feat: inject docker labels when nginx proxy implementation is in use
This will allow users to switch to a docker label-based nginx proxy server transparently without rebuilds (after the first one), which would mimic how the caddy, haproxy, and traefik proxy implementations work. See https://github.com/dokku/nginx-docker-proxy for an example server implementation.
This commit is contained in:
@@ -39,17 +39,17 @@ cmd-nginx-report-single() {
|
||||
local flag_map=(
|
||||
"--nginx-access-log-format: $(fn-nginx-access-log-format "$APP")"
|
||||
"--nginx-access-log-path: $(fn-nginx-access-log-path "$APP")"
|
||||
"--nginx-bind-address-ipv4: $(fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv4" "")"
|
||||
"--nginx-bind-address-ipv6: $(fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv6" "::")"
|
||||
"--nginx-client-max-body-size: $(fn-plugin-property-get-default "nginx" "$APP" "client-max-body-size" "")"
|
||||
"--nginx-bind-address-ipv4: $(fn-nginx-bind-address-ipv4 "$APP")"
|
||||
"--nginx-bind-address-ipv6: $(fn-nginx-bind-address-ipv6 "$APP")"
|
||||
"--nginx-client-max-body-size: $(fn-nginx-client-max-body-size "$APP")"
|
||||
"--nginx-disable-custom-config: $(fn-plugin-property-get-default "nginx" "$APP" "disable-custom-config" "false")"
|
||||
"--nginx-error-log-path: $(fn-nginx-error-log-path "$APP")"
|
||||
"--nginx-global-hsts: $(fn-plugin-property-get-default "nginx" "--global" "hsts" "true")"
|
||||
"--nginx-computed-hsts: $(fn-nginx-hsts-is-enabled "$APP")"
|
||||
"--nginx-hsts: $(fn-plugin-property-get-default "nginx" "$APP" "hsts" "")"
|
||||
"--nginx-hsts-include-subdomains: $(fn-plugin-property-get-default "nginx" "$APP" "hsts-include-subdomains" "true")"
|
||||
"--nginx-hsts-max-age: $(fn-plugin-property-get-default "nginx" "$APP" "hsts-max-age" "15724800")"
|
||||
"--nginx-hsts-preload: $(fn-plugin-property-get-default "nginx" "$APP" "hsts-preload" "false")"
|
||||
"--nginx-hsts-include-subdomains: $(fn-nginx-hsts-include-subdomains "$APP")"
|
||||
"--nginx-hsts-max-age: $(fn-nginx-hsts-max-age "$APP")"
|
||||
"--nginx-hsts-preload: $(fn-nginx-hsts-preload "$APP")"
|
||||
"--nginx-computed-nginx-conf-sigil-path: $(fn-nginx-computed-nginx-conf-sigil-path "$APP")"
|
||||
"--nginx-global-nginx-conf-sigil-path: $(fn-nginx-global-nginx-conf-sigil-path)"
|
||||
"--nginx-nginx-conf-sigil-path: $(fn-nginx-nginx-conf-sigil-path "$APP")"
|
||||
@@ -59,10 +59,10 @@ cmd-nginx-report-single() {
|
||||
"--nginx-proxy-busy-buffers-size: $(fn-nginx-proxy-busy-buffers-size "$APP")"
|
||||
"--nginx-proxy-read-timeout: $(fn-nginx-proxy-read-timeout "$APP")"
|
||||
"--nginx-last-visited-at: $(fn-nginx-vhosts-last-visited-at "$APP")"
|
||||
"--nginx-x-forwarded-for-value: $(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-for-value" "\$remote_addr")"
|
||||
"--nginx-x-forwarded-port-value: $(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-port-value" "\$server_port")"
|
||||
"--nginx-x-forwarded-proto-value: $(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-proto-value" "\$scheme")"
|
||||
"--nginx-x-forwarded-ssl: $(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-ssl" "")"
|
||||
"--nginx-x-forwarded-for-value: $(fn-nginx-x-forwarded-for-value "$APP")"
|
||||
"--nginx-x-forwarded-port-value: $(fn-nginx-x-forwarded-port-value "$APP")"
|
||||
"--nginx-x-forwarded-proto-value: $(fn-nginx-x-forwarded-proto-value "$APP")"
|
||||
"--nginx-x-forwarded-ssl: $(fn-nginx-x-forwarded-ssl "$APP")"
|
||||
)
|
||||
|
||||
if [[ -z "$INFO_FLAG" ]]; then
|
||||
|
||||
58
plugins/nginx-vhosts/docker-args-process-deploy
Executable file
58
plugins/nginx-vhosts/docker-args-process-deploy
Executable file
@@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env bash
|
||||
set -eo pipefail
|
||||
[[ $DOKKU_TRACE ]] && set -x
|
||||
source "$PLUGIN_CORE_AVAILABLE_PATH/common/functions"
|
||||
source "$PLUGIN_AVAILABLE_PATH/nginx-vhosts/functions"
