity\User;
use App\Repository\UserRepository;
class SecurityController extends AbstractController
{
@@ -35,12 +34,32 @@ class SecurityController extends AbstractController
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
}
#[Route(path: '/addAdmin', name: 'app_security_addAdmin')]
#[Route(path: '/setup', name: 'app_security_addAdmin')]
public function addAdmin(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $entityManager): Response
{
$setupStatus = $entityManager->find(ConfigVariable::class, "SETUP_STATUS");
if($setupStatus == null || $setupStatus == 1) {
return new Response("Setup was already done");
}
$entityManager->beginTransaction();
try {
//Create system variables.
$var_setup = new ConfigVariable();
$var_setup->setKey("SETUP_STATUS");
$var_setup->setValue("1");
$var_setup->setSection("SYSTEM");
$entityManager->persist($var_setup);
//Create user Admin.
$user = new User();
$user->setUsername("admin");
$user->setRoles(["ROLE_USER", "ROLE_ADMIN"]);
$user->setRoles(["ROLE_USER", "ROLE_ADMIN", "ROLE_SUPERADMIN"]);
$plaintextPassword = "admin";
// hash the password (based on the security.yaml config for the $user class)
@@ -51,8 +70,15 @@ class SecurityController extends AbstractController
$user->setPassword($hashedPassword);
$entityManager->persist($user);
$entityManager->flush();
return new Response("Created user - Admin");
$entityManager->flush();
$entityManager->commit();
} catch (\Throwable $th) {
$entityManager->rollback();
throw $th;
}
return new Response("Setup completed :)");
}
}