Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c7dbf5a1c3 |
@@ -38,7 +38,7 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
push: true
|
push: true
|
||||||
tags: ${{vars.REGISTRY_INSTANCE}}/somnia/somniarooms:devbuild
|
tags: ${{vars.REGISTRY_INSTANCE}}/daniel-garmig/somniarooms:devbuild
|
||||||
target: frankenphp_prod
|
target: frankenphp_prod
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
secrets: |
|
secrets: |
|
||||||
|
|||||||
@@ -23,17 +23,3 @@ Stop containers
|
|||||||
```
|
```
|
||||||
docker compose down --remove-orphans
|
docker compose down --remove-orphans
|
||||||
```
|
```
|
||||||
|
|
||||||
### Prod:
|
|
||||||
|
|
||||||
You can use docker compose for prod or build and deploy a prod image.
|
|
||||||
|
|
||||||
**Build Prod image**
|
|
||||||
```
|
|
||||||
docker build -t somniarooms:prod --target frankenphp_prod .
|
|
||||||
```
|
|
||||||
|
|
||||||
**Deploy prod image**
|
|
||||||
```
|
|
||||||
docker run -d -it -p 80:80 -p 443:443 --name somniarooms --env-file ./env.prod.local somniarooms:prod
|
|
||||||
```
|
|
||||||
|
|||||||
-198
@@ -1,198 +0,0 @@
|
|||||||
# SomniaRooms - How to deploy.
|
|
||||||
|
|
||||||
SomniaRooms is designed to be easy to deploy and use.
|
|
||||||
|
|
||||||
Production images for Docker Containers are available from Gitea Registry.
|
|
||||||
|
|
||||||
Documentation on how to deploy them as containers can be found at [Readme](../README.md).
|
|
||||||
|
|
||||||
## Docker compose examples.
|
|
||||||
|
|
||||||
Here are some deploy examples using docker compose:
|
|
||||||
|
|
||||||
SomniaRooms back-end and front-end can run on the same machine, but some config is needed to work.
|
|
||||||
|
|
||||||
### Deploy back-end and front-end on different servers (different ip address).
|
|
||||||
If your servers have different IP addresses everything is a little bit easier. You can set-up subdomains for each one.
|
|
||||||
|
|
||||||
Use the following docker compose files for back-end and front-end.
|
|
||||||
|
|
||||||
Back-end:
|
|
||||||
```yml
|
|
||||||
services:
|
|
||||||
somniarooms-back:
|
|
||||||
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
|
|
||||||
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&ch> MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
|
||||||
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
|
||||||
APP_SECRET: ChangeMySecret
|
|
||||||
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
|
|
||||||
volumes:
|
|
||||||
- caddy_data:/data
|
|
||||||
- caddy_config:/config
|
|
||||||
ports:
|
|
||||||
# HTTP
|
|
||||||
- target: 80
|
|
||||||
published: 80
|
|
||||||
protocol: tcp
|
|
||||||
# HTTPS
|
|
||||||
- target: 443
|
|
||||||
published: 443
|
|
||||||
protocol: tcp
|
|
||||||
# HTTP/3
|
|
||||||
- target: 443
|
|
||||||
published: 443
|
|
||||||
protocol: udp
|
|
||||||
depends_on:
|
|
||||||
- database
|
|
||||||
|
|
||||||
database:
|
|
||||||
image: postgres:16-alpine
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: somniarooms
|
|
||||||
# You should definitely change the password in production
|
|
||||||
POSTGRES_PASSWORD: ChangeMe!
|
|
||||||
POSTGRES_USER: somnia
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD", "pg_isready"]
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
start_period: 60s
|
|
||||||
volumes:
|
|
||||||
- database_data:/var/lib/postgresql/data:rw
|
|
||||||
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
caddy_data:
|
|
||||||
caddy_config:
|
|
||||||
database_data:
|
|
||||||
```
|
|
||||||
|
|
||||||
Config details
|
|
||||||
- SERVER_NAME -> if set to https a SSL cert will be obtained. If you set http, SSL will be disabled.
|
|
||||||
|
|
||||||
|
|
||||||
Front-end:
|
|
||||||
```yml
|
|
||||||
services:
|
|
||||||
somniarooms-front:
|
|
||||||
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
# You should set your public IP/hostname to back-end.
|
|
||||||
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
|
|
||||||
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
|
|
||||||
ports:
|
|
||||||
# HTTP
|
|
||||||
- target: 80
|
|
||||||
published: 80
|
|
||||||
# HTTPS
|
|
||||||
- target: 443
|
|
||||||
published: 443
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
### Deploy on the same server.
|
|
||||||
Right now, it's quite difficult to set back-end app on a port different from 80/443. Back-end uses Caddy as webserver and automatically try to get SSL certs from let's encrypt.