|
||||
|
||||
trigger-nginx-vhosts-docker-args-process-deploy() {
|
||||
declare desc="nginx-vhosts docker-args-process-deploy plugin trigger"
|
||||
declare trigger="docker-args-process-deploy"
|
||||
declare APP="$1" IMAGE_SOURCE_TYPE="$2" IMAGE_TAG="$3" PROC_TYPE="$4" CONTAINER_INDEX="$5"
|
||||
local output
|
||||
local STDIN=$(cat)
|
||||
|
||||
if [[ "$PROC_TYPE" != "web" ]]; then
|
||||
return
|
||||
fi
|
||||
|
||||
if [[ "$(plugn trigger proxy-type "$APP")" != "nginx" ]]; then
|
||||
return
|
||||
fi
|
||||
|
||||
if [[ "$(plugn trigger proxy-is-enabled "$APP")" != "true" ]]; then
|
||||
return
|
||||
fi
|
||||
|
||||
if ! plugn trigger domains-vhost-enabled "$APP" 2>/dev/null; then
|
||||
return
|
||||
fi
|
||||
|
||||
# ensure we have a port mapping
|
||||
plugn trigger ports-configure "$APP"
|
||||
|
||||
output="$output '--label=nginx.access-log-format=$(fn-nginx-access-log-format "$APP")'"
|
||||
output="$output '--label=nginx.bind-address-ipv4=$(fn-nginx-bind-address-ipv4 "$APP")'"
|
||||
output="$output '--label=nginx.bind-address-ipv6=$(fn-nginx-bind-address-ipv6 "$APP")'"
|
||||
output="$output '--label=nginx.client-max-body-size=$(fn-nginx-client-max-body-size "$APP")'"
|
||||
output="$output '--label=nginx.hsts-include-subdomains=$(fn-nginx-hsts-include-subdomains "$APP")'"
|
||||
output="$output '--label=nginx.hsts-max-age=$(fn-nginx-hsts-max-age "$APP")'"
|
||||
output="$output '--label=nginx.hsts-preload=$(fn-nginx-hsts-preload "$APP")'"
|
||||
output="$output '--label=nginx.hsts=$(fn-nginx-hsts-is-enabled "$APP")'"
|
||||
output="$output '--label=nginx.https-port=443'"
|
||||
output="$output '--label=nginx.domains=$(plugn trigger domains-list "$APP" | xargs)'"
|
||||
output="$output '--label=nginx.initial-network=$(plugn trigger network-get-property "$APP" initial-network)'"
|
||||
output="$output '--label=nginx.port-mapping=$(plugn trigger ports-get "$APP" | xargs)'"
|
||||
output="$output '--label=nginx.proxy-buffer-size=$(fn-nginx-proxy-buffer-size "$APP")'"
|
||||
output="$output '--label=nginx.proxy-buffering=$(fn-nginx-proxy-buffering "$APP")'"
|
||||
output="$output '--label=nginx.proxy-buffers=$(fn-nginx-proxy-buffers "$APP")'"
|
||||
output="$output '--label=nginx.proxy-busy-buffer-size=$(fn-nginx-proxy-busy-buffers-size "$APP")'"
|
||||
output="$output '--label=nginx.proxy-read-timeout=$(fn-nginx-proxy-read-timeout "$APP")'"
|
||||
output="$output '--label=nginx.x-forwarded-for-value=$(fn-nginx-x-forwarded-for-value "$APP")'"
|
||||
output="$output '--label=nginx.x-forwarded-port-value=$(fn-nginx-x-forwarded-port-value "$APP")'"
|
||||
output="$output '--label=nginx.x-forwarded-proto-value=$(fn-nginx-x-forwarded-proto-value "$APP")'"
|
||||
output="$output '--label=nginx.x-forwarded-ssl=$(fn-nginx-x-forwarded-ssl "$APP")'"
|
||||
|
||||
echo -n "$STDIN$output"
|
||||
}
|
||||
|
||||
trigger-nginx-vhosts-docker-args-process-deploy "$@"
|
||||
@@ -28,6 +28,20 @@ fn-nginx-access-log-path() {
|
||||
fn-plugin-property-get-default "nginx" "$APP" "access-log-path" "${NGINX_LOG_ROOT}/${APP}-access.log"
|
||||
}
|
||||
|
||||
fn-nginx-bind-address-ipv4() {
|
||||
declare desc="get the configured ipv4 bind address"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv4" ""
|
||||
}
|
||||
|
||||
fn-nginx-bind-address-ipv6() {
|
||||
declare desc="get the configured ipv6 bind address"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv6" "::"
|
||||
}
|
||||
|
||||
fn-nginx-proxy-buffer-size() {
|
||||
declare desc="get the configured proxy buffer size"
|
||||
declare APP="$1"
|
||||
@@ -78,6 +92,34 @@ fn-nginx-error-log-path() {
|
||||
fn-plugin-property-get-default "nginx" "$APP" "error-log-path" "${NGINX_LOG_ROOT}/${APP}-error.log"
|
||||
}
|
||||
|
||||
fn-nginx-x-forwarded-for-value() {
|
||||
declare desc="get the configured x-forwarded-for value"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-for-value" "\$remote_addr"
