Merge pull request #3095 from dokku/2823-proxy-env-vars
Migrate env for NGINX_* to PROXY_*
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
linters:
|
||||
shellcheck:
|
||||
shell: bash
|
||||
exclude: SC2034,SC1090
|
||||
exclude: SC2034,SC1090,SC2191
|
||||
golint:
|
||||
|
||||
files:
|
||||
|
||||
@@ -51,7 +51,7 @@ If desired, it is possible to disable vhosts with the domains plugin.
|
||||
dokku domains:disable myapp
|
||||
```
|
||||
|
||||
On subsequent deploys, the nginx virtualhost will be discarded. This is useful when deploying internal-facing services that should not be publicly routeable. As of 0.4.0, nginx will still be configured to proxy your app on some random high port. This allows internal services to maintain the same port between deployments. You may change this port by setting `DOKKU_NGINX_PORT` and/or `DOKKU_NGINX_SSL_PORT` (for services configured to use SSL.)
|
||||
On subsequent deploys, the nginx virtualhost will be discarded. This is useful when deploying internal-facing services that should not be publicly routeable. As of 0.4.0, nginx will still be configured to proxy your app on some random high port. This allows internal services to maintain the same port between deployments. You may change this port by setting `DOKKU_PROXY_PORT` and/or `DOKKU_PROXY_SSL_PORT` (for services configured to use SSL.)
|
||||
|
||||
|
||||
The domains plugin allows you to specify custom domains for applications. This plugin is aware of any ssl certificates that are imported via `certs:add`. Be aware that disabling domains (with `domains:disable`) will override any custom domains.
|
||||
|
||||
@@ -110,8 +110,8 @@ The following list config variables have special meaning and can be set in a var
|
||||
| `DOKKU_DOCKERFILE_ENTRYPOINT` | dockerfile entrypoint | `dokku config:set` | |
|
||||
| `DOKKU_DOCKERFILE_PORTS` | dockerfile ports | `dokku config:set` | |
|
||||
| `DOKKU_DOCKERFILE_START_CMD` | none | `dokku config:set` | |
|
||||
| `DOKKU_NGINX_PORT` | automatically assigned | `dokku config:set` | |
|
||||
| `DOKKU_NGINX_SSL_PORT` | automatically assigned | `dokku config:set` | |
|
||||
| `DOKKU_PROXY_PORT` | automatically assigned | `dokku config:set` | |
|
||||
| `DOKKU_PROXY_SSL_PORT` | automatically assigned | `dokku config:set` | |
|
||||
| `DOKKU_PROXY_PORT_MAP` | automatically assigned | `dokku proxy:ports-add` <br /> `dokku proxy:ports-remove`, `dokku proxy:ports-clear` | |
|
||||
| `DOKKU_SKIP_ALL_CHECKS` | none | `dokku config:set` | |
|
||||
| `DOKKU_SKIP_CLEANUP` | | `/etc/environment` <br /> `~dokku/.dokkurc` <br /> `~dokku/.dokkurc/*` | When a deploy is triggered, if this is set to a non-empty value, then old docker containers and images will not be removed. |
|
||||
|
||||
@@ -30,8 +30,8 @@ Dokku uses a templating library by the name of [sigil](https://github.com/glider
|
||||
{{ .APP_SSL_PATH }} Path to SSL certificate and key
|
||||
