Remove SSH key mounts and require HTTPS repository bootstrap
This commit is contained in:
@@ -25,15 +25,10 @@ Eine optionale Sammlung mit sechs Beispielen liegt in `beispiel-prompts.json` un
|
|||||||
/mnt/user/appdata/CasaDePrompt/
|
/mnt/user/appdata/CasaDePrompt/
|
||||||
├── bootstrap/
|
├── bootstrap/
|
||||||
│ └── Startpunkt.sh
|
│ └── Startpunkt.sh
|
||||||
├── ssh/
|
|
||||||
│ ├── athena_key
|
|
||||||
│ └── known_hosts
|
|
||||||
└── data/ # wird dauerhaft gespeichert
|
└── data/ # wird dauerhaft gespeichert
|
||||||
```
|
```
|
||||||
|
|
||||||
`Startpunkt.sh` aus diesem Repository nach `bootstrap/` kopieren. Den SSH-Key `athena_key` und eine **bereits geprüfte** `known_hosts` mit dem Eintrag für `[192.168.1.2]:33` nach `ssh/` kopieren. Auf dem Entwicklungsrechner ist dieser Host bereits bekannt. Private Schlüssel niemals ins Repository committen. Für den dauerhaften Betrieb reicht ein eigener, nur lesender Deploy-Key für dieses Repository; er kann unter dem gleichen Dateinamen gemountet werden.
|
`Startpunkt.sh` aus diesem Repository nach `bootstrap/` kopieren. Der Download erfolgt ausschließlich über HTTPS aus dem öffentlich lesbaren Repository. Keine SSH-Keys oder anderen Git-Zugangsdaten mounten oder kopieren.
|
||||||
|
|
||||||
Die SSH-Dateien sollten nur root zugänglich sein (`chmod 700 ssh`, `chmod 600 ssh/athena_key ssh/known_hosts`). Das Skript prüft den Hostschlüssel strikt; es akzeptiert keine fremden Schlüssel automatisch. Passwortgeschützte Keys benötigen einen Agent und werden von diesem einfachen Bootstrap nicht unterstützt.
|
|
||||||
|
|
||||||
### 2. Unraid-Vorlage einspielen
|
### 2. Unraid-Vorlage einspielen
|
||||||
|
|
||||||
@@ -52,12 +47,12 @@ Vorbelegt sind:
|
|||||||
| Image | `python:3.13-alpine` |
|
| Image | `python:3.13-alpine` |
|
||||||
| Netzwerk | `bridge` (normales Unraid-Netz über Portfreigabe) |
|
| Netzwerk | `bridge` (normales Unraid-Netz über Portfreigabe) |
|
||||||
| Web-Port | Host `8765` → Container `8000` |
|
| Web-Port | Host `8765` → Container `8000` |
|
||||||
| Repository | `ssh://git@192.168.1.2:33/michael/CasaDePrompt.git` |
|
| Repository | `https://git.casaderoll.de/michael/CasaDePrompt.git` |
|
||||||
| Branch | `main` |
|
| Branch | `main` |
|
||||||
| Startbefehl / Post Arguments | `/bin/sh /bootstrap/Startpunkt.sh` |
|
| Startbefehl / Post Arguments | `/bin/sh /bootstrap/Startpunkt.sh` |
|
||||||
| App-Benutzer | `99:100` |
|
| App-Benutzer | `99:100` |
|
||||||
|
|
||||||
Beim Start installiert das Skript Git/SSH und Python-Pakete, lädt den gewählten Branch bzw. Tag und startet die Anwendung ohne root-Rechte. Dafür benötigt es Zugriff auf dein Git, Alpine-Paketserver und PyPI. Ein Neustart lädt den aktuellen Stand erneut. Bei Download-/Installationsfehlern stoppt es mit einer Meldung, statt eine halb installierte App zu starten. Für reproduzierbare Updates einen Release-Tag in `APP_REF` verwenden.
