Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3db7d0577a | ||
|
|
ca160d1543 | ||
|
|
236cfe44e9 | ||
|
|
2fae2fb37f | ||
|
|
901454df3c |
+198
@@ -0,0 +1,198 @@
|
|||||||
|
# SomniaRooms - How to deploy.
|
||||||
|
|
||||||
|
SomniaRooms is designed to be easy to deploy and use.
|
||||||
|
|
||||||
|
Production images for Docker Containers are available from Gitea Registry.
|
||||||
|
|
||||||
|
Documentation on how to deploy them as containers can be found at [Readme](../README.md).
|
||||||
|
|
||||||
|
## Docker compose examples.
|
||||||
|
|
||||||
|
Here are some deploy examples using docker compose:
|
||||||
|
|
||||||
|
SomniaRooms back-end and front-end can run on the same machine, but some config is needed to work.
|
||||||
|
|
||||||
|
### Deploy back-end and front-end on different servers (different ip address).
|
||||||
|
If your servers have different IP addresses everything is a little bit easier. You can set-up subdomains for each one.
|
||||||
|
|
||||||
|
Use the following docker compose files for back-end and front-end.
|
||||||
|
|
||||||
|
Back-end:
|
||||||
|
```yml
|
||||||
|
services:
|
||||||
|
somniarooms-back:
|
||||||
|
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
|
||||||
|
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&ch> MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
||||||
|
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
||||||
|
APP_SECRET: ChangeMySecret
|
||||||
|
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
|
||||||
|
volumes:
|
||||||
|
- caddy_data:/data
|
||||||
|
- caddy_config:/config
|
||||||
|
ports:
|
||||||
|
# HTTP
|
||||||
|
- target: 80
|
||||||
|
published: 80
|
||||||
|
protocol: tcp
|
||||||
|
# HTTPS
|
||||||
|
- target: 443
|
||||||
|
published: 443
|
||||||
|
protocol: tcp
|
||||||
|
# HTTP/3
|
||||||
|
- target: 443
|
||||||
|
published: 443
|
||||||
|
protocol: udp
|
||||||
|
depends_on:
|
||||||
|
- database
|
||||||
|
|
||||||
|
database:
|
||||||
|
image: postgres:16-alpine
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: somniarooms
|
||||||
|
# You should definitely change the password in production
|
||||||
|
POSTGRES_PASSWORD: ChangeMe!
|
||||||
|
POSTGRES_USER: somnia
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "pg_isready"]
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
start_period: 60s
|
||||||
|
volumes:
|
||||||
|
- database_data:/var/lib/postgresql/data:rw
|
||||||
|
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
caddy_data:
|
||||||
|
caddy_config:
|
||||||
|
database_data:
|
||||||
|
```
|
||||||
|
|
||||||
|
Config details
|
||||||
|
- SERVER_NAME -> if set to https a SSL cert will be obtained. If you set http, SSL will be disabled. (Read more about this [here](https://caddyserver.com/docs/automatic-https))
|
||||||
|
|
||||||
|
|
||||||
|
Front-end:
|
||||||
|
```yml
|
||||||
|
services:
|
||||||
|
somniarooms-front:
|
||||||
|
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
# You should set your public IP/hostname to back-end.
|
||||||
|
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
|
||||||
|
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
|
||||||
|
ports:
|
||||||
|
# HTTP
|
||||||
|
- target: 80
|
||||||
|
published: 80
|
||||||
|
# HTTPS
|
||||||
|
- target: 443
|
||||||
|
published: 443
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
### Deploy on the same server.
|
||||||
|
Right now, it's quite difficult to set back-end app on a port different from 80/443. Back-end uses Caddy as webserver and automatically try to get SSL certs from let's encrypt.
|
||||||
|
|
||||||
|
My go-to option will be using some reverse-proxy to redirect requests to back or front by domain name.
|
||||||
|
|
||||||
|
This is an example of deployment using Traefik.