|
|
||||||
|
|
||||||
My go-to option will be using some reverse-proxy to redirect requests to back or front by domain name.
|
|
||||||
|
|
||||||
This is an example of deployment using Traefik.
|
|
||||||
```yml
|
|
||||||
services:
|
|
||||||
reverse-proxy:
|
|
||||||
# The official v3 Traefik docker image
|
|
||||||
image: traefik:v3.0
|
|
||||||
restart: unless-stopped
|
|
||||||
# Enables the web UI and tells Traefik to listen to docker
|
|
||||||
command:
|
|
||||||
- --api.insecure=true
|
|
||||||
- --providers.docker
|
|
||||||
- --entrypoints.web.address=:80
|
|
||||||
- --entrypoints.websecure.address=:443
|
|
||||||
- --entrypoints.web.http.redirections.entryPoint.to=websecure
|
|
||||||
- --entrypoints.web.http.redirections.entryPoint.scheme=https
|
|
||||||
- --certificatesresolvers.lets-encrypt.acme.tlschallenge=true
|
|
||||||
- --certificatesresolvers.lets-encrypt.acme.email=your_email # <-- Your email here!
|
|
||||||
- --certificatesresolvers.lets-encrypt.acme.storage=/letsencrypt/acme.json
|
|
||||||
ports:
|
|
||||||
# The HTTP port
|
|
||||||
- "80:80"
|
|
||||||
# The HTTPS port
|
|
||||||
- "443:443"
|
|
||||||
# The Web UI (enabled by --api.insecure=true)
|
|
||||||
- "8080:8080"
|
|
||||||
volumes:
|
|
||||||
# So that Traefik can listen to the Docker events
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
# acme.json should be created on host instance
|
|
||||||
- .certs/:/letsencrypt/
|
|
||||||
|
|
||||||
somniarooms-back:
|
|
||||||
image: gitea.uberelectronnetwork.cc/somnia/somniarooms:devbuild
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
SERVER_NAME: https://api.somnia.dev # <-- Your hostname here!
|
|
||||||
DATABASE_URL: postgresql://somnia:ChangeMe!@database/somniarooms?serverVersion=16&charset=utf8
|
|
||||||
MERCURE_PUBLISHER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
|
||||||
MERCURE_SUBSCRIBER_JWT_KEY: ChangeThisMercureHubJWTSecretKey!
|
|
||||||
APP_SECRET: ChangeMySecret
|
|
||||||
FRANKENPHP_CONFIG: "" # <-- Dont touch this line unless you know what are doing.
|
|
||||||
volumes:
|
|
||||||
- caddy_data:/data
|
|
||||||
- caddy_config:/config
|
|
||||||
depends_on:
|
|
||||||
- database
|
|
||||||
labels:
|
|
||||||
# HTTPS YOUR APP
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.routers.somniarooms-back.rule=Host(`api.somnia.dev`)" # <-- Your back-end hostname here!
|
|
||||||
- "traefik.http.routers.somniarooms-back.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.somniarooms-back.tls=true"
|
|
||||||
- "traefik.http.routers.somniarooms-back.tls.certresolver=lets-encrypt"
|
|
||||||
|
|
||||||
somniarooms-front:
|
|
||||||
image: gitea.uberelectronnetwork.cc/somnia/somniaroomsapp:devbuild
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
# You should set your public IP/hostname to back-end.
|
|
||||||
SOMNIAROOMS_BACKEND_HOST: https://api.somnia.dev # <-- Your back-end hostname here!
|
|
||||||
SOMNIAROOMS_BACKEND_PORT: 443 # <-- Your back-end port here! (443 if using https)
|
|
||||||
depends_on:
|
|
||||||
- somniarooms-back
|
|
||||||
labels:
|
|
||||||
- "traefik.http.routers.somniarooms-front.rule=Host(`app.somnia.dev`)" # <-- Your front-end hostname here!
|
|
||||||
|
|
||||||
|
|
||||||
database:
|
|
||||||
image: postgres:16-alpine
|
|
||||||
environment:
|
|
||||||
POSTGRES_DB: somniarooms
|
|
||||||
# You should definitely change the password in production
|
|
||||||
POSTGRES_PASSWORD: ChangeMe!
