Compare commits

..
27 Commits
Author SHA1 Message Date
b0xxer 9da4f8c7c8 Test of .gitea ignore issue 2025-04-18 06:52:50 -05:00
b0xxer 0aed963891 Delete .gitea/workflows/demo.yml 2025-04-17 18:44:12 -05:00
b0xxer 0deb454490 Update .gitea/workflows/demo.yml 2025-04-17 18:43:54 -05:00
b0xxer a4357bc83d Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Successful in 1m1s
2025-04-17 11:36:18 -05:00
b0xxer e210313554 Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 11s
2025-04-17 11:35:04 -05:00
b0xxer 081331331c Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Successful in 15s
2025-04-17 11:33:04 -05:00
b0xxer 81361d5438 Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Successful in 24s
2025-04-17 10:51:35 -05:00
b0xxer f402af4e04 Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 1s
2025-04-17 09:55:03 -05:00
b0xxer 13b04272d8 Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 9s
2025-04-17 09:53:14 -05:00
b0xxer 261822055b Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Has been cancelled
2025-04-17 09:43:22 -05:00
b0xxer 9e47161130 Update .gitea/workflows/demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Has been cancelled
2025-04-17 09:15:12 -05:00
b0xxer 379631d5d9 Delete .gitea/workflows/test.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 3s
2025-04-17 09:13:28 -05:00
b0xxer a7769c1d2a add alpine test
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 1s
Podman Test / podman-job (push) Has been cancelled
2025-04-17 09:10:40 -05:00
b0xxer e671a350b4 added security-opts
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 1s
2025-04-17 08:32:13 -05:00
b0xxer 45553fdb1e added demo.yml
Gitea Actions Demo / Explore-Gitea-Actions (push) Failing after 1s
2025-04-17 07:43:05 -05:00
b0xxer 7fdefe6741 * Added initial template for postgresql Container 2025-04-16 14:28:27 -05:00
b0xxer 98989b8a68 Added node-red and pgadmin to the apps role 2025-04-16 13:13:49 -05:00
b0xxer 5deb8114ed fixups 2025-04-15 12:01:25 -05:00
b0xxer 122eed02d6 Only set systemd service files if enabled
Delete service files if disabled
added proper mode to files
2025-04-15 11:48:13 -05:00
b0xxer a73c915245 * Modified .env for lnbits to make admin screen on by default and add
user-id-only / create-user
2025-04-11 14:16:56 -05:00
b0xxer f25f1f8297 * Added pid file declaration to start command for clightning
* Added poetry install for lnbits
2025-04-11 07:38:34 -05:00
b0xxer aff55b0335 * Updated gitignore 2025-04-10 06:58:01 -05:00
b0xxer 7443835a05 * Added HealthCmd, HealthInterval, HealthRetries, and HealthStartPeriod
to bitcoin-node-container
2025-04-10 06:42:41 -05:00
b0xxer cdfd6a6fa6 Added TimeoutStopSec=300 to bitcoin-node container 2025-04-10 05:56:49 -05:00
b0xxer fd79eec04b * Added nodered, pgadmin, and postgresql container files 2025-04-09 14:20:48 -05:00
b0xxer d6b1a330c7 * Added virt-install 2025-04-09 12:52:09 -05:00
b0xxer 0a3e693a08 * Fixed caddy Containerfile version error
* Added qemu-kvm, libvirt, cockpit-machines, etc
* Enabled libvirtd service
2025-04-09 12:13:30 -05:00
38 changed files with 869 additions and 16 deletions
View File
+2
View File
@@ -1,2 +1,4 @@
venv
.vscode/settings.json
.vscode/
n0xb0x.code-workspace
+20 -7
View File
@@ -12,7 +12,7 @@ n0xb0x.local
app_list=['bitcoin.yml']
ansible_user=b0xxy
ansible_password=b0xxy
#registry_url=git.boxxy.net/b0xxer/
#registry_url=git.b0xx.org/b0xxer
registry_url=localhost
registry_user=
registry_pass=
@@ -22,25 +22,38 @@ zerotier_network=
[n0xb0x:vars]
hostname=n0xb0x
app_list=['caddy.yml','bitcoin.yml','electrs.yml','clightning.yml','lnbits.yml','rtl.yml', 'docs.yml']
available_apps=['caddy.yml','bitcoin.yml','electrs.yml','clightning.yml','lnbits.yml','rtl.yml', 'docs.yml', 'node-red.yml', 'pgadmin.yml', 'postgres.yml']
ansible_user=n0xb0x
ansible_password=n0xb0x
#registry_url=git.boxxy.net/b0xxer/
#registry_url=git.b0xx.org/b0xxer
registry_url=localhost
registry_user=
registry_pass=
bitcoin_version=26.0
caddy_version=2.7.6
clightning_version=23.11.2
clightning_platform=Fedora-28-amd64
bitcoin_enabled=true
bitcoin_rpcuser=n0xb0x
bitcoin_rpcpassword=8BaOf-luoLM-5zA8V0ozLOtqzZZch2knK9gWIBfafDw
bitcoin_rpcauth=n0xb0x:413f1f82906117464e662853bce33577$80a039d800184a1cffd1de5468b5b2a7442ab1d368a13782e5283e575a9f57b2
caddy_version=2.7.6
caddy_enabled=true
clightning_enabled=true
clightning_version=23.11.2
clightning_platform=Fedora-28-amd64
electrs_enabled=true
electrs_version=0.10.2
rtl_enabled=true
rtl_version=0.15.0
rtl_password=n0xb0x
lnbits_version=0.12.1
lnbits_version=v1.0.0
node-red_version=4.0.9
node-red_enabled=true
pgadmin_enabled=true
pgadmin_email=pgadmin@b0xx.org
pgadmin_password=b0xxer
postgres_version=16.1
postgres_enabled=true
tor_version=1.0
tor_enabled=true
zerotier_network=74a75ebfb84ab0db
#Update wariness - 1 = very reluctant to update, 0 = eager to update
#timezone - which timezone update schedule is in
+1
View File
@@ -0,0 +1 @@
podman build --tag node-red:{{nodered_version}} .
