refactor: consolidate property fetching for nginx plugin into golang codebase

Also update the documentation to include docs for all properties.
This commit is contained in:
Jose Diaz-Gonzalez
2024-02-05 13:25:03 -05:00
parent 6625846ecc
commit d4b445985b
14 changed files with 1448 additions and 492 deletions

View File

@@ -49,110 +49,6 @@ The nginx server can be stopped via `nginx:stop`.
dokku nginx:stop
```
### Binding to specific addresses
> [!IMPORTANT]
> New as of 0.19.2
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
By default, nginx will listen to all interfaces (`[::]` for IPv6, `0.0.0.0` for IPv4) when proxying requests to applications. This may be changed using the `bind-address-ipv4` and `bind-address-ipv6` properties. This is useful in cases where the proxying should be internal to a network or if there are multiple network interfaces that should respond with different content.
```shell
dokku nginx:set node-js-app bind-address-ipv4 127.0.0.1
dokku nginx:set node-js-app bind-address-ipv6 ::1
```
This may be reverted by setting an empty bind address.
```shell
dokku nginx:set node-js-app bind-address-ipv4
dokku nginx:set node-js-app bind-address-ipv6
```
> [!WARNING]
> Validation is not performed on either value.
Users with apps that contain a custom `nginx.conf.sigil` file will need to modify the files to respect the new `NGINX_BIND_ADDRESS_IPV4` and `NGINX_BIND_ADDRESS_IPV6` variables.
### HSTS Header
> [!IMPORTANT]
> New as of 0.20.0
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
If SSL certificates are present, HSTS will be automatically enabled. It can be toggled via `nginx:set`:
```shell
dokku nginx:set node-js-app hsts true
dokku nginx:set node-js-app hsts false
```
The following options are also available via the `nginx:set` command:
- `hsts` (type: boolean, default: `true`): Enables or disables HSTS for your application.
- `hsts-include-subdomains` (type: boolean, default: `true`): Tells the browser that the HSTS policy also applies to all subdomains of the current domain.
- `hsts-max-age` (type: integer, default: `15724800`): Time in seconds to cache HSTS configuration.
- `hsts-preload` (type: boolean, default: `false`): Tells most major web browsers to include the domain in their HSTS preload lists.
Beware that if you enable the header and a subsequent deploy of your application results in an HTTP deploy (for whatever reason), the way the header works means that a browser will not attempt to request the HTTP version of your site if the HTTPS version fails until the max-age is reached.
#### Globally disabling the HSTS Header
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
HSTS Header can be disabled for all apps by setting the `hsts` property to false after passing the `--global` flag to `nginx:set`.
```shell
dokku nginx:set --global hsts false
```
Once the HSTS setting is disabled globally, it can be re-enabled on a per-app basis by setting the `hsts` property as normal.
```shell
dokku nginx:set node-js-app hsts true
```
### Running behind another proxy — configuring `X-Forwarded-*` headers
Dokku's default Nginx configuration passes the de-facto standard HTTP headers [`X-Forwarded-For`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For), [`X-Forwarded-Proto`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-Proto), and `X-Forwarded-Port` to your application.
These headers indicate the IP address of the original client making the request, the protocol of the original request (HTTP or HTTPS), and the port number of the original request, respectively.
If you have another HTTP proxy sitting in between the end user and your server (for example, a load balancer, or a CDN), then the values of these headers will contain information about (e.g. the IP address of) the the closest proxy, and not the end user.
To fix this, assuming that the other proxy also passes `X-Forwarded-*` headers, which in turn contain information about the end user, you can tell Nginx include those values in the `X-Forwarded-*` headers that it sends to your application. You can do this via `nginx:set`, like so:
```shell
dokku nginx:set node-js-app x-forwarded-for-value '$http_x_forwarded_for'
dokku nginx:set node-js-app x-forwarded-port-value '$http_x_forwarded_port'
dokku nginx:set node-js-app x-forwarded-proto-value '$http_x_forwarded_proto'
```
However, note that you should only do this if:
1. Requests to your website always go through a trusted proxy.
2. That proxy is configured to send the aforementioned `X-Forwarded-*` headers.
Otherwise, if it's possible for clients to make HTTP requests directly against your server, bypassing the other proxy, or if the other proxy is not configured to set these headers, then a client can basically pass any arbitrary values for these headers (which your app then presumably reads) and thereby fake an IP address, for example.
There's also the `X-Forwarded-Ssl` header which a less common alternative to `X-Forwarded-Proto` — and because of that, isn't included in Dokku's default Nginx configuration.
But you can tell Nginx to send this header as well, if necessary.
```shell
# force-setting value to `on`
dokku nginx:set node-js-app x-forwarded-ssl on
# force-setting value to `off`
dokku nginx:set node-js-app x-forwarded-ssl off
# removing the value from nginx.conf (default)
dokku nginx:set node-js-app x-forwarded-ssl
```
### Checking access logs
> [!NOTE]
@@ -184,130 +80,6 @@ You may also follow the logs by specifying the `-t` flag.
dokku nginx:error-logs node-js-app -t
```
### Changing log path
> [!IMPORTANT]
> New as of 0.20.1
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
The path to where log files are stored can be changed by calling the `nginx:set` command with the following options:
- `access-log-path` (type: string, default: `${NGINX_LOG_ROOT}/${APP}-access.log`): Log path for nginx access logs
- `error-log-path` (type: string, default: `${NGINX_LOG_ROOT}/${APP}-error.log`): Log path for nginx error logs
The defaults should not be changed without verifying that the paths will be writeable by nginx. However, this setting is useful for enabling or disabling logging by setting the values to `off`.
```shell
dokku nginx:set node-js-app access-log-path off
dokku nginx:set node-js-app error-log-path off
```
The default value may be set by passing an empty value for the option:
```shell
dokku nginx:set node-js-app access-log-path
dokku nginx:set node-js-app error-log-path
```
In all cases, the nginx config must be regenerated after setting the above values.
### Changing log format
> [!IMPORTANT]
> New as of 0.22.0
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
The format of the access log can be changed by calling the `nginx:set` command as follows:
```shell
dokku nginx:set node-js-app access-log-format custom-format
```
Prior to changing the log-format, log formats should be specified at a file such as `/etc/nginx/conf.d/00-log-formats.conf`. This will ensure they are available within your app's nginx context. For instance, the following may be added to the above file. It only needs to be specified once to be used for all apps.
```nginx
# /etc/nginx/conf.d/00-log-formats.conf
# escape=json was added in nginx 1.11.8
log_format json_combined escape=json
'{'
'"time_local":"$time_local",'
'"remote_addr":"$remote_addr",'
'"remote_user":"$remote_user",'
'"request":"$request",'
'"status":"$status",'
'"body_bytes_sent":"$body_bytes_sent",'
'"request_time":"$request_time",'
'"http_referrer":"$http_referer",'
'"http_user_agent":"$http_user_agent"'
'}';
```
Next, the format should be set for the given app.
```shell
dokku nginx:set node-js-app access-log-format json_combined
```
Finally, a proxy rebuild will change the format as desired.
```shell
dokku proxy:build-config node-js-app
```
### Specifying a read timeout
> [!IMPORTANT]
> New as of 0.21.0
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
When proxying requests to your applications, it may be useful to specify a proxy read timeout. This can be done via the `nginx:set` command as follows:
```shell
dokku nginx:set node-js-app proxy-read-timeout 120s
```
The default value is `60s`, and all numeric values _must_ have a trailing time value specified (`s` for seconds, `m` for minutes).
The default value may be set by passing an empty value for the option:
```shell
dokku nginx:set node-js-app proxy-read-timeout
```
In all cases, the nginx config must be regenerated after setting the above value.
### Specifying a custom client_max_body_size
> [!IMPORTANT]
> New as of 0.23.0
> [!NOTE]
> Changing this value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
Users can override the default `client_max_body_size` value - which limits file uploads - via `nginx:set`. Changing this value will only apply to every `server` stanza of the default `nginx.conf.sigil`; users of custom `nginx.conf.sigil` files must update their templates to support the new value.
```shell
dokku nginx:set node-js-app client-max-body-size 50m
```
The default value is empty string, which will result in nginx falling back to any configured, higher-level defaults (or `1m` if unconfigued; all numerical values _must_ have a size unit specified (`k` for kilobytes, `m` for megabytes).
The default value may be set by passing an empty value for the option:
```shell
dokku nginx:set node-js-app client-max-body-size
```
In all cases, the nginx config must be regenerated after setting the above value.
Changing this value when using the PHP buildpack (or any other buildpack that uses an intermediary server) will require changing the value in the server config shipped with that buildpack. Consult your buildpack documentation for further details.
### Showing the nginx config
For debugging purposes, it may be useful to show the nginx config. This can be achieved via the `nginx:show-config` command.
@@ -341,6 +113,65 @@ The `--clean` flag may also be specified for a given app:
dokku nginx:validate-config node-js-app --clean
```
### Custom Error Pages
By default, Dokku provides custom error pages for the following three categories of errors:
- 4xx: For all non-404 errors with a 4xx response code.
- 404: For "404 Not Found" errors.
- 5xx: For all 5xx error responses
These are provided as an alternative to the generic Nginx error page, are shared for _all_ applications, and their contents are located on disk at `/var/lib/dokku/data/nginx-vhosts/dokku-errors`. To customize them for a specific app, create a custom `nginx.conf.sigil` as described above and change the paths to point elsewhere.
### Default site
By default, Dokku will route any received request with an unknown HOST header value to the lexicographically first site in the nginx config stack. This means that accessing the dokku server via its IP address or a bogus domain name may return a seemingly random website.
> [!WARNING]
> Some versions of Nginx may create a default site when installed. This site is simply a static page which says "Welcome to Nginx", and if this default site is enabled, Nginx will not route any requests with an unknown HOST header to Dokku. If you want Dokku to receive all requests, run the following commands:
>
> ```
> rm /etc/nginx/sites-enabled/default
> dokku nginx:stop
> dokku nginx:start
> ```
If services should only be accessed via their domain name, you may want to disable the default site by adding the following configuration to the global nginx configuration.
Create the file at `/etc/nginx/conf.d/00-default-vhost.conf`:
```nginx
server {
listen 80 default_server;
listen [::]:80 default_server;
# If services hosted by dokku are available via HTTPS, it is recommended
# to also uncomment the following section.
#
# Please note that in order to let this work, you need an SSL certificate. However
# it does not need to be valid. Users of Debian-based distributions can install the
# `ssl-cert` package with `sudo apt install ssl-cert` to automatically generate
# a self-signed certificate that is stored at `/etc/ssl/certs/ssl-cert-snakeoil.pem`.
#
#listen 443 ssl;
#listen [::]:443 ssl;
#ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
#ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
server_name _;
access_log off;
return 444;
}
```
Make sure to reload nginx after creating this file by running `systemctl reload nginx.service`.
This will catch all unknown HOST header values and close the connection without responding. You can replace the `return 444;` with `return 410;` which will cause nginx to respond with an error page.