|
||||||
|
```yml
|
||||||
|
services:
|
||||||
|
reverse-proxy:
|
||||||
|
# The official v3 Traefik docker image
|
||||||
|
image: traefik:v3.0
|
||||||
|
restart: unless-stopped
|
||||||
|
# Enables the web UI and tells Traefik to listen to docker
|
||||||
|
command:
|
||||||
|
- --api.insecure=true
|
||||||
|
- --providers.docker
|
||||||
|
- --entrypoints.web.address=:80
|
||||||
|
- --entrypoints.websecure.address=:443
|
||||||
|
- --entrypoints.web.http.redirections.entryPoint.to=websecure
|
||||||
|
- --entrypoints.web.http.redirections.entryPoint.scheme=https
|
||||||
|
- --certificatesresolvers.lets-encrypt.acme.tlschallenge=true
|
||||||
|
- --certificatesresolvers.lets-encrypt.acme.email=your_email # <-- Your email here!
|
||||||
|
- --certificatesresolvers.lets-encrypt.acme.storage=/letsencrypt/acme.json
|
||||||
|
ports:
|
||||||
|
# The HTTP port
|
||||||
|
- "80:80"
|
||||||
|
# The HTTPS port
|
||||||
|
- "443:443"
|
||||||
|
# The Web UI (enabled by --api.insecure=true)
|
||||||
|
- "8080:8080"
|
||||||
|
volumes:
|
||||||
|
# So that Traefik can listen to the Docker events
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
# acme.json should be created on host instance
|
||||||
|
- .certs/:/letsencrypt/
|
||||||
|
|
||||||
|
somniarooms-back:
|
||||||
|
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
|
||||||
|
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&charset=utf8
|
||||||
|
MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
||||||
|
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
||||||
|
APP_SECRET: ChangeMySecret
|
||||||
|
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
|
||||||
|
volumes:
|
||||||
|
- caddy_data:/data
|
||||||
|
- caddy_config:/config
|
||||||
|
depends_on:
|
||||||
|
- database
|
||||||
|
labels:
|
||||||
|
# HTTPS YOUR APP
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.routers.somniarooms-back.rule=Host(`api.somnia.dev`)" # <-- Your back-end hostname here!
|
||||||
|
- "traefik.http.routers.somniarooms-back.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.somniarooms-back.tls=true"
|
||||||
|
- "traefik.http.routers.somniarooms-back.tls.certresolver=lets-encrypt"
|
||||||
|
|
||||||
|
somniarooms-front:
|
||||||
|
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
# You should set your public IP/hostname to back-end.
|
||||||
|
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
|
||||||
|
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
|
||||||
|
depends_on:
|
||||||
|
- somniarooms-back
|
||||||
|
labels:
|
||||||
|
- "traefik.http.routers.somniarooms-front.rule=Host(`app.somnia.dev`)" # <-- Your front-end hostname here!
|
||||||
|
|
||||||
|
|
||||||
|
database:
|
||||||
|
image: postgres:16-alpine
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: somniarooms
|
||||||
|
# You should definitely change the password in production
|
||||||
|
POSTGRES_PASSWORD: ChangeMe!
|
||||||
|
POSTGRES_USER: somnia
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "pg_isready"]
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
start_period: 60s
|
||||||
|
volumes:
|
||||||
|
- database_data:/var/lib/postgresql/data:rw
|
||||||
|
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
caddy_data:
|
||||||
|
caddy_config:
|
||||||
|
database_data:
|
||||||
|
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## What's next?