+19
View File
@@ -0,0 +1,19 @@
[
{
"id": "f6f2187d.f17ca8",
"type": "tab",
"label": "Flow 1",
"disabled": false,
"info": ""
},
{
"id": "3cc11d24.ff01a2",
"type": "comment",
"z": "f6f2187d.f17ca8",
"name": "WARNING: please check you have started this container with a volume that is mounted to /data\\n otherwise any flow changes are lost when you redeploy or upgrade the container\\n (e.g. upgrade to a more recent node-red docker image).\\n If you are using named volumes you can ignore this warning.\\n Double click or see info side panel to learn how to start Node-RED in Docker to save your work",
"info": "\nTo start docker with a bind mount volume (-v option), for example:\n\n```\ndocker run -it -p 1880:1880 -v /home/user/node_red_data:/data --name mynodered nodered/node-red\n```\n\nwhere `/home/user/node_red_data` is a directory on your host machine where you want to store your flows.\n\nIf you do not do this then you can experiment and redploy flows, but if you restart or upgrade the container the flows will be disconnected and lost. \n\nThey will still exist in a hidden data volume, which can be recovered using standard docker techniques, but that is much more complex than just starting with a named volume as described above.",
"x": 350,
"y": 80,
"wires": []
}
]
+34
View File
@@ -0,0 +1,34 @@
var http = require('http');
var https = require('https');
var settings = require('/data/settings.js');
var request;
process.env["NODE_TLS_REJECT_UNAUTHORIZED"] = 0;
var options = {
host : "127.0.0.1",
port : settings.uiPort || 1880,
timeout : 4000
};
if (settings.hasOwnProperty("https")) {
request = https.request(options, (res) => {
//console.log(`STATUS: ${res.statusCode}`);
if ((res.statusCode >= 200) && (res.statusCode < 500)) { process.exit(0); }
else { process.exit(1); }
});
}
else {
request = http.request(options, (res) => {
//console.log(`STATUS: ${res.statusCode}`);
if ((res.statusCode >= 200) && (res.statusCode < 500)) { process.exit(0); }
else { process.exit(1); }
});
}
request.on('error', function(err) {
//console.log('ERROR',err);
process.exit(1);
});
request.end();
+37
View File
@@ -0,0 +1,37 @@
{
"name": "node-red-docker",
"version": "4.0.9",
"description": "Low-code programming for event-driven applications",
"homepage": "http://nodered.org",
"license": "Apache-2.0",
"repository": {
"type": "git",
"url": "https://github.com/node-red/node-red-docker.git"
},
"main": "node_modules/node-red/red/red.js",
"scripts": {
"start": "node $NODE_OPTIONS node_modules/node-red/red.js $FLOWS",
"debug": "node --inspect=0.0.0.0:9229 $NODE_OPTIONS node_modules/node-red/red.js $FLOWS",
"debug_brk": "node --inspect=0.0.0.0:9229 --inspect-brk $NODE_OPTIONS node_modules/node-red/red.js $FLOWS"
},
"contributors": [
{
"name": "Dave Conway-Jones"
},
{
"name": "Nick O'Leary"
},
{
"name": "James Thomas"
},
{
"name": "Raymond Mouthaan"
}
],
"dependencies": {
"node-red": "4.0.9"
},
"engines": {
"node": ">=18"
}
}
+1
View File
@@ -0,0 +1 @@
podman run --rm -v nodered:/data:Z -p 1880:1880 --name node-red node-red:latest
+14
View File
@@ -0,0 +1,14 @@
#!/bin/bash
trap stop SIGINT SIGTERM
function stop() {
kill $CHILD_PID
wait $CHILD_PID
}
node $NODE_OPTIONS node_modules/node-red/red.js --userDir /data $FLOWS "${@}" &
CHILD_PID="$!"
wait "${CHILD_PID}"
@@ -0,0 +1,10 @@
#!/bin/bash
set -ex
# Installing Devtools
if [[ ${TAG_SUFFIX} != *"minimal" ]]; then
echo "Installing devtools"
apk add --no-cache --virtual devtools build-base linux-headers udev python3
else
echo "Skip installing devtools"
fi
@@ -0,0 +1,10 @@
#!/bin/bash
set -ex
# Remove native GPIO node if exists
if [[ -d "/usr/src/node-red/node_modules/@node-red/nodes/core/hardware" ]]; then
echo "Removing native GPIO node"
rm -r /usr/src/node-red/node_modules/@node-red/nodes/core/hardware
else
echo "Skip removing native GPIO node"
fi
+16
View File
@@ -80,12 +80,14 @@
ansible.builtin.file:
path: ~/.config/containers/systemd
state: directory
mode: '0640'
tags: [apps,bitcoin]
- name: bitcoin - Copy bitcoin-node.container file
ansible.builtin.template:
src: bitcoin/bitcoin-node.container.j2
dest: ~/containers/bitcoin/bitcoin-node.container
mode: '0640'
notify:
- reload_systemctl
- restart_bitcoin
@@ -97,6 +99,15 @@
dest: ~/.config/containers/systemd/bitcoin-node.container
state: link
force: true
mode: '0640'
when: bitcoin_enabled | default(false)
tags: [apps,bitcoin]
- name: bitcoin - Remove bitcoin-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/bitcoin-node.container
state: absent
when: not (bitcoin_enabled | default(false))
tags: [apps,bitcoin]
- name: bitcoin - Create containers/bitcoin Dir
@@ -104,6 +115,7 @@
path: ~/containers/bitcoin/bin
recurse: true
state: directory
mode: '0640'
notify: rebuild_bitcoin
tags: [apps,bitcoin]
@@ -111,6 +123,7 @@
ansible.builtin.copy:
src: bitcoin/Containerfile
dest: ~/containers/bitcoin/Containerfile
mode: '0640'
notify: rebuild_bitcoin
tags: [apps,bitcoin]
@@ -118,6 +131,7 @@
ansible.builtin.copy:
src: bitcoin/entrypoint.sh
dest: ~/containers/bitcoin/entrypoint.sh
mode: '0700'
notify: rebuild_bitcoin
