Files
traberphandClaude Opus 5.5 e70d15f861
Build image / build (push) Successful in 3m18s
Build container image in CI, bake in datasets, configure auth via env
- Dockerfile bakes the app and every CSV in data/ into an nginx image
- UI discovers data/*.csv via nginx JSON autoindex and offers a
  dropdown when there is more than one dataset
- docker-entrypoint.d/40-basic-auth.sh creates .htpasswd from
  BASIC_AUTH_USER / BASIC_AUTH_PASSWORD(_FILE) and refuses to start
  without credentials; replaces set-password.sh
- Gitea Actions workflow builds and pushes
  registry.traberph.de/public/interval_viz (latest, sha-*, semver)
- Escape resets the chart zoom

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 11:12:12 +02:00

36 lines
1.5 KiB
Bash
Executable File

#!/bin/sh
# Creates the basic-auth file for nginx from environment variables.
#
# BASIC_AUTH_USER user name
# BASIC_AUTH_PASSWORD password, or
# BASIC_AUTH_PASSWORD_FILE path to a file containing the password (e.g. a mounted secret)
#
# Without these variables an already mounted /etc/nginx/.htpasswd is used.
# If neither exists the container refuses to start, so the app is never served unprotected.
set -eu
HTPASSWD=/etc/nginx/.htpasswd
ME=$(basename "$0")
if [ -n "${BASIC_AUTH_PASSWORD_FILE:-}" ]; then
[ -r "$BASIC_AUTH_PASSWORD_FILE" ] || { echo "$ME: cannot read $BASIC_AUTH_PASSWORD_FILE" >&2; exit 1; }
BASIC_AUTH_PASSWORD=$(cat "$BASIC_AUTH_PASSWORD_FILE")
fi
if [ -n "${BASIC_AUTH_USER:-}" ] || [ -n "${BASIC_AUTH_PASSWORD:-}" ]; then
: "${BASIC_AUTH_USER:?$ME: BASIC_AUTH_USER is not set}"
: "${BASIC_AUTH_PASSWORD:?$ME: BASIC_AUTH_PASSWORD is empty}"
case "$BASIC_AUTH_USER" in *:*) echo "$ME: BASIC_AUTH_USER must not contain ':'" >&2; exit 1 ;; esac
# SHA-512 crypt; password is passed on stdin so it never shows up in the process list
hash=$(printf '%s' "$BASIC_AUTH_PASSWORD" | mkpasswd -m sha512 -P 0)
printf '%s:%s\n' "$BASIC_AUTH_USER" "$hash" > "$HTPASSWD"
chmod 644 "$HTPASSWD"
echo "$ME: basic auth configured for user '$BASIC_AUTH_USER'"
elif [ -s "$HTPASSWD" ]; then
echo "$ME: using existing $HTPASSWD"
else
echo "$ME: no credentials - set BASIC_AUTH_USER and BASIC_AUTH_PASSWORD (or mount $HTPASSWD)" >&2
exit 1
fi