|
||||||
|
|
||||||
|
Remember you can run your docker compose files using:
|
||||||
|
```
|
||||||
|
docker compose up -d --wait
|
||||||
|
```
|
||||||
@@ -2,15 +2,14 @@
|
|||||||
|
|
||||||
namespace App\Controller;
|
namespace App\Controller;
|
||||||
|
|
||||||
|
use App\Entity\User;
|
||||||
|
use App\Entity\ConfigVariable;
|
||||||
|
use Doctrine\ORM\EntityManagerInterface;
|
||||||
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
||||||
use Symfony\Component\HttpFoundation\Response;
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
|
||||||
use Symfony\Component\Routing\Attribute\Route;
|
use Symfony\Component\Routing\Attribute\Route;
|
||||||
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
|
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
|
||||||
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
|
|
||||||
use Doctrine\ORM\EntityManagerInterface;
|
|
||||||
|
|
||||||
use App\Entity\User;
|
|
||||||
use App\Repository\UserRepository;
|
|
||||||
|
|
||||||
class SecurityController extends AbstractController
|
class SecurityController extends AbstractController
|
||||||
{
|
{
|
||||||
@@ -35,24 +34,52 @@ class SecurityController extends AbstractController
|
|||||||
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
|
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
|
||||||
}
|
}
|
||||||
|
|
||||||
#[Route(path: '/addAdmin', name: 'app_security_addAdmin')]
|
#[Route(path: '/setup', name: 'app_security_addAdmin')]
|
||||||
public function addAdmin(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $entityManager): Response
|
public function addAdmin(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $entityManager): Response
|
||||||
{
|
{
|
||||||
$user = new User();
|
$configRepo = $entityManager->getRepository(ConfigVariable::class);
|
||||||
$user->setUsername("admin");
|
$setupStatus = $configRepo->findBy(["key" => "SETUP_STATUS"]);
|
||||||
$user->setRoles(["ROLE_USER", "ROLE_ADMIN"]);
|
|
||||||
$plaintextPassword = "admin";
|
|
||||||
|
|
||||||
// hash the password (based on the security.yaml config for the $user class)
|
if($setupStatus != null && $setupStatus[0] != null && $setupStatus[0]->getValue() != 1) {
|
||||||
$hashedPassword = $passwordHasher->hashPassword(
|
return new Response("Setup was already done");
|
||||||
$user,
|
}
|
||||||
$plaintextPassword
|
|
||||||
);
|
|
||||||
$user->setPassword($hashedPassword);
|
|
||||||
|
|
||||||
$entityManager->persist($user);
|
|
||||||
$entityManager->flush();
|
|
||||||
|
|
||||||
return new Response("Created user - Admin");
|
$entityManager->beginTransaction();
|
||||||
|
|
||||||
|
try {
|
||||||
|
|
||||||
|
//Create system variables.
|
||||||
|
$var_setup = new ConfigVariable();
|
||||||
|
$var_setup->setKey("SETUP_STATUS");
|
||||||
|
$var_setup->setValue("1");
|
||||||
|
$var_setup->setSection("SYSTEM");
|
||||||
|
$entityManager->persist($var_setup);
|
||||||
|
|
||||||
|
|
||||||
|
//Create user Admin.
|
||||||
|
$user = new User();
|
||||||
|
$user->setUsername("admin");
|
||||||
|
$user->setRoles(["ROLE_USER", "ROLE_ADMIN", "ROLE_SUPERADMIN"]);
|
||||||
|
$plaintextPassword = "admin";
|
||||||
|
|
||||||
|
// hash the password (based on the security.yaml config for the $user class)
|
||||||
|
$hashedPassword = $passwordHasher->hashPassword(
|
||||||
|
$user,
|
||||||
|
$plaintextPassword
|
||||||
|
);
|
||||||
|
$user->setPassword($hashedPassword);
|
||||||
|
|
||||||
|
$entityManager->persist($user);
|
||||||
|
|
||||||
|
$entityManager->flush();
|
||||||
|
$entityManager->commit();
|
||||||
|
|
||||||
|
} catch (\Throwable $th) {
|
||||||
|
$entityManager->rollback();
|
||||||
|
throw $th;
|
||||||
|
}
|
||||||
|
|
||||||
|
return new Response("Setup completed :)");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user