{{ .DOKKU_ROOT }} Global Dokku root directory (ex: app dir would be `{{ .DOKKU_ROOT }}/{{ .APP }}`)
|
||||
{{ .DOKKU_APP_LISTENERS }} List of IP:PORT pairs of app containers
|
||||
{{ .NGINX_PORT }} Non-SSL nginx listener port (same as `DOKKU_NGINX_PORT` config var)
|
||||
{{ .NGINX_SSL_PORT }} SSL nginx listener port (same as `DOKKU_NGINX_SSL_PORT` config var)
|
||||
{{ .PROXY_PORT }} Non-SSL nginx listener port (same as `DOKKU_PROXY_PORT` config var)
|
||||
{{ .PROXY_SSL_PORT }} SSL nginx listener port (same as `DOKKU_PROXY_SSL_PORT` config var)
|
||||
{{ .NOSSL_SERVER_NAME }} List of non-SSL VHOSTS
|
||||
{{ .PROXY_PORT_MAP }} List of port mappings (same as `DOKKU_PROXY_PORT_MAP` config var)
|
||||
{{ .PROXY_UPSTREAM_PORTS }} List of configured upstream ports (derived from `DOKKU_PROXY_PORT_MAP` config var)
|
||||
@@ -46,7 +46,7 @@ Dokku uses a templating library by the name of [sigil](https://github.com/glider
|
||||
|
||||
The default nginx.conf template will include everything from your apps `nginx.conf.d/` subdirectory in the main `server {}` block (see above):
|
||||
|
||||
```go
|
||||
```
|
||||
include {{ .DOKKU_ROOT }}/{{ .APP }}/nginx.conf.d/*.conf;
|
||||
```
|
||||
|
||||
|
||||
@@ -129,8 +129,8 @@ If your server runs behind an HTTP/S load balancer, then Nginx will see all requ
|
||||
|
||||
```go
|
||||
server {
|
||||
listen [::]:{{ .NGINX_PORT }};
|
||||
listen {{ .NGINX_PORT }};
|
||||
listen [::]:{{ .PROXY_PORT }};
|
||||
listen {{ .PROXY_PORT }};
|
||||
server_name {{ .NOSSL_SERVER_NAME }};
|
||||
access_log /var/log/nginx/{{ .APP }}-access.log;
|
||||
error_log /var/log/nginx/{{ .APP }}-error.log;
|
||||
|
||||
@@ -88,29 +88,29 @@ configure_nginx_ports() {
|
||||
declare desc="configure nginx listening ports"
|
||||
local APP=$1; verify_app_name "$APP"
|
||||
local RAW_TCP_PORTS="$(get_app_raw_tcp_ports "$APP")"
|
||||
local DOKKU_NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
|
||||
local DOKKU_NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
|
||||
local DOKKU_PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
|
||||
local DOKKU_PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
|
||||
local DOKKU_PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
|
||||
local IS_APP_VHOST_ENABLED="$(is_app_vhost_enabled "$APP")"
|
||||
local UPSTREAM_PORT="5000"
|
||||
|
||||
if [[ -z "$DOKKU_NGINX_PORT" ]] && [[ -z "$RAW_TCP_PORTS" ]]; then
|
||||
if [[ -z "$DOKKU_PROXY_PORT" ]] && [[ -z "$RAW_TCP_PORTS" ]]; then
|
||||
if [[ "$IS_APP_VHOST_ENABLED" == "false" ]]; then
|
||||
dokku_log_info1 "no nginx port set. setting to random open high port"
|
||||
local NGINX_PORT=$(get_available_port)
|
||||
dokku_log_info1 "no proxy port set. setting to random open high port"
|
||||
local PROXY_PORT=$(get_available_port)
|
||||
else
|
||||
local NGINX_PORT=80
|
||||
local PROXY_PORT=80
|
||||
fi
|
||||
config_set --no-restart "$APP" DOKKU_NGINX_PORT="$NGINX_PORT"
|
||||
config_set --no-restart "$APP" DOKKU_PROXY_PORT="$PROXY_PORT"
|
