Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 4812621376 | |||
| 8b98706d27 | |||
| e36207347f | |||
| 5228eeaa23 |
@@ -3,6 +3,22 @@
|
|||||||
## Pending
|
## Pending
|
||||||
|
|
||||||
|
|
||||||
|
## 2026-05-24 - 1.28.0
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- add enterprise-ready App Store runtime support for declared volumes and raw published ports
|
||||||
|
- validate app template schemas before install, fail invalid port/volume declarations early, and preserve declarations across upgrades and backups
|
||||||
|
- preflight Docker/host published port conflicts and back up declared service volume data
|
||||||
|
- show App Store volume mounts and raw host port exposure before deploy
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
|
||||||
|
- fix Onebox dashboard system metrics rendering and traffic polling
|
||||||
|
- update `@serve.zone/catalog` to `^2.12.5`
|
||||||
|
- preserve an existing managed dcrouter config file instead of rewriting it on container creation
|
||||||
|
- remove stale external gateway routes during route reconciliation
|
||||||
|
|
||||||
## 2026-05-21 - 1.27.0
|
## 2026-05-21 - 1.27.0
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@serve.zone/onebox",
|
"name": "@serve.zone/onebox",
|
||||||
"version": "1.27.0",
|
"version": "1.28.0",
|
||||||
"exports": "./mod.ts",
|
"exports": "./mod.ts",
|
||||||
"tasks": {
|
"tasks": {
|
||||||
"test": "deno test --allow-all test/",
|
"test": "deno test --allow-all test/",
|
||||||
|
|||||||
+5
-5
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@serve.zone/onebox",
|
"name": "@serve.zone/onebox",
|
||||||
"version": "1.27.0",
|
"version": "1.28.0",
|
||||||
"description": "Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers",
|
"description": "Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers",
|
||||||
"main": "mod.ts",
|
"main": "mod.ts",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
@@ -58,12 +58,12 @@
|
|||||||
"@api.global/typedsocket": "^4.1.3",
|
"@api.global/typedsocket": "^4.1.3",
|
||||||
"@design.estate/dees-catalog": "^3.81.0",
|
"@design.estate/dees-catalog": "^3.81.0",
|
||||||
"@design.estate/dees-element": "^2.2.4",
|
"@design.estate/dees-element": "^2.2.4",
|
||||||
"@serve.zone/catalog": "^2.12.4"
|
"@serve.zone/catalog": "^2.12.5"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@git.zone/tsbundle": "^2.10.1",
|
"@git.zone/tsbundle": "^2.10.4",
|
||||||
"@git.zone/tsdeno": "^1.3.1",
|
"@git.zone/tsdeno": "^1.3.2",
|
||||||
"@git.zone/tswatch": "^3.3.3"
|
"@git.zone/tswatch": "^3.3.5"
|
||||||
},
|
},
|
||||||
"private": true,
|
"private": true,
|
||||||
"pnpm": {
|
"pnpm": {
|
||||||
|
|||||||
Generated
+429
-222
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,113 @@
|
|||||||
|
import { assertEquals, assertThrows } from '@std/assert';
|
||||||
|
|
||||||
|
import { AppStoreManager } from '../ts/classes/appstore.ts';
|
||||||
|
import { OneboxDockerManager } from '../ts/classes/docker.ts';
|
||||||
|
import type { IAppVersionConfig } from '../ts/classes/appstore-types.ts';
|
||||||
|
import type { IService } from '../ts/types.ts';
|
||||||
|
|
||||||
|
const createAppStore = () => new AppStoreManager({} as any);
|
||||||
|
|
||||||
|
const baseConfig: IAppVersionConfig = {
|
||||||
|
image: 'example/app:1.0.0',
|
||||||
|
port: 3000,
|
||||||
|
envVars: [
|
||||||
|
{
|
||||||
|
key: 'APP_PORT',
|
||||||
|
value: '3000',
|
||||||
|
description: 'Application port',
|
||||||
|
required: true,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
const baseService: IService = {
|
||||||
|
id: 1,
|
||||||
|
name: 'test-service',
|
||||||
|
image: 'example/app:1.0.0',
|
||||||
|
envVars: {},
|
||||||
|
port: 3000,
|
||||||
|
status: 'stopped',
|
||||||
|
createdAt: Date.now(),
|
||||||
|
updatedAt: Date.now(),
|
||||||
|
};
|
||||||
|
|
||||||
|
Deno.test('appstore normalizes and validates app template runtime fields', () => {
|
||||||
|
const appStore = createAppStore();
|
||||||
|
|
||||||
|
const normalizedVolumes = appStore.normalizeVolumes([
|
||||||
|
'/data/app',
|
||||||
|
{ mountPath: '/config', readOnly: true },
|
||||||
|
]);
|
||||||
|
|
||||||
|
assertEquals(normalizedVolumes, [
|
||||||
|
{ mountPath: '/data/app' },
|
||||||
|
{ mountPath: '/config', readOnly: true },
|
||||||
|
]);
|
||||||
|
|
||||||
|
appStore.validateAppVersionConfig({
|
||||||
|
...baseConfig,
|
||||||
|
volumes: normalizedVolumes,
|
||||||
|
publishedPorts: [
|
||||||
|
{ targetPort: 3000, publishedPort: 3000, protocol: 'tcp' },
|
||||||
|
{ targetPort: 20000, targetPortEnd: 20002, publishedPort: 20000, publishedPortEnd: 20002, protocol: 'udp' },
|
||||||
|
],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
Deno.test('appstore rejects invalid template ports and volumes', () => {
|
||||||
|
const appStore = createAppStore();
|
||||||
|
|
||||||
|
assertThrows(
|
||||||
|
() => appStore.validateAppVersionConfig({ ...baseConfig, port: 70000 }),
|
||||||
|
Error,
|
||||||
|
'Invalid app config port',
|
||||||
|
);
|
||||||
|
|
||||||
|
assertThrows(
|
||||||
|
() => appStore.normalizeVolumes([{ mountPath: 'relative/path' }]),
|
||||||
|
Error,
|
||||||
|
'mountPath must be an absolute path',
|
||||||
|
);
|
||||||
|
|
||||||
|
assertThrows(
|
||||||
|
() => appStore.validateAppVersionConfig({
|
||||||
|
...baseConfig,
|
||||||
|
publishedPorts: [
|
||||||
|
{ targetPort: 3000, targetPortEnd: 3002, publishedPort: 3000, publishedPortEnd: 3001, protocol: 'tcp' },
|
||||||
|
],
|
||||||
|
}),
|
||||||
|
Error,
|
||||||
|
'ranges must have the same size',
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
Deno.test('docker service spec validation rejects unsafe volume and port declarations', () => {
|
||||||
|
const dockerManager = new OneboxDockerManager();
|
||||||
|
|
||||||
|
dockerManager.validateServiceSpec({
|
||||||
|
...baseService,
|
||||||
|
volumes: [{ mountPath: '/data/app' }],
|
||||||
|
publishedPorts: [{ targetPort: 3000, publishedPort: 3000, protocol: 'tcp' }],
|
||||||
|
});
|
||||||
|
|
||||||
|
assertThrows(
|
||||||
|
() => dockerManager.validateServiceSpec({
|
||||||
|
...baseService,
|
||||||
|
volumes: [{ mountPath: 'relative/path' }],
|
||||||
|
}),
|
||||||
|
Error,
|
||||||
|
'must be an absolute path',
|
||||||
|
);
|
||||||
|
|
||||||
|
assertThrows(
|
||||||
|
() => dockerManager.validateServiceSpec({
|
||||||
|
...baseService,
|
||||||
|
publishedPorts: [
|
||||||
|
{ targetPort: 3001, publishedPort: 3000, hostIp: '127.0.0.1', protocol: 'tcp' },
|
||||||
|
{ targetPort: 3000, publishedPort: 3000, protocol: 'tcp' },
|
||||||
|
],
|
||||||
|
}),
|
||||||
|
Error,
|
||||||
|
'Duplicate published port',
|
||||||
|
);
|
||||||
|
});
|
||||||
@@ -7,6 +7,7 @@ class FakeDatabase {
|
|||||||
public settings = new Map<string, string>();
|
public settings = new Map<string, string>();
|
||||||
public secretSettings = new Map<string, string>();
|
public secretSettings = new Map<string, string>();
|
||||||
public domains: IDomain[] = [];
|
public domains: IDomain[] = [];
|
||||||
|
public services: IService[] = [];
|
||||||
public certificates = new Map<string, ISslCertificate>();
|
public certificates = new Map<string, ISslCertificate>();
|
||||||
private nextDomainId = 1;
|
private nextDomainId = 1;
|
||||||
|
|
||||||
@@ -42,6 +43,10 @@ class FakeDatabase {
|
|||||||
return this.domains.filter((entry) => entry.dnsProvider === provider);
|
return this.domains.filter((entry) => entry.dnsProvider === provider);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
getAllServices(): IService[] {
|
||||||
|
return this.services;
|
||||||
|
}
|
||||||
|
|
||||||
getSSLCertificate(domain: string): ISslCertificate | null {
|
getSSLCertificate(domain: string): ISslCertificate | null {
|
||||||
return this.certificates.get(domain) ?? null;
|
return this.certificates.get(domain) ?? null;
|
||||||
}
|
}
|
||||||
@@ -241,6 +246,82 @@ Deno.test('ExternalGatewayManager deletes service routes through dcrouter gatewa
|
|||||||
assertEquals((capturedDeleteRequest.ownership as any).hostname, 'hello.example.com');
|
assertEquals((capturedDeleteRequest.ownership as any).hostname, 'hello.example.com');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
Deno.test('ExternalGatewayManager removes stale gateway routes during reconciliation', async () => {
|
||||||
|
const oneboxRef = makeOneboxRef();
|
||||||
|
oneboxRef.database.settings.set('serverIP', '203.0.113.10');
|
||||||
|
oneboxRef.database.services.push({
|
||||||
|
id: 1,
|
||||||
|
name: 'active',
|
||||||
|
image: 'nginx:latest',
|
||||||
|
envVars: {},
|
||||||
|
port: 3000,
|
||||||
|
domain: 'active.example.com',
|
||||||
|
status: 'running',
|
||||||
|
createdAt: 1,
|
||||||
|
updatedAt: 1,
|
||||||
|
});
|
||||||
|
|
||||||
|
const deletes: Record<string, unknown>[] = [];
|
||||||
|
const manager = new ExternalGatewayManager(oneboxRef as any);
|
||||||
|
(manager as any).fireDcRouterRequest = async (method: string, requestData: Record<string, unknown>) => {
|
||||||
|
if (method === 'getGatewayClientContext') {
|
||||||
|
return { context: { role: 'gatewayClient', gatewayClient: { type: 'onebox', id: 'onebox-token' } } };
|
||||||
|
}
|
||||||
|
if (method === 'syncGatewayClientRoute') {
|
||||||
|
if (requestData.delete) {
|
||||||
|
deletes.push(requestData);
|
||||||
|
return { success: true, action: 'deleted' };
|
||||||
|
}
|
||||||
|
return { success: true, action: 'updated', routeId: 'active-route' };
|
||||||
|
}
|
||||||
|
if (method === 'exportCertificate') {
|
||||||
|
return { success: false };
|
||||||
|
}
|
||||||
|
if (method === 'getGatewayClientDnsRecords') {
|
||||||
|
return {
|
||||||
|
records: [
|
||||||
|
{
|
||||||
|
id: 'active-record',
|
||||||
|
domainId: 'domain-1',
|
||||||
|
name: 'active',
|
||||||
|
type: 'A',
|
||||||
|
value: '203.0.113.10',
|
||||||
|
ttl: 300,
|
||||||
|
source: 'route',
|
||||||
|
status: 'active',
|
||||||
|
gatewayClientType: 'onebox',
|
||||||
|
gatewayClientId: 'onebox-token',
|
||||||
|
appId: 'active',
|
||||||
|
hostname: 'active.example.com',
|
||||||
|
routeId: 'active-route',
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: 'stale-record',
|
||||||
|
domainId: 'domain-1',
|
||||||
|
name: 'stale',
|
||||||
|
type: 'A',
|
||||||
|
value: '203.0.113.10',
|
||||||
|
ttl: 300,
|
||||||
|
source: 'route',
|
||||||
|
status: 'active',
|
||||||
|
gatewayClientType: 'onebox',
|
||||||
|
gatewayClientId: 'onebox-token',
|
||||||
|
appId: 'stale',
|
||||||
|
hostname: 'stale.example.com',
|
||||||
|
routeId: 'stale-route',
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
throw new Error(`Unexpected method: ${method}`);
|
||||||
|
};
|
||||||
|
|
||||||
|
await manager.syncServiceRoutes();
|
||||||
|
|
||||||
|
assertEquals(deletes.length, 1);
|
||||||
|
assertEquals((deletes[0].ownership as any).hostname, 'stale.example.com');
|
||||||
|
});
|
||||||
|
|
||||||
Deno.test('ExternalGatewayManager imports exported dcrouter certificates into Onebox', async () => {
|
Deno.test('ExternalGatewayManager imports exported dcrouter certificates into Onebox', async () => {
|
||||||
const oneboxRef = makeOneboxRef();
|
const oneboxRef = makeOneboxRef();
|
||||||
const manager = new ExternalGatewayManager(oneboxRef as any);
|
const manager = new ExternalGatewayManager(oneboxRef as any);
|
||||||
|
|||||||
@@ -3,6 +3,6 @@
|
|||||||
*/
|
*/
|
||||||
export const commitinfo = {
|
export const commitinfo = {
|
||||||
name: '@serve.zone/onebox',
|
name: '@serve.zone/onebox',
|
||||||
version: '1.27.0',
|
version: '1.28.0',
|
||||||
description: 'Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers'
|
description: 'Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers'
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -19,6 +19,27 @@ export interface ICatalogApp {
|
|||||||
tags?: string[];
|
tags?: string[];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IAppCatalogVolume {
|
||||||
|
name?: string;
|
||||||
|
source?: string;
|
||||||
|
mountPath: string;
|
||||||
|
driver?: string;
|
||||||
|
readOnly?: boolean;
|
||||||
|
backup?: boolean;
|
||||||
|