The configuration file must be loaded before `/etc/nginx/conf.d/dokku.conf`, so it can not be arranged as a vhost in `/etc/nginx/sites-enabled` that is only processed afterwards.
Alternatively, you may push an app to your Dokku host with a name like "00-default". As long as it lists first in `ls /home/dokku/*/nginx.conf | head`, it will be used as the default nginx vhost.
### Customizing the nginx configuration
> [!IMPORTANT]
@@ -445,64 +276,188 @@ location / {
Please adjust the `Procfile` and `nginx.conf` file as appropriate.
### Custom Error Pages
### Setting Properties for the nginx config
By default, Dokku provides custom error pages for the following three categories of errors:
The nginx plugin exposes a variety of properties configurable via the `nginx:set` command. The properties are used to configure the generated `nginx.conf` file from the `nginx.conf.sigil` template. The value precedence is app-specific, then global, and finally the Dokku default.
- 4xx: For all non-404 errors with a 4xx response code.
- 404: For "404 Not Found" errors.
- 5xx: For all 5xx error responses
The nginx:set command takes an app name or the `--global` flag.
These are provided as an alternative to the generic Nginx error page, are shared for _all_ applications, and their contents are located on disk at `/var/lib/dokku/data/nginx-vhosts/dokku-errors`. To customize them for a specific app, create a custom `nginx.conf.sigil` as described above and change the paths to point elsewhere.
```shell
# set a property for the node-js-app
dokku nginx:set node-js-app property-name some-value
### Default site
By default, Dokku will route any received request with an unknown HOST header value to the lexicographically first site in the nginx config stack. This means that accessing the dokku server via its IP address or a bogus domain name may return a seemingly random website.
> [!WARNING]
> some versions of Nginx may create a default site when installed. This site is simply a static page which says "Welcome to Nginx", and if this default site is enabled, Nginx will not route any requests with an unknown HOST header to Dokku. If you want Dokku to receive all requests, run the following commands:
>
> ```
> rm /etc/nginx/sites-enabled/default
> dokku nginx:stop
> dokku nginx:start
> ```
If services should only be accessed via their domain name, you may want to disable the default site by adding the following configuration to the global nginx configuration.
Create the file at `/etc/nginx/conf.d/00-default-vhost.conf`:
```nginx
server {
listen 80 default_server;
listen [::]:80 default_server;
# If services hosted by dokku are available via HTTPS, it is recommended
# to also uncomment the following section.
#
# Please note that in order to let this work, you need an SSL certificate. However
# it does not need to be valid. Users of Debian-based distributions can install the
# `ssl-cert` package with `sudo apt install ssl-cert` to automatically generate
# a self-signed certificate that is stored at `/etc/ssl/certs/ssl-cert-snakeoil.pem`.
#
#listen 443 ssl;
#listen [::]:443 ssl;
#ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
#ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
server_name _;
access_log off;
return 444;
}
# set a property globally
dokku nginx:set --global property-name some-value
```
Make sure to reload nginx after creating this file by running `systemctl reload nginx.service`.
Additionally, setting an empty value will result in reverting the value back to it's default. For app-specific values, this means that Dokku will revert to the globally specified (or global default) value.
This will catch all unknown HOST header values and close the connection without responding. You can replace the `return 444;` with `return 410;` which will cause nginx to respond with an error page.
```shell
# default the value back to the global value for node-js-app
dokku nginx:set node-js-app property-name
The configuration file must be loaded before `/etc/nginx/conf.d/dokku.conf`, so it can not be arranged as a vhost in `/etc/nginx/sites-enabled` that is only processed afterwards.
# use the dokku default as the global value
dokku nginx:set --global property-name
```
Changing these value globally or on a per-app basis will require rebuilding the nginx config via the `proxy:build-config` command.
> [!WARNING]
> Validation is not performed against the values, and they are used as is within Dokku.
| Property | Default | Type | Explanation |
| --------------------------|---------------------------------------|---------|-------------------------------------------------------------------------------------|
| access-log-format | empty string | string | Name of custom log format to use (log format must be specified elsewhere) |
| access-log-path | `${NGINX_LOG_ROOT}/${APP}-access.log` | string | Log path for nginx access logs (set to `off` to disable) |
| bind-address-ipv4 | `0.0.0.0` | string | Default IPv4 address to bind to |
| bind-address-ipv6 | `[::]` | string | Default IPv6 address to bind to |
| client-max-body-size | `1m` | string | Size (with units) of client request body (usually modified for file uploads) |
| error-log-path | `${NGINX_LOG_ROOT}/${APP}-error.log` | string | Log path for nginx error logs (set to `off` to disable) |
| hsts | `true` | boolean | Enables or disables HSTS for your application |
| hsts-include-subdomains | `true` | boolean | Forces the browser to apply the HSTS policy to all app subdomains |
| hsts-max-age | `15724800` | integer | Time in seconds to cache HSTS configuration |
| hsts-preload | `false` | boolean | Tells the browser to include the domain in their HSTS preload lists |
| nginx-conf-sigil-path | `nginx.conf.sigil` | string | Path in the repository to the `nginx.conf.sigil` file |
| proxy-buffer-size | `8k` (# is os pagesize) | string | Size of the buffer used for reading the first part of proxied server response |
| proxy-buffering | `on` | string | Enables or disables buffering of responses from the proxied server |
| proxy-buffers | `8 8k` | string | Number and size of the buffers used for reading the proxied server response, for a single connection |
| proxy-busy-buffers-size | `16k` | string | Limits the total size of buffers that can be busy sending a response to the client while the response is not yet fully read. |
| proxy-read-timeout | `60s` | string | Timeout (with units) for reading response from your backend server |
| x-forwarded-for-value | `$remote_addr` | string | Used for specifying the header value to set for the `X-Forwared-For` header |
| x-forwarded-port-value | `$server_port` | string | Used for specifying the header value to set for the `X-Forwared-Port` header |
| x-forwarded-proto-value | `$scheme` | string | Used for specifying the header value to set for the `X-Forwared-Proto` header |
| x-forwarded-ssl | empty string | string | Less commonly used alternative to `X-Forwarded-Proto` (valid values: `on` or `off`) |
#### Binding to specific addresses
> [!NOTE]
> Users with apps that contain a custom `nginx.conf.sigil` file will need to modify the files to respect the new `NGINX_BIND_ADDRESS_IPV4` and `NGINX_BIND_ADDRESS_IPV6` variables.
Properties:
- `bind-address-ipv4`
- `bind-address-ipv6`
This is useful in cases where the proxying should be internal to a network or if there are multiple network interfaces that should respond with different content.
#### HSTS Header
> [!WARNING]
> if you enable the header and a subsequent deploy of your application results in an HTTP deploy (for whatever reason), the way the header works means that a browser will not attempt to request the HTTP version of your site if the HTTPS version fails until the max-age is reached.
Properties:
- `hsts`
- `hsts-include-subdomains`
- `hsts-max-age`
- `hsts-preload`
If SSL certificates are present, HSTS will be automatically enabled.
#### Running behind another proxy — configuring `X-Forwarded-*` headers
> [!WARNING]
> These values should only be modified if there is an intermediate Load balancer or CDN between the user and the Dokku server hosting your application.
Properties:
- `x-forwarded-for-value`
- `x-forwarded-port-value`
- `x-forwarded-proto-value`
- `x-forwarded-ssl`
Dokku's default Nginx configuration passes the de-facto standard HTTP headers [`X-Forwarded-For`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For), [`X-Forwarded-Proto`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-Proto), and `X-Forwarded-Port` to your application.
These headers indicate the IP address of the original client making the request, the protocol of the original request (HTTP or HTTPS), and the port number of the original request, respectively.
If you have another HTTP proxy sitting in between the end user and your server (for example, a load balancer, or a CDN), then the values of these headers will contain information about (e.g. the IP address of) the the closest proxy, and not the end user.
To fix this, assuming that the other proxy also passes `X-Forwarded-*` headers, which in turn contain information about the end user, you can tell Nginx include those values in the `X-Forwarded-*` headers that it sends to your application. You can do this via `nginx:set`, like so:
```shell
dokku nginx:set node-js-app x-forwarded-for-value '$http_x_forwarded_for'
dokku nginx:set node-js-app x-forwarded-port-value '$http_x_forwarded_port'
dokku nginx:set node-js-app x-forwarded-proto-value '$http_x_forwarded_proto'
```
However, note that you should only do this if:
1. Requests to your website always go through a trusted proxy.
2. That proxy is configured to send the aforementioned `X-Forwarded-*` headers.
Otherwise, if it's possible for clients to make HTTP requests directly against your server, bypassing the other proxy, or if the other proxy is not configured to set these headers, then a client can basically pass any arbitrary values for these headers (which your app then presumably reads) and thereby fake an IP address, for example.
There's also the `X-Forwarded-Ssl` header which a less common alternative to `X-Forwarded-Proto` — and because of that, isn't included in Dokku's default Nginx configuration. It can be turned `on` if need be:
```shell
# force-setting value to `on`
dokku nginx:set node-js-app x-forwarded-ssl on
```
#### Changing log path
> [!WARNING]
> The defaults should not be changed without verifying that the paths will be writeable by nginx.
Properties:
- `access-log-path`
- `error-log-path`
These setting can be useful for enabling or disabling logging by setting the values to `off`.
```shell
dokku nginx:set node-js-app access-log-path off
dokku nginx:set node-js-app error-log-path off
```
#### Changing log format
Properties:
- `acccess-log-format`
Prior to changing the log-format, log formats should be specified at a file such as `/etc/nginx/conf.d/00-log-formats.conf`. This will ensure they are available within your app's nginx context. For instance, the following may be added to the above file. It only needs to be specified once to be used for all apps.
```nginx
# /etc/nginx/conf.d/00-log-formats.conf
# escape=json was added in nginx 1.11.8
log_format json_combined escape=json
'{'
'"time_local":"$time_local",'
'"remote_addr":"$remote_addr",'
'"remote_user":"$remote_user",'
'"request":"$request",'
'"status":"$status",'
'"body_bytes_sent":"$body_bytes_sent",'
'"request_time":"$request_time",'
'"http_referrer":"$http_referer",'
'"http_user_agent":"$http_user_agent"'
'}';
```
#### Specifying a read timeout
> [!NOTE]
> All numeric values _must_ have a trailing time value specified (`s` for seconds, `m` for minutes).
Properties:
- `proxy-read-timeout`
#### Specifying a custom client_max_body_size
> [!NOTE]
> All numerical values _must_ have a trailing size unit specified (`k` for kilobytes, `m` for megabytes).
Properties:
- `client-max-body-size`
This property is commonly used to increase the max file upload size.
Changing this value when using the PHP buildpack (or any other buildpack that uses an intermediary server) will require changing the value in the server config shipped with that buildpack. Consult your buildpack documentation for further details.
Alternatively, you may push an app to your Dokku host with a name like "00-default". As long as it lists first in `ls /home/dokku/*/nginx.conf | head`, it will be used as the default nginx vhost.
## Other