||||
fi
|
||||
if [[ -z "$DOKKU_NGINX_SSL_PORT" ]]; then
|
||||
if [[ -z "$DOKKU_PROXY_SSL_PORT" ]]; then
|
||||
if (is_ssl_enabled "$APP"); then
|
||||
local NGINX_SSL_PORT=443
|
||||
local PROXY_SSL_PORT=443
|
||||
if [[ -z "$RAW_TCP_PORTS" ]] && [[ "$IS_APP_VHOST_ENABLED" == "false" ]]; then
|
||||
dokku_log_info1 "no nginx ssl port set. setting to random open high port"
|
||||
NGINX_SSL_PORT=$(get_available_port)
|
||||
dokku_log_info1 "no proxy ssl port set. setting to random open high port"
|
||||
PROXY_SSL_PORT=$(get_available_port)
|
||||
fi
|
||||
config_set --no-restart "$APP" DOKKU_NGINX_SSL_PORT="$NGINX_SSL_PORT"
|
||||
config_set --no-restart "$APP" DOKKU_PROXY_SSL_PORT="$PROXY_SSL_PORT"
|
||||
fi
|
||||
fi
|
||||
if [[ -z "$DOKKU_PROXY_PORT_MAP" ]]; then
|
||||
@@ -120,13 +120,13 @@ configure_nginx_ports() {
|
||||
local PROXY_PORT_MAP+=" http:${RAW_TCP_PORT}:${RAW_TCP_PORT} "
|
||||
done
|
||||
else
|
||||
local NGINX_PORT=${NGINX_PORT:-$DOKKU_NGINX_PORT}
|
||||
local NGINX_SSL_PORT=${NGINX_SSL_PORT:-$DOKKU_NGINX_SSL_PORT}
|
||||
local PROXY_PORT=${PROXY_PORT:-$DOKKU_PROXY_PORT}
|
||||
local PROXY_SSL_PORT=${PROXY_SSL_PORT:-$DOKKU_PROXY_SSL_PORT}
|
||||
[[ -f "$DOKKU_ROOT/$APP/PORT.web.1" ]] && local UPSTREAM_PORT="$(< "$DOKKU_ROOT/$APP/PORT.web.1")"
|
||||
if [[ -n "$NGINX_PORT" ]] && [[ -n "$NGINX_SSL_PORT" ]]; then
|
||||
local PROXY_PORT_MAP+=" http:${NGINX_PORT}:$UPSTREAM_PORT https:${NGINX_SSL_PORT}:$UPSTREAM_PORT "
|
||||
elif [[ -n "$NGINX_PORT" ]]; then
|
||||
local PROXY_PORT_MAP+=" http:${NGINX_PORT}:$UPSTREAM_PORT "
|
||||
if [[ -n "$PROXY_PORT" ]] && [[ -n "$PROXY_SSL_PORT" ]]; then
|
||||
local PROXY_PORT_MAP+=" http:${PROXY_PORT}:$UPSTREAM_PORT https:${PROXY_SSL_PORT}:$UPSTREAM_PORT "
|
||||
elif [[ -n "$PROXY_PORT" ]]; then
|
||||
local PROXY_PORT_MAP+=" http:${PROXY_PORT}:$UPSTREAM_PORT "
|
||||
fi
|
||||
fi
|
||||
if [[ -n "$PROXY_PORT_MAP" ]]; then
|
||||
@@ -236,8 +236,8 @@ nginx_build_config() {
|
||||
|
||||
# setup nginx listen ports
|
||||
configure_nginx_ports "$APP"
|
||||
local NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
|
||||
local NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
|
||||
local PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
|
||||
local PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
|
||||
local PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
|
||||
|
||||
local PORT_MAP
|
||||
@@ -306,7 +306,9 @@ nginx_build_config() {
|
||||
HTTP2_SUPPORTED="$HTTP2_SUPPORTED"
|
||||
DOKKU_APP_LISTEN_PORT="$DOKKU_APP_LISTEN_PORT" DOKKU_APP_LISTEN_IP="$DOKKU_APP_LISTEN_IP"
|
||||
APP_SSL_PATH="$APP_SSL_PATH" SSL_INUSE="$SSL_INUSE" SSL_SERVER_NAME="$SSL_SERVER_NAME"
|
||||
NGINX_PORT="$NGINX_PORT" NGINX_SSL_PORT="$NGINX_SSL_PORT" RAW_TCP_PORTS="$RAW_TCP_PORTS"
|
||||
# @TODO: Remove this after a few versions
|
||||
NGINX_PORT="$PROXY_PORT" NGINX_SSL_PORT="$PROXY_SSL_PORT"
|
||||
PROXY_PORT="$PROXY_PORT" PROXY_SSL_PORT="$PROXY_SSL_PORT" RAW_TCP_PORTS="$RAW_TCP_PORTS"