options?: Record<string, string>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TAppCatalogVolumeSpec = string | IAppCatalogVolume;
|
||||||
|
|
||||||
|
export interface IAppCatalogPublishedPort {
|
||||||
|
targetPort: number;
|
||||||
|
targetPortEnd?: number;
|
||||||
|
publishedPort?: number;
|
||||||
|
publishedPortEnd?: number;
|
||||||
|
protocol?: 'tcp' | 'udp';
|
||||||
|
hostIp?: string;
|
||||||
|
}
|
||||||
|
|
||||||
export interface IAppMeta {
|
export interface IAppMeta {
|
||||||
id: string;
|
id: string;
|
||||||
name: string;
|
name: string;
|
||||||
@@ -35,7 +56,8 @@ export interface IAppVersionConfig {
|
|||||||
image: string;
|
image: string;
|
||||||
port: number;
|
port: number;
|
||||||
envVars?: Array<{ key: string; value: string; description: string; required?: boolean }>;
|
envVars?: Array<{ key: string; value: string; description: string; required?: boolean }>;
|
||||||
volumes?: string[];
|
volumes?: TAppCatalogVolumeSpec[];
|
||||||
|
publishedPorts?: IAppCatalogPublishedPort[];
|
||||||
platformRequirements?: {
|
platformRequirements?: {
|
||||||
mongodb?: boolean;
|
mongodb?: boolean;
|
||||||
s3?: boolean;
|
s3?: boolean;
|
||||||
@@ -46,6 +68,17 @@ export interface IAppVersionConfig {
|
|||||||
minOneboxVersion?: string;
|
minOneboxVersion?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IAppInstallOptions {
|
||||||
|
appId: string;
|
||||||
|
version?: string;
|
||||||
|
serviceName: string;
|
||||||
|
domain?: string;
|
||||||
|
port?: number;
|
||||||
|
publishedPorts?: IAppCatalogPublishedPort[];
|
||||||
|
envVars?: Record<string, string>;
|
||||||
|
autoDNS?: boolean;
|
||||||
|
}
|
||||||
|
|
||||||
export interface IMigrationContext {
|
export interface IMigrationContext {
|
||||||
service: {
|
service: {
|
||||||
name: string;
|
name: string;
|
||||||
@@ -61,6 +94,9 @@ export interface IMigrationResult {
|
|||||||
success: boolean;
|
success: boolean;
|
||||||
envVars?: Record<string, string>;
|
envVars?: Record<string, string>;
|
||||||
image?: string;
|
image?: string;
|
||||||
|
port?: number;
|
||||||
|
volumes?: IAppCatalogVolume[];
|
||||||
|
publishedPorts?: IAppCatalogPublishedPort[];
|
||||||
warnings: string[];
|
warnings: string[];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+225
-2
@@ -8,6 +8,8 @@ import type {
|
|||||||
ICatalog,
|
ICatalog,
|
||||||
ICatalogApp,
|
ICatalogApp,
|
||||||
IAppMeta,
|
IAppMeta,
|
||||||
|
IAppCatalogVolume,
|
||||||
|
IAppInstallOptions,
|
||||||
IAppVersionConfig,
|
IAppVersionConfig,
|
||||||
IMigrationContext,
|
IMigrationContext,
|
||||||
IMigrationResult,
|
IMigrationResult,
|
||||||
@@ -16,7 +18,8 @@ import type {
|
|||||||
import { logger } from '../logging.ts';
|
import { logger } from '../logging.ts';
|
||||||
import { getErrorMessage } from '../utils/error.ts';
|
import { getErrorMessage } from '../utils/error.ts';
|
||||||
import type { Onebox } from './onebox.ts';
|
import type { Onebox } from './onebox.ts';
|
||||||
import type { IService } from '../types.ts';
|
import type { IService, IServiceVolume } from '../types.ts';
|
||||||
|
import { projectInfo } from '../info.ts';
|
||||||
|
|
||||||
export class AppStoreManager {
|
export class AppStoreManager {
|
||||||
private oneboxRef: Onebox;
|
private oneboxRef: Onebox;
|
||||||
@@ -90,12 +93,50 @@ export class AppStoreManager {
|
|||||||
*/
|
*/
|
||||||
async getAppVersionConfig(appId: string, version: string): Promise<IAppVersionConfig> {
|
async getAppVersionConfig(appId: string, version: string): Promise<IAppVersionConfig> {
|
||||||
try {
|
try {
|
||||||
return await this.fetchJson(`apps/${appId}/versions/${version}/config.json`) as IAppVersionConfig;
|
const config = await this.fetchJson(`apps/${appId}/versions/${version}/config.json`) as IAppVersionConfig;
|
||||||
|
this.validateAppVersionConfig(config, `${appId}@${version}`);
|
||||||
|
return config;
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new Error(`Failed to fetch config for ${appId}@${version}: ${getErrorMessage(error)}`);
|
throw new Error(`Failed to fetch config for ${appId}@${version}: ${getErrorMessage(error)}`);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async installApp(optionsArg: IAppInstallOptions): Promise<IService> {
|
||||||
|
this.validateInstallOptions(optionsArg);
|
||||||
|
const appMeta = await this.getAppMeta(optionsArg.appId);
|
||||||
|
const version = optionsArg.version || appMeta.latestVersion;
|
||||||
|
const config = await this.getAppVersionConfig(optionsArg.appId, version);
|
||||||
|
this.assertRuntimeCompatibility(config);
|
||||||
|
const servicePort = optionsArg.port || config.port;
|
||||||
|
this.assertValidPort(servicePort, 'install service port');
|
||||||
|
const volumes = this.normalizeVolumes(config.volumes);
|
||||||
|
const publishedPorts = optionsArg.publishedPorts || config.publishedPorts || [];
|
||||||
|
this.validatePublishedPorts(publishedPorts, `${optionsArg.appId}@${version}`);
|
||||||
|
|
||||||
|
const envVars = this.getAppStoreEnvVars(config, optionsArg.envVars || {});
|
||||||
|
if (this.requiresTemplateValue(envVars, 'SERVICE_DOMAIN') && !optionsArg.domain) {
|
||||||
|
throw new Error('A domain is required because the app template uses ${SERVICE_DOMAIN}');
|
||||||
|
}
|
||||||
|
|
||||||
|
return await this.oneboxRef.services.deployService({
|
||||||
|
name: optionsArg.serviceName,
|
||||||
|
image: config.image,
|
||||||
|
port: servicePort,
|
||||||
|
domain: optionsArg.domain,
|
||||||
|
autoDNS: optionsArg.autoDNS,
|
||||||
|
envVars,
|
||||||
|
volumes,
|
||||||
|
publishedPorts,
|
||||||
|
enableMongoDB: Boolean(config.platformRequirements?.mongodb),
|
||||||
|
enableS3: Boolean(config.platformRequirements?.s3),
|
||||||
|
enableClickHouse: Boolean(config.platformRequirements?.clickhouse),
|
||||||
|
enableRedis: Boolean(config.platformRequirements?.redis),
|
||||||
|
enableMariaDB: Boolean(config.platformRequirements?.mariadb),
|
||||||
|
appTemplateId: optionsArg.appId,
|
||||||
|
appTemplateVersion: version,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Compare deployed services against catalog to find those with available upgrades
|
* Compare deployed services against catalog to find those with available upgrades
|
||||||
*/
|
*/
|
||||||
@@ -165,6 +206,9 @@ export class AppStoreManager {
|
|||||||
return {
|
return {
|
||||||
success: true,
|
success: true,
|
||||||
image: config.image,
|
image: config.image,
|
||||||
|
port: config.port,
|
||||||
|
volumes: this.normalizeVolumes(config.volumes),
|
||||||
|
publishedPorts: config.publishedPorts,
|
||||||
envVars: undefined, // Keep existing env vars
|
envVars: undefined, // Keep existing env vars
|
||||||
warnings: [],
|
warnings: [],
|
||||||
};
|
};
|
||||||
@@ -265,6 +309,18 @@ export class AppStoreManager {
|
|||||||
updates.image = migrationResult.image;
|
updates.image = migrationResult.image;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (migrationResult.port) {
|
||||||
|
updates.port = migrationResult.port;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (migrationResult.volumes) {
|
||||||
|
updates.volumes = migrationResult.volumes;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (migrationResult.publishedPorts) {
|
||||||
|
updates.publishedPorts = migrationResult.publishedPorts;
|
||||||
|
}
|
||||||
|
|
||||||
if (migrationResult.envVars) {
|
if (migrationResult.envVars) {
|
||||||
// Merge: migration result provides base, user overrides preserved
|
// Merge: migration result provides base, user overrides preserved
|
||||||
const mergedEnvVars = { ...migrationResult.envVars };
|
const mergedEnvVars = { ...migrationResult.envVars };
|
||||||
@@ -332,4 +388,171 @@ export class AppStoreManager {
|
|||||||
}
|
}
|
||||||
return response.text();
|
return response.text();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public normalizeVolumes(volumesArg: IAppVersionConfig['volumes'] = []): IServiceVolume[] {
|
||||||
|
return volumesArg.map((volumeArg, indexArg): IAppCatalogVolume => {
|
||||||
|
if (typeof volumeArg === 'string') {
|
||||||
|
return { mountPath: volumeArg };
|
||||||
|
}
|
||||||
|
return volumeArg;
|
||||||
|
}).map((volumeArg, indexArg) => {
|
||||||
|
this.validateVolume(volumeArg, `volume ${indexArg + 1}`);
|
||||||
|
return volumeArg;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public validateAppVersionConfig(configArg: IAppVersionConfig, labelArg = 'app config'): void {
|
||||||
|
if (!configArg || typeof configArg !== 'object') {
|
||||||
|
throw new Error(`Invalid ${labelArg}: config must be an object`);
|
||||||
|
}
|
||||||
|
if (!configArg.image || typeof configArg.image !== 'string') {
|
||||||
|
throw new Error(`Invalid ${labelArg}: image is required`);
|
||||||
|
}
|
||||||
|
if (configArg.image.endsWith(':latest')) {
|
||||||
|
logger.warn(`App template ${labelArg} uses a mutable ':latest' image tag`);
|
||||||
|
}
|
||||||
|
this.assertValidPort(configArg.port, `${labelArg} port`);
|
||||||
|
|
||||||
|
for (const envVar of configArg.envVars || []) {
|
||||||
|
if (!envVar.key || !/^[A-Z_][A-Z0-9_]*$/.test(envVar.key)) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: env var key '${envVar.key}' is not valid`);
|
||||||
|
}
|
||||||
|
if (envVar.value !== undefined && typeof envVar.value !== 'string') {
|
||||||
|
throw new Error(`Invalid ${labelArg}: env var '${envVar.key}' value must be a string`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
this.normalizeVolumes(configArg.volumes);
|
||||||
|
this.validatePublishedPorts(configArg.publishedPorts || [], labelArg);
|
||||||
|
}
|
||||||
|
|
||||||
|
private validateInstallOptions(optionsArg: IAppInstallOptions): void {
|
||||||
|
if (!optionsArg.appId || !/^[a-z0-9][a-z0-9-]*$/.test(optionsArg.appId)) {
|
||||||
|
throw new Error(`Invalid app id: ${optionsArg.appId}`);
|
||||||
|
}
|
||||||
|
if (!optionsArg.serviceName || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,119}$/.test(optionsArg.serviceName)) {
|
||||||
|
throw new Error(`Invalid service name: ${optionsArg.serviceName}`);
|
||||||
|
}
|
||||||
|
if (optionsArg.port !== undefined) {
|
||||||
|
this.assertValidPort(optionsArg.port, 'install service port');
|
||||||
|
}
|
||||||
|
if (optionsArg.publishedPorts) {
|
||||||
|
this.validatePublishedPorts(optionsArg.publishedPorts, `install options for ${optionsArg.appId}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private validateVolume(volumeArg: IAppCatalogVolume, labelArg: string): void {
|
||||||
|
if (!volumeArg.mountPath || !volumeArg.mountPath.startsWith('/')) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: mountPath must be an absolute path`);
|
||||||
|
}
|
||||||
|
if (volumeArg.mountPath.includes(':')) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: mountPath must not contain ':'`);
|
||||||
|
}
|
||||||
|
if ((volumeArg.source || volumeArg.name)?.includes(':')) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: source/name must not contain ':'`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private validatePublishedPorts(
|
||||||
|
publishedPortsArg: IAppVersionConfig['publishedPorts'] = [],
|
||||||
|
labelArg: string,
|
||||||
|
): void {
|
||||||
|
const seenPublishedPorts = new Set<string>();
|
||||||
|
for (const portArg of publishedPortsArg) {
|
||||||
|
const protocol = portArg.protocol || 'tcp';
|
||||||
|
const targetStart = portArg.targetPort;
|
||||||
|
const targetEnd = portArg.targetPortEnd || targetStart;
|
||||||
|
const publishedStart = portArg.publishedPort || targetStart;
|
||||||
|
const publishedEnd = portArg.publishedPortEnd || (publishedStart + (targetEnd - targetStart));
|
||||||
|
const hostIp = portArg.hostIp || '0.0.0.0';
|
||||||
|
|
||||||
|
if (!['tcp', 'udp'].includes(protocol)) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: published port protocol '${protocol}' is not supported`);
|
||||||
|
}
|
||||||
|
this.assertValidPort(targetStart, `${labelArg} targetPort`);
|
||||||
|
this.assertValidPort(targetEnd, `${labelArg} targetPortEnd`);
|
||||||
|
this.assertValidPort(publishedStart, `${labelArg} publishedPort`);
|
||||||
|
this.assertValidPort(publishedEnd, `${labelArg} publishedPortEnd`);
|
||||||
|