tags: [apps,bitcoin]
@@ -125,6 +139,7 @@
ansible.builtin.copy:
src: bitcoin/bin/btc_init
dest: ~/containers/bitcoin/bin/btc_init
mode: '0700'
notify: rebuild_bitcoin
tags: [apps,bitcoin]
@@ -132,6 +147,7 @@
ansible.builtin.template:
src: bitcoin/bin/btc_oneshot.j2
dest: ~/containers/bitcoin/bin/btc_oneshot
mode: '0700'
notify: rebuild_bitcoin
tags: [apps,bitcoin]
+11 -1
View File
@@ -12,11 +12,13 @@
ansible.builtin.template:
src: caddy/Containerfile.j2
dest: ~/containers/caddy/Containerfile
mode: '0640'
- name: caddy - Copy caddy-node.container
ansible.builtin.template:
src: caddy/caddy-node.container.j2
dest: ~/containers/caddy/caddy-node.container
mode: '0640'
- name: caddy - Copy build.sh
ansible.builtin.template:
@@ -30,10 +32,18 @@
dest: ~/.config/containers/systemd/caddy-node.container
state: link
force: true
mode: '0640'
when: caddy_enabled | default(false)
- name: caddy - Remove caddy-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/caddy-node.container
state: absent
when: not (caddy_enabled | default(false))
- name: caddy - Copy Caddyfile to ~/vol/caddy
ansible.builtin.template:
src: caddy/Caddyfile.j2
dest: ~/vol/caddy/Caddyfile
mode: '0640'
+14
View File
@@ -5,12 +5,14 @@
ansible.builtin.file:
path: ~/vol/clightning/.clightning
state: directory
mode: '0640'
tags: [apps,clightning]
- name: clightning - Copy clightning-node.container file
ansible.builtin.template:
src: clightning/clightning-node.container.j2
dest: ~/containers/clightning/clightning-node.container
mode: '0640'
notify: reload_systemctl
tags: [apps,clightning]
@@ -20,6 +22,15 @@
dest: ~/.config/containers/systemd/clightning-node.container
state: link
force: true
mode: '0640'
when: clightning_enabled | default(false)
tags: [apps,clightning]
- name: clightning - Remove clightning-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/clightning-node.container
state: absent
when: not (clightning_enabled | default(false))
tags: [apps,clightning]
- name: clightning - Create Containers/bitcoin Dir
@@ -27,6 +38,7 @@
path: ~/containers/clightning
recurse: true
state: directory
mode: '0640'
notify: rebuild_clightning
tags: [apps,clightning]
@@ -34,6 +46,7 @@
ansible.builtin.template:
src: clightning/Containerfile.j2
dest: ~/containers/clightning/Containerfile
mode: '0640'
notify: rebuild_clightning
tags: [apps,clightning]
@@ -41,6 +54,7 @@
ansible.builtin.copy:
src: clightning/entrypoint.sh
dest: ~/containers/clightning/entrypoint.sh
mode: '0700'
tags: [apps,clightning]
- name: clightning - Copy build script
+14
View File
@@ -5,12 +5,14 @@
ansible.builtin.file:
path: ~/vol/.electrs
state: directory
mode: '0640'
tags: [apps,electrs]
- name: electrs - Copy electrs-node.container file
ansible.builtin.template:
src: electrs/electrs-node.container.j2
dest: ~/containers/electrs/electrs-node.container
mode: '0640'
notify: reload_systemctl
tags: [apps,electrs]
@@ -20,6 +22,15 @@
dest: ~/.config/containers/systemd/electrs-node.container
state: link
force: true
mode: '0640'
when: electrs_enabled | default(false)
tags: [apps,electrs]
- name: electrs - Remove electrs-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/electrs-node.container
state: absent
when: not (electrs_enabled | default(false))
tags: [apps,electrs]
- name: electrs - Create Containers/bitcoin Dir
@@ -27,6 +38,7 @@
path: ~/containers/electrs
recurse: true
state: directory
mode: '0640'
notify: rebuild_electrs
tags: [apps,electrs]
@@ -34,6 +46,7 @@
ansible.builtin.template:
src: electrs/Containerfile.j2
dest: ~/containers/electrs/Containerfile
mode: '0640'
notify: rebuild_electrs
tags: [apps,electrs]
@@ -41,6 +54,7 @@
ansible.builtin.template:
src: electrs/electrs-init.sh.j2
dest: ~/containers/electrs/electrs-init.sh
mode: '0700'
tags: [apps,electrs]
- name: electrs - Copy build script
+14 -1
View File
@@ -6,24 +6,36 @@
ansible.builtin.file:
path: ~/containers/lnbits
state: directory
mode: '0640'
tags: [apps,lnbits]
- name: lnbits - Create lnbits vol directory
ansible.builtin.file:
path: ~/vol/lnbits
state: directory
mode: '0640'
tags: [apps,lnbits]
- name: lnbits - Copy Containerfile
ansible.builtin.template:
src: lnbits/Containerfile.j2
dest: ~/containers/lnbits/Containerfile
mode: '0640'
tags: [apps,lnbits]
- name: lnbits - Copy lnbits-node.container
ansible.builtin.template:
src: lnbits/lnbits-node.container.j2
dest: ~/containers/lnbits/lnbits-node.container
mode: '0640'
when: lnbits_enabled | default(false)
tags: [apps,lnbits]
- name: lnbits - Remove lnbits-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/lnbits-node.container
state: absent
when: not (lnbits_enabled | default(false))
tags: [apps,lnbits]
- name: lnbits - Copy build.sh
@@ -36,7 +48,8 @@
- name: lnbits - Copy .env file
ansible.builtin.template:
src: lnbits/.env.j2
dest: ~/containers/lnbits/.env
dest: ~/vol/lnbits/env
mode: '0640'
tags: [apps,lnbits]
+1 -1
View File
@@ -7,7 +7,7 @@
ansible.builtin.include_tasks:
file: "{{ item }}"
with_items:
- "{{ app_list }}"
- "{{ available_apps }}"
tags:
- apps
+97
View File
@@ -0,0 +1,97 @@
- name: node-red - Create containers/node-red dir