|
||||
PROXY_PORT_MAP="$PROXY_PORT_MAP" PROXY_UPSTREAM_PORTS="$PROXY_UPSTREAM_PORTS")
|
||||
|
||||
# execute sigil template processing
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
#!/usr/bin/env bash
|
||||
set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
|
||||
source "$PLUGIN_CORE_AVAILABLE_PATH/common/functions"
|
||||
|
||||
case "$DOKKU_DISTRO" in
|
||||
debian)
|
||||
@@ -73,6 +74,26 @@ cp "${PLUGIN_CORE_AVAILABLE_PATH}/nginx-vhosts/templates/500-error.html" "${DOKK
|
||||
# patch broken nginx 1.8.0 logrotate
|
||||
[[ -f /etc/logrotate.d/nginx ]] && sed -i -e 's/invoke-rc.d/service/g' /etc/logrotate.d/nginx
|
||||
|
||||
# @TODO: Remove this after a few versions
|
||||
dokku_log_info1 "Migrating DOKKU_NGINX env variables. The following variables will be migrated"
|
||||
dokku_log_info2 "DOKKU_NGINX_PORT -> DOKKU_PROXY_PORT"
|
||||
dokku_log_info2 "DOKKU_NGINX_SSL_PORT -> DOKKU_PROXY_SSL_PORT"
|
||||
for app in $(dokku_apps); do
|
||||
nginx_port="$(config_get "$app" DOKKU_NGINX_PORT || true)"
|
||||
nginx_ssl_port="$(config_get "$app" DOKKU_NGINX_SSL_PORT || true)"
|
||||
if [[ -n "$nginx_port" ]]; then
|
||||
dokku_log_info1 "Migrating DOKKU_NGINX_PORT to DOKKU_PROXY_PORT for $app"
|
||||
config_set --no-restart "$app" DOKKU_PROXY_PORT="$nginx_port"
|
||||
config_unset --no-restart "$app" DOKKU_NGINX_PORT
|
||||
fi
|
||||
if [[ -n "$nginx_ssl_port" ]]; then
|
||||
dokku_log_info1 "Migrating DOKKU_NGINX_SSL_PORT to DOKKU_PROXY_SSL_PORT for $app"
|
||||
config_set --no-restart "$app" DOKKU_PROXY_SSL_PORT="$nginx_ssl_port"
|
||||
config_unset --no-restart "$app" DOKKU_NGINX_SSL_PORT
|
||||
fi
|
||||
done
|
||||
dokku_log_info2 "Migration complete"
|
||||
|
||||
case "$DOKKU_DISTRO" in
|
||||
debian)
|
||||
NGINX_INIT="/usr/sbin/invoke-rc.d"
|
||||
|
||||
@@ -9,7 +9,7 @@ nginx_post_certs_remove() {
|
||||
local trigger="nginx_post_certs_remove"
|
||||
local APP="$1"
|
||||
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_NGINX_SSL_PORT
|
||||
config_unset --no-restart "$APP" DOKKU_PROXY_SSL_PORT
|
||||
|
||||
# shellcheck disable=SC2046
|
||||
remove_proxy_ports "$APP" $(filter_app_proxy_ports "$APP" "https" "443")
|
||||
|
||||
@@ -9,15 +9,15 @@ nginx_post_certs_update() {
|
||||
local trigger="nginx_post_certs_update"
|
||||
local APP="$1"
|
||||
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
|
||||
local DOKKU_NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
|
||||
local DOKKU_NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
|
||||
local DOKKU_PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
|
||||
local DOKKU_PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
|
||||
local DOKKU_PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
|
||||
|
||||
if [[ "$DOKKU_NGINX_PORT" == "80" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_NGINX_PORT
|
||||
if [[ "$DOKKU_PROXY_PORT" == "80" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_PROXY_PORT