if (targetEnd < targetStart || publishedEnd < publishedStart) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: published port ranges must be ascending`);
|
||||||
|
}
|
||||||
|
if ((targetEnd - targetStart) !== (publishedEnd - publishedStart)) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: target and published port ranges must have the same size`);
|
||||||
|
}
|
||||||
|
if ((targetEnd - targetStart) > 1000) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: published port ranges may not exceed 1001 ports`);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (let offset = 0; offset <= targetEnd - targetStart; offset++) {
|
||||||
|
const publishedPort = publishedStart + offset;
|
||||||
|
const publishedKey = `${hostIp}/${protocol}/${publishedPort}`;
|
||||||
|
const wildcardKey = `0.0.0.0/${protocol}/${publishedPort}`;
|
||||||
|
const conflictsWithWildcard = hostIp === '0.0.0.0'
|
||||||
|
? Array.from(seenPublishedPorts).some((keyArg) => keyArg.endsWith(`/${protocol}/${publishedPort}`))
|
||||||
|
: seenPublishedPorts.has(wildcardKey);
|
||||||
|
if (seenPublishedPorts.has(publishedKey) || conflictsWithWildcard) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: duplicate published port ${hostIp}:${publishedPort}/${protocol}`);
|
||||||
|
}
|
||||||
|
seenPublishedPorts.add(publishedKey);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private assertValidPort(portArg: number, labelArg: string): void {
|
||||||
|
if (!Number.isInteger(portArg) || portArg < 1 || portArg > 65535) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: ${portArg}. Expected an integer port between 1 and 65535.`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private getAppStoreEnvVars(
|
||||||
|
configArg: IAppVersionConfig,
|
||||||
|
overridesArg: Record<string, string>,
|
||||||
|
): Record<string, string> {
|
||||||
|
const envVars: Record<string, string> = {};
|
||||||
|
const missingRequiredEnvVars: string[] = [];
|
||||||
|
|
||||||
|
for (const envVar of configArg.envVars || []) {
|
||||||
|
const value = overridesArg[envVar.key] ?? envVar.value ?? '';
|
||||||
|
if (envVar.required && !value) {
|
||||||
|
missingRequiredEnvVars.push(envVar.key);
|
||||||
|
}
|
||||||
|
envVars[envVar.key] = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const [key, value] of Object.entries(overridesArg)) {
|
||||||
|
envVars[key] = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (missingRequiredEnvVars.length > 0) {
|
||||||
|
throw new Error(
|
||||||
|
`Missing required app env var(s): ${missingRequiredEnvVars.join(', ')}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return envVars;
|
||||||
|
}
|
||||||
|
|
||||||
|
private requiresTemplateValue(envVarsArg: Record<string, string>, templateNameArg: string): boolean {
|
||||||
|
return Object.values(envVarsArg).some((value) => value.includes(`\${${templateNameArg}}`));
|
||||||
|
}
|
||||||
|
|
||||||
|
private assertRuntimeCompatibility(configArg: IAppVersionConfig): void {
|
||||||
|
if (!configArg.minOneboxVersion) return;
|
||||||
|
if (this.compareVersions(projectInfo.version, configArg.minOneboxVersion) < 0) {
|
||||||
|
throw new Error(
|
||||||
|
`App requires Onebox >= ${configArg.minOneboxVersion}; current version is ${projectInfo.version}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private compareVersions(versionAArg: string, versionBArg: string): number {
|
||||||
|
const normalize = (versionArg: string) => versionArg.replace(/^v/, '').split('.').map((partArg) => Number(partArg) || 0);
|
||||||
|
const a = normalize(versionAArg);
|
||||||
|
const b = normalize(versionBArg);
|
||||||
|
for (let i = 0; i < Math.max(a.length, b.length); i++) {
|
||||||
|
const diff = (a[i] || 0) - (b[i] || 0);
|
||||||
|
if (diff !== 0) return diff > 0 ? 1 : -1;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -185,7 +185,12 @@ export class BackupManager {
|
|||||||
await this.exportDockerImage(service.image, `${tempDir}/data/image/image.tar`);
|
await this.exportDockerImage(service.image, `${tempDir}/data/image/image.tar`);
|
||||||
}
|
}
|
||||||
|
|
||||||
// 4. Build ingest items from temp directory files
|
// 4. Export declared service volume data when the volume opts into backup.
|
||||||
|
if (service.volumes?.some((volumeArg) => volumeArg.backup !== false)) {
|
||||||
|
await this.exportServiceVolumes(service, tempDir);
|
||||||
|
}
|
||||||
|
|
||||||
|
// 5. Build ingest items from temp directory files
|
||||||
const items: Array<{ stream: NodeJS.ReadableStream; name: string; type?: string }> = [];
|
const items: Array<{ stream: NodeJS.ReadableStream; name: string; type?: string }> = [];
|
||||||
|
|
||||||
// Service config
|
// Service config
|
||||||
@@ -218,6 +223,19 @@ export class BackupManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const volumeDataDir = `${tempDir}/data/volumes`;
|
||||||
|
try {
|
||||||
|
for await (const filePath of this.walkFiles(volumeDataDir)) {
|
||||||
|
items.push({
|
||||||
|
stream: plugins.nodeFs.createReadStream(filePath),
|
||||||
|
name: plugins.path.relative(tempDir, filePath).replaceAll('\\', '/'),
|
||||||
|
type: 'volume',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// No service volume data was exported.
|
||||||
|
}
|
||||||
|
|
||||||
// Docker image
|
// Docker image
|
||||||
if (includeImage && service.image) {
|
if (includeImage && service.image) {
|
||||||
const imagePath = `${tempDir}/data/image/image.tar`;
|
const imagePath = `${tempDir}/data/image/image.tar`;
|
||||||
@@ -233,7 +251,7 @@ export class BackupManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// 5. Build snapshot tags
|
// 6. Build snapshot tags
|
||||||
const tags: Record<string, string> = {
|
const tags: Record<string, string> = {
|
||||||
serviceName: service.name,
|
serviceName: service.name,
|
||||||
serviceId: String(service.id),
|
serviceId: String(service.id),
|
||||||
@@ -245,10 +263,10 @@ export class BackupManager {
|
|||||||
tags.scheduleId = String(options.scheduleId);
|
tags.scheduleId = String(options.scheduleId);
|
||||||
}
|
}
|
||||||
|
|
||||||
// 6. Ingest multi-item snapshot into containerarchive
|
// 7. Ingest multi-item snapshot into containerarchive
|
||||||
const snapshot = await this.archive.ingestMulti(items, { tags });
|
const snapshot = await this.archive.ingestMulti(items, { tags });
|
||||||
|
|
||||||
// 7. Store backup record in database
|
// 8. Store backup record in database
|
||||||
const backup: IBackup = {
|
const backup: IBackup = {
|
||||||
serviceId: service.id!,
|
serviceId: service.id!,
|
||||||
serviceName: service.name,
|
serviceName: service.name,
|
||||||
@@ -675,6 +693,8 @@ export class BackupManager {
|
|||||||
registry: serviceConfig.registry,
|
registry: serviceConfig.registry,
|
||||||
port: serviceConfig.port,
|
port: serviceConfig.port,
|
||||||
domain: serviceConfig.domain,
|
domain: serviceConfig.domain,
|
||||||
|
volumes: serviceConfig.volumes,
|
||||||
|
publishedPorts: serviceConfig.publishedPorts,
|
||||||
useOneboxRegistry: serviceConfig.useOneboxRegistry,
|
useOneboxRegistry: serviceConfig.useOneboxRegistry,
|
||||||
registryRepository: serviceConfig.registryRepository,
|
registryRepository: serviceConfig.registryRepository,
|
||||||
registryImageTag: serviceConfig.registryImageTag,
|
registryImageTag: serviceConfig.registryImageTag,
|
||||||
@@ -705,6 +725,8 @@ export class BackupManager {
|
|||||||
port: serviceConfig.port,
|
port: serviceConfig.port,
|
||||||
domain: options.mode === 'clone' ? undefined : serviceConfig.domain,
|
domain: options.mode === 'clone' ? undefined : serviceConfig.domain,
|
||||||
envVars: serviceConfig.envVars,
|
envVars: serviceConfig.envVars,
|
||||||
|
volumes: serviceConfig.volumes,
|
||||||
|
publishedPorts: serviceConfig.publishedPorts,
|
||||||
useOneboxRegistry: serviceConfig.useOneboxRegistry,
|
useOneboxRegistry: serviceConfig.useOneboxRegistry,
|
||||||
registryImageTag: serviceConfig.registryImageTag,
|
registryImageTag: serviceConfig.registryImageTag,
|
||||||
autoUpdateOnPush: serviceConfig.autoUpdateOnPush,
|
autoUpdateOnPush: serviceConfig.autoUpdateOnPush,
|
||||||
@@ -729,6 +751,8 @@ export class BackupManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
await this.restoreServiceVolumes(service, serviceConfig.volumes || [], tempDir, warnings);
|
||||||
|
|
||||||
// Cleanup
|
// Cleanup
|
||||||
await Deno.remove(tempDir, { recursive: true });
|
await Deno.remove(tempDir, { recursive: true });
|
||||||
|
|
||||||
@@ -791,6 +815,8 @@ export class BackupManager {
|
|||||||
image: service.image,
|
image: service.image,
|
||||||
registry: service.registry,
|
registry: service.registry,
|
||||||
envVars: service.envVars,
|
envVars: service.envVars,
|
||||||
|
volumes: service.volumes,
|
||||||
|
publishedPorts: service.publishedPorts,
|
||||||
port: service.port,
|
port: service.port,
|
||||||
domain: service.domain,
|
domain: service.domain,
|
||||||
useOneboxRegistry: service.useOneboxRegistry,
|
useOneboxRegistry: service.useOneboxRegistry,
|
||||||
@@ -802,6 +828,62 @@ export class BackupManager {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private getVolumeBackupName(volumeArg: { mountPath: string }, indexArg: number): string {
|
||||||
|
const safeMountPath = volumeArg.mountPath
|
||||||
|
.replace(/^\/+/, '')
|
||||||
|
.replace(/\/+$/g, '')
|
||||||
|
.replace(/[^a-zA-Z0-9_.-]+/g, '-') || 'root';
|
||||||
|
return `${String(indexArg).padStart(3, '0')}-${safeMountPath}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
private async exportServiceVolumes(serviceArg: IService, tempDirArg: string): Promise<void> {
|
||||||
|
if (!serviceArg.containerID) {
|
||||||
|
throw new Error(`Cannot export service volumes for ${serviceArg.name}: service has no container ID`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const volumes = (serviceArg.volumes || []).filter((volumeArg) => volumeArg.backup !== false);
|
||||||
|
for (let i = 0; i < volumes.length; i++) {
|
||||||
|
const volume = volumes[i];
|
||||||
|
const backupName = this.getVolumeBackupName(volume, i);
|
||||||
|
const outputPath = `${tempDirArg}/data/volumes/${backupName}`;
|
||||||
|
await Deno.mkdir(outputPath, { recursive: true });
|
||||||
|
await this.copyFromContainer(serviceArg.containerID, `${volume.mountPath}/.`, outputPath);
|
||||||
|
logger.info(`Exported volume ${volume.mountPath} for service ${serviceArg.name}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private async restoreServiceVolumes(
|
||||||
|
serviceArg: IService,
|
||||||
|
volumesArg: NonNullable<IBackupServiceConfig['volumes']>,
|
||||||
|
tempDirArg: string,
|
||||||
|
warningsArg: string[],
|
||||||
|
): Promise<void> {
|
||||||
|
if (!serviceArg.containerID) {
|
||||||
|
if (volumesArg.some((volumeArg) => volumeArg.backup !== false)) {
|
||||||
|
warningsArg.push(`Could not restore service volumes for ${serviceArg.name}: service has no container ID`);
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const volumes = volumesArg.filter((volumeArg) => volumeArg.backup !== false);
|
||||||
|
for (let i = 0; i < volumes.length; i++) {
|
||||||
|
const volume = volumes[i];
|
||||||
|
const backupName = this.getVolumeBackupName(volume, i);
|
||||||
|
const inputPath = `${tempDirArg}/data/volumes/${backupName}`;
|
||||||
|
try {
|
||||||
|
await Deno.stat(inputPath);
|
||||||
|
} catch {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
await this.copyToContainer(`${inputPath}/.`, serviceArg.containerID, volume.mountPath);
|
||||||
|
logger.info(`Restored volume ${volume.mountPath} for service ${serviceArg.name}`);
|
||||||
|
} catch (error) {
|
||||||
|
warningsArg.push(`Volume restore failed for ${volume.mountPath}: ${getErrorMessage(error)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Export MongoDB database
|
* Export MongoDB database
|
||||||
*/
|
*/
|
||||||
|
|||||||
+274
-15
@@ -5,14 +5,258 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
import * as plugins from '../plugins.ts';
|
import * as plugins from '../plugins.ts';
|
||||||
import type { IService, IContainerStats } from '../types.ts';
|
import type { IService, IContainerStats, IServicePublishedPort } from '../types.ts';
|
