Merge pull request #3095 from dokku/2823-proxy-env-vars

Migrate env for NGINX_* to PROXY_*
This commit is contained in:
Jose Diaz-Gonzalez
2018-04-03 10:27:09 -04:00
committed by GitHub
13 changed files with 67 additions and 44 deletions

View File

@@ -1,7 +1,7 @@
linters:
shellcheck:
shell: bash
exclude: SC2034,SC1090
exclude: SC2034,SC1090,SC2191
golint:
files:

View File

@@ -51,7 +51,7 @@ If desired, it is possible to disable vhosts with the domains plugin.
dokku domains:disable myapp
```
On subsequent deploys, the nginx virtualhost will be discarded. This is useful when deploying internal-facing services that should not be publicly routeable. As of 0.4.0, nginx will still be configured to proxy your app on some random high port. This allows internal services to maintain the same port between deployments. You may change this port by setting `DOKKU_NGINX_PORT` and/or `DOKKU_NGINX_SSL_PORT` (for services configured to use SSL.)
On subsequent deploys, the nginx virtualhost will be discarded. This is useful when deploying internal-facing services that should not be publicly routeable. As of 0.4.0, nginx will still be configured to proxy your app on some random high port. This allows internal services to maintain the same port between deployments. You may change this port by setting `DOKKU_PROXY_PORT` and/or `DOKKU_PROXY_SSL_PORT` (for services configured to use SSL.)
The domains plugin allows you to specify custom domains for applications. This plugin is aware of any ssl certificates that are imported via `certs:add`. Be aware that disabling domains (with `domains:disable`) will override any custom domains.

View File

@@ -110,8 +110,8 @@ The following list config variables have special meaning and can be set in a var
| `DOKKU_DOCKERFILE_ENTRYPOINT` | dockerfile entrypoint | `dokku config:set` | |
| `DOKKU_DOCKERFILE_PORTS` | dockerfile ports | `dokku config:set` | |
| `DOKKU_DOCKERFILE_START_CMD` | none | `dokku config:set` | |
| `DOKKU_NGINX_PORT` | automatically assigned | `dokku config:set` | |
| `DOKKU_NGINX_SSL_PORT` | automatically assigned | `dokku config:set` | |
| `DOKKU_PROXY_PORT` | automatically assigned | `dokku config:set` | |
| `DOKKU_PROXY_SSL_PORT` | automatically assigned | `dokku config:set` | |
| `DOKKU_PROXY_PORT_MAP` | automatically assigned | `dokku proxy:ports-add` <br /> `dokku proxy:ports-remove`, `dokku proxy:ports-clear` | |
| `DOKKU_SKIP_ALL_CHECKS` | none | `dokku config:set` | |
| `DOKKU_SKIP_CLEANUP` | | `/etc/environment` <br /> `~dokku/.dokkurc` <br /> `~dokku/.dokkurc/*` | When a deploy is triggered, if this is set to a non-empty value, then old docker containers and images will not be removed. |

View File

@@ -30,8 +30,8 @@ Dokku uses a templating library by the name of [sigil](https://github.com/glider
{{ .APP_SSL_PATH }} Path to SSL certificate and key
{{ .DOKKU_ROOT }} Global Dokku root directory (ex: app dir would be `{{ .DOKKU_ROOT }}/{{ .APP }}`)
{{ .DOKKU_APP_LISTENERS }} List of IP:PORT pairs of app containers
{{ .NGINX_PORT }} Non-SSL nginx listener port (same as `DOKKU_NGINX_PORT` config var)
{{ .NGINX_SSL_PORT }} SSL nginx listener port (same as `DOKKU_NGINX_SSL_PORT` config var)
{{ .PROXY_PORT }} Non-SSL nginx listener port (same as `DOKKU_PROXY_PORT` config var)
{{ .PROXY_SSL_PORT }} SSL nginx listener port (same as `DOKKU_PROXY_SSL_PORT` config var)
{{ .NOSSL_SERVER_NAME }} List of non-SSL VHOSTS
{{ .PROXY_PORT_MAP }} List of port mappings (same as `DOKKU_PROXY_PORT_MAP` config var)
{{ .PROXY_UPSTREAM_PORTS }} List of configured upstream ports (derived from `DOKKU_PROXY_PORT_MAP` config var)
@@ -46,7 +46,7 @@ Dokku uses a templating library by the name of [sigil](https://github.com/glider
The default nginx.conf template will include everything from your apps `nginx.conf.d/` subdirectory in the main `server {}` block (see above):
```go
```
include {{ .DOKKU_ROOT }}/{{ .APP }}/nginx.conf.d/*.conf;
```