ansible.builtin.file:
path: ~/containers/node-red
state: directory
mode: '0750'
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Create ~/vol/node-red dir
ansible.builtin.file:
path: ~/vol/node-red
state: directory
mode: '0750'
tags: [apps,node-red]
- name: node-red - Copy package.json
ansible.builtin.file:
src: node-red/package.json
dest: ~/containers/node-red/package.json
mode: '0640'
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Copy flows.json
ansible.builtin.file:
src: node-red/flows.json
dest: ~/containers/node-red/flows.json
mode: '0640'
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Copy healthcheck.js
ansible.builtin.file:
src: node-red/healthcheck.js
dest: ~/containers/node-red/healthcheck.js
mode: '0640'
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Copy run.sh
ansible.builtin.file:
src: node-red/run.sh
dest: ~/containers/node-red/run.sh
mode: '0640'
tags: [apps,node-red]
- name: node-red - Copy scripts directory and files
ansible.builtin.copy:
src: node-red/scripts
dest: ~/containers/node-red/scripts
mode: '0750'
recursive: true
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Copy Containerfile
ansible.builtin.template:
src: nodered/Containerfile.j2
dest: ~/containers/node-red/Containerfile
mode: '0640'
notify: reload_systemctl
tags: [apps,node-red]
- name: node-red - Copy nodered-node.container
ansible.builtin.template:
src: nodered/node-red-node.container.j2
dest: ~/containers/node-red/nodered-node.container
mode: '0640'
notify: reload_systemctl
tags: [apps,node-red]
- name: node-red - Copy build.sh
ansible.builtin.template:
src: node-red/build.sh.j2
dest: ~/containers/node-red/build.sh
mode: "0700"
notify: rebuild_node-red
tags: [apps,node-red]
- name: node-red - Link node-red-node to .config/containers/systemd
ansible.builtin.file:
src: ~/containers/node-red/node-red-node.container
dest: ~/.config/containers/systemd/node-red-node.container
state: link
force: true
mode: '0640'
when: node-red_enabled | default(false)
notify: reload_systemctl
tags: [apps,node-red]
- name: node-red - Remove node-red-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/node-red-node.container
state: absent
when: not (node-red_enabled | default(false))
notify: reload_systemctl
tags: [apps,node-red]
+14 -1
View File
@@ -12,6 +12,7 @@
path: ~/containers/rtl
recurse: true
state: directory
mode: '0640'
notify: rebuild_rtl
tags: [apps,rtl]
@@ -19,6 +20,7 @@
ansible.builtin.template:
src: rtl/Containerfile.j2
dest: ~/containers/rtl/Containerfile
mode: '0640'
notify: rebuild_rtl
tags: [apps,rtl]
@@ -46,6 +48,7 @@
ansible.builtin.template:
src: rtl/rtl-node.container.j2
dest: ~/containers/rtl/rtl-node.container
mode: '0640'
notify: reload_systemctl
tags: [apps,rtl]
@@ -55,13 +58,23 @@
dest: ~/.config/containers/systemd/rtl-node.container
state: link
force: true
mode: '0640'
when: rtl_enabled | default(false)
notify: reload_systemctl
tags: [apps,rtl]
- name: rtl - Remove rtl-node.container if disabled
ansible.builtin.file:
path: ~/.config/containers/systemd/rtl-node.container
state: absent
when: not (rtl_enabled | default(false))
tags: [apps,rtl]
- name: rtl - Copy RTL-Config file
- name: rtl - Copy RTL-Config file
ansible.builtin.template:
src: rtl/RTL-Config.json.j2
dest: ~/vol/rtl/RTL-Config.json
mode: '0640'
notify: reload_systemctl
tags: [apps,rtl]
@@ -16,6 +16,11 @@ Volume=/home/{{ansible_user}}/vol/bitcoin/.bitcoin:/bitcoin/.bitcoin:Z
Restart=always
# Extend Timeout to allow time to pull the image
TimeoutStartSec=900
TimeoutStopSec=300
HealthCmd=/bin/sh -c "bitcoin-cli getblockchaininfo || exit 1"
HealthInterval=180s
HealthRetries=5
HealthStartPeriod=1000s
# ExecStartPre flag and other systemd commands can go here, see systemd.unit(5) man page.
# ExecStartPre=/usr/share/mincontainer/setup.sh
+2 -2
View File
@@ -6,8 +6,8 @@ WORKDIR /app
RUN microdnf update -y \
&& microdnf install -y wget tar gzip nss-tools \
&& wget https://github.com/caddyserver/caddy/releases/download/v2.7.6/caddy_${VERSION}_linux_amd64.tar.gz \
&& wget https://github.com/caddyserver/caddy/releases/download/v2.7.6/caddy_${VERSION}_checksums.txt \
&& wget https://github.com/caddyserver/caddy/releases/download/v${VERSION}/caddy_${VERSION}_linux_amd64.tar.gz \
&& wget https://github.com/caddyserver/caddy/releases/download/v${VERSION}/caddy_${VERSION}_checksums.txt \
&& sha512sum --ignore-missing --check caddy_${VERSION}_checksums.txt \
&& tar xf caddy_${VERSION}_linux_amd64.tar.gz \
&& rm -f caddy_${VERSION}_linux.amd64.tar.gz LICENSE README.md caddy_${VERSION}_checksums.txt \
@@ -4,7 +4,7 @@ Description=Core Lightning Server
[Container]
Image={{ registry_url }}/clightning:{{ clightning_version }}
PodmanArgs=--pod bitcoin-pod
Exec=--bitcoin-rpcuser={{bitcoin_rpcuser}} --bitcoin-rpcpassword={{bitcoin_rpcpassword}} --clnrest-port=3001 --clnrest-host=0.0.0.0 --clnrest-certs=/root/.lightning
Exec=--pid-file=/root/.lightning/lightning.pid --bitcoin-rpcuser={{bitcoin_rpcuser}} --bitcoin-rpcpassword={{bitcoin_rpcpassword}} --clnrest-port=3001 --clnrest-host=0.0.0.0 --clnrest-certs=/root/.lightning