||||||
import { logger } from '../logging.ts';
|
import { logger } from '../logging.ts';
|
||||||
import { getErrorMessage } from '../utils/error.ts';
|
import { getErrorMessage } from '../utils/error.ts';
|
||||||
|
|
||||||
|
type TExpandedPublishedPort = Required<Pick<
|
||||||
|
IServicePublishedPort,
|
||||||
|
'targetPort' | 'publishedPort' | 'protocol' | 'hostIp'
|
||||||
|
>>;
|
||||||
|
|
||||||
export class OneboxDockerManager {
|
export class OneboxDockerManager {
|
||||||
private dockerClient: InstanceType<typeof plugins.docker.Docker> | null = null;
|
private dockerClient: InstanceType<typeof plugins.docker.Docker> | null = null;
|
||||||
private networkName = 'onebox-network';
|
private networkName = 'onebox-network';
|
||||||
|
|
||||||
|
private getDockerSafeName(valueArg: string, maxLengthArg = 120): string {
|
||||||
|
const safeName = valueArg
|
||||||
|
.replace(/[^a-zA-Z0-9_.-]+/g, '-')
|
||||||
|
.replace(/^[^a-zA-Z0-9]+|[^a-zA-Z0-9]+$/g, '')
|
||||||
|
.slice(0, maxLengthArg)
|
||||||
|
.replace(/[^a-zA-Z0-9]+$/g, '');
|
||||||
|
return safeName || 'data';
|
||||||
|
}
|
||||||
|
|
||||||
|
private getServiceVolumeSource(serviceArg: IService, mountPathArg: string, requestedSourceArg?: string): string {
|
||||||
|
if (requestedSourceArg) {
|
||||||
|
return this.getDockerSafeName(requestedSourceArg);
|
||||||
|
}
|
||||||
|
const mountName = this.getDockerSafeName(mountPathArg.replace(/^\/+/, '').replace(/\/+$/g, ''), 40);
|
||||||
|
return this.getDockerSafeName(`onebox-${serviceArg.name}-${mountName}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
private getStandaloneVolumeBinds(serviceArg: IService): string[] {
|
||||||
|
return (serviceArg.volumes || []).map((volumeArg) => {
|
||||||
|
const source = this.getServiceVolumeSource(serviceArg, volumeArg.mountPath, volumeArg.source || volumeArg.name);
|
||||||
|
return `${source}:${volumeArg.mountPath}${volumeArg.readOnly ? ':ro' : ''}`;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private getSwarmVolumeMounts(serviceArg: IService): Array<Record<string, unknown>> {
|
||||||
|
return (serviceArg.volumes || []).map((volumeArg) => ({
|
||||||
|
Type: 'volume',
|
||||||
|
Source: this.getServiceVolumeSource(serviceArg, volumeArg.mountPath, volumeArg.source || volumeArg.name),
|
||||||
|
Target: volumeArg.mountPath,
|
||||||
|
ReadOnly: Boolean(volumeArg.readOnly),
|
||||||
|
VolumeOptions: {
|
||||||
|
DriverConfig: {
|
||||||
|
Name: volumeArg.driver || 'local',
|
||||||
|
Options: volumeArg.options || {},
|
||||||
|
},
|
||||||
|
Labels: {
|
||||||
|
'managed-by': 'onebox',
|
||||||
|
'onebox-service': serviceArg.name,
|
||||||
|
'onebox-mount-path': volumeArg.mountPath,
|
||||||
|
'onebox-backup': String(volumeArg.backup !== false),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
public validateServiceSpec(serviceArg: IService): void {
|
||||||
|
this.assertValidPort(serviceArg.port, `service port for ${serviceArg.name}`);
|
||||||
|
|
||||||
|
for (const volumeArg of serviceArg.volumes || []) {
|
||||||
|
if (!volumeArg.mountPath || !volumeArg.mountPath.startsWith('/')) {
|
||||||
|
throw new Error(`Volume mountPath for service ${serviceArg.name} must be an absolute path`);
|
||||||
|
}
|
||||||
|
if (volumeArg.mountPath.includes(':')) {
|
||||||
|
throw new Error(`Volume mountPath for service ${serviceArg.name} must not contain ':'`);
|
||||||
|
}
|
||||||
|
if ((volumeArg.source || volumeArg.name)?.includes(':')) {
|
||||||
|
throw new Error(`Volume source/name for service ${serviceArg.name} must not contain ':'`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
this.expandPublishedPorts(serviceArg);
|
||||||
|
}
|
||||||
|
|
||||||
|
private assertValidPort(portArg: number, labelArg: string): void {
|
||||||
|
if (!Number.isInteger(portArg) || portArg < 1 || portArg > 65535) {
|
||||||
|
throw new Error(`Invalid ${labelArg}: ${portArg}. Expected an integer port between 1 and 65535.`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private expandPublishedPorts(serviceArg: IService): TExpandedPublishedPort[] {
|
||||||
|
const expandedPorts: TExpandedPublishedPort[] = [];
|
||||||
|
const seenPublishedPorts = new Set<string>();
|
||||||
|
|
||||||
|
for (const portArg of serviceArg.publishedPorts || []) {
|
||||||
|
const protocol = portArg.protocol || 'tcp';
|
||||||
|
const targetStart = portArg.targetPort;
|
||||||
|
const targetEnd = portArg.targetPortEnd || targetStart;
|
||||||
|
const publishedStart = portArg.publishedPort || targetStart;
|
||||||
|
const publishedEnd = portArg.publishedPortEnd || (publishedStart + (targetEnd - targetStart));
|
||||||
|
const hostIp = portArg.hostIp || '0.0.0.0';
|
||||||
|
|
||||||
|
if (!['tcp', 'udp'].includes(protocol)) {
|
||||||
|
throw new Error(`Invalid published port protocol for service ${serviceArg.name}: ${protocol}`);
|
||||||
|
}
|
||||||
|
this.assertValidPort(targetStart, `published targetPort for service ${serviceArg.name}`);
|
||||||
|
this.assertValidPort(targetEnd, `published targetPortEnd for service ${serviceArg.name}`);
|
||||||
|
this.assertValidPort(publishedStart, `published publishedPort for service ${serviceArg.name}`);
|
||||||
|
this.assertValidPort(publishedEnd, `published publishedPortEnd for service ${serviceArg.name}`);
|
||||||
|
if (targetEnd < targetStart) {
|
||||||
|
throw new Error(`Invalid target port range for service ${serviceArg.name}: ${targetStart}-${targetEnd}`);
|
||||||
|
}
|
||||||
|
if (publishedEnd < publishedStart) {
|
||||||
|
throw new Error(`Invalid published port range for service ${serviceArg.name}: ${publishedStart}-${publishedEnd}`);
|
||||||
|
}
|
||||||
|
if ((targetEnd - targetStart) !== (publishedEnd - publishedStart)) {
|
||||||
|
throw new Error(
|
||||||
|
`Published port range size must match target port range size for service ${serviceArg.name}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (!this.isValidHostIp(hostIp)) {
|
||||||
|
throw new Error(`Invalid hostIp for service ${serviceArg.name}: ${hostIp}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (let offset = 0; offset <= targetEnd - targetStart; offset++) {
|
||||||
|
const publishedPort = publishedStart + offset;
|
||||||
|
const publishedKey = `${hostIp}/${protocol}/${publishedPort}`;
|
||||||
|
const wildcardKey = `0.0.0.0/${protocol}/${publishedPort}`;
|
||||||
|
const conflictsWithWildcard = hostIp === '0.0.0.0'
|
||||||
|
? Array.from(seenPublishedPorts).some((keyArg) => keyArg.endsWith(`/${protocol}/${publishedPort}`))
|
||||||
|
: seenPublishedPorts.has(wildcardKey);
|
||||||
|
if (seenPublishedPorts.has(publishedKey) || conflictsWithWildcard) {
|
||||||
|
throw new Error(`Duplicate published port for service ${serviceArg.name}: ${hostIp}:${publishedPort}/${protocol}`);
|
||||||
|
}
|
||||||
|
seenPublishedPorts.add(publishedKey);
|
||||||
|
expandedPorts.push({
|
||||||
|
targetPort: targetStart + offset,
|
||||||
|
publishedPort,
|
||||||
|
protocol,
|
||||||
|
hostIp,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return expandedPorts;
|
||||||
|
}
|
||||||
|
|
||||||
|
private isValidHostIp(hostIpArg: string): boolean {
|
||||||
|
if (['0.0.0.0', '127.0.0.1', '::', '::1', 'localhost'].includes(hostIpArg)) return true;
|
||||||
|
if (/^(\d{1,3}\.){3}\d{1,3}$/.test(hostIpArg)) {
|
||||||
|
return hostIpArg.split('.').every((partArg) => Number(partArg) >= 0 && Number(partArg) <= 255);
|
||||||
|
}
|
||||||
|
return /^[0-9a-fA-F:]+$/.test(hostIpArg);
|
||||||
|
}
|
||||||
|
|
||||||
|
private async assertPublishedPortsAvailable(serviceArg: IService): Promise<void> {
|
||||||
|
const publishedPorts = this.expandPublishedPorts(serviceArg);
|
||||||
|
if (publishedPorts.length === 0) return;
|
||||||
|
|
||||||
|
await this.assertPublishedPortsNotUsedByDocker(serviceArg, publishedPorts);
|
||||||
|
await this.assertPublishedPortsNotUsedByHost(serviceArg, publishedPorts);
|
||||||
|
}
|
||||||
|
|
||||||
|
private async assertPublishedPortsNotUsedByDocker(
|
||||||
|
serviceArg: IService,
|
||||||
|
publishedPortsArg: TExpandedPublishedPort[],
|
||||||
|
): Promise<void> {
|
||||||
|
const requestedPorts = new Set(
|
||||||
|
publishedPortsArg.map((portArg) => `${portArg.protocol}/${portArg.publishedPort}`),
|
||||||
|
);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const containersResponse = await this.dockerClient!.request('GET', '/containers/json?all=true', {});
|
||||||
|
if (containersResponse.statusCode === 200 && Array.isArray(containersResponse.body)) {
|
||||||
|
for (const containerArg of containersResponse.body) {
|
||||||
|
const labels = containerArg.Labels || {};
|
||||||
|
if (labels['onebox-service'] === serviceArg.name) continue;
|
||||||
|
for (const portArg of containerArg.Ports || []) {
|
||||||
|
if (!portArg.PublicPort || !portArg.Type) continue;
|
||||||
|
if (requestedPorts.has(`${portArg.Type}/${portArg.PublicPort}`)) {
|
||||||
|
throw new Error(
|
||||||
|
`Published port ${portArg.PublicPort}/${portArg.Type} is already used by container ${containerArg.Names?.[0] || containerArg.Id}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const servicesResponse = await this.dockerClient!.request('GET', '/services', {});
|
||||||
|
if (servicesResponse.statusCode === 200 && Array.isArray(servicesResponse.body)) {
|
||||||
|
for (const service of servicesResponse.body) {
|
||||||
|
if (service.Spec?.Name === `onebox-${serviceArg.name}`) continue;
|
||||||
|
for (const portArg of service.Endpoint?.Ports || []) {
|
||||||
|
if (!portArg.PublishedPort || !portArg.Protocol) continue;
|
||||||
|
if (requestedPorts.has(`${portArg.Protocol}/${portArg.PublishedPort}`)) {
|
||||||
|
throw new Error(
|
||||||
|
`Published port ${portArg.PublishedPort}/${portArg.Protocol} is already used by Docker service ${service.Spec?.Name || service.ID}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
if (error instanceof Error && error.message.startsWith('Published port ')) throw error;
|
||||||
|
logger.warn(`Could not complete Docker published-port preflight: ${getErrorMessage(error)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private async assertPublishedPortsNotUsedByHost(
|
||||||
|
serviceArg: IService,
|
||||||
|
publishedPortsArg: TExpandedPublishedPort[],
|
||||||
|
): Promise<void> {
|
||||||
|
for (const portArg of publishedPortsArg) {
|
||||||
|
try {
|
||||||
|
if (portArg.protocol === 'udp') {
|
||||||
|
await this.assertUdpPortAvailable(portArg.hostIp, portArg.publishedPort);
|
||||||
|
} else {
|
||||||
|
const listener = Deno.listen({ hostname: portArg.hostIp, port: portArg.publishedPort });
|
||||||
|
listener.close();
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
throw new Error(
|
||||||
|
`Published port ${portArg.hostIp}:${portArg.publishedPort}/${portArg.protocol} for service ${serviceArg.name} is not available: ${getErrorMessage(error)}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private async assertUdpPortAvailable(hostIpArg: string, portArg: number): Promise<void> {
|
||||||
|
const dgram = await import('node:dgram');
|
||||||
|
const socket = dgram.createSocket(hostIpArg.includes(':') ? 'udp6' : 'udp4');
|
||||||
|
await new Promise<void>((resolve, reject) => {
|
||||||
|
socket.once('error', reject);
|
||||||
|
socket.bind(portArg, hostIpArg, () => {
|
||||||
|
socket.close();
|
||||||
|
resolve();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private getStandalonePortConfig(serviceArg: IService): {
|
||||||
|
exposedPorts: Record<string, Record<string, never>>;
|
||||||
|
portBindings: Record<string, Array<{ HostIp: string; HostPort: string }>>;
|
||||||
|
} {
|
||||||
|
const exposedPorts: Record<string, Record<string, never>> = {
|
||||||
|
[`${serviceArg.port}/tcp`]: {},
|
||||||
|
};
|
||||||
|
const portBindings: Record<string, Array<{ HostIp: string; HostPort: string }>> = {
|
||||||
|
[`${serviceArg.port}/tcp`]: [],
|
||||||
|
};
|
||||||
|
|
||||||
|
for (const publishedPort of this.expandPublishedPorts(serviceArg)) {
|
||||||
|
const key = `${publishedPort.targetPort}/${publishedPort.protocol}`;
|
||||||
|
exposedPorts[key] = {};
|
||||||
|
portBindings[key] = [{ HostIp: publishedPort.hostIp, HostPort: String(publishedPort.publishedPort) }];
