check / check (push) Successful in 1m58s
`bin/entrypoint.sh` now runs `netwatch-server prepare-data-dir`, which refuses a `DATA_DIR` that is not `/data` or a path below it written in full, then creates `DATA_DIR`, gives `/data` and everything in it to `netwatch`, and sets mode 750 on `/data` and `DATA_DIR`. Every step goes through a Go `os.Root` opened on `/data`, and the modes are set on the opened directories rather than by name, so neither a symbolic link already there nor one a host process swaps in while the container starts can make root create or change anything outside `/data`. The README says which `DATA_DIR` values are accepted. Model: opus-5-5
78 lines
1.8 KiB
Go
78 lines
1.8 KiB
Go
// Package main is the entry point for netwatch-server.
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
"os/user"
|
|
|
|
"sneak.berlin/go/netwatch/internal/config"
|
|
"sneak.berlin/go/netwatch/internal/globals"
|
|
"sneak.berlin/go/netwatch/internal/handlers"
|
|
"sneak.berlin/go/netwatch/internal/healthcheck"
|
|
"sneak.berlin/go/netwatch/internal/logger"
|
|
"sneak.berlin/go/netwatch/internal/middleware"
|
|
"sneak.berlin/go/netwatch/internal/reportbuf"
|
|
"sneak.berlin/go/netwatch/internal/server"
|
|
|
|
"go.uber.org/fx"
|
|
)
|
|
|
|
//nolint:gochecknoglobals // set via ldflags at build time
|
|
var (
|
|
Appname = "netwatch-server"
|
|
Version string
|
|
)
|
|
|
|
func main() {
|
|
// "netwatch-server check-cidr CIDR" exits 1, with the error, if
|
|
// this server would refuse CIDR in its TRUSTED_PROXIES.
|
|
// bin/entrypoint.sh runs it on each entry it gives nginx.
|
|
if len(os.Args) == 3 && os.Args[1] == "check-cidr" {
|
|
_, err := middleware.ParseTrustedProxies(os.Args[2:])
|
|
if err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
return
|
|
}
|
|
|
|
// "netwatch-server prepare-data-dir DATA_DIR" gets DATA_DIR ready
|
|
// for the netwatch user, or exits 1 with the error; see
|
|
// reportbuf.PrepareDataDir. bin/entrypoint.sh runs it as root
|
|
// before it starts this server as that user.
|
|
if len(os.Args) == 3 && os.Args[1] == "prepare-data-dir" {
|
|
netwatch, err := user.Lookup("netwatch")
|
|
if err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
err = reportbuf.PrepareDataDir("/data", os.Args[2], netwatch)
|
|
if err != nil {
|
|
fmt.Fprintf(os.Stderr, "DATA_DIR '%s': %v\n", os.Args[2], err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
return
|
|
}
|
|
|
|
globals.Appname = Appname
|
|
globals.Version = Version
|
|
|
|
fx.New(
|
|
fx.Provide(
|
|
config.New,
|
|
globals.New,
|
|
handlers.New,
|
|
healthcheck.New,
|
|
logger.New,
|
|
middleware.New,
|
|
reportbuf.New,
|
|
server.New,
|
|
),
|
|
fx.Invoke(func(*server.Server) {}),
|
|
).Run()
|
|
}
|