# Use volume
Volume=/home/{{ansible_user}}/vol/bitcoin/.bitcoin:/data/.bitcoin:ro,Z
+6 -1
View File
@@ -10,7 +10,7 @@
# The rest of the settings will be stored in your database and you will be able to change them
# only through the Admin UI.
# Disable this to make LNbits use this config file again.
LNBITS_ADMIN_UI=false
LNBITS_ADMIN_UI=true
# Change theme
LNBITS_SITE_TITLE="LNbits"
@@ -228,3 +228,8 @@ LOG_RETENTION="3 months"
# for database cleanup commands
# CLEANUP_WALLETS_DAYS=90
#
# addins for USER_MANAGER user-id-only auth
LNBITS_USER_MANAGER_AUTH_METHOD=user-id-only
LNBITS_USER_MANAGER_AUTO_CREATE_USER=1
LNBITS_USER_MANAGER_AUTO_CREATE_WALLET=1
+1 -1
View File
@@ -35,4 +35,4 @@ ENV LNBITS_HOST="0.0.0.0"
EXPOSE $LNBITS_PORT
CMD ["sh", "-c", "poetry run lnbits --port $LNBITS_PORT --host $LNBITS_HOST"]
CMD ["sh", "-c", "poetry install && poetry run lnbits --port $LNBITS_PORT --host $LNBITS_HOST"]
@@ -10,6 +10,7 @@ PodmanArgs=--pod bitcoin-pod
# Use volume
Volume=/home/n0xb0x/vol/clightning/.lightning:/.lightning:Z
Volume=/home/n0xb0x/vol/lnbits/:/app/data:Z
Volume=/home/n0xb0x/vol/lnbits/env:/app/.env:Z
[Service]
# Restart service when sleep finishes
@@ -0,0 +1,104 @@
FROM docker.io/almalinux/9-base:latest AS base
ARG NODE_VERSION=20
ARG NODE_RED_VERSION={{ nodered_version }}
# Copy scripts
COPY scripts/*.sh /tmp/
COPY healthcheck.js /
# Install tools, create Node-RED app and data dir, add user and set rights
RUN set -ex && \
dnf update -y && dnf install -y epel-release \
&& dnf install -y --allowerasing bash tzdata curl nano wget git openssl ca-certificates iputils \
&& mkdir -p /usr/src/node-red /data \
&& dnf module -y enable nodejs:${NODE_VERSION} \
&& dnf install -y nodejs \
&& dnf clean all \
## && deluser --remove-home node \
# adduser --home /usr/src/node-red --disabled-password --no-create-home node-red --uid 1000 && \
&& useradd --home-dir /usr/src/node-red --uid 1000 node-red \
&& chown -R node-red:root /data && chmod -R g+rwX /data \
&& chown -R node-red:root /usr/src/node-red && chmod -R g+rwX /usr/src/node-red
# chown -R node-red:node-red /data && \
# chown -R node-red:node-red /usr/src/node-red
# Set work directory
WORKDIR /usr/src/node-red
# Setup SSH known_hosts file
#COPY known_hosts.sh .
#RUN ./known_hosts.sh /etc/ssh/ssh_known_hosts && rm /usr/src/node-red/known_hosts.sh
#RUN echo "PubkeyAcceptedKeyTypes +ssh-rsa" >> /etc/ssh/ssh_config
# package.json contains Node-RED NPM module and node dependencies
COPY package.json .
COPY flows.json /data
COPY scripts/entrypoint.sh .
RUN chmod u+x ./entrypoint.sh
#### Stage BUILD #######################################################################################################
FROM base AS build
# Install Build tools
RUN dnf update -y && dnf install -y epel-release python \
&& dnf clean all \
&& rm -rf /var/cache/* /var/log* /tmp/*
RUN npm install --unsafe-perm --no-update-notifier --no-fund --only=production && \
npm uninstall node-red-node-gpio && \
cp -R node_modules prod_node_modules
#### Stage RELEASE #####################################################################################################
FROM base AS release
ARG BUILD_DATE
ARG BUILD_VERSION
ARG BUILD_REF
ARG NODE_RED_VERSION
ARG ARCH
ARG TAG_SUFFIX=default
LABEL org.label-schema.build-date=${BUILD_DATE} \
org.label-schema.docker.dockerfile="nodered/Containerfile" \
org.label-schema.license="Apache-2.0" \
org.label-schema.name="Node-RED" \
org.label-schema.version=${BUILD_VERSION} \
org.label-schema.description="Low-code programming for event-driven applications." \
org.label-schema.url="https://nodered.org" \
org.label-schema.vcs-ref=${BUILD_REF} \
org.label-schema.vcs-type="Git" \
org.label-schema.vcs-url="https://github.com/node-red/node-red-docker" \
org.opencontainers.image.source="https://github.com/node-red/node-red-docker" \
org.label-schema.arch=${ARCH} \
authors="Dave Conway-Jones, Nick O'Leary, James Thomas, Raymond Mouthaan"
COPY --from=build /usr/src/node-red/prod_node_modules ./node_modules
# Chown, install devtools & Clean up
RUN chown -R node-red:root /usr/src/node-red \
&& dnf update -y && dnf install -y python-devel python3 \
&& dnf groupinstall -y "Development Tools" \
&& rm -r /tmp/*
RUN npm config set cache /data/.npm --global
USER node-red
# Env variables
ENV NODE_RED_VERSION=$NODE_RED_VERSION \
NODE_PATH=/usr/src/node-red/node_modules:/data/node_modules \
PATH=/usr/src/node-red/node_modules/.bin:${PATH} \
FLOWS=flows.json
# ENV NODE_RED_ENABLE_SAFE_MODE=true # Uncomment to enable safe start mode (flows not running)
# ENV NODE_RED_ENABLE_PROJECTS=true # Uncomment to enable projects option
# Expose the listening port of node-red
EXPOSE 1880
# Add a healthcheck (default every 30 secs)
HEALTHCHECK CMD node /healthcheck.js
ENTRYPOINT ["./entrypoint.sh"]
@@ -0,0 +1 @@
podman build --tag node-red:{{node-red_version}} .