View File

@@ -129,8 +129,8 @@ If your server runs behind an HTTP/S load balancer, then Nginx will see all requ
```go
server {
listen [::]:{{ .NGINX_PORT }};
listen {{ .NGINX_PORT }};
listen [::]:{{ .PROXY_PORT }};
listen {{ .PROXY_PORT }};
server_name {{ .NOSSL_SERVER_NAME }};
access_log /var/log/nginx/{{ .APP }}-access.log;
error_log /var/log/nginx/{{ .APP }}-error.log;

View File

@@ -88,29 +88,29 @@ configure_nginx_ports() {
declare desc="configure nginx listening ports"
local APP=$1; verify_app_name "$APP"
local RAW_TCP_PORTS="$(get_app_raw_tcp_ports "$APP")"
local DOKKU_NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
local DOKKU_NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
local DOKKU_PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
local DOKKU_PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
local DOKKU_PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
local IS_APP_VHOST_ENABLED="$(is_app_vhost_enabled "$APP")"
local UPSTREAM_PORT="5000"
if [[ -z "$DOKKU_NGINX_PORT" ]] && [[ -z "$RAW_TCP_PORTS" ]]; then
if [[ -z "$DOKKU_PROXY_PORT" ]] && [[ -z "$RAW_TCP_PORTS" ]]; then
if [[ "$IS_APP_VHOST_ENABLED" == "false" ]]; then
dokku_log_info1 "no nginx port set. setting to random open high port"
local NGINX_PORT=$(get_available_port)
dokku_log_info1 "no proxy port set. setting to random open high port"
local PROXY_PORT=$(get_available_port)
else
local NGINX_PORT=80
local PROXY_PORT=80
fi
config_set --no-restart "$APP" DOKKU_NGINX_PORT="$NGINX_PORT"
config_set --no-restart "$APP" DOKKU_PROXY_PORT="$PROXY_PORT"
fi
if [[ -z "$DOKKU_NGINX_SSL_PORT" ]]; then
if [[ -z "$DOKKU_PROXY_SSL_PORT" ]]; then
if (is_ssl_enabled "$APP"); then
local NGINX_SSL_PORT=443
local PROXY_SSL_PORT=443
if [[ -z "$RAW_TCP_PORTS" ]] && [[ "$IS_APP_VHOST_ENABLED" == "false" ]]; then
dokku_log_info1 "no nginx ssl port set. setting to random open high port"
NGINX_SSL_PORT=$(get_available_port)
dokku_log_info1 "no proxy ssl port set. setting to random open high port"
PROXY_SSL_PORT=$(get_available_port)
fi
config_set --no-restart "$APP" DOKKU_NGINX_SSL_PORT="$NGINX_SSL_PORT"
config_set --no-restart "$APP" DOKKU_PROXY_SSL_PORT="$PROXY_SSL_PORT"
fi
fi
if [[ -z "$DOKKU_PROXY_PORT_MAP" ]]; then
@@ -120,13 +120,13 @@ configure_nginx_ports() {
local PROXY_PORT_MAP+=" http:${RAW_TCP_PORT}:${RAW_TCP_PORT} "
done
else
local NGINX_PORT=${NGINX_PORT:-$DOKKU_NGINX_PORT}
local NGINX_SSL_PORT=${NGINX_SSL_PORT:-$DOKKU_NGINX_SSL_PORT}
local PROXY_PORT=${PROXY_PORT:-$DOKKU_PROXY_PORT}
local PROXY_SSL_PORT=${PROXY_SSL_PORT:-$DOKKU_PROXY_SSL_PORT}
[[ -f "$DOKKU_ROOT/$APP/PORT.web.1" ]] && local UPSTREAM_PORT="$(< "$DOKKU_ROOT/$APP/PORT.web.1")"
if [[ -n "$NGINX_PORT" ]] && [[ -n "$NGINX_SSL_PORT" ]]; then
local PROXY_PORT_MAP+=" http:${NGINX_PORT}:$UPSTREAM_PORT https:${NGINX_SSL_PORT}:$UPSTREAM_PORT "
elif [[ -n "$NGINX_PORT" ]]; then
local PROXY_PORT_MAP+=" http:${NGINX_PORT}:$UPSTREAM_PORT "
if [[ -n "$PROXY_PORT" ]] && [[ -n "$PROXY_SSL_PORT" ]]; then
local PROXY_PORT_MAP+=" http:${PROXY_PORT}:$UPSTREAM_PORT https:${PROXY_SSL_PORT}:$UPSTREAM_PORT "
