mirror of
https://github.com/R0m1k3/TodoFlow.git
synced 2026-10-11 17:28:17 +02:00
preserve API key across container updates
This commit is contained in:
1 parent
e4a56f2fc6
commit
d9c1720523
2 files changed
+53
-1
No files matched your search
+2
-1
@@ -30,11 +30,12 @@ ENV PYTHONUNBUFFERED=1
|
|||||||
RUN mkdir -p /app/data
|
RUN mkdir -p /app/data
|
||||||
|
|
||||||
# Création d'un utilisateur système non-privilégié pour des raisons de sécurité
|
# Création d'un utilisateur système non-privilégié pour des raisons de sécurité
|
||||||
RUN useradd -u 8888 appuser && chown -R appuser:appuser /app
|
RUN chmod +x /app/entrypoint.sh && useradd -u 8888 appuser && chown -R appuser:appuser /app
|
||||||
USER appuser
|
USER appuser
|
||||||
|
|
||||||
EXPOSE 8000
|
EXPOSE 8000
|
||||||
|
|
||||||
# Lancement d'Uvicorn
|
# Lancement d'Uvicorn
|
||||||
|
ENTRYPOINT ["/app/entrypoint.sh"]
|
||||||
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
|
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
|
||||||
|
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
DEFAULT_API_KEYS_RAW="widget-token-secure-789,ai-agent-token-secure-101"
|
||||||
|
PERSISTED_ENV_FILE="${PERSISTED_ENV_FILE:-/app/data/.env}"
|
||||||
|
APP_ENV_FILE="${APP_ENV_FILE:-/app/.env}"
|
||||||
|
|
||||||
|
read_env_value() {
|
||||||
|
file="$1"
|
||||||
|
name="$2"
|
||||||
|
|
||||||
|
if [ ! -f "$file" ]; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
sed -n "s/^[[:space:]]*${name}[[:space:]]*=[[:space:]]*//p" "$file" \
|
||||||
|
| tail -n 1 \
|
||||||
|
| sed 's/^"//; s/"$//; s/^'\''//; s/'\''$//'
|
||||||
|
}
|
||||||
|
|
||||||
|
write_env_value() {
|
||||||
|
file="$1"
|
||||||
|
name="$2"
|
||||||
|
value="$3"
|
||||||
|
|
||||||
|
mkdir -p "$(dirname "$file")"
|
||||||
|
|
||||||
|
if [ -f "$file" ] && grep -q "^[[:space:]]*${name}[[:space:]]*=" "$file"; then
|
||||||
|
escaped_value=$(printf '%s' "$value" | sed 's/[\/&]/\\&/g')
|
||||||
|
sed -i "s/^[[:space:]]*${name}[[:space:]]*=.*/${name}=${escaped_value}/" "$file"
|
||||||
|
else
|
||||||
|
printf '%s=%s\n' "$name" "$value" >> "$file"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
persisted_api_keys="$(read_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" || true)"
|
||||||
|
app_env_api_keys="$(read_env_value "$APP_ENV_FILE" "API_KEYS_RAW" || true)"
|
||||||
|
current_api_keys="${API_KEYS_RAW:-}"
|
||||||
|
|
||||||
|
if [ -n "$persisted_api_keys" ] && { [ -z "$current_api_keys" ] || [ "$current_api_keys" = "$DEFAULT_API_KEYS_RAW" ]; }; then
|
||||||
|
export API_KEYS_RAW="$persisted_api_keys"
|
||||||
|
elif [ -n "$app_env_api_keys" ] && { [ -z "$current_api_keys" ] || [ "$current_api_keys" = "$DEFAULT_API_KEYS_RAW" ]; }; then
|
||||||
|
export API_KEYS_RAW="$app_env_api_keys"
|
||||||
|
if [ "$app_env_api_keys" != "$DEFAULT_API_KEYS_RAW" ]; then
|
||||||
|
write_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" "$app_env_api_keys"
|
||||||
|
fi
|
||||||
|
elif [ -n "$current_api_keys" ] && [ "$current_api_keys" != "$DEFAULT_API_KEYS_RAW" ]; then
|
||||||
|
write_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" "$current_api_keys"
|
||||||
|
fi
|
||||||
|
|
||||||
|
exec "$@"
|
||||||
Reference in new issue
Block a user