View File

@@ -1,5 +1,5 @@
GOARCH ?= amd64
BUILD = pagesize
BUILD = pagesize nginx-property
PLUGIN_NAME = nginx-vhosts
clean-pagesize:
@@ -8,4 +8,10 @@ clean-pagesize:
pagesize: clean-pagesize **/**/pagesize.go
GOARCH=$(GOARCH) go build -ldflags="-s -w" $(GO_ARGS) -o pagesize src/pagesize/pagesize.go
clean-nginx-property:
rm -rf nginx-property
nginx-property: clean-nginx-property **/**/nginx-property.go
GOARCH=$(GOARCH) go build -ldflags="-s -w" $(GO_ARGS) -o nginx-property src/nginx-property/nginx-property.go
include ../../common.mk

View File

@@ -38,31 +38,69 @@ cmd-nginx-report-single() {
verify_app_name "$APP"
local flag_map=(
"--nginx-access-log-format: $(fn-nginx-access-log-format "$APP")"
"--nginx-computed-access-log-format: $(fn-nginx-computed-access-log-format "$APP")"
"--nginx-global-access-log-format: $(fn-nginx-global-access-log-format "$APP")"
"--nginx-access-log-path: $(fn-nginx-access-log-path "$APP")"
"--nginx-computed-access-log-path: $(fn-nginx-computed-access-log-path "$APP")"
"--nginx-global-access-log-path: $(fn-nginx-global-access-log-path "$APP")"
"--nginx-bind-address-ipv4: $(fn-nginx-bind-address-ipv4 "$APP")"
"--nginx-computed-bind-address-ipv4: $(fn-nginx-computed-bind-address-ipv4 "$APP")"
"--nginx-global-bind-address-ipv4: $(fn-nginx-global-bind-address-ipv4 "$APP")"
"--nginx-bind-address-ipv6: $(fn-nginx-bind-address-ipv6 "$APP")"
"--nginx-computed-bind-address-ipv6: $(fn-nginx-computed-bind-address-ipv6 "$APP")"
"--nginx-global-bind-address-ipv6: $(fn-nginx-global-bind-address-ipv6 "$APP")"
"--nginx-client-max-body-size: $(fn-nginx-client-max-body-size "$APP")"
"--nginx-disable-custom-config: $(fn-plugin-property-get-default "nginx" "$APP" "disable-custom-config" "false")"
"--nginx-computed-client-max-body-size: $(fn-nginx-computed-client-max-body-size "$APP")"
"--nginx-global-client-max-body-size: $(fn-nginx-global-client-max-body-size "$APP")"
"--nginx-disable-custom-config: $(fn-nginx-disable-custom-config "$APP")"
"--nginx-computed-disable-custom-config: $(fn-nginx-computed-disable-custom-config "$APP")"
"--nginx-global-disable-custom-config: $(fn-nginx-global-disable-custom-config "$APP")"
"--nginx-error-log-path: $(fn-nginx-error-log-path "$APP")"
"--nginx-global-hsts: $(fn-plugin-property-get-default "nginx" "--global" "hsts" "true")"
"--nginx-computed-hsts: $(fn-nginx-hsts-is-enabled "$APP")"
"--nginx-hsts: $(fn-plugin-property-get-default "nginx" "$APP" "hsts" "")"
"--nginx-computed-error-log-path: $(fn-nginx-computed-error-log-path "$APP")"
"--nginx-global-error-log-path: $(fn-nginx-global-error-log-path "$APP")"
"--nginx-hsts-include-subdomains: $(fn-nginx-hsts-include-subdomains "$APP")"
"--nginx-computed-hsts-include-subdomains: $(fn-nginx-computed-hsts-include-subdomains "$APP")"
"--nginx-global-hsts-include-subdomains: $(fn-nginx-global-hsts-include-subdomains "$APP")"
"--nginx-hsts-max-age: $(fn-nginx-hsts-max-age "$APP")"
"--nginx-computed-hsts-max-age: $(fn-nginx-computed-hsts-max-age "$APP")"
"--nginx-global-hsts-max-age: $(fn-nginx-global-hsts-max-age "$APP")"
"--nginx-hsts-preload: $(fn-nginx-hsts-preload "$APP")"
"--nginx-computed-nginx-conf-sigil-path: $(fn-nginx-computed-nginx-conf-sigil-path "$APP")"
"--nginx-global-nginx-conf-sigil-path: $(fn-nginx-global-nginx-conf-sigil-path)"
"--nginx-nginx-conf-sigil-path: $(fn-nginx-nginx-conf-sigil-path "$APP")"
"--nginx-proxy-buffer-size: $(fn-nginx-proxy-buffer-size "$APP")"
"--nginx-proxy-buffering: $(fn-nginx-proxy-buffering "$APP")"
"--nginx-proxy-buffers: $(fn-nginx-proxy-buffers "$APP")"
"--nginx-proxy-busy-buffers-size: $(fn-nginx-proxy-busy-buffers-size "$APP")"
"--nginx-proxy-read-timeout: $(fn-nginx-proxy-read-timeout "$APP")"
"--nginx-computed-hsts-preload: $(fn-nginx-computed-hsts-preload "$APP")"
"--nginx-global-hsts-preload: $(fn-nginx-global-hsts-preload "$APP")"
"--nginx-hsts: $(fn-nginx-hsts "$APP")"
"--nginx-computed-hsts: $(fn-nginx-computed-hsts "$APP")"
"--nginx-global-hsts: $(fn-nginx-global-hsts "$APP")"
"--nginx-last-visited-at: $(fn-nginx-vhosts-last-visited-at "$APP")"
"--nginx-nginx-conf-sigil-path: $(fn-nginx-nginx-conf-sigil-path "$APP")"
"--nginx-computed-nginx-conf-sigil-path: $(fn-nginx-computed-nginx-conf-sigil-path "$APP")"
"--nginx-global-nginx-conf-sigil-path: $(fn-nginx-global-nginx-conf-sigil-path "$APP")"
"--nginx-proxy-buffer-size: $(fn-nginx-proxy-buffer-size "$APP")"
"--nginx-computed-proxy-buffer-size: $(fn-nginx-computed-proxy-buffer-size "$APP")"
"--nginx-global-proxy-buffer-size: $(fn-nginx-global-proxy-buffer-size "$APP")"
"--nginx-proxy-buffering: $(fn-nginx-proxy-buffering "$APP")"
"--nginx-computed-proxy-buffering: $(fn-nginx-computed-proxy-buffering "$APP")"
"--nginx-global-proxy-buffering: $(fn-nginx-global-proxy-buffering "$APP")"
"--nginx-proxy-buffers: $(fn-nginx-proxy-buffers "$APP")"
"--nginx-computed-proxy-buffers: $(fn-nginx-computed-proxy-buffers "$APP")"
"--nginx-global-proxy-buffers: $(fn-nginx-global-proxy-buffers "$APP")"
"--nginx-proxy-busy-buffers-size: $(fn-nginx-proxy-busy-buffers-size "$APP")"
"--nginx-computed-proxy-busy-buffers-size: $(fn-nginx-computed-proxy-busy-buffers-size "$APP")"
"--nginx-global-proxy-busy-buffers-size: $(fn-nginx-global-proxy-busy-buffers-size "$APP")"
"--nginx-proxy-read-timeout: $(fn-nginx-proxy-read-timeout "$APP")"
"--nginx-computed-proxy-read-timeout: $(fn-nginx-computed-proxy-read-timeout "$APP")"
"--nginx-global-proxy-read-timeout: $(fn-nginx-global-proxy-read-timeout "$APP")"
"--nginx-x-forwarded-for-value: $(fn-nginx-x-forwarded-for-value "$APP")"
"--nginx-computed-x-forwarded-for-value: $(fn-nginx-computed-x-forwarded-for-value "$APP")"
"--nginx-global-x-forwarded-for-value: $(fn-nginx-global-x-forwarded-for-value "$APP")"
"--nginx-x-forwarded-port-value: $(fn-nginx-x-forwarded-port-value "$APP")"
"--nginx-computed-x-forwarded-port-value: $(fn-nginx-computed-x-forwarded-port-value "$APP")"
"--nginx-global-x-forwarded-port-value: $(fn-nginx-global-x-forwarded-port-value "$APP")"
"--nginx-x-forwarded-proto-value: $(fn-nginx-x-forwarded-proto-value "$APP")"
"--nginx-computed-x-forwarded-proto-value: $(fn-nginx-computed-x-forwarded-proto-value "$APP")"
"--nginx-global-x-forwarded-proto-value: $(fn-nginx-global-x-forwarded-proto-value "$APP")"
"--nginx-x-forwarded-ssl: $(fn-nginx-x-forwarded-ssl "$APP")"
"--nginx-computed-x-forwarded-ssl: $(fn-nginx-computed-x-forwarded-ssl "$APP")"
"--nginx-global-x-forwarded-ssl: $(fn-nginx-global-x-forwarded-ssl "$APP")"
)
if [[ -z "$INFO_FLAG" ]]; then