@@ -0,0 +1,16 @@
[Unit]
Description=Node-Red Container
After=network-online.target
[Container]
#Image=docker.io/nodered/node-red:{{ nodered_version }}
Image={{podman_registry}}/node-red:{{ nodered_version }}
ContainerName=node-red
Volume=node-red:/data:Z
PublishPort=0.0.0.0:1880:1880
[Service]
Restart=Always
[Install]
WantedBy=multi-user.target
@@ -0,0 +1,33 @@
FROM docker.io/almalinux/9-init:latest
COPY entrypoint.sh entrypoint.sh
RUN dnf install -y epel-release \
&& dnf update \
&& dnf install -y https://ftp.postgresql.org/pub/pgadmin/pgadmin4/yum/pgadmin4-redhat-repo-2-1.noarch.rpm \
&& dnf install -y pgadmin4-web policycoreutils-python-utils \
&& dnf clean all \
&& rm -rf /var/cache/* /tmp/* \
&& mkdir -p /var/log/pgadmin /var/lib/pgadmin \
&& PGADMIN_SETUP_EMAIL=pgadmin@b0xx.org PGADMIN_SETUP_PASSWORD=b0xx /usr/pgadmin4/venv/bin/python3 /usr/pgadmin4/web/setup.py setup-db \
&& chown -R apache:apache /var/log/pgadmin \
&& chown -R apache:apache /var/lib/pgadmin \
&& ln -s /usr/lib/systemd/system/httpd.service /etc/systemd/system/multi-user.target.wants/httpd.service
# && chown apache: /var/log/pgadmin /var/lib/pgadmin -R
# && systemctl enable --now httpd
# && sudo AUTOMATED=1 PGADMIN_SETUP_EMAIL={{pgadmin_email}} PGADMIN_SETUP_PASSWORD={{pagadmin_password}} /usr/pgadmin4/bin/setup-web.sh
#CMD ["httpd", "-D", "FOREGROUND"]
#CMD ["/entrypoint.sh"]
EXPOSE 80
CMD ["/usr/sbin/init"]
@@ -0,0 +1,33 @@
FROM docker.io/almalinux/9-init:latest
COPY entrypoint.sh entrypoint.sh
RUN dnf install -y epel-release \
&& dnf update \
&& dnf install -y https://ftp.postgresql.org/pub/pgadmin/pgadmin4/yum/pgadmin4-redhat-repo-2-1.noarch.rpm \
&& dnf install -y pgadmin4-web policycoreutils-python-utils \
&& dnf clean all \
&& rm -rf /var/cache/* /tmp/* \
&& mkdir -p /var/log/pgadmin /var/lib/pgadmin \
&& PGADMIN_SETUP_EMAIL={{pgadmin_email}} PGADMIN_SETUP_PASSWORD={{pgadmin_password}} /usr/pgadmin4/venv/bin/python3 /usr/pgadmin4/web/setup.py setup-db \
&& chown -R apache:apache /var/log/pgadmin \
&& chown -R apache:apache /var/lib/pgadmin \
&& ln -s /usr/lib/systemd/system/httpd.service /etc/systemd/system/multi-user.target.wants/httpd.service
# && chown apache: /var/log/pgadmin /var/lib/pgadmin -R
# && systemctl enable --now httpd
# && sudo AUTOMATED=1 PGADMIN_SETUP_EMAIL={{pgadmin_email}} PGADMIN_SETUP_PASSWORD={{pagadmin_password}} /usr/pgadmin4/bin/setup-web.sh
#CMD ["httpd", "-D", "FOREGROUND"]
#CMD ["/entrypoint.sh"]
EXPOSE 80
CMD ["/usr/sbin/init"]
+192
View File
@@ -0,0 +1,192 @@
#!/usr/bin/env bash
# Fixup the passwd file, in case we're on OpenShift
if ! whoami > /dev/null 2>&1; then
if [ "$(id -u)" -ne 5050 ]; then
if [ -w /etc/passwd ]; then
echo "${USER_NAME:-pgadminr}:x:$(id -u):0:${USER_NAME:-pgadminr} user:${HOME}:/sbin/nologin" >> /etc/passwd
fi
fi
fi
# usage: file_env VAR [DEFAULT] ie: file_env 'XYZ_DB_PASSWORD' 'example'
# (will allow for "$XYZ_DB_PASSWORD_FILE" to fill in the value of
# "$XYZ_DB_PASSWORD" from a file, for Docker's secrets feature)
function file_env() {
local var="$1"
local fileVar="${var}_FILE"
local def="${2:-}"
if [ "${!var:-}" ] && [ "${!fileVar:-}" ]; then
printf >&2 'error: both %s and %s are set (but are exclusive)\n' "$var" "$fileVar"
exit 1
fi
local val="$def"
if [ "${!var:-}" ]; then
val="${!var}"
elif [ "${!fileVar:-}" ]; then
val="$(< "${!fileVar}")"
fi
export "$var"="$val"
unset "$fileVar"
}
# Set values for config variables that can be passed using secrets
if [ -n "${PGADMIN_CONFIG_CONFIG_DATABASE_URI_FILE}" ]; then
file_env PGADMIN_CONFIG_CONFIG_DATABASE_URI
fi
file_env PGADMIN_DEFAULT_PASSWORD
# TO enable custom path for config_distro, pass config distro path via environment variable.
export CONFIG_DISTRO_FILE_PATH="${PGADMIN_CUSTOM_CONFIG_DISTRO_FILE:-/pgadmin4/config_distro.py}"
# Populate config_distro.py. This has some default config, as well as anything
# provided by the user through the PGADMIN_CONFIG_* environment variables.
# Only update the file on first launch. The empty file is created only in default path during the
# container build so it can have the required ownership.
if [ ! -e "${CONFIG_DISTRO_FILE_PATH}" ] || [ "$(wc -m "${CONFIG_DISTRO_FILE_PATH}" 2>/dev/null | awk '{ print $1 }')" = "0" ]; then
cat << EOF > "${CONFIG_DISTRO_FILE_PATH}"
CA_FILE = '/etc/ssl/certs/ca-certificates.crt'
LOG_FILE = '/dev/null'
HELP_PATH = '../../docs'
DEFAULT_BINARY_PATHS = {
'pg': '/usr/local/pgsql-17',
'pg-17': '/usr/local/pgsql-17',
'pg-16': '/usr/local/pgsql-16',
'pg-15': '/usr/local/pgsql-15',
'pg-14': '/usr/local/pgsql-14',
'pg-13': '/usr/local/pgsql-13'
}
EOF
# This is a bit kludgy, but necessary as the container uses BusyBox/ash as
# it's shell and not bash which would allow a much cleaner implementation
for var in $(env | grep "^PGADMIN_CONFIG_" | cut -d "=" -f 1); do
# shellcheck disable=SC2086
# shellcheck disable=SC2046
echo ${var#PGADMIN_CONFIG_} = $(eval "echo \$$var") >> "${CONFIG_DISTRO_FILE_PATH}"