|
||||||
|
}
|
||||||
|
|
||||||
|
return { exposedPorts, portBindings };
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Initialize Docker client and create onebox network
|
* Initialize Docker client and create onebox network
|
||||||
*/
|
*/
|
||||||
@@ -122,6 +366,9 @@ export class OneboxDockerManager {
|
|||||||
*/
|
*/
|
||||||
async createContainer(service: IService): Promise<string> {
|
async createContainer(service: IService): Promise<string> {
|
||||||
try {
|
try {
|
||||||
|
this.validateServiceSpec(service);
|
||||||
|
await this.assertPublishedPortsAvailable(service);
|
||||||
|
|
||||||
// Check if Docker is in Swarm mode
|
// Check if Docker is in Swarm mode
|
||||||
let isSwarmMode = false;
|
let isSwarmMode = false;
|
||||||
try {
|
try {
|
||||||
@@ -158,6 +405,8 @@ export class OneboxDockerManager {
|
|||||||
env.push(`${key}=${value}`);
|
env.push(`${key}=${value}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const portConfig = this.getStandalonePortConfig(service);
|
||||||
|
|
||||||
// Create container using Docker REST API directly
|
// Create container using Docker REST API directly
|
||||||
const response = await this.dockerClient!.request('POST', `/containers/create?name=onebox-${service.name}`, {
|
const response = await this.dockerClient!.request('POST', `/containers/create?name=onebox-${service.name}`, {
|
||||||
Image: fullImage,
|
Image: fullImage,
|
||||||
@@ -166,18 +415,14 @@ export class OneboxDockerManager {
|
|||||||
'managed-by': 'onebox',
|
'managed-by': 'onebox',
|
||||||
'onebox-service': service.name,
|
'onebox-service': service.name,
|
||||||
},
|
},
|
||||||
ExposedPorts: {
|
ExposedPorts: portConfig.exposedPorts,
|
||||||
[`${service.port}/tcp`]: {},
|
|
||||||
},
|
|
||||||
HostConfig: {
|
HostConfig: {
|
||||||
NetworkMode: this.networkName,
|
NetworkMode: this.networkName,
|
||||||
RestartPolicy: {
|
RestartPolicy: {
|
||||||
Name: 'unless-stopped',
|
Name: 'unless-stopped',
|
||||||
},
|
},
|
||||||
PortBindings: {
|
PortBindings: portConfig.portBindings,
|
||||||
// Don't bind to host ports - nginx will proxy
|
Binds: this.getStandaloneVolumeBinds(service),
|
||||||
[`${service.port}/tcp`]: [],
|
|
||||||
},
|
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -207,6 +452,25 @@ export class OneboxDockerManager {
|
|||||||
env.push(`${key}=${value}`);
|
env.push(`${key}=${value}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const expandedPublishedPorts = this.expandPublishedPorts(service);
|
||||||
|
const endpointPorts: Array<Record<string, unknown>> = [];
|
||||||
|
if (!expandedPublishedPorts.some((publishedPort) => publishedPort.protocol === 'tcp' && publishedPort.targetPort === service.port)) {
|
||||||
|
endpointPorts.push({
|
||||||
|
Protocol: 'tcp',
|
||||||
|
TargetPort: service.port,
|
||||||
|
PublishMode: 'host',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const publishedPort of expandedPublishedPorts) {
|
||||||
|
endpointPorts.push({
|
||||||
|
Protocol: publishedPort.protocol,
|
||||||
|
TargetPort: publishedPort.targetPort,
|
||||||
|
PublishedPort: publishedPort.publishedPort,
|
||||||
|
PublishMode: 'host',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Create Swarm service using Docker REST API
|
// Create Swarm service using Docker REST API
|
||||||
const response = await this.dockerClient!.request('POST', '/services/create', {
|
const response = await this.dockerClient!.request('POST', '/services/create', {
|
||||||
Name: `onebox-${service.name}`,
|
Name: `onebox-${service.name}`,
|
||||||
@@ -218,6 +482,7 @@ export class OneboxDockerManager {
|
|||||||
ContainerSpec: {
|
ContainerSpec: {
|
||||||
Image: fullImage,
|
Image: fullImage,
|
||||||
Env: env,
|
Env: env,
|
||||||
|
Mounts: this.getSwarmVolumeMounts(service),
|
||||||
Labels: {
|
Labels: {
|
||||||
'managed-by': 'onebox',
|
'managed-by': 'onebox',
|
||||||
'onebox-service': service.name,
|
'onebox-service': service.name,
|
||||||
@@ -239,13 +504,7 @@ export class OneboxDockerManager {
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
EndpointSpec: {
|
EndpointSpec: {
|
||||||
Ports: [
|
Ports: endpointPorts,
|
||||||
{
|
|
||||||
Protocol: 'tcp',
|
|
||||||
TargetPort: service.port,
|
|
||||||
PublishMode: 'host',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -133,6 +133,45 @@ export class ExternalGatewayManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
await this.syncDomains();
|
await this.syncDomains();
|
||||||
|
await this.syncServiceRoutes();
|
||||||
|
}
|
||||||
|
|
||||||
|
public async syncServiceRoutes(): Promise<void> {
|
||||||
|
const services = this.database.getAllServices()
|
||||||
|
.filter((service) => service.domain && service.status === 'running');
|
||||||
|
const activeHostnames = new Set(services.map((service) => service.domain!));
|
||||||
|
|
||||||
|
for (const service of services) {
|
||||||
|
try {
|
||||||
|
await this.syncServiceRoute(service);
|
||||||
|
} catch (error) {
|
||||||
|
logger.warn(`Failed to sync external gateway route for ${service.domain}: ${getErrorMessage(error)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.deleteStaleServiceRoutes(activeHostnames);
|
||||||
|
}
|
||||||
|
|
||||||
|
private async deleteStaleServiceRoutes(activeHostnamesArg: Set<string>): Promise<void> {
|
||||||
|
const records = await this.getGatewayDnsRecords();
|
||||||
|
const staleRecordsByHostname = new Map<string, IGatewayDnsRecord>();
|
||||||
|
|
||||||
|
for (const record of records) {
|
||||||
|
if (!record.hostname || activeHostnamesArg.has(record.hostname)) continue;
|
||||||
|
if (!record.routeId && !record.appId && !record.serviceName) continue;
|
||||||
|
staleRecordsByHostname.set(record.hostname, record);
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const record of staleRecordsByHostname.values()) {
|
||||||
|
try {
|
||||||
|
await this.deleteServiceRoute({
|
||||||
|
name: record.serviceName || record.appId,
|
||||||
|
domain: record.hostname,
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
logger.warn(`Failed to delete stale external gateway route for ${record.hostname}: ${getErrorMessage(error)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public async isConfigured(): Promise<boolean> {
|
public async isConfigured(): Promise<boolean> {
|
||||||
|
|||||||
@@ -227,6 +227,7 @@ export class ManagedDcRouterManager {
|
|||||||
const image = this.getImage();
|
const image = this.getImage();
|
||||||
const token = await this.getAdminToken();
|
const token = await this.getAdminToken();
|
||||||
const dataDir = await this.getAbsoluteDataDir();
|
const dataDir = await this.getAbsoluteDataDir();
|
||||||
|
await this.writeManagedConfig(dataDir);
|
||||||
|
|
||||||
await this.oneboxRef.docker.pullImage(image);
|
await this.oneboxRef.docker.pullImage(image);
|
||||||
|
|
||||||
@@ -234,6 +235,7 @@ export class ManagedDcRouterManager {
|
|||||||
Image: image,
|
Image: image,
|
||||||
Env: [
|
Env: [
|
||||||
`DCROUTER_BASE_DIR=${internalBaseDir}`,
|
`DCROUTER_BASE_DIR=${internalBaseDir}`,
|
||||||
|
`DCROUTER_CONFIG_PATH=${internalBaseDir}/managed-config.json`,
|
||||||
`DCROUTER_ADMIN_API_TOKEN=${token}`,
|
`DCROUTER_ADMIN_API_TOKEN=${token}`,
|
||||||
'DCROUTER_ADMIN_API_TOKEN_NAME=Onebox Managed Admin Token',
|
'DCROUTER_ADMIN_API_TOKEN_NAME=Onebox Managed Admin Token',
|
||||||
],
|
],
|
||||||
@@ -268,6 +270,26 @@ export class ManagedDcRouterManager {
|
|||||||
logger.success(`Managed dcrouter container started: ${response.body.Id}`);
|
logger.success(`Managed dcrouter container started: ${response.body.Id}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private async writeManagedConfig(dataDirArg: string): Promise<void> {
|
||||||
|
const configPath = plugins.path.join(dataDirArg, 'managed-config.json');
|
||||||
|
try {
|
||||||
|
const existingConfig = await Deno.readTextFile(configPath);
|
||||||
|
JSON.parse(existingConfig);
|
||||||
|
return;
|
||||||
|
} catch (error) {
|
||||||
|
if (!(error instanceof Deno.errors.NotFound)) {
|
||||||
|
throw new Error(`Managed dcrouter config exists but is not valid JSON: ${getErrorMessage(error)}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const config = {
|
||||||
|
smartProxyConfig: {
|
||||||
|
routes: [],
|
||||||
|
},
|
||||||
|
};
|
||||||
|
await Deno.writeTextFile(configPath, JSON.stringify(config, null, 2));
|
||||||
|
}
|
||||||
|
|
||||||
private async getExistingContainer(): Promise<any | null> {
|
private async getExistingContainer(): Promise<any | null> {
|
||||||
const filters = encodeURIComponent(JSON.stringify({ name: [containerName] }));
|
const filters = encodeURIComponent(JSON.stringify({ name: [containerName] }));
|
||||||
const response = await this.dockerClient!.request('GET', `/containers/json?all=true&filters=${filters}`, {});
|
const response = await this.dockerClient!.request('GET', `/containers/json?all=true&filters=${filters}`, {});
|
||||||
|
|||||||
@@ -95,6 +95,8 @@ export class OneboxServicesManager {
|
|||||||
image: options.useOneboxRegistry ? imageToPull : options.image,
|
image: options.useOneboxRegistry ? imageToPull : options.image,
|
||||||
registry: options.registry,
|
registry: options.registry,
|
||||||
envVars: options.envVars || {},
|
envVars: options.envVars || {},
|
||||||
|
volumes: options.volumes || [],
|
||||||
|
publishedPorts: options.publishedPorts || [],
|
||||||
port: options.port,
|
port: options.port,
|
||||||
domain: options.domain,
|
domain: options.domain,
|
||||||
status: 'stopped',
|
status: 'stopped',
|
||||||
@@ -578,6 +580,8 @@ export class OneboxServicesManager {
|
|||||||
port?: number;
|
port?: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
envVars?: Record<string, string>;
|
envVars?: Record<string, string>;
|
||||||
|
volumes?: IService['volumes'];
|
||||||
|
publishedPorts?: IService['publishedPorts'];
|
||||||
}
|
}
|
||||||
): Promise<IService> {
|
): Promise<IService> {
|
||||||
try {
|
try {
|
||||||
@@ -616,6 +620,8 @@ export class OneboxServicesManager {
|
|||||||
if (updates.port !== undefined) updateData.port = updates.port;
|
if (updates.port !== undefined) updateData.port = updates.port;
|
||||||
if (updates.domain !== undefined) updateData.domain = updates.domain;
|
if (updates.domain !== undefined) updateData.domain = updates.domain;
|
||||||
if (updates.envVars !== undefined) updateData.envVars = updates.envVars;
|
if (updates.envVars !== undefined) updateData.envVars = updates.envVars;
|
||||||
|
if (updates.volumes !== undefined) updateData.volumes = updates.volumes;
|
||||||
|
if (updates.publishedPorts !== undefined) updateData.publishedPorts = updates.publishedPorts;
|
||||||
|
|
||||||
this.database.updateService(service.id!, updateData);
|
this.database.updateService(service.id!, updateData);
|
||||||
|
|
||||||
|
|||||||
@@ -175,8 +175,10 @@ export class SmartProxyManager {
|
|||||||
throw new Error(`Failed to create SmartProxy service: HTTP ${response.statusCode} - ${JSON.stringify(response.body)}`);
|
throw new Error(`Failed to create SmartProxy service: HTTP ${response.statusCode} - ${JSON.stringify(response.body)}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
logger.info(`SmartProxy service created: ${response.body.ID}`);
|
const serviceId = response.body.ID;
|
||||||
|
logger.info(`SmartProxy service created: ${serviceId}`);
|
||||||
|
|
||||||
|
await this.waitForServiceTaskRunning(serviceId);
|
||||||
await this.waitForReady();
|
await this.waitForReady();
|
||||||
this.serviceRunning = true;
|
this.serviceRunning = true;
|
||||||
await this.reloadConfig({ skipRunningCheck: true });
|
await this.reloadConfig({ skipRunningCheck: true });
|
||||||
@@ -232,6 +234,37 @@ export class SmartProxyManager {
|
|||||||
throw new Error('SmartProxy service failed to start within timeout');
|
throw new Error('SmartProxy service failed to start within timeout');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private async waitForServiceTaskRunning(
|
||||||
|
serviceIdArg: string,
|
||||||
|
maxAttempts = 30,
|
||||||
|
intervalMs = 1000,
|
||||||
|
): Promise<void> {
|
||||||
|
let lastState = 'unknown';
|
||||||
|
|
||||||
|