|
||||
fi
|
||||
if [[ "$DOKKU_NGINX_SSL_PORT" == "443" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_NGINX_SSL_PORT
|
||||
if [[ "$DOKKU_PROXY_SSL_PORT" == "443" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_PROXY_SSL_PORT
|
||||
fi
|
||||
if [[ "$DOKKU_PROXY_PORT_MAP" == *http:80:* ]]; then
|
||||
# shellcheck disable=SC2046
|
||||
|
||||
@@ -9,7 +9,7 @@ nginx_pre_disable_vhost_trigger() {
|
||||
local trigger="nginx_pre_disable_vhost_trigger"
|
||||
local APP="$1"
|
||||
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_NGINX_PORT DOKKU_NGINX_SSL_PORT DOKKU_PROXY_PORT_MAP
|
||||
config_unset --no-restart "$APP" DOKKU_PROXY_PORT DOKKU_PROXY_SSL_PORT DOKKU_PROXY_PORT_MAP
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@ nginx_pre_enable_vhost_trigger() {
|
||||
local trigger="nginx_pre_enable_vhost_trigger"
|
||||
local APP="$1"
|
||||
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
|
||||
config_unset --no-restart "$APP" DOKKU_NGINX_PORT DOKKU_NGINX_SSL_PORT DOKKU_PROXY_PORT_MAP
|
||||
config_unset --no-restart "$APP" DOKKU_PROXY_PORT DOKKU_PROXY_SSL_PORT DOKKU_PROXY_PORT_MAP
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ server {
|
||||
access_log /var/log/nginx/{{ $.APP }}-access.log;
|
||||
error_log /var/log/nginx/{{ $.APP }}-error.log;
|
||||
{{ if (and (eq $listen_port "80") ($.SSL_INUSE)) }}
|
||||
return 301 https://$host:{{ $.NGINX_SSL_PORT }}$request_uri;
|
||||
return 301 https://$host:{{ $.PROXY_SSL_PORT }}$request_uri;
|
||||
{{ else }}
|
||||
location / {
|
||||
|
||||
@@ -69,7 +69,7 @@ server {
|
||||
ssl_prefer_server_ciphers on;
|
||||
|
||||
keepalive_timeout 70;
|
||||
{{ if and (eq $.SPDY_SUPPORTED "true") (ne $.HTTP2_SUPPORTED "true") }}add_header Alternate-Protocol {{ $.NGINX_SSL_PORT }}:npn-spdy/2;{{ end }}
|
||||
{{ if and (eq $.SPDY_SUPPORTED "true") (ne $.HTTP2_SUPPORTED "true") }}add_header Alternate-Protocol {{ $.PROXY_SSL_PORT }}:npn-spdy/2;{{ end }}
|
||||
|
||||
location / {
|
||||
|
||||
|
||||
@@ -277,12 +277,12 @@ server {
|
||||
listen [::]:{{ \$listen_port }};
|
||||
listen {{ \$listen_port }};
|
||||
server_name {{ $.NOSSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN;
|
||||
return 301 https://\$host:{{ $.NGINX_SSL_PORT }}\$request_uri;
|
||||
return 301 https://\$host:{{ $.PROXY_SSL_PORT }}\$request_uri;
|
||||
}
|
||||
{{ else if eq \$scheme "https"}}
|
||||
server {
|
||||
listen [::]:{{ $.NGINX_SSL_PORT }} ssl spdy;
|
||||
listen {{ $.NGINX_SSL_PORT }} ssl spdy;
|
||||
listen [::]:{{ $.PROXY_SSL_PORT }} ssl spdy;
|
||||
listen {{ $.PROXY_SSL_PORT }} ssl spdy;
|
||||
{{ if $.SSL_SERVER_NAME }}server_name {{ $.SSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN; {{ end }}
|
||||
{{ if $.NOSSL_SERVER_NAME }}server_name {{ $.NOSSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN; {{ end }}
|
||||
ssl_certificate {{ $.APP_SSL_PATH }}/server.crt;
|
||||
|
||||
Reference in New Issue
Block a user