done
fi
# Check whether the external configuration database exists if it is being used.
external_config_db_exists="False"
if [ -n "${PGADMIN_CONFIG_CONFIG_DATABASE_URI}" ]; then
external_config_db_exists=$(cd /pgadmin4/pgadmin/utils && /venv/bin/python3 -c "from check_external_config_db import check_external_config_db; val = check_external_config_db("${PGADMIN_CONFIG_CONFIG_DATABASE_URI}"); print(val)")
fi
# DRY of the code to load the PGADMIN_SERVER_JSON_FILE
function load_server_json_file() {
export PGADMIN_SERVER_JSON_FILE="${PGADMIN_SERVER_JSON_FILE:-/pgadmin4/servers.json}"
EXTRA_ARGS=""
if [ "${PGADMIN_REPLACE_SERVERS_ON_STARTUP}" = "True" ]; then
EXTRA_ARGS="--replace"
fi
if [ -f "${PGADMIN_SERVER_JSON_FILE}" ]; then
# When running in Desktop mode, no user is created
# so we have to import servers anonymously
if [ "${PGADMIN_CONFIG_SERVER_MODE}" = "False" ]; then
/venv/bin/python3 /pgadmin4/setup.py load-servers "${PGADMIN_SERVER_JSON_FILE}" ${EXTRA_ARGS}
else
/venv/bin/python3 /pgadmin4/setup.py load-servers "${PGADMIN_SERVER_JSON_FILE}" --user "${PGADMIN_DEFAULT_EMAIL}" ${EXTRA_ARGS}
fi
fi
}
if [ ! -f /var/lib/pgadmin/pgadmin4.db ] && [ "${external_config_db_exists}" = "False" ]; then
if [ -z "${PGADMIN_DEFAULT_EMAIL}" ] || { [ -z "${PGADMIN_DEFAULT_PASSWORD}" ] && [ -z "${PGADMIN_DEFAULT_PASSWORD_FILE}" ]; }; then
echo 'You need to define the PGADMIN_DEFAULT_EMAIL and PGADMIN_DEFAULT_PASSWORD or PGADMIN_DEFAULT_PASSWORD_FILE environment variables.'
exit 1
fi
# Validate PGADMIN_DEFAULT_EMAIL
CHECK_EMAIL_DELIVERABILITY="False"
if [ -n "${PGADMIN_CONFIG_CHECK_EMAIL_DELIVERABILITY}" ]; then
CHECK_EMAIL_DELIVERABILITY=${PGADMIN_CONFIG_CHECK_EMAIL_DELIVERABILITY}
fi
ALLOW_SPECIAL_EMAIL_DOMAINS="[]"
if [ -n "${PGADMIN_CONFIG_ALLOW_SPECIAL_EMAIL_DOMAINS}" ]; then
ALLOW_SPECIAL_EMAIL_DOMAINS=${PGADMIN_CONFIG_ALLOW_SPECIAL_EMAIL_DOMAINS}
fi
GLOBALLY_DELIVERABLE="True"
if [ -n "${PGADMIN_CONFIG_GLOBALLY_DELIVERABLE}" ]; then
GLOBALLY_DELIVERABLE=${PGADMIN_CONFIG_GLOBALLY_DELIVERABLE}
fi
email_config="{'CHECK_EMAIL_DELIVERABILITY': ${CHECK_EMAIL_DELIVERABILITY}, 'ALLOW_SPECIAL_EMAIL_DOMAINS': ${ALLOW_SPECIAL_EMAIL_DOMAINS}, 'GLOBALLY_DELIVERABLE': ${GLOBALLY_DELIVERABLE}}"
echo "email config is ${email_config}"
is_valid_email=$(cd /pgadmin4/pgadmin/utils && /venv/bin/python3 -c "from validation_utils import validate_email; val = validate_email('${PGADMIN_DEFAULT_EMAIL}', ${email_config}); print(val)")
if echo "${is_valid_email}" | grep "False" > /dev/null; then
echo "'${PGADMIN_DEFAULT_EMAIL}' does not appear to be a valid email address. Please reset the PGADMIN_DEFAULT_EMAIL environment variable and try again."
echo "Validation output: ${is_valid_email}"
exit 1
fi
# Switch back to root directory for further process
cd /pgadmin4
# Set the default username and password in a
# backwards compatible way
export PGADMIN_SETUP_EMAIL="${PGADMIN_DEFAULT_EMAIL}"
export PGADMIN_SETUP_PASSWORD="${PGADMIN_DEFAULT_PASSWORD}"
# Initialize DB before starting Gunicorn
# Importing pgadmin4 (from this script) is enough
/venv/bin/python3 run_pgadmin.py
export PGADMIN_PREFERENCES_JSON_FILE="${PGADMIN_PREFERENCES_JSON_FILE:-/pgadmin4/preferences.json}"
# Pre-load any required servers
load_server_json_file
# Pre-load any required preferences
if [ -f "${PGADMIN_PREFERENCES_JSON_FILE}" ]; then
if [ "${PGADMIN_CONFIG_SERVER_MODE}" = "False" ]; then
DESKTOP_USER=$(cd /pgadmin4 && /venv/bin/python3 -c 'import config; print(config.DESKTOP_USER)')
/venv/bin/python3 /pgadmin4/setup.py set-prefs "${DESKTOP_USER}" --input-file "${PGADMIN_PREFERENCES_JSON_FILE}"
else
/venv/bin/python3 /pgadmin4/setup.py set-prefs "${PGADMIN_DEFAULT_EMAIL}" --input-file "${PGADMIN_PREFERENCES_JSON_FILE}"
fi
fi
# Copy the pgpass file passed using secrets
if [ -f "${PGPASS_FILE}" ]; then
if [ "${PGADMIN_CONFIG_SERVER_MODE}" = "False" ]; then
cp ${PGPASS_FILE} /var/lib/pgadmin/.pgpass
chmod 600 /var/lib/pgadmin/.pgpass
else
PGADMIN_USER_CONFIG_DIR=$(echo "${PGADMIN_DEFAULT_EMAIL}" | sed 's/@/_/g')