for (let i = 0; i < maxAttempts; i++) {
|
||||||
|
const tasksResponse = await this.dockerClient!.request(
|
||||||
|
'GET',
|
||||||
|
`/tasks?filters=${encodeURIComponent(JSON.stringify({ service: [serviceIdArg] }))}`,
|
||||||
|
{},
|
||||||
|
);
|
||||||
|
|
||||||
|
if (tasksResponse.statusCode === 200 && Array.isArray(tasksResponse.body)) {
|
||||||
|
const tasks = tasksResponse.body;
|
||||||
|
const runningTask = tasks.find((task: any) => task.Status?.State === 'running');
|
||||||
|
if (runningTask) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const latestTask = tasks[0];
|
||||||
|
lastState = latestTask?.Status?.State || lastState;
|
||||||
|
}
|
||||||
|
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, intervalMs));
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error(`SmartProxy service task did not reach running state (last state: ${lastState})`);
|
||||||
|
}
|
||||||
|
|
||||||
async stop(): Promise<void> {
|
async stop(): Promise<void> {
|
||||||
try {
|
try {
|
||||||
await this.ensureDockerClient();
|
await this.ensureDockerClient();
|
||||||
|
|||||||
@@ -214,33 +214,25 @@ async function handleAppStoreCommand(onebox: Onebox, subcommand: string, args: s
|
|||||||
|
|
||||||
const appMeta = await onebox.appStore.getAppMeta(appId);
|
const appMeta = await onebox.appStore.getAppMeta(appId);
|
||||||
const version = getArg(args, '--version') || appMeta.latestVersion;
|
const version = getArg(args, '--version') || appMeta.latestVersion;
|
||||||
const config = await onebox.appStore.getAppVersionConfig(appId, version);
|
|
||||||
const serviceName = getArg(args, '--name') || appId;
|
const serviceName = getArg(args, '--name') || appId;
|
||||||
const domain = getArg(args, '--domain');
|
const domain = getArg(args, '--domain');
|
||||||
const port = parseInt(getArg(args, '--port') || String(config.port), 10);
|
const portArg = getArg(args, '--port');
|
||||||
const envVars = getAppStoreEnvVars(config, parseEnvArgs(args));
|
const port = portArg ? parseInt(portArg, 10) : undefined;
|
||||||
const autoDNS = getBooleanArg(args, '--auto-dns', true);
|
const autoDNS = getBooleanArg(args, '--auto-dns', true);
|
||||||
|
|
||||||
requireValue(serviceName, '--name');
|
requireValue(serviceName, '--name');
|
||||||
|
if (port !== undefined) {
|
||||||
assertValidPort(port, '--port');
|
assertValidPort(port, '--port');
|
||||||
if (requiresTemplateValue(envVars, 'SERVICE_DOMAIN')) {
|
|
||||||
requireValue(domain, '--domain');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
const service = await onebox.services.deployService({
|
const service = await onebox.appStore.installApp({
|
||||||
name: serviceName,
|
appId,
|
||||||
image: config.image,
|
version,
|
||||||
port,
|
serviceName,
|
||||||
domain,
|
domain,
|
||||||
|
port,
|
||||||
autoDNS,
|
autoDNS,
|
||||||
envVars,
|
envVars: parseEnvArgs(args),
|
||||||
enableMongoDB: Boolean(config.platformRequirements?.mongodb),
|
|
||||||
enableS3: Boolean(config.platformRequirements?.s3),
|
|
||||||
enableClickHouse: Boolean(config.platformRequirements?.clickhouse),
|
|
||||||
enableRedis: Boolean(config.platformRequirements?.redis),
|
|
||||||
enableMariaDB: Boolean(config.platformRequirements?.mariadb),
|
|
||||||
appTemplateId: appId,
|
|
||||||
appTemplateVersion: version,
|
|
||||||
});
|
});
|
||||||
|
|
||||||
logger.success(`Installed ${appMeta.name} ${version} as ${service.name}`);
|
logger.success(`Installed ${appMeta.name} ${version} as ${service.name}`);
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
import { BaseMigration } from './base-migration.ts';
|
||||||
|
import type { TQueryFunction } from '../types.ts';
|
||||||
|
|
||||||
|
export class Migration016ServiceVolumes extends BaseMigration {
|
||||||
|
readonly version = 16;
|
||||||
|
readonly description = 'Add persistent volume declarations to services';
|
||||||
|
|
||||||
|
up(query: TQueryFunction): void {
|
||||||
|
query(`ALTER TABLE services ADD COLUMN volumes TEXT DEFAULT '[]'`);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
import { BaseMigration } from './base-migration.ts';
|
||||||
|
import type { TQueryFunction } from '../types.ts';
|
||||||
|
|
||||||
|
export class Migration017ServicePublishedPorts extends BaseMigration {
|
||||||
|
readonly version = 17;
|
||||||
|
readonly description = 'Add raw published port declarations to services';
|
||||||
|
|
||||||
|
up(query: TQueryFunction): void {
|
||||||
|
query(`ALTER TABLE services ADD COLUMN published_ports TEXT DEFAULT '[]'`);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -22,6 +22,8 @@ import { Migration012GfsRetention } from './migration-012-gfs-retention.ts';
|
|||||||
import { Migration013AppTemplateVersion } from './migration-013-app-template-version.ts';
|
import { Migration013AppTemplateVersion } from './migration-013-app-template-version.ts';
|
||||||
import { Migration014ContainerArchive } from './migration-014-containerarchive.ts';
|
import { Migration014ContainerArchive } from './migration-014-containerarchive.ts';
|
||||||
import { Migration015SmartProxyPlatformService } from './migration-015-smartproxy-platform-service.ts';
|
import { Migration015SmartProxyPlatformService } from './migration-015-smartproxy-platform-service.ts';
|
||||||
|
import { Migration016ServiceVolumes } from './migration-016-service-volumes.ts';
|
||||||
|
import { Migration017ServicePublishedPorts } from './migration-017-service-published-ports.ts';
|
||||||
import type { BaseMigration } from './base-migration.ts';
|
import type { BaseMigration } from './base-migration.ts';
|
||||||
|
|
||||||
export class MigrationRunner {
|
export class MigrationRunner {
|
||||||
@@ -48,6 +50,8 @@ export class MigrationRunner {
|
|||||||
new Migration013AppTemplateVersion(),
|
new Migration013AppTemplateVersion(),
|
||||||
new Migration014ContainerArchive(),
|
new Migration014ContainerArchive(),
|
||||||
new Migration015SmartProxyPlatformService(),
|
new Migration015SmartProxyPlatformService(),
|
||||||
|
new Migration016ServiceVolumes(),
|
||||||
|
new Migration017ServicePublishedPorts(),
|
||||||
].sort((a, b) => a.version - b.version);
|
].sort((a, b) => a.version - b.version);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -14,17 +14,19 @@ export class ServiceRepository extends BaseRepository {
|
|||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
this.query(
|
this.query(
|
||||||
`INSERT INTO services (
|
`INSERT INTO services (
|
||||||
name, image, registry, env_vars, port, domain, container_id, status,
|
name, image, registry, env_vars, volumes, published_ports, port, domain, container_id, status,
|
||||||
created_at, updated_at,
|
created_at, updated_at,
|
||||||
use_onebox_registry, registry_repository, registry_image_tag,
|
use_onebox_registry, registry_repository, registry_image_tag,
|
||||||
auto_update_on_push, image_digest, platform_requirements,
|
auto_update_on_push, image_digest, platform_requirements,
|
||||||
app_template_id, app_template_version
|
app_template_id, app_template_version
|
||||||
) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
|
) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
|
||||||
[
|
[
|
||||||
service.name,
|
service.name,
|
||||||
service.image,
|
service.image,
|
||||||
service.registry || null,
|
service.registry || null,
|
||||||
JSON.stringify(service.envVars),
|
JSON.stringify(service.envVars),
|
||||||
|
JSON.stringify(service.volumes || []),
|
||||||
|
JSON.stringify(service.publishedPorts || []),
|
||||||
service.port,
|
service.port,
|
||||||
service.domain || null,
|
service.domain || null,
|
||||||
service.containerID || null,
|
service.containerID || null,
|
||||||
@@ -82,6 +84,14 @@ export class ServiceRepository extends BaseRepository {
|
|||||||
fields.push('env_vars = ?');
|
fields.push('env_vars = ?');
|
||||||
values.push(JSON.stringify(updates.envVars));
|
values.push(JSON.stringify(updates.envVars));
|
||||||
}
|
}
|
||||||
|
if (updates.volumes !== undefined) {
|
||||||
|
fields.push('volumes = ?');
|
||||||
|
values.push(JSON.stringify(updates.volumes));
|
||||||
|
}
|
||||||
|
if (updates.publishedPorts !== undefined) {
|
||||||
|
fields.push('published_ports = ?');
|
||||||
|
values.push(JSON.stringify(updates.publishedPorts));
|
||||||
|
}
|
||||||
if (updates.port !== undefined) {
|
if (updates.port !== undefined) {
|
||||||
fields.push('port = ?');
|
fields.push('port = ?');
|
||||||
values.push(updates.port);
|
values.push(updates.port);
|
||||||
@@ -169,18 +179,42 @@ export class ServiceRepository extends BaseRepository {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let volumes = [];
|
||||||
|
const volumesRaw = row.volumes ?? row[20];
|
||||||
|
if (volumesRaw && volumesRaw !== 'undefined' && volumesRaw !== 'null') {
|
||||||
|
try {
|
||||||
|
volumes = JSON.parse(String(volumesRaw));
|
||||||
|
} catch (e) {
|
||||||
|
logger.warn(`Failed to parse volumes for service: ${getErrorMessage(e)}`);
|
||||||
|
volumes = [];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
let publishedPorts = [];
|
||||||
|
const publishedPortsRaw = row.published_ports;
|
||||||
|
if (publishedPortsRaw && publishedPortsRaw !== 'undefined' && publishedPortsRaw !== 'null') {
|
||||||
|
try {
|
||||||
|
publishedPorts = JSON.parse(String(publishedPortsRaw));
|
||||||
|
} catch (e) {
|
||||||
|
logger.warn(`Failed to parse published_ports for service: ${getErrorMessage(e)}`);
|
||||||
|
publishedPorts = [];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
id: Number(row.id || row[0]),
|
id: Number(row.id || row[0]),
|
||||||
name: String(row.name || row[1]),
|
name: String(row.name || row[1]),
|
||||||
image: String(row.image || row[2]),
|
image: String(row.image || row[2]),
|
||||||
registry: (row.registry || row[3]) ? String(row.registry || row[3]) : undefined,
|
registry: (row.registry || row[3]) ? String(row.registry || row[3]) : undefined,
|
||||||
envVars,
|
envVars,
|
||||||
port: Number(row.port || row[5]),
|
volumes,
|
||||||
domain: (row.domain || row[6]) ? String(row.domain || row[6]) : undefined,
|
publishedPorts,
|
||||||
containerID: (row.container_id || row[7]) ? String(row.container_id || row[7]) : undefined,
|
port: Number(row.port ?? row[6] ?? row[5]),
|
||||||
status: String(row.status || row[8]) as IService['status'],
|
domain: (row.domain ?? row[7] ?? row[6]) ? String(row.domain ?? row[7] ?? row[6]) : undefined,
|
||||||
createdAt: Number(row.created_at || row[9]),
|
containerID: (row.container_id ?? row[8] ?? row[7]) ? String(row.container_id ?? row[8] ?? row[7]) : undefined,
|
||||||
updatedAt: Number(row.updated_at || row[10]),
|
status: String(row.status ?? row[9] ?? row[8]) as IService['status'],
|
||||||
|
createdAt: Number(row.created_at ?? row[10] ?? row[9]),
|
||||||
|
updatedAt: Number(row.updated_at ?? row[11] ?? row[10]),
|
||||||
useOneboxRegistry: row.use_onebox_registry ? Boolean(row.use_onebox_registry) : undefined,
|
useOneboxRegistry: row.use_onebox_registry ? Boolean(row.use_onebox_registry) : undefined,
|
||||||
registryRepository: row.registry_repository ? String(row.registry_repository) : undefined,
|
registryRepository: row.registry_repository ? String(row.registry_repository) : undefined,
|
||||||
registryImageTag: row.registry_image_tag ? String(row.registry_image_tag) : undefined,
|
registryImageTag: row.registry_image_tag ? String(row.registry_image_tag) : undefined,
|
||||||
|
|||||||
@@ -41,6 +41,17 @@ export class AppStoreHandler {
|
|||||||
),
|
),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
this.typedrouter.addTypedHandler(
|
||||||
|
new plugins.typedrequest.TypedHandler<interfaces.requests.IReq_InstallAppTemplate>(
|
||||||
|
'installAppTemplate',
|
||||||
|
async (dataArg) => {
|
||||||
|
await requireAdminIdentity(this.opsServerRef.adminHandler, dataArg);
|
||||||
|
const service = await this.opsServerRef.oneboxRef.appStore.installApp(dataArg.install);
|
||||||
|
return { service };
|
||||||
|
},
|
||||||
|
),
|
||||||
|
);
|
||||||
|
|
||||||
// Get services with available upgrades
|
// Get services with available upgrades
|
||||||
this.typedrouter.addTypedHandler(
|
this.typedrouter.addTypedHandler(
|
||||||
