Compare commits

..

6 commits

8 changed files with 117 additions and 52 deletions

View file

@ -43,3 +43,12 @@ IDHUB_ENABLE_EMAIL=false
IDHUB_ENABLE_2FACTOR_AUTH=false
IDHUB_ENABLE_DOMAIN_CHECKER=false
IDHUB_PREDEFINED_TOKEN='27f944ce-3d58-4f48-b068-e4aa95f97c95'
# IDHUB- Postgres
###
IDHUB_DB_NAME="idhub"
IDHUB_DB_USER="ereuse"
IDHUB_DB_PASSWORD="ereuse"
IDHUB_DB_HOST="idhub-postgres"
IDHUB_DB_PORT=5432

View file

@ -0,0 +1,11 @@
services:
idhub:
environment:
- DEBUG=true
- CREATE_TEST_USERS=true
volumes:
- .:/opt/idhub
idhub-postgres:
ports:
- 5433:5432

View file

@ -0,0 +1,10 @@
services:
idhub:
environment:
- DEBUG=false
- CREATE_TEST_USERS=false
volumes:
- idhub_data:/opt/idhub
volumes:
idhub_data:

View file

@ -7,21 +7,20 @@ services:
context: .
dockerfile: docker/idhub.Dockerfile
environment:
# General
- DOMAIN=${IDHUB_DOMAIN:-localhost}
- ALLOWED_HOSTS=${IDHUB_ALLOWED_HOSTS:-$IDHUB_DOMAIN}
- DEBUG=true
- DEMO=${IDHUB_DEMO:-}
# Admin & User
- INITIAL_ADMIN_EMAIL=${IDHUB_ADMIN_EMAIL}
- INITIAL_ADMIN_PASSWORD=${IDHUB_ADMIN_PASSWD}
- CREATE_TEST_USERS=true
# Email Configuration
- ENABLE_EMAIL=${IDHUB_ENABLE_EMAIL:-true}
- ENABLE_2FACTOR_AUTH=${IDHUB_ENABLE_2FACTOR_AUTH:-true}
- ENABLE_DOMAIN_CHECKER=${IDHUB_ENABLE_DOMAIN_CHECKER:-true}
- PREDEFINED_TOKEN=${IDHUB_PREDEFINED_TOKEN:-}
- SECRET_KEY=${IDHUB_SECRET_KEY:-publicsecretisnotsecureVtmKBfxpVV47PpBCF2Nzz2H6qnbd}
- STATIC_ROOT=${IDHUB_STATIC_ROOT:-/static/}
- MEDIA_ROOT=${IDHUB_MEDIA_ROOT:-/media/}
- PORT=${IDHUB_PORT:-9001}
- DEFAULT_FROM_EMAIL=${IDHUB_DEFAULT_FROM_EMAIL}
- EMAIL_HOST=${IDHUB_EMAIL_HOST}
- EMAIL_HOST_USER=${IDHUB_EMAIL_HOST_USER}
@ -29,10 +28,47 @@ services:
- EMAIL_PORT=${IDHUB_EMAIL_PORT}
- EMAIL_USE_TLS=${IDHUB_EMAIL_USE_TLS}
- EMAIL_BACKEND=${IDHUB_EMAIL_BACKEND}
- SUPPORTED_CREDENTIALS=${IDHUB_SUPPORTED_CREDENTIALS:-}
# Auth & Security
- SECRET_KEY=${IDHUB_SECRET_KEY:-publicsecretisnotsecureVtmKBfxpVV47PpBCF2Nzz2H6qnbd}
- PREDEFINED_TOKEN=${IDHUB_PREDEFINED_TOKEN:-}
- ENABLE_2FACTOR_AUTH=${IDHUB_ENABLE_2FACTOR_AUTH:-true}
# App
- SYNC_ORG_DEV=${IDHUB_SYNC_ORG_DEV}
- STATIC_ROOT=${IDHUB_STATIC_ROOT:-/static/}
- MEDIA_ROOT=${IDHUB_MEDIA_ROOT:-/media/}
- PORT=${IDHUB_PORT:-9001}
- SUPPORTED_CREDENTIALS=${IDHUB_SUPPORTED_CREDENTIALS:-}
# DB vars
- DB_PORT=${IDHUB_DB_PORT:-5432}
- DB_HOST=${IDHUB_DB_HOST:-devicehub-postgres}
- DB_NAME=${IDHUB_DB_NAME}
- DB_USER=${IDHUB_DB_USER}
- DB_PASSWORD=${IDHUB_DB_PASSWORD}
ports:
- ${IDHUB_PORT:-9001}:${IDHUB_PORT:-9001}
# TODO manage volumes dev vs prod
depends_on:
idhub-postgres:
condition: service_healthy
restart: true
idhub-postgres:
image: postgres:17
environment:
- POSTGRES_DB=${IDHUB_DB_NAME}
- POSTGRES_USER=${IDHUB_DB_USER}
- POSTGRES_PASSWORD=${IDHUB_DB_PASSWORD}
volumes:
- .:/opt/idhub
- idhub_pg_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${IDHUB_DB_USER} -d ${IDHUB_DB_NAME}"]
start_period: 1s
interval: 1s
timeout: 10s
retries: 10
volumes:
idhub_pg_data:

View file

@ -4,7 +4,6 @@ FROM python:3.11.7-slim-bookworm
RUN apt update && \
apt-get install -y \
git \
sqlite3 \
jq \
libpango-1.0-0 libpangoft2-1.0-0 \
&& pip install cffi brotli \

View file

@ -28,36 +28,42 @@ END
}
deployment_strategy() {
# detect if existing deployment (TODO only works with sqlite)
if [ -f "${idhub_dir}/db.sqlite3" ]; then
echo "INFO: detected EXISTING deployment"
./manage.py migrate
init_flagfile="${idhub_dir}/already_configured.idhub"
if [ ! -f "${init_flagfile}" ]; then
echo "INFO: detected NEW deployment"
# this file helps all docker containers to guess number of hosts involved
# right now is only needed by new deployment for oidc
if [ -d "/sharedsecret" ]; then
touch /sharedsecret/${DOMAIN}
fi
# move the migrate thing in docker entrypoint
# inspired by https://medium.com/analytics-vidhya/django-with-docker-and-docker-compose-python-part-2-8415976470cc
echo "INFO detected NEW deployment"
./manage.py migrate
if [ "${DEMO:-}" = 'true' ]; then
printf "This is DEVELOPMENT/PILOTS_EARLY DEPLOYMENT: including demo hardcoded data\n" >&2
PREDEFINED_TOKEN="${PREDEFINED_TOKEN:-}"
./manage.py demo_data "${PREDEFINED_TOKEN}"
fi
if [ "${OIDC_ORGS:-}" ]; then
config_oidc4vp
else
echo "Note: skipping oidc4vp config"
fi
# remain next command as the last operation for this if conditional
touch "${init_flagfile}"
else
echo "INFO: detected PREVIOUS deployment"
./manage.py migrate
# warn admin that it should re-enter password to keep the service working
./manage.py send_mail_admins
else
# this file helps all docker containers to guess number of hosts involved
# right now is only needed by new deployment for oidc
if [ -d "/sharedsecret" ]; then
touch /sharedsecret/${DOMAIN}
fi
# move the migrate thing in docker entrypoint
# inspired by https://medium.com/analytics-vidhya/django-with-docker-and-docker-compose-python-part-2-8415976470cc
echo "INFO detected NEW deployment"
./manage.py migrate
if [ "${DEMO:-}" = 'true' ]; then
printf "This is DEVELOPMENT/PILOTS_EARLY DEPLOYMENT: including demo hardcoded data\n" >&2
PREDEFINED_TOKEN="${PREDEFINED_TOKEN:-}"
./manage.py demo_data "${PREDEFINED_TOKEN}"
fi
if [ "${OIDC_ORGS:-}" ]; then
config_oidc4vp
else
echo "Note: skipping oidc4vp config"
fi
fi
}

View file

@ -35,3 +35,4 @@ pyroaring==0.4.5
coverage==7.4.3
gunicorn==21.2.0
pyvckit
psycopg2-binary==2.9.10

View file

@ -121,22 +121,15 @@ WSGI_APPLICATION = 'trustchain_idhub.wsgi.application'
# Database
# https://docs.djangoproject.com/en/4.2/ref/settings/#databases
DATABASES = {
# 'default': {
# 'ENGINE': 'django.db.backends.sqlite3',
# 'NAME': BASE_DIR / 'db.sqlite3',
# }
'default': config(
'DATABASE_URL',
default='sqlite:///' + os.path.join(BASE_DIR, 'db.sqlite3'),
cast=db_url
)
# 'default': config(
# 'DATABASE_URL',
# default='sqlite:///' + os.path.join(BASE_DIR, 'db.sqlite3'),
# cast=db_url
# )
'default': {
'ENGINE': os.getenv('DB_ENGINE', 'django.db.backends.postgresql'),
'NAME': os.getenv('IDHUB_DB_NAME', 'idhub'),
'USER': os.getenv('IDHUB_DB_USER', 'ereuse'),
'PASSWORD': os.getenv('IDHUB_DB_PASSWORD', 'ereuse'),
'HOST': os.getenv('IDHUB_DB_HOST', 'idhub-postgres'),
'PORT': os.getenv('IDHUB_DB_PORT', '5432'),
}
}