elif [[ -n "$PROXY_PORT" ]]; then
local PROXY_PORT_MAP+=" http:${PROXY_PORT}:$UPSTREAM_PORT "
fi
fi
if [[ -n "$PROXY_PORT_MAP" ]]; then
@@ -236,8 +236,8 @@ nginx_build_config() {
# setup nginx listen ports
configure_nginx_ports "$APP"
local NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
local NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
local PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
local PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
local PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
local PORT_MAP
@@ -306,7 +306,9 @@ nginx_build_config() {
HTTP2_SUPPORTED="$HTTP2_SUPPORTED"
DOKKU_APP_LISTEN_PORT="$DOKKU_APP_LISTEN_PORT" DOKKU_APP_LISTEN_IP="$DOKKU_APP_LISTEN_IP"
APP_SSL_PATH="$APP_SSL_PATH" SSL_INUSE="$SSL_INUSE" SSL_SERVER_NAME="$SSL_SERVER_NAME"
NGINX_PORT="$NGINX_PORT" NGINX_SSL_PORT="$NGINX_SSL_PORT" RAW_TCP_PORTS="$RAW_TCP_PORTS"
# @TODO: Remove this after a few versions
NGINX_PORT="$PROXY_PORT" NGINX_SSL_PORT="$PROXY_SSL_PORT"
PROXY_PORT="$PROXY_PORT" PROXY_SSL_PORT="$PROXY_SSL_PORT" RAW_TCP_PORTS="$RAW_TCP_PORTS"
PROXY_PORT_MAP="$PROXY_PORT_MAP" PROXY_UPSTREAM_PORTS="$PROXY_UPSTREAM_PORTS")
# execute sigil template processing

View File

@@ -1,5 +1,6 @@
#!/usr/bin/env bash
set -eo pipefail; [[ $DOKKU_TRACE ]] && set -x
source "$PLUGIN_CORE_AVAILABLE_PATH/common/functions"
case "$DOKKU_DISTRO" in
debian)
@@ -73,6 +74,26 @@ cp "${PLUGIN_CORE_AVAILABLE_PATH}/nginx-vhosts/templates/500-error.html" "${DOKK
# patch broken nginx 1.8.0 logrotate
[[ -f /etc/logrotate.d/nginx ]] && sed -i -e 's/invoke-rc.d/service/g' /etc/logrotate.d/nginx
# @TODO: Remove this after a few versions
dokku_log_info1 "Migrating DOKKU_NGINX env variables. The following variables will be migrated"
dokku_log_info2 "DOKKU_NGINX_PORT -> DOKKU_PROXY_PORT"
dokku_log_info2 "DOKKU_NGINX_SSL_PORT -> DOKKU_PROXY_SSL_PORT"
for app in $(dokku_apps); do
nginx_port="$(config_get "$app" DOKKU_NGINX_PORT || true)"
nginx_ssl_port="$(config_get "$app" DOKKU_NGINX_SSL_PORT || true)"
if [[ -n "$nginx_port" ]]; then
dokku_log_info1 "Migrating DOKKU_NGINX_PORT to DOKKU_PROXY_PORT for $app"
config_set --no-restart "$app" DOKKU_PROXY_PORT="$nginx_port"
config_unset --no-restart "$app" DOKKU_NGINX_PORT
fi
if [[ -n "$nginx_ssl_port" ]]; then
dokku_log_info1 "Migrating DOKKU_NGINX_SSL_PORT to DOKKU_PROXY_SSL_PORT for $app"
config_set --no-restart "$app" DOKKU_PROXY_SSL_PORT="$nginx_ssl_port"
config_unset --no-restart "$app" DOKKU_NGINX_SSL_PORT
fi
done
dokku_log_info2 "Migration complete"
case "$DOKKU_DISTRO" in
debian)
NGINX_INIT="/usr/sbin/invoke-rc.d"

View File

@@ -9,7 +9,7 @@ nginx_post_certs_remove() {
local trigger="nginx_post_certs_remove"
local APP="$1"
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
config_unset --no-restart "$APP" DOKKU_NGINX_SSL_PORT
config_unset --no-restart "$APP" DOKKU_PROXY_SSL_PORT
# shellcheck disable=SC2046
remove_proxy_ports "$APP" $(filter_app_proxy_ports "$APP" "https" "443")

View File

@@ -9,15 +9,15 @@ nginx_post_certs_update() {
local trigger="nginx_post_certs_update"
local APP="$1"