|
||||
}
|
||||
|
||||
fn-nginx-x-forwarded-port-value() {
|
||||
declare desc="get the configured x-forwarded-port value"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-port-value" "\$server_port"
|
||||
}
|
||||
|
||||
fn-nginx-x-forwarded-proto-value() {
|
||||
declare desc="get the configured x-forwarded-proto value"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-proto-value" "\$scheme"
|
||||
}
|
||||
|
||||
fn-nginx-x-forwarded-ssl() {
|
||||
declare desc="get the configured x-forwarded-ssl value"
|
||||
declare APP="$1"
|
||||
|
||||
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-ssl" ""
|
||||
}
|
||||
|
||||
get_nginx_location() {
|
||||
declare desc="check that nginx is at the expected location and return it"
|
||||
fn-nginx-vhosts-nginx-location
|
||||
@@ -413,14 +455,14 @@ nginx_build_config() {
|
||||
local NGINX_TEMPLATE_SOURCE="app-supplied"
|
||||
fi
|
||||
|
||||
local NGINX_BIND_ADDRESS_IP4="$(fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv4" "")"
|
||||
local NGINX_BIND_ADDRESS_IP6="$(fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv6" "::")"
|
||||
local NGINX_BIND_ADDRESS_IP4="$(fn-nginx-bind-address-ipv4 "$APP")"
|
||||
local NGINX_BIND_ADDRESS_IP6="$(fn-nginx-bind-address-ipv6 "$APP")"
|
||||
[[ -z "$NGINX_BIND_ADDRESS_IP6" ]] && NGINX_BIND_ADDRESS_IP6="::"
|
||||
|
||||
local PROXY_X_FORWARDED_FOR="$(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-for-value" "\$remote_addr")"
|
||||
local PROXY_X_FORWARDED_PORT="$(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-port-value" "\$server_port")"
|
||||
local PROXY_X_FORWARDED_PROTO="$(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-proto-value" "\$scheme")"
|
||||
local PROXY_X_FORWARDED_SSL="$(fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-ssl" "")"
|
||||
local PROXY_X_FORWARDED_FOR="$(fn-nginx-x-forwarded-for-value "$APP")"
|
||||
local PROXY_X_FORWARDED_PORT="$(fn-nginx-x-forwarded-port-value "$APP")"
|
||||
local PROXY_X_FORWARDED_PROTO="$(fn-nginx-x-forwarded-proto-value "$APP")"
|
||||
local PROXY_X_FORWARDED_SSL="$(fn-nginx-x-forwarded-ssl "$APP")"
|
||||
|
||||
eval "$(config_export app "$APP")"
|
||||
local SIGIL_PARAMS=(-f "$NGINX_TEMPLATE" APP="$APP" DOKKU_ROOT="$DOKKU_ROOT"
|
||||
|
||||
@@ -13,6 +13,21 @@ fn-nginx-vhosts-last-visited-at() {
|
||||
fi
|
||||
}
|
||||
|
||||
fn-nginx-hsts-include-subdomains() {
|
||||
declare APP="$1"
|
||||
fn-plugin-property-get-default "nginx" "$APP" "hsts-include-subdomains" "true"
|
||||
}
|
||||
|
||||
fn-nginx-hsts-max-age() {
|
||||
declare APP="$1"
|
||||
fn-plugin-property-get-default "nginx" "$APP" "hsts-max-age" "15724800"
|
||||
}
|
||||
|
||||
fn-nginx-hsts-preload() {
|
||||
declare APP="$1"
|
||||
fn-plugin-property-get-default "nginx" "$APP" "hsts-preload" "false"
|
||||
}
|
||||
|
||||
fn-nginx-hsts-is-enabled() {
|
||||
declare APP="$1"
|
||||
local hsts_is_enabled="$(fn-plugin-property-get-default "nginx" "$APP" "hsts" "")"
|
||||
@@ -49,9 +64,9 @@ fn-nginx-nginx-conf-sigil-path() {
|
||||
fn-nginx-vhosts-manage-hsts() {
|
||||
declare APP="$1" SSL_ENABLED="$2"
|
||||
local HSTS="$(fn-nginx-hsts-is-enabled "$APP")"
|
||||
local HSTS_INCLUDE_SUBDOMAINS="$(fn-plugin-property-get-default "nginx" "$APP" "hsts-include-subdomains" "true")"
|
||||
local HSTS_MAX_AGE="$(fn-plugin-property-get-default "nginx" "$APP" "hsts-max-age" "15724800")"
|
||||
local HSTS_PRELOAD="$(fn-plugin-property-get-default "nginx" "$APP" "hsts-preload" "false")"
|
||||
local HSTS_INCLUDE_SUBDOMAINS="$(fn-nginx-hsts-include-subdomains "$APP")"
|
||||
local HSTS_MAX_AGE="$(fn-nginx-hsts-max-age "$APP")"
|
||||
local HSTS_PRELOAD="$(fn-nginx-hsts-preload "$APP")"
|
||||
local NGINX_HSTS_CONF="$DOKKU_ROOT/$APP/nginx.conf.d/hsts.conf"
|
||||
local HSTS_TEMPLATE="$PLUGIN_AVAILABLE_PATH/nginx-vhosts/templates/hsts.conf.sigil"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user