new plugins.typedrequest.TypedHandler<interfaces.requests.IReq_GetUpgradeableServices>(
|
new plugins.typedrequest.TypedHandler<interfaces.requests.IReq_GetUpgradeableServices>(
|
||||||
|
|||||||
+27
@@ -9,6 +9,8 @@ export interface IService {
|
|||||||
image: string;
|
image: string;
|
||||||
registry?: string;
|
registry?: string;
|
||||||
envVars: Record<string, string>;
|
envVars: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
port: number;
|
port: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
containerID?: string;
|
containerID?: string;
|
||||||
@@ -30,6 +32,27 @@ export interface IService {
|
|||||||
appTemplateVersion?: string;
|
appTemplateVersion?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IServiceVolume {
|
||||||
|
name?: string;
|
||||||
|
source?: string;
|
||||||
|
mountPath: string;
|
||||||
|
driver?: string;
|
||||||
|
readOnly?: boolean;
|
||||||
|
backup?: boolean;
|
||||||
|
options?: Record<string, string>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TServicePortProtocol = 'tcp' | 'udp';
|
||||||
|
|
||||||
|
export interface IServicePublishedPort {
|
||||||
|
targetPort: number;
|
||||||
|
targetPortEnd?: number;
|
||||||
|
publishedPort?: number;
|
||||||
|
publishedPortEnd?: number;
|
||||||
|
protocol?: TServicePortProtocol;
|
||||||
|
hostIp?: string;
|
||||||
|
}
|
||||||
|
|
||||||
// Registry types
|
// Registry types
|
||||||
export interface IRegistry {
|
export interface IRegistry {
|
||||||
id?: number;
|
id?: number;
|
||||||
@@ -299,6 +322,8 @@ export interface IServiceDeployOptions {
|
|||||||
image: string;
|
image: string;
|
||||||
registry?: string;
|
registry?: string;
|
||||||
envVars?: Record<string, string>;
|
envVars?: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
port: number;
|
port: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
autoSSL?: boolean;
|
autoSSL?: boolean;
|
||||||
@@ -397,6 +422,8 @@ export interface IBackupServiceConfig {
|
|||||||
image: string;
|
image: string;
|
||||||
registry?: string;
|
registry?: string;
|
||||||
envVars: Record<string, string>;
|
envVars: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
port: number;
|
port: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
useOneboxRegistry?: boolean;
|
useOneboxRegistry?: boolean;
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -12,6 +12,8 @@ export interface IService {
|
|||||||
image: string;
|
image: string;
|
||||||
registry?: string;
|
registry?: string;
|
||||||
envVars: Record<string, string>;
|
envVars: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
port: number;
|
port: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
containerID?: string;
|
containerID?: string;
|
||||||
@@ -33,12 +35,35 @@ export interface IService {
|
|||||||
appTemplateVersion?: string;
|
appTemplateVersion?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IServiceVolume {
|
||||||
|
name?: string;
|
||||||
|
source?: string;
|
||||||
|
mountPath: string;
|
||||||
|
driver?: string;
|
||||||
|
readOnly?: boolean;
|
||||||
|
backup?: boolean;
|
||||||
|
options?: Record<string, string>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TServicePortProtocol = 'tcp' | 'udp';
|
||||||
|
|
||||||
|
export interface IServicePublishedPort {
|
||||||
|
targetPort: number;
|
||||||
|
targetPortEnd?: number;
|
||||||
|
publishedPort?: number;
|
||||||
|
publishedPortEnd?: number;
|
||||||
|
protocol?: TServicePortProtocol;
|
||||||
|
hostIp?: string;
|
||||||
|
}
|
||||||
|
|
||||||
export interface IServiceCreate {
|
export interface IServiceCreate {
|
||||||
name: string;
|
name: string;
|
||||||
image: string;
|
image: string;
|
||||||
port: number;
|
port: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
envVars?: Record<string, string>;
|
envVars?: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
useOneboxRegistry?: boolean;
|
useOneboxRegistry?: boolean;
|
||||||
registryImageTag?: string;
|
registryImageTag?: string;
|
||||||
autoUpdateOnPush?: boolean;
|
autoUpdateOnPush?: boolean;
|
||||||
@@ -57,6 +82,8 @@ export interface IServiceUpdate {
|
|||||||
port?: number;
|
port?: number;
|
||||||
domain?: string;
|
domain?: string;
|
||||||
envVars?: Record<string, string>;
|
envVars?: Record<string, string>;
|
||||||
|
volumes?: IServiceVolume[];
|
||||||
|
publishedPorts?: IServicePublishedPort[];
|
||||||
}
|
}
|
||||||
|
|
||||||
export interface IContainerStats {
|
export interface IContainerStats {
|
||||||
|
|||||||
@@ -16,7 +16,8 @@ export interface IAppVersionConfig {
|
|||||||
image: string;
|
image: string;
|
||||||
port: number;
|
port: number;
|
||||||
envVars?: Array<{ key: string; value: string; description: string; required?: boolean }>;
|
envVars?: Array<{ key: string; value: string; description: string; required?: boolean }>;
|
||||||
volumes?: string[];
|
volumes?: Array<string | data.IServiceVolume>;
|
||||||
|
publishedPorts?: data.IServicePublishedPort[];
|
||||||
platformRequirements?: {
|
platformRequirements?: {
|
||||||
mongodb?: boolean;
|
mongodb?: boolean;
|
||||||
s3?: boolean;
|
s3?: boolean;
|
||||||
@@ -27,6 +28,17 @@ export interface IAppVersionConfig {
|
|||||||
minOneboxVersion?: string;
|
minOneboxVersion?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IAppInstallOptions {
|
||||||
|
appId: string;
|
||||||
|
version?: string;
|
||||||
|
serviceName: string;
|
||||||
|
domain?: string;
|
||||||
|
port?: number;
|
||||||
|
publishedPorts?: data.IServicePublishedPort[];
|
||||||
|
envVars?: Record<string, string>;
|
||||||
|
autoDNS?: boolean;
|
||||||
|
}
|
||||||
|
|
||||||
export interface IAppMeta {
|
export interface IAppMeta {
|
||||||
id: string;
|
id: string;
|
||||||
name: string;
|
name: string;
|
||||||
@@ -76,6 +88,20 @@ export interface IReq_GetAppConfig extends plugins.typedrequestInterfaces.implem
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface IReq_InstallAppTemplate extends plugins.typedrequestInterfaces.implementsTR<
|
||||||
|
plugins.typedrequestInterfaces.ITypedRequest,
|
||||||
|
IReq_InstallAppTemplate
|
||||||
|
> {
|
||||||
|
method: 'installAppTemplate';
|
||||||
|
request: {
|
||||||
|
identity: data.IIdentity;
|
||||||
|
install: IAppInstallOptions;
|
||||||
|
};
|
||||||
|
response: {
|
||||||
|
service: data.IService;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
export interface IReq_GetUpgradeableServices extends plugins.typedrequestInterfaces.implementsTR<
|
export interface IReq_GetUpgradeableServices extends plugins.typedrequestInterfaces.implementsTR<
|
||||||
plugins.typedrequestInterfaces.ITypedRequest,
|
plugins.typedrequestInterfaces.ITypedRequest,
|
||||||
IReq_GetUpgradeableServices
|
IReq_GetUpgradeableServices
|
||||||
|
|||||||
@@ -3,6 +3,6 @@
|
|||||||
*/
|
*/
|
||||||
export const commitinfo = {
|
export const commitinfo = {
|
||||||
name: '@serve.zone/onebox',
|
name: '@serve.zone/onebox',
|
||||||
version: '1.27.0',
|
version: '1.28.0',
|
||||||
description: 'Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers'
|
description: 'Self-hosted container platform with automatic SSL and DNS - a mini Heroku for single servers'
|
||||||
}
|
}
|
||||||
|
|||||||
+4
-1
@@ -1048,7 +1048,10 @@ const dispatchCombinedRefreshAction = async () => {
|
|||||||
if (!loginState.isLoggedIn) return;
|
if (!loginState.isLoggedIn) return;
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await systemStatePart.dispatchAction(fetchSystemStatusAction, null);
|
await Promise.all([
|
||||||
|
systemStatePart.dispatchAction(fetchSystemStatusAction, null),
|
||||||
|
networkStatePart.dispatchAction(fetchTrafficStatsAction, null),
|
||||||
|
]);
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
// Silently fail on auto-refresh
|
// Silently fail on auto-refresh
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -288,6 +288,34 @@ export class ObViewAppStore extends DeesElement {
|
|||||||
text-align: center;
|
text-align: center;
|
||||||
color: var(--ci-shade-4, #71717a);
|
color: var(--ci-shade-4, #71717a);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.footprint-list {
|
||||||
|
display: grid;
|
||||||
|
gap: 8px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.footprint-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
gap: 12px;
|
||||||
|
padding: 10px 12px;
|
||||||
|
border: 1px solid var(--ci-shade-2, #27272a);
|
||||||
|
border-radius: 6px;
|
||||||
|
font-size: 13px;
|
||||||
|
color: var(--ci-shade-6, #d4d4d8);
|
||||||
|
}
|
||||||
|
|
||||||
|
.footprint-meta {
|
||||||
|
color: var(--ci-shade-4, #71717a);
|
||||||
|
font-family: monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
.exposure-warning {
|
||||||
|
margin-top: 10px;
|
||||||
|
color: #fbbf24;
|
||||||
|
font-size: 12px;
|
||||||
|
line-height: 1.5;
|
||||||
|
}
|
||||||
`,
|
`,
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -410,6 +438,8 @@ export class ObViewAppStore extends DeesElement {
|
|||||||
</div>
|
</div>
|
||||||
` : ''}
|
` : ''}
|
||||||
|
|
||||||
|
${this.renderDeploymentFootprint(config)}
|
||||||
|
|
||||||
<!-- Version & Image -->
|
<!-- Version & Image -->
|
||||||
<div class="detail-card">
|
<div class="detail-card">
|
||||||
<div class="section-label">Version</div>
|
<div class="section-label">Version</div>
|
||||||
@@ -489,6 +519,8 @@ export class ObViewAppStore extends DeesElement {
|
|||||||
Onebox routes this domain to the deployed app. Required when the app uses SERVICE_DOMAIN.
|
Onebox routes this domain to the deployed app. Required when the app uses SERVICE_DOMAIN.
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
${this.renderDeployConfirmation(config)}
|
||||||
|
|
||||||
<div class="actions-row">
|
<div class="actions-row">
|
||||||
<button class="btn btn-secondary" @click=${() => { this.currentView = 'grid'; }}>Cancel</button>
|
<button class="btn btn-secondary" @click=${() => { this.currentView = 'grid'; }}>Cancel</button>
|
||||||
<button class="btn btn-primary" @click=${() => this.handleDeploy()}>
|
<button class="btn btn-primary" @click=${() => this.handleDeploy()}>
|
||||||
@@ -509,6 +541,73 @@ export class ObViewAppStore extends DeesElement {
|
|||||||
`;
|
`;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private renderDeploymentFootprint(config: interfaces.requests.IAppVersionConfig): TemplateResult | '' {
|
||||||
|
const volumes = this.getConfigVolumes(config);
|
||||||
|
const publishedPorts = config.publishedPorts || [];
|
||||||
|
|
||||||
|
if (volumes.length === 0 && publishedPorts.length === 0) {
|
||||||
|
return '';
|
||||||
|
}
|
||||||
|
|
||||||
|
return html`
|
||||||
|
<div class="detail-card">
|
||||||
|
<div class="section-label">Deployment Footprint</div>
|
||||||
|
<div class="footprint-list">
|
||||||
|
${volumes.map((volume) => html`
|
||||||
|
<div class="footprint-item">
|
||||||
|
<span>Volume mount</span>
|
||||||
|
<span class="footprint-meta">
|
||||||
|
${volume.source || volume.name || 'managed volume'}:${volume.mountPath}${volume.readOnly ? ':ro' : ''}
|
||||||
|
</span>
|
||||||
|
</div>
|
||||||
|
`)}
|
||||||
|
${publishedPorts.map((port) => html`
|
||||||
|
<div class="footprint-item">
|
||||||
|
<span>Published host port</span>
|
||||||
|
<span class="footprint-meta">${this.formatPublishedPort(port)}</span>
|
||||||
|
</div>
|
||||||
|
`)}
|
||||||
|
</div>
|
||||||
|
${publishedPorts.length > 0 ? html`
|
||||||
|
<div class="exposure-warning">
|
||||||
|
This app publishes raw host ports outside the HTTP proxy. Confirm firewall and network policy before deploying.
|
||||||
|
</div>
|
||||||
|
` : ''}
|
||||||
|
</div>
|
||||||
|
`;
|
||||||
|
}
|
||||||
|
|
||||||
|
private renderDeployConfirmation(config: interfaces.requests.IAppVersionConfig): TemplateResult | '' {
|
||||||
|
const volumes = this.getConfigVolumes(config);
|
||||||
|
const publishedPorts = config.publishedPorts || [];
|
||||||
|
if (volumes.length === 0 && publishedPorts.length === 0) return '';
|
||||||
|
|
||||||
|
return html`
|
||||||
|
<div class="exposure-warning">
|
||||||
|
Deploying this app will create ${volumes.length} persistent volume(s)
|
||||||
|
${publishedPorts.length > 0 ? html`and expose ${publishedPorts.length} host port declaration(s)` : ''}.