mkdir -p /var/lib/pgadmin/storage/${PGADMIN_USER_CONFIG_DIR}
cp ${PGPASS_FILE} /var/lib/pgadmin/storage/${PGADMIN_USER_CONFIG_DIR}/.pgpass
chmod 600 /var/lib/pgadmin/storage/${PGADMIN_USER_CONFIG_DIR}/.pgpass
fi
fi
# If already initialised and PGADMIN_REPLACE_SERVERS_ON_STARTUP is set to true, then load the server json file.
elif [ "${PGADMIN_REPLACE_SERVERS_ON_STARTUP}" = "True" ]; then
load_server_json_file
fi
# Start Postfix to handle password resets etc.
if [ -z "${PGADMIN_DISABLE_POSTFIX}" ]; then
sudo /usr/sbin/postfix start
fi
# Get the session timeout from the pgAdmin config. We'll use this (in seconds)
# to define the Gunicorn worker timeout
TIMEOUT=$(cd /pgadmin4 && /venv/bin/python3 -c 'import config; print(config.SESSION_EXPIRATION_TIME * 60 * 60 * 24)')
# NOTE: currently pgadmin can run only with 1 worker due to sessions implementation
# Using --threads to have multi-threaded single-process worker
if [ -n "${PGADMIN_ENABLE_SOCK}" ]; then
BIND_ADDRESS="unix:/run/pgadmin/pgadmin.sock"
else
if [ -n "${PGADMIN_ENABLE_TLS}" ]; then
BIND_ADDRESS="${PGADMIN_LISTEN_ADDRESS:-[::]}:${PGADMIN_LISTEN_PORT:-443}"
else
BIND_ADDRESS="${PGADMIN_LISTEN_ADDRESS:-[::]}:${PGADMIN_LISTEN_PORT:-80}"
fi
fi
if [ -n "${PGADMIN_ENABLE_TLS}" ]; then
exec /venv/bin/gunicorn --limit-request-line "${GUNICORN_LIMIT_REQUEST_LINE:-8190}" --timeout "${TIMEOUT}" --bind "${BIND_ADDRESS}" -w 1 --threads "${GUNICORN_THREADS:-25}" --access-logfile "${GUNICORN_ACCESS_LOGFILE:--}" --keyfile /certs/server.key --certfile /certs/server.cert -c gunicorn_config.py run_pgadmin:app
else
exec /venv/bin/gunicorn --limit-request-line "${GUNICORN_LIMIT_REQUEST_LINE:-8190}" --timeout "${TIMEOUT}" --bind "${BIND_ADDRESS}" -w 1 --threads "${GUNICORN_THREADS:-25}" --access-logfile "${GUNICORN_ACCESS_LOGFILE:--}" -c gunicorn_config.py run_pgadmin:app
fi
@@ -0,0 +1,17 @@
[Unit]
Description=PGAdmin Database Tool
After=network-online.target
[Container]
Image=docker.io/dpage/pgadmin4:8
ContainerName=pgadmin
Volume=pgadmin:/var/lib/pgadmin:Z
PublishPort=0.0.0.0:5050:80
Environment=PGADMIN_DEFAULT_PASSWORD=monarc
Environment=PGADMIN_DEFAULT_EMAIL=admin@monarc.systems
[Service]
Restart=always
[Install]
WantedBy=multi-user.target
@@ -0,0 +1,61 @@
###############################################################################
#
# IMPORTANT:
#
# If runtime or build time dependencies are changed in this file, the committer
# *must* ensure the DEB and RPM package maintainers are informed as soon as
# possible.
#
###############################################################################
Flask==3.0.*; python_version <= '3.8'
Flask==3.1.*; python_version >= '3.9'
Flask-Login==0.*
Flask-Mail==0.*
Flask-Migrate==4.*
Flask-SQLAlchemy==3.1.*
Flask-WTF==1.2.*
Flask-Compress==1.*
Flask-Paranoid==0.*
Flask-Babel==4.0.*
Flask-Security-Too==5.5.*; python_version >= '3.10'
Flask-Security-Too==5.4.*; python_version <= '3.9'
Flask-SocketIO==5.5.*
WTForms==3.2.*; python_version >= '3.10'
WTForms==3.1.*; python_version <= '3.9'
passlib==1.*
pytz==2024.*; python_version <= '3.8'
pytz==2025.*; python_version >= '3.9'
speaklater3==1.*
sqlparse==0.*
psutil==6.1.*
psycopg[c]==3.2.4
python-dateutil==2.*
SQLAlchemy==2.*
bcrypt==4.2.*
cryptography==44.0.*
sshtunnel==0.*
ldap3==2.*
gssapi==1.9.*
user-agents==2.2.0
pywinpty==2.0.*; sys_platform=="win32"
Authlib==1.3.*; python_version <= '3.8'
Authlib==1.4.*; python_version >= '3.9'
pyotp==2.*
qrcode==7.*; python_version <= '3.8'
qrcode[pil]==8.*; python_version >= '3.9'
boto3==1.36.*
urllib3==1.26.*
azure-mgmt-rdbms==10.1.0
azure-mgmt-resource==23.2.0
azure-mgmt-subscription==3.1.1
azure-identity==1.19.0
google-api-python-client==2.*
google-auth-oauthlib==1.2.1
keyring==25.*
Werkzeug==3.0.*; python_version <= '3.8'
Werkzeug==3.1.*; python_version >= '3.9'
typer[all]==0.15.*
setuptools==75.*; python_version >= '3.12'
jsonformatter~=0.3.4
libgravatar==1.0.*
@@ -0,0 +1,24 @@
FROM almalinux:9-base
# Install PostgreSQL 16 using built-in module
RUN dnf -y update && \
dnf -y module enable postgresql:{{postsgresql_version}} && \
dnf -y install postgresql-server && \
dnf clean all
# Create directory structure without initializing
RUN mkdir -p /var/lib/pgsql/data && \
chown -R postgres:postgres /var/lib/pgsql && \
chmod 700 /var/lib/pgsql/data
# Add entrypoint script
COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
USER postgres
ENV PGDATA=/var/lib/pgsql/data
EXPOSE 5432
ENTRYPOINT ["/entrypoint.sh"]
CMD ["postgres", "-D", "/var/lib/pgsql/data"]
@@ -0,0 +1,11 @@
#!/bin/bash
set -e
# Initialize only if data directory is empty
if [ -z "$(ls -A $PGDATA)" ]; then
echo "Initializing PostgreSQL database..."
/usr/bin/postgresql-setup --initdb
fi
exec "$@"
@@ -0,0 +1,17 @@
[Unit]
Description=PostgreSQL 16 Container
[Container]
Image=docker.io/library/postgres:16
ContainerName=postgresql
Environment=POSTGRES_USER=monarc
Environment=POSTGRES_PASSWORD=monarc
Environment=POSTGRES_DB=novusdb
Volume=postgresql:/var/lib/postgresql/data
PublishPort=0.0.0.0:5432:5432
[Service]
Restart=always
[Install]
WantedBy=multi-user.target default.target
+9
View File
@@ -70,6 +70,15 @@
state: started
enabled: true
tags: config
- name: Enable libvirtd Service
become: true
become_method: sudo
ansible.builtin.systemd_service:
name: libvirtd
state: started
enabled: true
tags: config
- name: Enable mdns in Firewall
become: true
+6
View File
@@ -41,9 +41,15 @@
- cockpit-ostree
- cockpit-podman
- cockpit-storaged
- cockpit-machines
- zerotier-one
- python3-pip
- smartmontools
- qemu-kvm
- qemu-system-x86
- libvirt-daemon-driver-qemu
- libvirt-client
- virt-install
tags: install
- name: Install local tools