View File

@@ -6,120 +6,6 @@ source "$PLUGIN_AVAILABLE_PATH/certs/functions"
source "$PLUGIN_AVAILABLE_PATH/config/functions"
source "$PLUGIN_AVAILABLE_PATH/nginx-vhosts/internal-functions"
fn-nginx-log-root() {
declare desc="get the nginx log root"
local NGINX_LOG_ROOT="/var/log/nginx"
fn-nginx-vhosts-uses-openresty && NGINX_LOG_ROOT="/var/log/openresty"
echo "$NGINX_LOG_ROOT"
}
fn-nginx-access-log-format() {
declare desc="get the configured access log format"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "access-log-format" ""
}
fn-nginx-access-log-path() {
declare desc="get the configured access log path"
declare APP="$1"
local NGINX_LOG_ROOT="$(fn-nginx-log-root)"
fn-plugin-property-get-default "nginx" "$APP" "access-log-path" "${NGINX_LOG_ROOT}/${APP}-access.log"
}
fn-nginx-bind-address-ipv4() {
declare desc="get the configured ipv4 bind address"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv4" ""
}
fn-nginx-bind-address-ipv6() {
declare desc="get the configured ipv6 bind address"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "bind-address-ipv6" "::"
}
fn-nginx-proxy-buffer-size() {
declare desc="get the configured proxy buffer size"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "proxy-buffer-size" "$(fn-get-pagesize)"
}
fn-nginx-proxy-buffering() {
declare desc="get the configured proxy buffering"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "proxy-buffering" "on"
}
fn-nginx-proxy-buffers() {
declare desc="get the configured proxy buffers"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "proxy-buffers" "8 $(fn-get-pagesize)"
}
fn-nginx-proxy-busy-buffers-size() {
declare desc="get the configured proxy busy buffers size"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "proxy-busy-buffers-size" "$(($(fn-get-pagesize) * 2))"
}
fn-nginx-proxy-read-timeout() {
declare desc="get the configured proxy read timeout"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "proxy-read-timeout" "60s"
}
fn-nginx-client-max-body-size() {
declare desc="get the configured client max body size"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "client-max-body-size" ""
}
fn-nginx-error-log-path() {
declare desc="get the configured access log path"
declare APP="$1"
local NGINX_LOG_ROOT="$(fn-nginx-log-root)"
fn-plugin-property-get-default "nginx" "$APP" "error-log-path" "${NGINX_LOG_ROOT}/${APP}-error.log"
}
fn-nginx-x-forwarded-for-value() {
declare desc="get the configured x-forwarded-for value"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-for-value" "\$remote_addr"
}
fn-nginx-x-forwarded-port-value() {
declare desc="get the configured x-forwarded-port value"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-port-value" "\$server_port"
}
fn-nginx-x-forwarded-proto-value() {
declare desc="get the configured x-forwarded-proto value"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-proto-value" "\$scheme"
}
fn-nginx-x-forwarded-ssl() {
declare desc="get the configured x-forwarded-ssl value"
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "x-forwarded-ssl" ""
}
get_nginx_location() {
declare desc="check that nginx is at the expected location and return it"
fn-nginx-vhosts-nginx-location
@@ -182,7 +68,7 @@ nginx_logs() {
declare NGINX_LOGS_TYPE="${1#nginx:}" APP="$2"
local NGINX_LOGS_TYPE=${NGINX_LOGS_TYPE%-logs}
local NGINX_LOGS_PATH="$("fn-nginx-${NGINX_LOGS_TYPE}-log-path" "$APP")"
local NGINX_LOGS_PATH="$("fn-nginx-computed-${NGINX_LOGS_TYPE}-log-path" "$APP")"
if [[ "$NGINX_LOGS_PATH" == "off" ]] || [[ "$NGINX_LOGS_PATH" == "/dev/null" ]]; then
dokku_log_fail "$NGINX_LOGS_TYPE logs are disabled for this app"
@@ -226,7 +112,7 @@ get_custom_nginx_template() {
local IMAGE_TAG="$(get_running_image_tag "$APP")"
local IMAGE=$(get_deploying_app_image_name "$APP" "$IMAGE_TAG")
local NGINX_TEMPLATE_NAME="nginx.conf.sigil"
local DISABLE_CUSTOM_CONFIG="$(fn-plugin-property-get-default "nginx" "$APP" "disable-custom-config" "false")"
local DISABLE_CUSTOM_CONFIG="$(fn-nginx-computed-disable-custom-config "$APP")"
if [[ "$DISABLE_CUSTOM_CONFIG" == "true" ]]; then
return
@@ -420,15 +306,15 @@ nginx_build_config() {
GRPC_SUPPORTED="$(is_grpc_enabled "$NGINX_VERSION")"
local NGINX_LOG_ROOT="$(fn-nginx-log-root)"
local NGINX_ACCESS_LOG_FORMAT="$(fn-nginx-access-log-format "$APP")"
local NGINX_ACCESS_LOG_PATH="$(fn-nginx-access-log-path "$APP")"
local NGINX_ERROR_LOG_PATH="$(fn-nginx-error-log-path "$APP")"
local CLIENT_MAX_BODY_SIZE="$(fn-nginx-client-max-body-size "$APP")"
local PROXY_READ_TIMEOUT="$(fn-nginx-proxy-read-timeout "$APP")"
local PROXY_BUFFER_SIZE="$(fn-nginx-proxy-buffer-size "$APP")"
local PROXY_BUFFERING="$(fn-nginx-proxy-buffering "$APP")"
local PROXY_BUFFERS="$(fn-nginx-proxy-buffers "$APP")"
local PROXY_BUSY_BUFFERS_SIZE="$(fn-nginx-proxy-busy-buffers-size "$APP")"
local NGINX_ACCESS_LOG_FORMAT="$(fn-nginx-computed-access-log-format "$APP")"
local NGINX_ACCESS_LOG_PATH="$(fn-nginx-computed-access-log-path "$APP")"
local NGINX_ERROR_LOG_PATH="$(fn-nginx-computed-error-log-path "$APP")"
local CLIENT_MAX_BODY_SIZE="$(fn-nginx-computed-client-max-body-size "$APP")"
local PROXY_READ_TIMEOUT="$(fn-nginx-computed-proxy-read-timeout "$APP")"
local PROXY_BUFFER_SIZE="$(fn-nginx-computed-proxy-buffer-size "$APP")"
local PROXY_BUFFERING="$(fn-nginx-computed-proxy-buffering "$APP")"
local PROXY_BUFFERS="$(fn-nginx-computed-proxy-buffers "$APP")"
local PROXY_BUSY_BUFFERS_SIZE="$(fn-nginx-computed-proxy-busy-buffers-size "$APP")"
if [[ -z "$DOKKU_APP_LISTENERS" ]]; then
dokku_log_warn_quiet "No web listeners specified for $APP"
@@ -453,14 +339,12 @@ nginx_build_config() {
local NGINX_TEMPLATE_SOURCE="app-supplied"
fi
local NGINX_BIND_ADDRESS_IP4="$(fn-nginx-bind-address-ipv4 "$APP")"
local NGINX_BIND_ADDRESS_IP6="$(fn-nginx-bind-address-ipv6 "$APP")"
[[ -z "$NGINX_BIND_ADDRESS_IP6" ]] && NGINX_BIND_ADDRESS_IP6="::"
local PROXY_X_FORWARDED_FOR="$(fn-nginx-x-forwarded-for-value "$APP")"
local PROXY_X_FORWARDED_PORT="$(fn-nginx-x-forwarded-port-value "$APP")"
local PROXY_X_FORWARDED_PROTO="$(fn-nginx-x-forwarded-proto-value "$APP")"
local PROXY_X_FORWARDED_SSL="$(fn-nginx-x-forwarded-ssl "$APP")"
local NGINX_BIND_ADDRESS_IP4="$(fn-nginx-computed-bind-address-ipv4 "$APP")"
local NGINX_BIND_ADDRESS_IP6="$(fn-nginx-computed-bind-address-ipv6 "$APP")"
local PROXY_X_FORWARDED_FOR="$(fn-nginx-computed-x-forwarded-for-value "$APP")"
local PROXY_X_FORWARDED_PORT="$(fn-nginx-computed-x-forwarded-port-value "$APP")"
local PROXY_X_FORWARDED_PROTO="$(fn-nginx-computed-x-forwarded-proto-value "$APP")"
local PROXY_X_FORWARDED_SSL="$(fn-nginx-computed-x-forwarded-ssl "$APP")"
eval "$(config_export app "$APP")"
local SIGIL_PARAMS=(-f "$NGINX_TEMPLATE" APP="$APP" DOKKU_ROOT="$DOKKU_ROOT"

View File

@@ -0,0 +1,26 @@
package nginxvhosts
import (
"os"
)
func getLogRoot() string {
logRoot := "/var/log/nginx"
if isOpenRestyInstalled() {
logRoot = "/var/log/openresty"
}
return logRoot
}
func isOpenRestyInstalled() bool {
fi, err := os.Stat("/usr/bin/openresty")
if err != nil {
return false
}
if fi.IsDir() {
return false
}
return true
}

View File

@@ -1,3 +1,30 @@
module github.com/dokku/dokku/plugins/nginx-vhosts
go 1.21
require (
github.com/dokku/dokku/plugins/common v0.0.0-00010101000000-000000000000
github.com/spf13/pflag v1.0.5
)
require (
github.com/alexellis/go-execute/v2 v2.2.1 // indirect
github.com/codegangsta/inject v0.0.0-20150114235600-33e0aa1cb7c0 // indirect
github.com/codeskyblue/go-sh v0.0.0-20190412065543-76bd3d59ff27 // indirect
github.com/fatih/color v1.16.0 // indirect
github.com/hashicorp/errwrap v1.0.0 // indirect
github.com/hashicorp/go-multierror v1.1.1 // indirect
github.com/kr/fs v0.1.0 // indirect
github.com/mattn/go-colorable v0.1.13 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/melbahja/goph v1.4.0 // indirect
github.com/otiai10/copy v1.14.0 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pkg/sftp v1.13.5 // indirect
github.com/ryanuber/columnize v2.1.2+incompatible // indirect
golang.org/x/crypto v0.18.0 // indirect
golang.org/x/sync v0.6.0 // indirect
golang.org/x/sys v0.16.0 // indirect
)
replace github.com/dokku/dokku/plugins/common => ../common