|
Beim Start installiert das Skript Git und Python-Pakete, lädt den gewählten Branch bzw. Tag und startet die Anwendung ohne root-Rechte. Dafür benötigt es Zugriff auf dein Git, Alpine-Paketserver und PyPI. Ein Neustart lädt den aktuellen Stand erneut. Bei Download-/Installationsfehlern stoppt es mit einer Meldung, statt eine halb installierte App zu starten. Für reproduzierbare Updates einen Release-Tag in `APP_REF` verwenden.
|
||||||
|
|
||||||
### 3. Anmelden
|
### 3. Anmelden
|
||||||
|
|
||||||
|
|||||||
+3
-10
@@ -2,33 +2,26 @@
|
|||||||
set -eu
|
set -eu
|
||||||
umask 077
|
umask 077
|
||||||
export DATA_DIR="${DATA_DIR:-/data}"
|
export DATA_DIR="${DATA_DIR:-/data}"
|
||||||
REPO_URL="${REPO_URL:-ssh://git@192.168.1.2:33/michael/CasaDePrompt.git}"
|
REPO_URL="${REPO_URL:-https://git.casaderoll.de/michael/CasaDePrompt.git}"
|
||||||
APP_REF="${APP_REF:-main}"
|
APP_REF="${APP_REF:-main}"
|
||||||
PUID="${PUID:-99}"
|
PUID="${PUID:-99}"
|
||||||
PGID="${PGID:-100}"
|
PGID="${PGID:-100}"
|
||||||
case "$PUID:$PGID" in *[!0-9:]*|:*|*:) echo 'PUID/PGID müssen numerisch sein.' >&2; exit 1;; esac
|
case "$PUID:$PGID" in *[!0-9:]*|:*|*:) echo 'PUID/PGID müssen numerisch sein.' >&2; exit 1;; esac
|
||||||
if [ "$(id -u)" = 0 ]; then
|
if [ "$(id -u)" = 0 ]; then
|
||||||
apk add --no-cache git openssh-client ca-certificates su-exec
|
apk add --no-cache git ca-certificates su-exec
|
||||||
fi
|
fi
|
||||||
mkdir -p "$DATA_DIR" /opt/casadeprompt
|
mkdir -p "$DATA_DIR" /opt/casadeprompt
|
||||||
chmod 755 /opt/casadeprompt
|
chmod 755 /opt/casadeprompt
|
||||||
if [ -n "${APP_SOURCE:-}" ]; then
|
if [ -n "${APP_SOURCE:-}" ]; then
|
||||||
APP_PATH="$APP_SOURCE"
|
APP_PATH="$APP_SOURCE"
|
||||||
else
|
else
|
||||||
|
case "$REPO_URL" in https://*) ;; *) echo "REPO_URL muss HTTPS verwenden." >&2; exit 1;; esac
|
||||||
case "$REPO_URL" in -*) echo 'Ungültige REPO_URL' >&2; exit 1;; esac
|
case "$REPO_URL" in -*) echo 'Ungültige REPO_URL' >&2; exit 1;; esac
|
||||||
case "$APP_REF" in -*) echo 'Ungültige APP_REF' >&2; exit 1;; esac
|
case "$APP_REF" in -*) echo 'Ungültige APP_REF' >&2; exit 1;; esac
|
||||||
if [ -f /run/ssh/athena_key ]; then
|
|
||||||
mkdir -p /opt/casa-ssh
|
|
||||||
cp /run/ssh/athena_key /opt/casa-ssh/key
|
|
||||||
chmod 600 /opt/casa-ssh/key
|
|
||||||
[ -f /run/ssh/known_hosts ] || { echo 'Bitte verifizierte known_hosts nach /run/ssh/known_hosts mounten.' >&2; exit 1; }
|
|
||||||
export GIT_SSH_COMMAND='ssh -i /opt/casa-ssh/key -o IdentitiesOnly=yes -o BatchMode=yes -o StrictHostKeyChecking=yes -o UserKnownHostsFile=/run/ssh/known_hosts'
|
|
||||||
fi
|
|
||||||
APP_PATH="$(mktemp -d /opt/casadeprompt/release.XXXXXX)"
|
APP_PATH="$(mktemp -d /opt/casadeprompt/release.XXXXXX)"
|
||||||
echo 'Lade CasaDePrompt aus dem Repository …'
|
