From 718a704868d0293638e9858cca80f6ab77cc6e30 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 26 Jun 2026 16:26:26 +0000 Subject: [PATCH] =?UTF-8?q?Rend=20AUTH=5FSECRET=20optionnel=20:=20g=C3=A9n?= =?UTF-8?q?=C3=A9ration=20auto=20+=20persistance=20au=20d=C3=A9ploiement?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Le compose ne requiert plus AUTH_SECRET (`:?` retiré). Si la variable est vide, docker-entrypoint.sh génère un secret aléatoire et le persiste dans le volume app-data (/app/data/auth_secret), réutilisé aux redémarrages. Surcharge possible en définissant AUTH_SECRET. Déploiement Portainer sans configuration requise. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01XwfhYHzC9hQWPDnQ2p53GL --- .env.example | 5 +++-- Dockerfile | 4 +++- README.md | 4 ++-- docker-compose.yml | 8 +++++++- docker-entrypoint.sh | 15 +++++++++++++++ 5 files changed, 30 insertions(+), 6 deletions(-) diff --git a/.env.example b/.env.example index 7ea2143..7c93a85 100644 --- a/.env.example +++ b/.env.example @@ -11,8 +11,9 @@ POSTGRES_PASSWORD=pleinr POSTGRES_DB=pleinr # ---- Auth.js (NextAuth v5) ---- -# Generate with: openssl rand -base64 32 -AUTH_SECRET=change-me-to-a-long-random-string +# Optional with docker-compose: if left unset, the container generates and +# persists one automatically. To set it yourself: openssl rand -base64 32 +AUTH_SECRET= # Public URL of the app (used by Auth.js for callbacks). # With docker-compose the app is published on host port 8413 by default. AUTH_URL=http://localhost:8413 diff --git a/Dockerfile b/Dockerfile index 548b8bb..2b0985c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -35,7 +35,9 @@ COPY --from=builder /app/dist ./dist COPY --from=builder /app/drizzle ./drizzle COPY docker-entrypoint.sh /app/docker-entrypoint.sh -RUN chmod +x /app/docker-entrypoint.sh && chown -R nextjs:nodejs /app +RUN mkdir -p /app/data \ + && chmod +x /app/docker-entrypoint.sh \ + && chown -R nextjs:nodejs /app USER nextjs EXPOSE 3000 diff --git a/README.md b/README.md index f7f465c..a21502b 100644 --- a/README.md +++ b/README.md @@ -24,8 +24,8 @@ L'application tourne dans **un seul conteneur Docker**. Postgres est un **conten ```bash cp .env.example .env -# éditez .env : au minimum, définissez AUTH_SECRET -# openssl rand -base64 32 +# AUTH_SECRET est optionnel : s'il est vide, le conteneur en génère un et le +# persiste automatiquement. Pour le fixer vous-même : openssl rand -base64 32 docker compose up --build ``` diff --git a/docker-compose.yml b/docker-compose.yml index aa01bfe..84a0f96 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -33,7 +33,9 @@ services: condition: service_healthy environment: DATABASE_URL: postgres://${POSTGRES_USER:-pleinr}:${POSTGRES_PASSWORD:-pleinr}@postgres:5432/${POSTGRES_DB:-pleinr} - AUTH_SECRET: ${AUTH_SECRET:?set AUTH_SECRET in your .env} + # Optional: if left empty, the container generates and persists one + # automatically (see docker-entrypoint.sh + the app-data volume). + AUTH_SECRET: ${AUTH_SECRET:-} AUTH_URL: ${AUTH_URL:-http://localhost:8413} SEED_ON_START: ${SEED_ON_START:-true} SEED_ADMIN_EMAIL: ${SEED_ADMIN_EMAIL:-admin@plein-r.fr} @@ -42,6 +44,10 @@ services: ports: # Host port rarely used (container stays on 3000). App reachable at http://HOST:8413 - "8413:3000" + volumes: + # Persists the auto-generated AUTH_SECRET across restarts. + - appdata:/app/data volumes: pgdata: + appdata: diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh index 3685e5d..be79c9b 100644 --- a/docker-entrypoint.sh +++ b/docker-entrypoint.sh @@ -1,6 +1,21 @@ #!/bin/sh set -e +# Ensure an AUTH_SECRET exists. If none is provided, generate one and persist it +# to the app-data volume so sessions stay valid across restarts. +if [ -z "$AUTH_SECRET" ]; then + SECRET_FILE=/app/data/auth_secret + if [ -f "$SECRET_FILE" ]; then + AUTH_SECRET=$(cat "$SECRET_FILE") + else + AUTH_SECRET=$(node -e "console.log(require('crypto').randomBytes(32).toString('base64'))") + mkdir -p /app/data + printf '%s' "$AUTH_SECRET" > "$SECRET_FILE" + echo "→ AUTH_SECRET généré et persisté dans $SECRET_FILE" + fi + export AUTH_SECRET +fi + echo "→ Applying database migrations…" node dist/migrate.cjs