View File

@@ -0,0 +1,95 @@
github.com/alexellis/go-execute/v2 v2.2.1 h1:4Ye3jiCKQarstODOEmqDSRCqxMHLkC92Bhse743RdOI=
github.com/alexellis/go-execute/v2 v2.2.1/go.mod h1:FMdRnUTiFAmYXcv23txrp3VYZfLo24nMpiIneWgKHTQ=
github.com/codegangsta/inject v0.0.0-20150114235600-33e0aa1cb7c0 h1:sDMmm+q/3+BukdIpxwO365v/Rbspp2Nt5XntgQRXq8Q=
github.com/codegangsta/inject v0.0.0-20150114235600-33e0aa1cb7c0/go.mod h1:4Zcjuz89kmFXt9morQgcfYZAYZ5n8WHjt81YYWIwtTM=
github.com/codeskyblue/go-sh v0.0.0-20190412065543-76bd3d59ff27 h1:HHUr4P/aKh4quafGxDT9LDasjGdlGkzLbfmmrlng3kA=
github.com/codeskyblue/go-sh v0.0.0-20190412065543-76bd3d59ff27/go.mod h1:VQx0hjo2oUeQkQUET7wRwradO6f+fN5jzXgB/zROxxE=
github.com/davecgh/go-spew v1.1.0 h1:ZDRjVQ15GmhC3fiQ8ni8+OwkZQO4DARzQgrnXU1Liz8=
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM=
github.com/fatih/color v1.16.0/go.mod h1:fL2Sau1YI5c0pdGEVCbKQbLXB6edEj1ZgiY4NijnWvE=
github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI=
github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
github.com/hashicorp/errwrap v1.0.0 h1:hLrqtEDnRye3+sgx6z4qVLNuviH3MR5aQ0ykNJa/UYA=
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
github.com/kr/fs v0.1.0 h1:Jskdu9ieNAYnjxsi0LbQp1ulIKZV1LAFgK1tWhpZgl8=
github.com/kr/fs v0.1.0/go.mod h1:FFnZGqtBN9Gxj7eW1uZ42v5BccTP0vu6NEaFoC2HwRg=
github.com/mattn/go-colorable v0.1.13 h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA=
github.com/mattn/go-colorable v0.1.13/go.mod h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg=
github.com/mattn/go-isatty v0.0.16/go.mod h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/melbahja/goph v1.4.0 h1:z0PgDbBFe66lRYl3v5dGb9aFgPy0kotuQ37QOwSQFqs=
github.com/melbahja/goph v1.4.0/go.mod h1:uG+VfK2Dlhk+O32zFrRlc3kYKTlV6+BtvPWd/kK7U68=
github.com/onsi/gomega v1.31.1 h1:KYppCUK+bUgAZwHOu7EXVBKyQA6ILvOESHkn/tgoqvo=
github.com/onsi/gomega v1.31.1/go.mod h1:y40C95dwAD1Nz36SsEnxvfFe8FFfNxzI5eJ0EYGyAy0=
github.com/otiai10/copy v1.14.0 h1:dCI/t1iTdYGtkvCuBG2BgR6KZa83PTclw4U5n2wAllU=
github.com/otiai10/copy v1.14.0/go.mod h1:ECfuL02W+/FkTWZWgQqXPWZgW9oeKCSQ5qVfSc4qc4w=
github.com/otiai10/mint v1.5.1 h1:XaPLeE+9vGbuyEHem1JNk3bYc7KKqyI/na0/mLd/Kks=
github.com/otiai10/mint v1.5.1/go.mod h1:MJm72SBthJjz8qhefc4z1PYEieWmy8Bku7CjcAqyUSM=
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
github.com/pkg/sftp v1.13.5 h1:a3RLUqkyjYRtBTZJZ1VRrKbN3zhuPLlUc3sphVz81go=
github.com/pkg/sftp v1.13.5/go.mod h1:wHDZ0IZX6JcBYRK1TH9bcVq8G7TLpVHYIGJRFnmPfxg=
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/ryanuber/columnize v2.1.2+incompatible h1:C89EOx/XBWwIXl8wm8OPJBd7kPF25UfsK2X7Ph/zCAk=
github.com/ryanuber/columnize v2.1.2+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
github.com/spf13/pflag v1.0.5 h1:iy+VFUOCP1a+8yFto/drg2CJ5u0yRoB7fZw3DKv/JXA=
github.com/spf13/pflag v1.0.5/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
github.com/stretchr/testify v1.7.0 h1:nwc3DEeHmmLAfoZucVR881uASk0Mfjw8xYJ99tb5CcY=
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
golang.org/x/crypto v0.0.0-20211215153901-e495a2d5b3d3/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
golang.org/x/crypto v0.6.0/go.mod h1:OFC/31mSvZgRz0V1QTNCzfAI1aIRzbiufJtkMIlEp58=
golang.org/x/crypto v0.18.0 h1:PGVlW0xEltQnzFZ55hkuX5+KLyrMYhHld1YHO4AKcdc=
golang.org/x/crypto v0.18.0/go.mod h1:R0j02AL6hcrfOiy9T4ZYp/rcWeMxM3L6QYxlOuEG1mg=
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
golang.org/x/net v0.19.0 h1:zTwKpTd2XuCqf8huc7Fo2iSy+4RHPd10s4KzeTnVr1c=
golang.org/x/net v0.19.0/go.mod h1:CfAk/cbD4CthTvqiEl8NpboMuiuOYsAr/7NOjZJtv1U=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.6.0 h1:5BMeUDZ7vkXGfEr1x9B4bRcTH4lpkTkpdh0T/J+qjbQ=
golang.org/x/sync v0.6.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20211216021012-1d35b9e2eb4e/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.16.0 h1:xWw16ngr6ZMtmxDyKyIgsE93KNKz5HKmMa3b8ALHidU=
golang.org/x/sys v0.16.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
golang.org/x/term v0.16.0 h1:m+B6fahuftsE9qjo0VWp2FW0mB3MTJvR0BaMQrq0pmE=
golang.org/x/term v0.16.0/go.mod h1:yn7UURbUtPyrVJPGPq404EukNFxcm/foM+bV/bfcDsY=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
golang.org/x/text v0.14.0 h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ=
golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

View File

@@ -37,7 +37,7 @@ fn-nginx-vhosts-migrate-nginx-conf-sigil() {
fn-plugin-property-write "nginx" "--global" "nginx-conf-sigil-migrated" "true"
for APP in $(dokku_apps "false" 2>/dev/null); do
local DISABLE_CUSTOM_CONFIG="$(fn-plugin-property-get-default "nginx" "$APP" "disable-custom-config" "false")"
local DISABLE_CUSTOM_CONFIG="$(fn-nginx-computed-disable-custom-config "$APP")"
if [[ "$DISABLE_CUSTOM_CONFIG" == "true" ]]; then
continue
fi

