1 Commits
Author SHA1 Message Date
Michael d9c1720523 preserve API key across container updates 2026-05-28 08:10:41 +02:00
2 changed files with 53 additions and 1 deletions

No files matched your search

+2 -1
View File
@@ -30,11 +30,12 @@ ENV PYTHONUNBUFFERED=1
RUN mkdir -p /app/data
# Création d'un utilisateur système non-privilégié pour des raisons de sécurité
RUN useradd -u 8888 appuser && chown -R appuser:appuser /app
RUN chmod +x /app/entrypoint.sh && useradd -u 8888 appuser && chown -R appuser:appuser /app
USER appuser
EXPOSE 8000
# Lancement d'Uvicorn
ENTRYPOINT ["/app/entrypoint.sh"]
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
+51
View File
@@ -0,0 +1,51 @@
#!/bin/sh
set -eu
DEFAULT_API_KEYS_RAW="widget-token-secure-789,ai-agent-token-secure-101"
PERSISTED_ENV_FILE="${PERSISTED_ENV_FILE:-/app/data/.env}"
APP_ENV_FILE="${APP_ENV_FILE:-/app/.env}"
read_env_value() {
file="$1"
name="$2"
if [ ! -f "$file" ]; then
return 0
fi
sed -n "s/^[[:space:]]*${name}[[:space:]]*=[[:space:]]*//p" "$file" \
| tail -n 1 \
| sed 's/^"//; s/"$//; s/^'\''//; s/'\''$//'
}
write_env_value() {
file="$1"
name="$2"
value="$3"
mkdir -p "$(dirname "$file")"
if [ -f "$file" ] && grep -q "^[[:space:]]*${name}[[:space:]]*=" "$file"; then
escaped_value=$(printf '%s' "$value" | sed 's/[\/&]/\\&/g')
sed -i "s/^[[:space:]]*${name}[[:space:]]*=.*/${name}=${escaped_value}/" "$file"
else
printf '%s=%s\n' "$name" "$value" >> "$file"
fi
}
persisted_api_keys="$(read_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" || true)"
app_env_api_keys="$(read_env_value "$APP_ENV_FILE" "API_KEYS_RAW" || true)"
current_api_keys="${API_KEYS_RAW:-}"
if [ -n "$persisted_api_keys" ] && { [ -z "$current_api_keys" ] || [ "$current_api_keys" = "$DEFAULT_API_KEYS_RAW" ]; }; then
export API_KEYS_RAW="$persisted_api_keys"
elif [ -n "$app_env_api_keys" ] && { [ -z "$current_api_keys" ] || [ "$current_api_keys" = "$DEFAULT_API_KEYS_RAW" ]; }; then
export API_KEYS_RAW="$app_env_api_keys"
if [ "$app_env_api_keys" != "$DEFAULT_API_KEYS_RAW" ]; then
write_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" "$app_env_api_keys"
fi
elif [ -n "$current_api_keys" ] && [ "$current_api_keys" != "$DEFAULT_API_KEYS_RAW" ]; then
write_env_value "$PERSISTED_ENV_FILE" "API_KEYS_RAW" "$current_api_keys"
fi
exec "$@"