echo 'Lade CasaDePrompt aus dem Repository …'
|
||||||
git clone --quiet --depth 1 --branch "$APP_REF" -- "$REPO_URL" "$APP_PATH"
|
git clone --quiet --depth 1 --branch "$APP_REF" -- "$REPO_URL" "$APP_PATH"
|
||||||
rm -rf "$APP_PATH/.git"
|
rm -rf "$APP_PATH/.git"
|
||||||
rm -f /opt/casa-ssh/key
|
|
||||||
fi
|
fi
|
||||||
[ -f "$APP_PATH/requirements.txt" ] && [ -f "$APP_PATH/atelier/app.py" ] || { echo 'Repository muss die Anwendung im Hauptverzeichnis enthalten.' >&2; exit 1; }
|
[ -f "$APP_PATH/requirements.txt" ] && [ -f "$APP_PATH/atelier/app.py" ] || { echo 'Repository muss die Anwendung im Hauptverzeichnis enthalten.' >&2; exit 1; }
|
||||||
python -m venv /opt/casa-venv
|
python -m venv /opt/casa-venv
|
||||||
|
|||||||
@@ -8,15 +8,14 @@
|
|||||||
<Shell>sh</Shell>
|
<Shell>sh</Shell>
|
||||||
<Icon>http://192.168.1.2:8765/static/icon.png</Icon>
|
<Icon>http://192.168.1.2:8765/static/icon.png</Icon>
|
||||||
<WebUI>http://[IP]:[PORT:8000]/</WebUI>
|
<WebUI>http://[IP]:[PORT:8000]/</WebUI>
|
||||||
<Overview>Privates Prompt-Archiv mit SQLite, Versionierung, OpenAI-kompatibler KI-Anbindung und MCP. Startpunkt.sh, athena_key und verifizierte known_hosts vor dem Start auf dem NAS ablegen. Keine zusätzliche Datenbank erforderlich.</Overview>
|
<Overview>Privates Prompt-Archiv mit SQLite, Versionierung, OpenAI-kompatibler KI-Anbindung und MCP. Startpunkt.sh vor dem Start auf dem NAS ablegen. Keine zusätzliche Datenbank erforderlich.</Overview>
|
||||||
<Category>Productivity:</Category>
|
<Category>Productivity:</Category>
|
||||||
<ExtraParams>--restart unless-stopped</ExtraParams>
|
<ExtraParams>--restart unless-stopped</ExtraParams>
|
||||||
<PostArgs>/bin/sh /bootstrap/Startpunkt.sh</PostArgs>
|
<PostArgs>/bin/sh /bootstrap/Startpunkt.sh</PostArgs>
|
||||||
<Config Name="Weboberfläche und MCP" Target="8000" Default="8765" Mode="tcp" Description="Weboberfläche: http://UNRAID-IP:8765 · MCP: http://UNRAID-IP:8765/mcp/" Type="Port" Display="always" Required="true" Mask="false">8765</Config>
|
<Config Name="Weboberfläche und MCP" Target="8000" Default="8765" Mode="tcp" Description="Weboberfläche: http://UNRAID-IP:8765 · MCP: http://UNRAID-IP:8765/mcp/" Type="Port" Display="always" Required="true" Mask="false">8765</Config>
|
||||||
<Config Name="Datenordner" Target="/data" Default="/mnt/user/appdata/CasaDePrompt/data" Mode="rw" Description="SQLite, Einstellungen und Zugangsschlüssel. Diesen Ordner sichern." Type="Path" Display="always" Required="true" Mask="false">/mnt/user/appdata/CasaDePrompt/data</Config>
|
<Config Name="Datenordner" Target="/data" Default="/mnt/user/appdata/CasaDePrompt/data" Mode="rw" Description="SQLite, Einstellungen und Zugangsschlüssel. Diesen Ordner sichern." Type="Path" Display="always" Required="true" Mask="false">/mnt/user/appdata/CasaDePrompt/data</Config>