View File

@@ -4,6 +4,213 @@ set -eo pipefail
source "$PLUGIN_CORE_AVAILABLE_PATH/common/functions"
source "$PLUGIN_CORE_AVAILABLE_PATH/common/property-functions"
fn-nginx-access-log-format() {
declare desc="get the configured access log format"
declare APP="$1"
fn-get-property --app "$APP" "access-log-format"
}
fn-nginx-computed-access-log-format() {
declare desc="get the computed access log format"
declare APP="$1"
fn-get-property --app "$APP" --computed "access-log-format"
}
fn-nginx-global-access-log-format() {
declare desc="get the global access log format"
declare APP="$1"
fn-get-property --app "$APP" --global "access-log-format"
}
fn-nginx-access-log-path() {
declare desc="get the configured access log path"
declare APP="$1"
fn-get-property --app "$APP" "access-log-path"
}
fn-nginx-computed-access-log-path() {
declare desc="get the computed access log path"
declare APP="$1"
fn-get-property --app "$APP" --computed "access-log-path"
}
fn-nginx-global-access-log-path() {
declare desc="get the global access log path"
declare APP="$1"
fn-get-property --app "$APP" --global "access-log-path"
}
fn-nginx-bind-address-ipv4() {
declare desc="get the configured ipv4 bind address"
declare APP="$1"
fn-get-property --app "$APP" "bind-address-ipv4"
}
fn-nginx-computed-bind-address-ipv4() {
declare desc="get the computed ipv4 bind address"
declare APP="$1"
fn-get-property --app "$APP" --computed "bind-address-ipv4"
}
fn-nginx-global-bind-address-ipv4() {
declare desc="get the global ipv4 bind address"
declare APP="$1"
fn-get-property --app "$APP" --global "bind-address-ipv4"
}
fn-nginx-bind-address-ipv6() {
declare desc="get the configured ipv6 bind address"
declare APP="$1"
fn-get-property --app "$APP" "bind-address-ipv6"
}
fn-nginx-computed-bind-address-ipv6() {
declare desc="get the computed ipv6 bind address"
declare APP="$1"
fn-get-property --app "$APP" --computed "bind-address-ipv6"
}
fn-nginx-global-bind-address-ipv6() {
declare desc="get the global ipv6 bind address"
declare APP="$1"
fn-get-property --app "$APP" --global "bind-address-ipv6"
}
fn-nginx-client-max-body-size() {
declare desc="get the configured client max body size"
declare APP="$1"
fn-get-property --app "$APP" "client-max-body-size"
}
fn-nginx-computed-client-max-body-size() {
declare desc="get the computed client max body size"
declare APP="$1"
fn-get-property --app "$APP" --computed "client-max-body-size"
}
fn-nginx-global-client-max-body-size() {
declare desc="get the global client max body size"
declare APP="$1"
fn-get-property --app "$APP" --global "client-max-body-size"
}
fn-nginx-disable-custom-config() {
declare desc="get the configured disable-custom-config value"
declare APP="$1"
fn-get-property --app "$APP" "disable-custom-config"
}
fn-nginx-computed-disable-custom-config() {
declare desc="get the computed disable-custom-config value"
declare APP="$1"
fn-get-property --app "$APP" --computed "disable-custom-config"
}
fn-nginx-global-disable-custom-config() {
declare desc="get the global disable-custom-config value"
declare APP="$1"
fn-get-property --app "$APP" --global "disable-custom-config"
}
fn-nginx-error-log-path() {
declare desc="get the configured error log path"
declare APP="$1"
fn-get-property --app "$APP" "error-log-path"
}
fn-nginx-computed-error-log-path() {
declare desc="get the computed error log path"
declare APP="$1"
fn-get-property --app "$APP" --computed "error-log-path"
}
fn-nginx-global-error-log-path() {
declare desc="get the global error log path"
declare APP="$1"
fn-get-property --app "$APP" --global "error-log-path"
}
fn-nginx-hsts-include-subdomains() {
declare APP="$1"
fn-get-property --app "$APP" "hsts-include-subdomains"
}
fn-nginx-computed-hsts-include-subdomains() {
declare APP="$1"
fn-get-property --app "$APP" --computed "hsts-include-subdomains"
}
fn-nginx-global-hsts-include-subdomains() {
declare APP="$1"
fn-get-property --app "$APP" --global "hsts-include-subdomains"
}
fn-nginx-hsts-max-age() {
declare APP="$1"
fn-get-property --app "$APP" "hsts-max-age"
}
fn-nginx-computed-hsts-max-age() {
declare APP="$1"
fn-get-property --app "$APP" --computed "hsts-max-age"
}
fn-nginx-global-hsts-max-age() {
declare APP="$1"
fn-get-property --app "$APP" --global "hsts-max-age"
}
fn-nginx-hsts-preload() {
declare APP="$1"
fn-get-property --app "$APP" "hsts-preload"
}
fn-nginx-computed-hsts-preload() {
declare APP="$1"
fn-get-property --app "$APP" --computed "hsts-preload"
}
fn-nginx-global-hsts-preload() {
declare APP="$1"
fn-get-property --app "$APP" --global "hsts-preload"
}
fn-nginx-hsts() {
declare APP="$1"
fn-get-property --app "$APP" "hsts"
}
fn-nginx-computed-hsts() {
declare APP="$1"
fn-get-property --app "$APP" --computed "hsts"
}
fn-nginx-global-hsts() {
declare APP="$1"
fn-get-property --app "$APP" --global "hsts"
}
fn-nginx-vhosts-last-visited-at() {
declare APP="$1"
local LOG_PATH=$(fn-nginx-access-log-path "$APP")
@@ -13,60 +220,223 @@ fn-nginx-vhosts-last-visited-at() {
fi
}
fn-nginx-hsts-include-subdomains() {
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "hsts-include-subdomains" "true"
}
fn-nginx-log-root() {
declare desc="get the nginx log root"
local NGINX_LOG_ROOT="/var/log/nginx"
fn-nginx-hsts-max-age() {
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "hsts-max-age" "15724800"
}
fn-nginx-hsts-preload() {
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "hsts-preload" "false"
}
fn-nginx-hsts-is-enabled() {
declare APP="$1"
local hsts_is_enabled="$(fn-plugin-property-get-default "nginx" "$APP" "hsts" "")"
if [[ "$hsts_is_enabled" == "" ]]; then
hsts_is_enabled="$(fn-plugin-property-get-default "nginx" "--global" "hsts" "true")"
fi
echo "$hsts_is_enabled"
}
fn-nginx-computed-nginx-conf-sigil-path() {
declare APP="$1"
local conf_sigil_path="$(fn-nginx-nginx-conf-sigil-path "$APP")"
if [[ "$conf_sigil_path" == "" ]]; then
conf_sigil_path="$(fn-nginx-global-nginx-conf-sigil-path)"
fi
echo "$conf_sigil_path"
}
fn-nginx-global-nginx-conf-sigil-path() {
declare APP="$1"
fn-plugin-property-get-default "nginx" "--global" "nginx-conf-sigil-path" "nginx.conf.sigil"
fn-nginx-vhosts-uses-openresty && NGINX_LOG_ROOT="/var/log/openresty"
echo "$NGINX_LOG_ROOT"
}
fn-nginx-nginx-conf-sigil-path() {
declare APP="$1"
fn-plugin-property-get-default "nginx" "$APP" "nginx-conf-sigil-path" ""
fn-get-property --app "$APP" "nginx-conf-sigil-path"
}
fn-nginx-computed-nginx-conf-sigil-path() {
declare APP="$1"
fn-get-property --computed --app "$APP" "nginx-conf-sigil-path"
}
fn-nginx-global-nginx-conf-sigil-path() {
declare APP="$1"
fn-get-property --global "nginx-conf-sigil-path"
}
fn-nginx-proxy-buffer-size() {
declare desc="get the configured proxy buffer size"
declare APP="$1"
fn-get-property --app "$APP" "proxy-buffer-size"
}
fn-nginx-computed-proxy-buffer-size() {
declare desc="get the computed proxy buffer size"
declare APP="$1"
fn-get-property --app "$APP" --computed "proxy-buffer-size"
}
fn-nginx-global-proxy-buffer-size() {
declare desc="get the global proxy buffer size"
declare APP="$1"
fn-get-property --app "$APP" --global "proxy-buffer-size"
}
fn-nginx-proxy-buffering() {
declare desc="get the configured proxy buffering"
declare APP="$1"
fn-get-property --app "$APP" "proxy-buffering"
}
fn-nginx-computed-proxy-buffering() {
declare desc="get the computed proxy buffering"
declare APP="$1"
fn-get-property --app "$APP" --computed "proxy-buffering"
}
fn-nginx-global-proxy-buffering() {
declare desc="get the global proxy buffering"
declare APP="$1"
fn-get-property --app "$APP" --global "proxy-buffering"
}
fn-nginx-proxy-buffers() {
declare desc="get the configured proxy buffers"
declare APP="$1"
fn-get-property --app "$APP" "proxy-buffers"
}
fn-nginx-computed-proxy-buffers() {
declare desc="get the computed proxy buffers"
declare APP="$1"
fn-get-property --app "$APP" --computed "proxy-buffers"
}
fn-nginx-global-proxy-buffers() {
declare desc="get the global proxy buffers"
declare APP="$1"
fn-get-property --app "$APP" --global "proxy-buffers"
}
fn-nginx-proxy-busy-buffers-size() {
declare desc="get the configured proxy busy buffers size"
declare APP="$1"
fn-get-property --app "$APP" "proxy-busy-buffers-size"
}
fn-nginx-computed-proxy-busy-buffers-size() {
declare desc="get the computed proxy busy buffers size"
declare APP="$1"
fn-get-property --app "$APP" --computed "proxy-busy-buffers-size"
}
fn-nginx-global-proxy-busy-buffers-size() {
declare desc="get the global proxy busy buffers size"
declare APP="$1"
fn-get-property --app "$APP" --global "proxy-busy-buffers-size"
}
fn-nginx-proxy-read-timeout() {
declare desc="get the configured proxy read timeout"
declare APP="$1"
fn-get-property --app "$APP" "proxy-read-timeout"
}
fn-nginx-computed-proxy-read-timeout() {
declare desc="get the computed proxy read timeout"
declare APP="$1"
fn-get-property --app "$APP" --computed "proxy-read-timeout"
}
fn-nginx-global-proxy-read-timeout() {
declare desc="get the global proxy read timeout"
declare APP="$1"
fn-get-property --app "$APP" --global "proxy-read-timeout"
}
fn-nginx-x-forwarded-for-value() {
declare desc="get the configured x-forwarded-for value"
declare APP="$1"
fn-get-property --app "$APP" "x-forwarded-for-value"
}
fn-nginx-computed-x-forwarded-for-value() {
declare desc="get the computed x-forwarded-for value"
declare APP="$1"
fn-get-property --app "$APP" --computed "x-forwarded-for-value"
}
fn-nginx-global-x-forwarded-for-value() {
declare desc="get the global x-forwarded-for value"
declare APP="$1"
fn-get-property --app "$APP" --global "x-forwarded-for-value"
}
fn-nginx-x-forwarded-port-value() {
declare desc="get the configured x-forwarded-port value"
declare APP="$1"
fn-get-property --app "$APP" "x-forwarded-port-value"
}
fn-nginx-computed-x-forwarded-port-value() {
declare desc="get the computed x-forwarded-port value"
declare APP="$1"
fn-get-property --app "$APP" --computed "x-forwarded-port-value"
}
fn-nginx-global-x-forwarded-port-value() {
declare desc="get the global x-forwarded-port value"
declare APP="$1"
fn-get-property --app "$APP" --global "x-forwarded-port-value"
}
fn-nginx-x-forwarded-proto-value() {
declare desc="get the configured x-forwarded-proto value"
declare APP="$1"
fn-get-property --app "$APP" "x-forwarded-proto-value"
}
fn-nginx-computed-x-forwarded-proto-value() {
declare desc="get the computed x-forwarded-proto value"
declare APP="$1"
fn-get-property --app "$APP" --computed "x-forwarded-proto-value"
}
fn-nginx-global-x-forwarded-proto-value() {
declare desc="get the global x-forwarded-proto value"
declare APP="$1"
fn-get-property --app "$APP" --global "x-forwarded-proto-value"
}
fn-nginx-x-forwarded-ssl() {
declare desc="get the configured x-forwarded-ssl value"
declare APP="$1"
fn-get-property --app "$APP" "x-forwarded-ssl"
}
fn-nginx-computed-x-forwarded-ssl() {
declare desc="get the computed x-forwarded-ssl value"
declare APP="$1"
fn-get-property --app "$APP" --computed "x-forwarded-ssl"
}
fn-nginx-global-x-forwarded-ssl() {
declare desc="get the global x-forwarded-ssl value"
declare APP="$1"
fn-get-property --app "$APP" --global "x-forwarded-ssl"
}
fn-nginx-vhosts-manage-hsts() {
declare APP="$1" SSL_ENABLED="$2"
local HSTS="$(fn-nginx-hsts-is-enabled "$APP")"
local HSTS_INCLUDE_SUBDOMAINS="$(fn-nginx-hsts-include-subdomains "$APP")"
local HSTS_MAX_AGE="$(fn-nginx-hsts-max-age "$APP")"
local HSTS_PRELOAD="$(fn-nginx-hsts-preload "$APP")"
local HSTS="$(fn-nginx-computed-hsts "$APP")"
local HSTS_INCLUDE_SUBDOMAINS="$(fn-nginx-computed-hsts-include-subdomains "$APP")"
local HSTS_MAX_AGE="$(fn-nginx-computed-hsts-max-age "$APP")"
local HSTS_PRELOAD="$(fn-nginx-computed-hsts-preload "$APP")"
local NGINX_HSTS_CONF="$DOKKU_ROOT/$APP/nginx.conf.d/hsts.conf"
local HSTS_TEMPLATE="$PLUGIN_AVAILABLE_PATH/nginx-vhosts/templates/hsts.conf.sigil"
@@ -166,10 +536,10 @@ fn-nginx-vhosts-nginx-init-cmd() {
esac
}
fn-get-pagesize() {
declare desc="return the underlying system's memory page size"
fn-get-property() {
declare desc="get a property from the nginx plugin"
"$PLUGIN_CORE_AVAILABLE_PATH/nginx-vhosts/pagesize"
"$PLUGIN_CORE_AVAILABLE_PATH/nginx-vhosts/nginx-property" "$@"
}
nginx_vhosts_validate_single_func() {

