Take every setting from PIXA_ variables and PORT (closes #128)
Each config key can now be set by PIXA_ plus the key in upper case
("." written as "_"), and the port by PORT. One list pairs keys with
variables; the typed getters read a present variable, even an empty
one, before the config file, so every existing check covers it, and
errors a variable can reach name both the key and the variable. An
empty string for blocked_networks or trusted_proxies is now an empty
list, as for allowlist_hosts. The image no longer bakes in
config.docker.yml or passes --config, and its HEALTHCHECK probes
${PORT:-8080}; the config file is looked for under /etc/pixa rather
than /etc/pixad, so a file mounted at /etc/pixa/config.yml is still
read.
Model: opus-5-5
This commit is contained in:
+7
-6
@@ -67,16 +67,17 @@ RUN adduser -D -H -s /sbin/nologin pixad && \
|
||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
|
||||
# Copy the image config; signing_key comes from PIXA_SIGNING_KEY.
|
||||
# Mount a file over /etc/pixa/config.yml to override anything else.
|
||||
COPY config.docker.yml /etc/pixa/config.yml
|
||||
|
||||
USER pixad
|
||||
WORKDIR /var/lib/pixa
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
# Shell form so the probe follows PORT; a port set only in a mounted
|
||||
# config file is not seen here.
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD wget --spider -q http://localhost:8080/.well-known/healthcheck.json || exit 1
|
||||
CMD wget --spider -q "http://localhost:${PORT:-8080}/.well-known/healthcheck.json" || exit 1
|
||||
|
||||
ENTRYPOINT ["/usr/local/bin/pixad", "--config", "/etc/pixa/config.yml"]
|
||||
# Settings come from PORT and the PIXA_ environment variables; only
|
||||
# PIXA_SIGNING_KEY is required. A config file mounted at
|
||||
# /etc/pixa/config.yml is optional and is read when present.
|
||||
ENTRYPOINT ["/usr/local/bin/pixad"]
|
||||
|
||||
Reference in New Issue
Block a user