|
||||||
<Config Name="Startskript-Ordner" Target="/bootstrap" Default="/mnt/user/appdata/CasaDePrompt/bootstrap" Mode="ro" Description="Hier muss Startpunkt.sh liegen." Type="Path" Display="always" Required="true" Mask="false">/mnt/user/appdata/CasaDePrompt/bootstrap</Config>
|
<Config Name="Startskript-Ordner" Target="/bootstrap" Default="/mnt/user/appdata/CasaDePrompt/bootstrap" Mode="ro" Description="Hier muss Startpunkt.sh liegen." Type="Path" Display="always" Required="true" Mask="false">/mnt/user/appdata/CasaDePrompt/bootstrap</Config>
|
||||||
<Config Name="Git-SSH-Zugang" Target="/run/ssh" Default="/mnt/user/appdata/CasaDePrompt/ssh" Mode="ro" Description="Ordner mit athena_key und known_hosts. Schreibgeschützt, nur für den Git-Download beim Start." Type="Path" Display="always" Required="true" Mask="false">/mnt/user/appdata/CasaDePrompt/ssh</Config>
|
<Config Name="Git-Repository" Target="REPO_URL" Default="https://git.casaderoll.de/michael/CasaDePrompt.git" Mode="" Description="HTTPS-Adresse des Repositorys." Type="Variable" Display="always" Required="true" Mask="false">https://git.casaderoll.de/michael/CasaDePrompt.git</Config>
|
||||||
<Config Name="Git-Repository" Target="REPO_URL" Default="ssh://git@192.168.1.2:33/michael/CasaDePrompt.git" Mode="" Description="SSH-Adresse des Repositorys." Type="Variable" Display="always" Required="true" Mask="false">ssh://git@192.168.1.2:33/michael/CasaDePrompt.git</Config>
|
|
||||||
<Config Name="Git-Branch oder Tag" Target="APP_REF" Default="main" Mode="" Description="Wird bei jedem Containerstart frisch geladen. Für feste Version einen Release-Tag eintragen." Type="Variable" Display="always" Required="true" Mask="false">main</Config>
|
<Config Name="Git-Branch oder Tag" Target="APP_REF" Default="main" Mode="" Description="Wird bei jedem Containerstart frisch geladen. Für feste Version einen Release-Tag eintragen." Type="Variable" Display="always" Required="true" Mask="false">main</Config>
|
||||||
<Config Name="Benutzer-ID" Target="PUID" Default="99" Mode="" Description="Unraid nobody = 99. Anwendung läuft ohne root-Rechte." Type="Variable" Display="advanced" Required="true" Mask="false">99</Config>
|
<Config Name="Benutzer-ID" Target="PUID" Default="99" Mode="" Description="Unraid nobody = 99. Anwendung läuft ohne root-Rechte." Type="Variable" Display="advanced" Required="true" Mask="false">99</Config>
|
||||||
<Config Name="Gruppen-ID" Target="PGID" Default="100" Mode="" Description="Unraid users = 100." Type="Variable" Display="advanced" Required="true" Mask="false">100</Config>
|
<Config Name="Gruppen-ID" Target="PGID" Default="100" Mode="" Description="Unraid users = 100." Type="Variable" Display="advanced" Required="true" Mask="false">100</Config>
|
||||||
|
|||||||
Reference in New Issue
Block a user