View File

@@ -0,0 +1,367 @@
package nginxvhosts
import (
"fmt"
"os"
"github.com/dokku/dokku/plugins/common"
)
func AppAccessLogFormat(appName string) string {
return common.PropertyGet("nginx", appName, "access-log-format")
}
func ComputedAccessLogFormat(appName string) string {
appValue := AppAccessLogFormat(appName)
if appValue != "" {
return appValue
}
return GlobalAccessLogFormat()
}
func GlobalAccessLogFormat() string {
return common.PropertyGet("nginx", "--global", "access-log-format")
}
func AppAccessLogPath(appName string) string {
return common.PropertyGet("nginx", appName, "access-log-path")
}
func ComputedAccessLogPath(appName string) string {
appValue := AppAccessLogPath(appName)
if appValue != "" {
return appValue
}
return GlobalAccessLogPath(appName)
}
func GlobalAccessLogPath(appName string) string {
defaultLogPath := fmt.Sprintf("%s/%s-access.log", getLogRoot(), appName)
return common.PropertyGetDefault("nginx", "--global", "access-log-path", defaultLogPath)
}
func AppBindAddressIPv4(appName string) string {
return common.PropertyGet("nginx", appName, "bind-address-ipv4")
}
func ComputedBindAddressIPv4(appName string) string {
appValue := AppBindAddressIPv4(appName)
if appValue != "" {
return appValue
}
return GlobalBindAddressIPv4()
}
func GlobalBindAddressIPv4() string {
return common.PropertyGet("nginx", "--global", "bind-address-ipv4")
}
func AppBindAddressIPv6(appName string) string {
return common.PropertyGet("nginx", appName, "bind-address-ipv6")
}
func ComputedBindAddressIPv6(appName string) string {
appValue := AppBindAddressIPv6(appName)
if appValue != "" {
return appValue
}
return GlobalBindAddressIPv6()
}
func GlobalBindAddressIPv6() string {
return common.PropertyGetDefault("nginx", "--global", "bind-address-ipv6", "::")
}
func AppClientMaxBodySize(appName string) string {
return common.PropertyGet("nginx", appName, "client-max-body-size")
}
func ComputedClientMaxBodySize(appName string) string {
appValue := AppClientMaxBodySize(appName)
if appValue != "" {
return appValue
}
return GlobalClientMaxBodySize()
}
func GlobalClientMaxBodySize() string {
return common.PropertyGetDefault("nginx", "--global", "client-max-body-size", "1m")
}
func AppDisableCustomConfig(appName string) string {
return common.PropertyGet("nginx", appName, "disable-custom-config")
}
func ComputedDisableCustomConfig(appName string) string {
appValue := AppDisableCustomConfig(appName)
if appValue != "" {
return appValue
}
return GlobalDisableCustomConfig()
}
func GlobalDisableCustomConfig() string {
return common.PropertyGetDefault("nginx", "--global", "disable-custom-config", "false")
}
func AppErrorLogPath(appName string) string {
return common.PropertyGet("nginx", appName, "error-log-path")
}
func ComputedErrorLogPath(appName string) string {
appValue := AppErrorLogPath(appName)
if appValue != "" {
return appValue
}
return GlobalErrorLogPath(appName)
}
func GlobalErrorLogPath(appName string) string {
defaultLogPath := fmt.Sprintf("%s/%s-error.log", getLogRoot(), appName)
return common.PropertyGetDefault("nginx", "--global", "error-log-path", defaultLogPath)
}
func AppHSTSIncludeSubdomains(appName string) string {
return common.PropertyGet("nginx", appName, "hsts-include-subdomains")
}
func ComputedHSTSIncludeSubdomains(appName string) string {
appValue := AppHSTSIncludeSubdomains(appName)
if appValue != "" {
return appValue
}
return GlobalHSTSIncludeSubdomains()
}
func GlobalHSTSIncludeSubdomains() string {
return common.PropertyGetDefault("nginx", "--global", "hsts-include-subdomains", "true")
}
func AppHSTSMaxAge(appName string) string {
return common.PropertyGet("nginx", appName, "hsts-max-age")
}
func ComputedHSTSMaxAge(appName string) string {
appValue := AppHSTSMaxAge(appName)
if appValue != "" {
return appValue
}
return GlobalHSTSMaxAge()
}
func GlobalHSTSMaxAge() string {
return common.PropertyGetDefault("nginx", "--global", "hsts-max-age", "15724800")
}
func AppHSTSPreload(appName string) string {
return common.PropertyGet("nginx", appName, "hsts-preload")
}
func ComputedHSTSPreload(appName string) string {
appValue := AppHSTSPreload(appName)
if appValue != "" {
return appValue
}
return GlobalHSTSPreload()
}
func GlobalHSTSPreload() string {
return common.PropertyGetDefault("nginx", "--global", "hsts-preload", "false")
}
func AppHSTS(appName string) string {
return common.PropertyGet("nginx", appName, "hsts")
}
func ComputedHSTS(appName string) string {
appValue := AppHSTS(appName)
if appValue != "" {
return appValue
}
return GlobalHSTS()
}
func GlobalHSTS() string {
return common.PropertyGetDefault("nginx", "--global", "hsts", "true")
}
func AppNginxConfSigilPath(appName string) string {
return common.PropertyGet("nginx", appName, "nginx-conf-sigil-path")
}
func ComputedNginxConfSigilPath(appName string) string {
appValue := AppNginxConfSigilPath(appName)
if appValue != "" {
return appValue
}
return GlobalNginxConfSigilPath()
}
func GlobalNginxConfSigilPath() string {
return common.PropertyGetDefault("nginx", "--global", "nginx-conf-sigil-path", "nginx.conf.sigil")
}
func AppProxyBufferSize(appName string) string {
return common.PropertyGet("nginx", appName, "proxy-buffer-size")
}
func ComputedProxyBufferSize(appName string) string {
appValue := AppProxyBufferSize(appName)
if appValue != "" {
return appValue
}
return GlobalProxyBufferSize()
}
func GlobalProxyBufferSize() string {
return common.PropertyGetDefault("nginx", "--global", "proxy-buffer-size", fmt.Sprintf("%dk", os.Getpagesize()/1024))
}
func AppProxyBuffering(appName string) string {
return common.PropertyGet("nginx", appName, "proxy-buffering")
}
func ComputedProxyBuffering(appName string) string {
appValue := AppProxyBuffering(appName)
if appValue != "" {
return appValue
}
return GlobalProxyBuffering()
}
func GlobalProxyBuffering() string {
return common.PropertyGetDefault("nginx", "--global", "proxy-buffering", "on")
}
func AppProxyBuffers(appName string) string {
return common.PropertyGet("nginx", appName, "proxy-buffers")
}
func ComputedProxyBuffers(appName string) string {
appValue := AppProxyBuffers(appName)
if appValue != "" {
return appValue
}
return GlobalProxyBuffers()
}
func GlobalProxyBuffers() string {
return common.PropertyGetDefault("nginx", "--global", "proxy-buffers", fmt.Sprintf("8 %dk", os.Getpagesize()/1024))
}
func AppProxyBusyBuffersSize(appName string) string {
return common.PropertyGet("nginx", appName, "proxy-busy-buffers-size")
}
func ComputedProxyBusyBuffersSize(appName string) string {
appValue := AppProxyBusyBuffersSize(appName)
if appValue != "" {
return appValue
}
return GlobalProxyBusyBuffersSize()
}
func GlobalProxyBusyBuffersSize() string {
return common.PropertyGetDefault("nginx", "--global", "proxy-busy-buffers-size", fmt.Sprintf("%dk", (os.Getpagesize()/1024)*2))
}
func AppProxyReadTimeout(appName string) string {
return common.PropertyGet("nginx", appName, "proxy-read-timeout")
}
func ComputedProxyReadTimeout(appName string) string {
appValue := AppProxyReadTimeout(appName)
if appValue != "" {
return appValue
}
return GlobalProxyReadTimeout()
}
func GlobalProxyReadTimeout() string {
return common.PropertyGetDefault("nginx", "--global", "proxy-read-timeout", "60s")
}
func AppXForwardedForValue(appName string) string {
return common.PropertyGet("nginx", appName, "x-forwarded-for-value")
}
func ComputedXForwardedForValue(appName string) string {
appValue := AppXForwardedForValue(appName)
if appValue != "" {
return appValue
}
return GlobalXForwardedForValue()
}
func GlobalXForwardedForValue() string {
return common.PropertyGetDefault("nginx", "--global", "x-forwarded-for-value", "$remote_addr")
}
func AppXForwardedPortValue(appName string) string {
return common.PropertyGet("nginx", appName, "x-forwarded-port-value")
}
func ComputedXForwardedPortValue(appName string) string {
appValue := AppXForwardedPortValue(appName)
if appValue != "" {
return appValue
}
return GlobalXForwardedPortValue()
}
func GlobalXForwardedPortValue() string {
return common.PropertyGetDefault("nginx", "--global", "x-forwarded-port-value", "$server_port")
}
func AppXForwardedProtoValue(appName string) string {
return common.PropertyGet("nginx", appName, "x-forwarded-proto-value")
}
func ComputedXForwardedProtoValue(appName string) string {
appValue := AppXForwardedProtoValue(appName)
if appValue != "" {
return appValue
}
return GlobalXForwardedProtoValue()
}
func GlobalXForwardedProtoValue() string {
return common.PropertyGetDefault("nginx", "--global", "x-forwarded-proto-value", "$scheme")
}
func AppXForwardedSSL(appName string) string {
return common.PropertyGet("nginx", appName, "x-forwarded-ssl")
}
func ComputedXForwardedSSL(appName string) string {
appValue := AppXForwardedSSL(appName)
if appValue != "" {
return appValue
}
return GlobalXForwardedSSL()
}
func GlobalXForwardedSSL() string {
return common.PropertyGetDefault("nginx", "--global", "x-forwarded-ssl", "")
}