|
|
||||||
POSTGRES_USER: somnia
|
|
||||||
healthcheck:
|
|
||||||
test: ["CMD", "pg_isready"]
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
start_period: 60s
|
|
||||||
volumes:
|
|
||||||
- database_data:/var/lib/postgresql/data:rw
|
|
||||||
# You may use a bind-mounted host directory instead, so that it is harder to acciden> # - ./docker/db/data:/var/lib/postgresql/data:rw
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
caddy_data:
|
|
||||||
caddy_config:
|
|
||||||
database_data:
|
|
||||||
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
## What's next?
|
|
||||||
|
|
||||||
Remember you can run your docker compose files using:
|
|
||||||
```
|
|
||||||
docker compose up -d --wait
|
|
||||||
```
|
|
||||||
@@ -2,14 +2,15 @@
|
|||||||
|
|
||||||
namespace App\Controller;
|
namespace App\Controller;
|
||||||
|
|
||||||
use App\Entity\User;
|
|
||||||
use App\Entity\ConfigVariable;
|
|
||||||
use Doctrine\ORM\EntityManagerInterface;
|
|
||||||
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
||||||
use Symfony\Component\HttpFoundation\Response;
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
|
|
||||||
use Symfony\Component\Routing\Attribute\Route;
|
use Symfony\Component\Routing\Attribute\Route;
|
||||||
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
|
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
|
||||||
|
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
|
||||||
|
use Doctrine\ORM\EntityManagerInterface;
|
||||||
|
|
||||||
|
use App\Entity\User;
|
||||||
|
use App\Repository\UserRepository;
|
||||||
|
|
||||||
class SecurityController extends AbstractController
|
class SecurityController extends AbstractController
|
||||||
{
|
{
|
||||||
@@ -34,51 +35,24 @@ class SecurityController extends AbstractController
|
|||||||
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
|
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
|
||||||
}
|
}
|
||||||
|
|
||||||
#[Route(path: '/setup', name: 'app_security_addAdmin')]
|
#[Route(path: '/addAdmin', name: 'app_security_addAdmin')]
|
||||||
public function addAdmin(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $entityManager): Response
|
public function addAdmin(UserPasswordHasherInterface $passwordHasher, EntityManagerInterface $entityManager): Response
|
||||||
{
|
{
|
||||||
$setupStatus = $entityManager->find(ConfigVariable::class, "SETUP_STATUS");
|
$user = new User();
|
||||||
|
$user->setUsername("admin");
|
||||||
|
$user->setRoles(["ROLE_USER", "ROLE_ADMIN"]);
|
||||||
|
$plaintextPassword = "admin";
|
||||||
|
|
||||||
if($setupStatus == null || $setupStatus == 1) {
|
// hash the password (based on the security.yaml config for the $user class)
|
||||||
return new Response("Setup was already done");
|
$hashedPassword = $passwordHasher->hashPassword(
|
||||||
}
|
$user,
|
||||||
|
$plaintextPassword
|
||||||
|
);
|
||||||
|
$user->setPassword($hashedPassword);
|
||||||
|
|
||||||
|
$entityManager->persist($user);
|
||||||
|
$entityManager->flush();
|
||||||
|
|
||||||
$entityManager->beginTransaction();
|
return new Response("Created user - Admin");
|
||||||
|
|
||||||
try {
|
|
||||||
|
|
||||||
//Create system variables.
|
|
||||||
$var_setup = new ConfigVariable();
|
|
||||||
$var_setup->setKey("SETUP_STATUS");
|
|
||||||
$var_setup->setValue("1");
|
|
||||||
$var_setup->setSection("SYSTEM");
|
|
||||||
$entityManager->persist($var_setup);
|
|
||||||
|
|
||||||
|
|
||||||
//Create user Admin.
|
|
||||||
$user = new User();
|
|
||||||
$user->setUsername("admin");
|
|
||||||
$user->setRoles(["ROLE_USER", "ROLE_ADMIN", "ROLE_SUPERADMIN"]);
|
|
||||||
$plaintextPassword = "admin";
|
|
||||||
|
|
||||||
// hash the password (based on the security.yaml config for the $user class)
|
|
||||||
$hashedPassword = $passwordHasher->hashPassword(
|
|
||||||
$user,
|
|
||||||
$plaintextPassword
|
|
||||||
);
|
|
||||||
$user->setPassword($hashedPassword);
|
|
||||||
|
|
||||||
$entityManager->persist($user);
|
|
||||||
|
|
||||||
$entityManager->flush();
|
|
||||||
$entityManager->commit();
|
|
||||||
|
|
||||||
} catch (\Throwable $th) {
|
|
||||||
$entityManager->rollback();
|
|
||||||
throw $th;
|
|
||||||
}
|
|
||||||
|
|
||||||
return new Response("Setup completed :)");
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user