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
local DOKKU_NGINX_PORT=$(config_get "$APP" DOKKU_NGINX_PORT)
local DOKKU_NGINX_SSL_PORT=$(config_get "$APP" DOKKU_NGINX_SSL_PORT)
local DOKKU_PROXY_PORT=$(config_get "$APP" DOKKU_PROXY_PORT)
local DOKKU_PROXY_SSL_PORT=$(config_get "$APP" DOKKU_PROXY_SSL_PORT)
local DOKKU_PROXY_PORT_MAP=$(config_get "$APP" DOKKU_PROXY_PORT_MAP)
if [[ "$DOKKU_NGINX_PORT" == "80" ]]; then
config_unset --no-restart "$APP" DOKKU_NGINX_PORT
if [[ "$DOKKU_PROXY_PORT" == "80" ]]; then
config_unset --no-restart "$APP" DOKKU_PROXY_PORT
fi
if [[ "$DOKKU_NGINX_SSL_PORT" == "443" ]]; then
config_unset --no-restart "$APP" DOKKU_NGINX_SSL_PORT
if [[ "$DOKKU_PROXY_SSL_PORT" == "443" ]]; then
config_unset --no-restart "$APP" DOKKU_PROXY_SSL_PORT
fi
if [[ "$DOKKU_PROXY_PORT_MAP" == *http:80:* ]]; then
# shellcheck disable=SC2046

View File

@@ -9,7 +9,7 @@ nginx_pre_disable_vhost_trigger() {
local trigger="nginx_pre_disable_vhost_trigger"
local APP="$1"
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
config_unset --no-restart "$APP" DOKKU_NGINX_PORT DOKKU_NGINX_SSL_PORT DOKKU_PROXY_PORT_MAP
config_unset --no-restart "$APP" DOKKU_PROXY_PORT DOKKU_PROXY_SSL_PORT DOKKU_PROXY_PORT_MAP
fi
}

View File

@@ -9,7 +9,7 @@ nginx_pre_enable_vhost_trigger() {
local trigger="nginx_pre_enable_vhost_trigger"
local APP="$1"
if [[ "$(get_app_proxy_type "$APP")" == "nginx" ]]; then
config_unset --no-restart "$APP" DOKKU_NGINX_PORT DOKKU_NGINX_SSL_PORT DOKKU_PROXY_PORT_MAP
config_unset --no-restart "$APP" DOKKU_PROXY_PORT DOKKU_PROXY_SSL_PORT DOKKU_PROXY_PORT_MAP
fi
}

View File

@@ -12,7 +12,7 @@ server {
access_log /var/log/nginx/{{ $.APP }}-access.log;
error_log /var/log/nginx/{{ $.APP }}-error.log;
{{ if (and (eq $listen_port "80") ($.SSL_INUSE)) }}
return 301 https://$host:{{ $.NGINX_SSL_PORT }}$request_uri;
return 301 https://$host:{{ $.PROXY_SSL_PORT }}$request_uri;
{{ else }}
location / {
@@ -69,7 +69,7 @@ server {
ssl_prefer_server_ciphers on;
keepalive_timeout 70;
{{ if and (eq $.SPDY_SUPPORTED "true") (ne $.HTTP2_SUPPORTED "true") }}add_header Alternate-Protocol {{ $.NGINX_SSL_PORT }}:npn-spdy/2;{{ end }}
{{ if and (eq $.SPDY_SUPPORTED "true") (ne $.HTTP2_SUPPORTED "true") }}add_header Alternate-Protocol {{ $.PROXY_SSL_PORT }}:npn-spdy/2;{{ end }}
location / {

View File

@@ -277,12 +277,12 @@ server {
listen [::]:{{ \$listen_port }};
listen {{ \$listen_port }};
server_name {{ $.NOSSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN;
return 301 https://\$host:{{ $.NGINX_SSL_PORT }}\$request_uri;
return 301 https://\$host:{{ $.PROXY_SSL_PORT }}\$request_uri;
}
{{ else if eq \$scheme "https"}}
server {
listen [::]:{{ $.NGINX_SSL_PORT }} ssl spdy;
listen {{ $.NGINX_SSL_PORT }} ssl spdy;
listen [::]:{{ $.PROXY_SSL_PORT }} ssl spdy;
listen {{ $.PROXY_SSL_PORT }} ssl spdy;
{{ if $.SSL_SERVER_NAME }}server_name {{ $.SSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN; {{ end }}
{{ if $.NOSSL_SERVER_NAME }}server_name {{ $.NOSSL_SERVER_NAME }} $CUSTOM_TEMPLATE_SSL_DOMAIN; {{ end }}
ssl_certificate {{ $.APP_SSL_PATH }}/server.crt;