View File

@@ -0,0 +1,183 @@
package main
import (
"fmt"
"os"
nginx_vhosts "github.com/dokku/dokku/plugins/nginx-vhosts"
flag "github.com/spf13/pflag"
)
func main() {
args := flag.NewFlagSet("ps:inspect", flag.ExitOnError)
appName := args.String("app", "", "app: the app to inspect")
global := args.Bool("global", false, "global: inspect global property")
computed := args.Bool("computed", false, "computed: inspect computed property")
err := args.Parse(os.Args[1:])
if err != nil {
os.Exit(1)
}
property := args.Arg(0)
var value string
if *computed {
value = computedValue(*appName, property)
} else if *global {
value = globalValue(*appName, property)
} else {
value = appValue(*appName, property)
}
fmt.Print(value)
}
func appValue(appName string, property string) string {
var value string
switch property {
case "access-log-format":
value = nginx_vhosts.AppAccessLogFormat(appName)
case "access-log-path":
value = nginx_vhosts.AppAccessLogPath(appName)
case "bind-address-ipv4":
value = nginx_vhosts.AppBindAddressIPv4(appName)
case "bind-address-ipv6":
value = nginx_vhosts.AppBindAddressIPv6(appName)
case "client-max-body-size":
value = nginx_vhosts.AppClientMaxBodySize(appName)
case "disable-custom-config":
value = nginx_vhosts.AppDisableCustomConfig(appName)
case "error-log-path":
value = nginx_vhosts.AppErrorLogPath(appName)
case "hsts-include-subdomains":
value = nginx_vhosts.AppHSTSIncludeSubdomains(appName)
case "hsts-max-age":
value = nginx_vhosts.AppHSTSMaxAge(appName)
case "hsts-preload":
value = nginx_vhosts.AppHSTSPreload(appName)
case "hsts":
value = nginx_vhosts.AppHSTS(appName)
case "nginx-conf-sigil-path":
value = nginx_vhosts.AppNginxConfSigilPath(appName)
case "proxy-buffer-size":
value = nginx_vhosts.AppProxyBufferSize(appName)
case "proxy-buffering":
value = nginx_vhosts.AppProxyBuffering(appName)
case "proxy-buffers":
value = nginx_vhosts.AppProxyBuffers(appName)
case "proxy-busy-buffers-size":
value = nginx_vhosts.AppProxyBusyBuffersSize(appName)
case "proxy-read-timeout":
value = nginx_vhosts.AppProxyReadTimeout(appName)
case "x-forwarded-for-value":
value = nginx_vhosts.AppXForwardedForValue(appName)
case "x-forwarded-port-value":
value = nginx_vhosts.AppXForwardedPortValue(appName)
case "x-forwarded-proto-value":
value = nginx_vhosts.AppXForwardedProtoValue(appName)
case "x-forwarded-ssl":
value = nginx_vhosts.AppXForwardedSSL(appName)
}
return value
}
func computedValue(appName string, property string) string {
var value string
switch property {
case "access-log-format":
value = nginx_vhosts.ComputedAccessLogFormat(appName)
case "access-log-path":
value = nginx_vhosts.ComputedAccessLogPath(appName)
case "bind-address-ipv4":
value = nginx_vhosts.ComputedBindAddressIPv4(appName)
case "bind-address-ipv6":
value = nginx_vhosts.ComputedBindAddressIPv6(appName)
case "client-max-body-size":
value = nginx_vhosts.ComputedClientMaxBodySize(appName)
case "disable-custom-config":
value = nginx_vhosts.ComputedDisableCustomConfig(appName)
case "error-log-path":
value = nginx_vhosts.ComputedErrorLogPath(appName)
case "hsts-include-subdomains":
value = nginx_vhosts.ComputedHSTSIncludeSubdomains(appName)
case "hsts-max-age":
value = nginx_vhosts.ComputedHSTSMaxAge(appName)
case "hsts-preload":
value = nginx_vhosts.ComputedHSTSPreload(appName)
case "hsts":
value = nginx_vhosts.ComputedHSTS(appName)
case "nginx-conf-sigil-path":
value = nginx_vhosts.ComputedNginxConfSigilPath(appName)
case "proxy-buffer-size":
value = nginx_vhosts.ComputedProxyBufferSize(appName)
case "proxy-buffering":
value = nginx_vhosts.ComputedProxyBuffering(appName)
case "proxy-buffers":
value = nginx_vhosts.ComputedProxyBuffers(appName)
case "proxy-busy-buffers-size":
value = nginx_vhosts.ComputedProxyBusyBuffersSize(appName)
case "proxy-read-timeout":
value = nginx_vhosts.ComputedProxyReadTimeout(appName)
case "x-forwarded-for-value":
value = nginx_vhosts.ComputedXForwardedForValue(appName)
case "x-forwarded-port-value":
value = nginx_vhosts.ComputedXForwardedPortValue(appName)
case "x-forwarded-proto-value":
value = nginx_vhosts.ComputedXForwardedProtoValue(appName)
case "x-forwarded-ssl":
value = nginx_vhosts.ComputedXForwardedSSL(appName)
}
return value
}
func globalValue(appName string, property string) string {
var value string
switch property {
case "access-log-format":
value = nginx_vhosts.GlobalAccessLogFormat()
case "access-log-path":
value = nginx_vhosts.GlobalAccessLogPath(appName)
case "bind-address-ipv4":
value = nginx_vhosts.GlobalBindAddressIPv4()
case "bind-address-ipv6":
value = nginx_vhosts.GlobalBindAddressIPv6()
case "client-max-body-size":
value = nginx_vhosts.GlobalClientMaxBodySize()
case "disable-custom-config":
value = nginx_vhosts.GlobalDisableCustomConfig()
case "error-log-path":
value = nginx_vhosts.GlobalErrorLogPath(appName)
case "hsts-include-subdomains":
value = nginx_vhosts.GlobalHSTSIncludeSubdomains()
case "hsts-max-age":
value = nginx_vhosts.GlobalHSTSMaxAge()
case "hsts-preload":
value = nginx_vhosts.GlobalHSTSPreload()
case "hsts":
value = nginx_vhosts.GlobalHSTS()
case "nginx-conf-sigil-path":
value = nginx_vhosts.GlobalNginxConfSigilPath()
case "proxy-buffer-size":
value = nginx_vhosts.GlobalProxyBufferSize()
case "proxy-buffering":
value = nginx_vhosts.GlobalProxyBuffering()
case "proxy-buffers":
value = nginx_vhosts.GlobalProxyBuffers()
case "proxy-busy-buffers-size":
value = nginx_vhosts.GlobalProxyBusyBuffersSize()
case "proxy-read-timeout":
value = nginx_vhosts.GlobalProxyReadTimeout()
case "x-forwarded-for-value":
value = nginx_vhosts.GlobalXForwardedForValue()
case "x-forwarded-port-value":
value = nginx_vhosts.GlobalXForwardedPortValue()
case "x-forwarded-proto-value":
value = nginx_vhosts.GlobalXForwardedProtoValue()
case "x-forwarded-ssl":
value = nginx_vhosts.GlobalXForwardedSSL()
}
return value
}

View File

@@ -6,5 +6,5 @@ import (
)
func main() {
fmt.Println(os.Getpagesize())
fmt.Println(os.Getpagesize() / 1024)
}

View File

@@ -154,7 +154,7 @@ fn-openresty-proxy-buffer-size() {
declare desc="get the configured proxy buffer size"
declare APP="$1"
fn-plugin-property-get-default "openresty" "$APP" "proxy-buffer-size" "$(fn-get-pagesize)"
fn-plugin-property-get-default "openresty" "$APP" "proxy-buffer-size" "$(fn-get-pagesize)k"
}
fn-openresty-proxy-buffering() {
@@ -168,14 +168,14 @@ fn-openresty-proxy-buffers() {
declare desc="get the configured proxy buffers"
declare APP="$1"
fn-plugin-property-get-default "openresty" "$APP" "proxy-buffers" "8 $(fn-get-pagesize)"
fn-plugin-property-get-default "openresty" "$APP" "proxy-buffers" "8 $(fn-get-pagesize)k"
}
fn-openresty-proxy-busy-buffers-size() {
declare desc="get the configured proxy busy buffers size"
declare APP="$1"
fn-plugin-property-get-default "openresty" "$APP" "proxy-busy-buffers-size" "$(($(fn-get-pagesize) * 2))"
fn-plugin-property-get-default "openresty" "$APP" "proxy-busy-buffers-size" "$(($(fn-get-pagesize) * 2))k"
}
fn-openresty-proxy-connect-timeout() {

View File

@@ -20,6 +20,26 @@ teardown() {
echo "status: $status"
assert_success
run /bin/bash -c "dokku nginx:show-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_output_contains "client_max_body_size 1m;"
run /bin/bash -c "dokku nginx:set $TEST_APP client-max-body-size 2m"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku proxy:build-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku nginx:show-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_output_contains "client_max_body_size 2m;"
run /bin/bash -c "dokku nginx:set $TEST_APP client-max-body-size"
echo "output: $output"
echo "status: $status"
@@ -33,22 +53,7 @@ teardown() {
run /bin/bash -c "dokku nginx:show-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_output_contains "client_max_body_size" 0
run /bin/bash -c "dokku nginx:set $TEST_APP client-max-body-size 1m"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku proxy:build-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku nginx:show-config $TEST_APP"
echo "output: $output"
echo "status: $status"
assert_output_contains "client_max_body_size 1m;" 1
assert_output_contains "client_max_body_size 1m;"
}
@test "(nginx-vhosts) nginx:set proxy-read-timeout" {