Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 37s
An empty key switches the pseudonym off: no X-Client-Id is sent, and a rate limit downstream falls back to one bucket shared by every visitor. That is the one state nobody chooses on purpose and the easiest to reach by forgetting a line in a .env — so the entrypoint now fills the key in with `openssl rand -base64 32` when nothing else did. Nobody picks this value, nothing outside the container needs to know it, and no two deployments need the same one, which is what makes generating it the right default rather than a convenience. A fresh key per container start costs a reset of the downstream rate-limit buckets — invisible against a one-minute window — and makes pseudonyms from before and after unlinkable, which is the property the key exists for rather than a loss. Passing one explicitly still wins, for whoever wants pseudonyms stable across restarts or identical on two proxies. base64 and not hex, deliberately: HAProxy's hmac() decodes the key as base64, and hex would be accepted and silently decoded into something else — a usable key, but it would quietly cost the guarantee that a malformed one stops the container at configuration parsing. The base image's entrypoint is the haproxy binary with no shell in between, so the wrapper is the whole chain and execs the same binary with the same arguments. CMD is restated rather than inherited. Verified by building the image and checking the config in all three states: unset (wrapper reports it generated one, config parses), set and valid (wrapper silent, config parses), set and not base64 (`[ALERT] invalid args in converter 'hmac' : failed to parse key`, container refuses to start). READMEs updated in both languages, and "address" is spelled "IP address" throughout — it was never anything else.
29 lines
1.3 KiB
Docker
29 lines
1.3 KiB
Docker
FROM bitnami/haproxy
|
|
|
|
# Copy config
|
|
COPY ./docker/haproxy.cfg /bitnami/haproxy/conf/haproxy.cfg
|
|
|
|
# Directory for the runtime API socket. HAProxy runs as uid 1001 here and binds
|
|
# a unix socket by creating `<path>.<pid>.tmp` and renaming it over the target,
|
|
# so it needs write permission on the *directory*, not just the file — which is
|
|
# also why a stale socket left by a previous run is harmless.
|
|
#
|
|
# /var/lib is owned by root, hence the explicit USER switch. Docker copies this
|
|
# ownership onto an empty named volume when it initialises one here, so the
|
|
# volume shared with certbot comes up writable by HAProxy without a chown at
|
|
# runtime.
|
|
USER root
|
|
RUN mkdir -p /var/lib/haproxy && chown 1001:1001 /var/lib/haproxy
|
|
USER 1001
|
|
|
|
# The base image's entrypoint is the haproxy binary itself, with no shell in
|
|
# between, so this wrapper is the whole chain: it fills in XFF_HMAC_KEY when
|
|
# nothing else did (see the script for why that is better than requiring it) and
|
|
# execs the same binary with the same arguments. CMD is restated rather than
|
|
# left to inheritance — it would be inherited, but a changed ENTRYPOINT is
|
|
# exactly where that stops being obvious to the next reader.
|
|
COPY --chmod=0755 ./docker/entrypoint.sh /entrypoint.sh
|
|
ENTRYPOINT ["/entrypoint.sh"]
|
|
CMD ["-f", "/bitnami/haproxy/conf/haproxy.cfg"]
|
|
|