Remove SSH key mounts and require HTTPS repository bootstrap

This commit is contained in:
Mikei386
2026-09-24 21:42:33 +02:00
parent bbb2371e5f
commit d704b01897
3 changed files with 8 additions and 21 deletions
+3 -10
View File
@@ -2,33 +2,26 @@
set -eu
umask 077
export DATA_DIR="${DATA_DIR:-/data}"
REPO_URL="${REPO_URL:-ssh://git@192.168.1.2:33/michael/CasaDePrompt.git}"
REPO_URL="${REPO_URL:-https://git.casaderoll.de/michael/CasaDePrompt.git}"
APP_REF="${APP_REF:-main}"
PUID="${PUID:-99}"
PGID="${PGID:-100}"
case "$PUID:$PGID" in *[!0-9:]*|:*|*:) echo 'PUID/PGID müssen numerisch sein.' >&2; exit 1;; esac
if [ "$(id -u)" = 0 ]; then
apk add --no-cache git openssh-client ca-certificates su-exec
apk add --no-cache git ca-certificates su-exec
fi
mkdir -p "$DATA_DIR" /opt/casadeprompt
chmod 755 /opt/casadeprompt
if [ -n "${APP_SOURCE:-}" ]; then
APP_PATH="$APP_SOURCE"
else
case "$REPO_URL" in https://*) ;; *) echo "REPO_URL muss HTTPS verwenden." >&2; exit 1;; esac
case "$REPO_URL" in -*) echo 'Ungültige REPO_URL' >&2; exit 1;; esac
case "$APP_REF" in -*) echo 'Ungültige APP_REF' >&2; exit 1;; esac
if [ -f /run/ssh/athena_key ]; then
mkdir -p /opt/casa-ssh
cp /run/ssh/athena_key /opt/casa-ssh/key
chmod 600 /opt/casa-ssh/key
[ -f /run/ssh/known_hosts ] || { echo 'Bitte verifizierte known_hosts nach /run/ssh/known_hosts mounten.' >&2; exit 1; }
export GIT_SSH_COMMAND='ssh -i /opt/casa-ssh/key -o IdentitiesOnly=yes -o BatchMode=yes -o StrictHostKeyChecking=yes -o UserKnownHostsFile=/run/ssh/known_hosts'
fi
APP_PATH="$(mktemp -d /opt/casadeprompt/release.XXXXXX)"
echo 'Lade CasaDePrompt aus dem Repository …'
git clone --quiet --depth 1 --branch "$APP_REF" -- "$REPO_URL" "$APP_PATH"
rm -rf "$APP_PATH/.git"
rm -f /opt/casa-ssh/key
fi
[ -f "$APP_PATH/requirements.txt" ] && [ -f "$APP_PATH/atelier/app.py" ] || { echo 'Repository muss die Anwendung im Hauptverzeichnis enthalten.' >&2; exit 1; }
python -m venv /opt/casa-venv