feat(docker): guide clone installation and validate paired update artifacts
This commit is contained in:
1 parent
a4266f297c
commit
8f55ff2d17
39 files changed
+473
-73
No files matched your search
+11
-13
@@ -2,7 +2,7 @@
|
||||
# ==============================================================================
|
||||
# docker-preflight.sh — Verify a VPS is ready to run the Dockerized EpicNext-CMS.
|
||||
#
|
||||
# Lets any supplied .env drive the checks. Checks (all idempotent, none mutating):
|
||||
# Does not execute dotenv. Endpoint probes use explicit environment overrides. Checks (all idempotent, none mutating):
|
||||
# 1. Docker + compose available and usable.
|
||||
# 2. Required runtime dirs exist (RW for UID 33 where the CMS writes).
|
||||
# 3. Volume owners are UID/GID 33 (www-data) on the host.
|
||||
@@ -73,17 +73,15 @@ for d in "${RW_DIRS[@]}"; do
|
||||
continue
|
||||
fi
|
||||
if [ ! -d "$d" ]; then err "not a directory: $d"; continue; fi
|
||||
# Test write as the target owner via a temp file drop (as root), then remove.
|
||||
if [ "$(id -u)" -eq 0 ]; then
|
||||
if touch "$d/.preflight-write-test" 2>/dev/null; then
|
||||
rm -f "$d/.preflight-write-test"
|
||||
ok "writable: $d"
|
||||
else
|
||||
err "not writable: $d (needs owner 33:33)"
|
||||
[ "$FIX" -eq 1 ] && { chown -R 33:33 "$d" && say " chown -R 33:33 $d" || err " chown failed"; }
|
||||
fi
|
||||
# Check the actual runtime identity, never root's ability to write.
|
||||
if [ "$(id -u)" -eq 33 ]; then
|
||||
if [ -w "$d" ] && [ -r "$d" ]; then ok "runtime access: $d"; else err "runtime access denied: $d"; fi
|
||||
elif [ "$(id -u)" -eq 0 ] && command -v setpriv >/dev/null 2>&1; then
|
||||
if setpriv --reuid=33 --regid=33 --clear-groups sh -c 'test -r "$1" && test -w "$1"' sh "$d"; then
|
||||
ok "runtime access as UID/GID 33: $d"
|
||||
else err "runtime access denied for UID/GID 33: $d"; fi
|
||||
else
|
||||
if [ -w "$d" ]; then ok "writable: $d"; else err "not writable: $d"; fi
|
||||
wrn "runtime access unverified: $d; updater checks candidate container access before migrations"
|
||||
fi
|
||||
done
|
||||
|
||||
@@ -102,8 +100,8 @@ done
|
||||
doing "4. Configuration + required services (.env, host network)"
|
||||
if [ -f "$ENV_FILE" ]; then
|
||||
ok ".env present: $ENV_FILE"
|
||||
### shellcheck disable=SC1090
|
||||
set -a; . "$ENV_FILE"; set +a
|
||||
say "Dotenv is not executed. Port checks below use explicit shell overrides/defaults, not DATABASE_URL or REDIS_URL."
|
||||
say "The updater validates real candidate configuration and mounted storage before migrations."
|
||||
else
|
||||
err ".env missing: $ENV_FILE (copy your production env here)"
|
||||
fi
|
||||
|
||||
Reference in new issue
Block a user