|
||||||
|
</div>
|
||||||
|
`;
|
||||||
|
}
|
||||||
|
|
||||||
|
private getConfigVolumes(config: interfaces.requests.IAppVersionConfig): interfaces.data.IServiceVolume[] {
|
||||||
|
return (config.volumes || []).map((volume) => {
|
||||||
|
if (typeof volume === 'string') {
|
||||||
|
return { mountPath: volume };
|
||||||
|
}
|
||||||
|
return volume;
|
||||||
|
}).filter((volume) => Boolean(volume.mountPath));
|
||||||
|
}
|
||||||
|
|
||||||
|
private formatPublishedPort(port: interfaces.data.IServicePublishedPort): string {
|
||||||
|
const protocol = port.protocol || 'tcp';
|
||||||
|
const target = port.targetPortEnd ? `${port.targetPort}-${port.targetPortEnd}` : String(port.targetPort);
|
||||||
|
const publishedStart = port.publishedPort || port.targetPort;
|
||||||
|
const publishedEnd = port.publishedPortEnd || (port.targetPortEnd ? publishedStart + (port.targetPortEnd - port.targetPort) : undefined);
|
||||||
|
const published = publishedEnd ? `${publishedStart}-${publishedEnd}` : String(publishedStart);
|
||||||
|
return `${port.hostIp || '0.0.0.0'}:${published}/${protocol} -> ${target}/${protocol}`;
|
||||||
|
}
|
||||||
|
|
||||||
private async handleViewDetails(e: CustomEvent) {
|
private async handleViewDetails(e: CustomEvent) {
|
||||||
const app = e.detail?.app;
|
const app = e.detail?.app;
|
||||||
if (!app) return;
|
if (!app) return;
|
||||||
@@ -625,25 +724,21 @@ export class ObViewAppStore extends DeesElement {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const platformReqs = config.platformRequirements || {};
|
try {
|
||||||
const serviceConfig: interfaces.data.IServiceCreate = {
|
const identity = appstate.loginStatePart.getState().identity;
|
||||||
name: this.serviceName || app.id,
|
if (!identity) return;
|
||||||
image: config.image,
|
const typedRequest = new plugins.domtools.plugins.typedrequest.TypedRequest<
|
||||||
port: config.port || 80,
|
interfaces.requests.IReq_InstallAppTemplate
|
||||||
|
>('/typedrequest', 'installAppTemplate');
|
||||||
|
await typedRequest.fire({
|
||||||
|
identity,
|
||||||
|
install: {
|
||||||
|
appId: app.id,
|
||||||
|
version: this.selectedVersion,
|
||||||
|
serviceName: this.serviceName || app.id,
|
||||||
domain: this.serviceDomain || undefined,
|
domain: this.serviceDomain || undefined,
|
||||||
envVars,
|
envVars,
|
||||||
enableMongoDB: platformReqs.mongodb || false,
|
},
|
||||||
enableS3: platformReqs.s3 || false,
|
|
||||||
enableClickHouse: platformReqs.clickhouse || false,
|
|
||||||
enableRedis: platformReqs.redis || false,
|
|
||||||
enableMariaDB: platformReqs.mariadb || false,
|
|
||||||
appTemplateId: app.id,
|
|
||||||
appTemplateVersion: this.selectedVersion,
|
|
||||||
};
|
|
||||||
|
|
||||||
try {
|
|
||||||
await appstate.servicesStatePart.dispatchAction(appstate.createServiceAction, {
|
|
||||||
config: serviceConfig,
|
|
||||||
});
|
});
|
||||||
setTimeout(() => {
|
setTimeout(() => {
|
||||||
appRouter.navigateToView('services');
|
appRouter.navigateToView('services');
|
||||||
|
|||||||
@@ -12,6 +12,20 @@ import {
|
|||||||
type TemplateResult,
|
type TemplateResult,
|
||||||
} from '@design.estate/dees-element';
|
} from '@design.estate/dees-element';
|
||||||
|
|
||||||
|
const byteUnits = ['B', 'KB', 'MB', 'GB', 'TB'];
|
||||||
|
|
||||||
|
function getByteUnitIndex(bytes: number): number {
|
||||||
|
if (!bytes || bytes === 0) return 0;
|
||||||
|
return Math.min(Math.floor(Math.log(bytes) / Math.log(1024)), byteUnits.length - 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
function formatBytes(bytes: number, forcedUnitIndex?: number): string {
|
||||||
|
if ((!bytes || bytes === 0) && forcedUnitIndex === undefined) return '0 B';
|
||||||
|
const unitIndex = forcedUnitIndex ?? getByteUnitIndex(bytes);
|
||||||
|
const value = bytes / Math.pow(1024, unitIndex);
|
||||||
|
return `${value.toFixed(1)} ${byteUnits[unitIndex]}`;
|
||||||
|
}
|
||||||
|
|
||||||
@customElement('ob-view-dashboard')
|
@customElement('ob-view-dashboard')
|
||||||
export class ObViewDashboard extends DeesElement {
|
export class ObViewDashboard extends DeesElement {
|
||||||
@state()
|
@state()
|
||||||
@@ -69,7 +83,42 @@ export class ObViewDashboard extends DeesElement {
|
|||||||
public static styles = [
|
public static styles = [
|
||||||
cssManager.defaultStyles,
|
cssManager.defaultStyles,
|
||||||
shared.viewHostCss,
|
shared.viewHostCss,
|
||||||
css``,
|
css`
|
||||||
|
.dashboard {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
gap: 24px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.section {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
}
|
||||||
|
|
||||||
|
.section-title {
|
||||||
|
font-size: 18px;
|
||||||
|
font-weight: 600;
|
||||||
|
color: ${cssManager.bdTheme('#18181b', '#fafafa')};
|
||||||
|
margin: 0 0 12px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.services-grid {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 16px;
|
||||||
|
align-items: stretch;
|
||||||
|
}
|
||||||
|
|
||||||
|
.services-grid > * {
|
||||||
|
height: 100%;
|
||||||
|
}
|
||||||
|
|
||||||
|
@media (min-width: 768px) {
|
||||||
|
.services-grid {
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`,
|
||||||
];
|
];
|
||||||
|
|
||||||
async connectedCallback() {
|
async connectedCallback() {
|
||||||
@@ -79,6 +128,7 @@ export class ObViewDashboard extends DeesElement {
|
|||||||
appstate.servicesStatePart.dispatchAction(appstate.fetchServicesAction, null),
|
appstate.servicesStatePart.dispatchAction(appstate.fetchServicesAction, null),
|
||||||
appstate.servicesStatePart.dispatchAction(appstate.fetchPlatformServicesAction, null),
|
appstate.servicesStatePart.dispatchAction(appstate.fetchPlatformServicesAction, null),
|
||||||
appstate.networkStatePart.dispatchAction(appstate.fetchNetworkStatsAction, null),
|
appstate.networkStatePart.dispatchAction(appstate.fetchNetworkStatsAction, null),
|
||||||
|
appstate.networkStatePart.dispatchAction(appstate.fetchTrafficStatsAction, null),
|
||||||
appstate.networkStatePart.dispatchAction(appstate.fetchCertificatesAction, null),
|
appstate.networkStatePart.dispatchAction(appstate.fetchCertificatesAction, null),
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
@@ -88,10 +138,15 @@ export class ObViewDashboard extends DeesElement {
|
|||||||
const services = this.servicesState.services;
|
const services = this.servicesState.services;
|
||||||
const platformServices = this.servicesState.platformServices;
|
const platformServices = this.servicesState.platformServices;
|
||||||
const networkStats = this.networkState.stats;
|
const networkStats = this.networkState.stats;
|
||||||
|
const trafficStats = this.networkState.trafficStats;
|
||||||
const certificates = this.networkState.certificates;
|
const certificates = this.networkState.certificates;
|
||||||
|
const statusCounts = trafficStats?.statusCounts || {};
|
||||||
|
|
||||||
const runningServices = services.filter((s) => s.status === 'running').length;
|
const runningServices = services.filter((s) => s.status === 'running').length;
|
||||||
const stoppedServices = services.filter((s) => s.status === 'stopped').length;
|
const stoppedServices = services.filter((s) => s.status === 'stopped').length;
|
||||||
|
const memoryUnitIndex = getByteUnitIndex(
|
||||||
|
status?.docker?.memoryTotal || status?.docker?.memoryUsage || 0,
|
||||||
|
);
|
||||||
|
|
||||||
const validCerts = certificates.filter((c) => c.isValid).length;
|
const validCerts = certificates.filter((c) => c.isValid).length;
|
||||||
const expiringCerts = certificates.filter(
|
const expiringCerts = certificates.filter(
|
||||||
@@ -99,22 +154,19 @@ export class ObViewDashboard extends DeesElement {
|
|||||||
).length;
|
).length;
|
||||||
const expiredCerts = certificates.filter((c) => !c.isValid).length;
|
const expiredCerts = certificates.filter((c) => !c.isValid).length;
|
||||||
|
|
||||||
return html`
|
const dashboardData = {
|
||||||
<ob-sectionheading>Dashboard</ob-sectionheading>
|
|
||||||
<sz-dashboard-view
|
|
||||||
.data=${{
|
|
||||||
cluster: {
|
cluster: {
|
||||||
totalServices: services.length,
|
totalServices: services.length,
|
||||||
running: runningServices,
|
running: runningServices,
|
||||||
stopped: stoppedServices,
|
stopped: stoppedServices,
|
||||||
dockerStatus: status?.docker?.running ? 'running' : 'stopped',
|
dockerStatus: status?.docker?.running ? 'running' as const : 'stopped' as const,
|
||||||
},
|
},
|
||||||
resourceUsage: {
|
resourceUsage: {
|
||||||
cpu: status?.docker?.cpuUsage || 0,
|
cpu: status?.docker?.cpuUsage || 0,
|
||||||
memoryUsed: status?.docker?.memoryUsage || 0,
|
memoryUsed: formatBytes(status?.docker?.memoryUsage || 0, memoryUnitIndex),
|
||||||
memoryTotal: status?.docker?.memoryTotal || 0,
|
memoryTotal: formatBytes(status?.docker?.memoryTotal || 0, memoryUnitIndex),
|
||||||
networkIn: status?.docker?.networkIn || 0,
|
networkIn: formatBytes(status?.docker?.networkIn || 0),
|
||||||
networkOut: status?.docker?.networkOut || 0,
|
networkOut: formatBytes(status?.docker?.networkOut || 0),
|
||||||
topConsumers: [],
|
topConsumers: [],
|
||||||
},
|
},
|
||||||
platformServices: platformServices
|
platformServices: platformServices
|
||||||
@@ -125,39 +177,75 @@ export class ObViewDashboard extends DeesElement {
|
|||||||
running: ps.status === 'running',
|
running: ps.status === 'running',
|
||||||
})),
|
})),
|
||||||
traffic: {
|
traffic: {
|
||||||
requests: 0,
|
requests: trafficStats?.requestCount || 0,
|
||||||
errors: 0,
|
errors: trafficStats?.errorCount || 0,
|
||||||
errorPercent: 0,
|
errorPercent: trafficStats?.errorRate || 0,
|
||||||
avgResponse: 0,
|
avgResponse: trafficStats?.avgResponseTime || 0,
|
||||||
reqPerMin: 0,
|
reqPerMin: trafficStats?.requestsPerMinute || 0,
|
||||||
status2xx: 0,
|
status2xx: statusCounts['2xx'] || 0,
|
||||||
status3xx: 0,
|
status3xx: statusCounts['3xx'] || 0,
|
||||||
status4xx: 0,
|
status4xx: statusCounts['4xx'] || 0,
|
||||||
status5xx: 0,
|
status5xx: statusCounts['5xx'] || 0,
|
||||||
},
|
},
|
||||||
proxy: {
|
proxy: {
|
||||||
httpPort: networkStats?.proxy?.httpPort || 80,
|
httpPort: String(networkStats?.proxy?.httpPort || 80),
|
||||||
httpsPort: networkStats?.proxy?.httpsPort || 443,
|
httpsPort: String(networkStats?.proxy?.httpsPort || 443),
|
||||||
httpActive: networkStats?.proxy?.running || false,
|
httpActive: networkStats?.proxy?.running || false,
|
||||||
httpsActive: networkStats?.proxy?.running || false,
|
httpsActive: networkStats?.proxy?.running || false,
|
||||||
routeCount: networkStats?.proxy?.routes || 0,
|
routeCount: String(networkStats?.proxy?.routes || 0),
|
||||||
},
|
},
|
||||||
certificates: {
|
certificates: {
|
||||||
valid: validCerts,
|
valid: validCerts,
|
||||||
expiring: expiringCerts,
|
expiring: expiringCerts,
|
||||||
expired: expiredCerts,
|
expired: expiredCerts,
|
||||||
},
|
},
|
||||||
dnsConfigured: true,
|
dnsConfigured: status?.dns?.configured || false,
|
||||||
acmeConfigured: true,
|
acmeConfigured: status?.ssl?.configured || false,
|
||||||
quickActions: [
|
quickActions: [
|
||||||
{ label: 'Deploy Service', icon: 'lucide:Plus', primary: true },
|
{ label: 'Deploy Service', icon: 'lucide:Plus', primary: true },
|
||||||
{ label: 'Add Domain', icon: 'lucide:Globe' },
|
{ label: 'Add Domain', icon: 'lucide:Globe' },
|
||||||
{ label: 'View Logs', icon: 'lucide:FileText' },
|
{ label: 'View Logs', icon: 'lucide:FileText' },
|
||||||
],
|
],
|
||||||
}}
|
};
|
||||||
@action-click=${(e: CustomEvent) => this.handleQuickAction(e)}
|
|
||||||
|
return html`
|
||||||
|
<ob-sectionheading>Dashboard</ob-sectionheading>
|
||||||
|
<div class="dashboard">
|
||||||
|
<section class="section">
|
||||||
|
<h2 class="section-title">Cluster Overview</h2>
|
||||||
|
<sz-status-grid-cluster .stats=${dashboardData.cluster}></sz-status-grid-cluster>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="section">
|
||||||
|
<h2 class="section-title">Services & Resources</h2>
|
||||||
|
<div class="services-grid">
|
||||||
|
<sz-resource-usage-card .data=${dashboardData.resourceUsage}></sz-resource-usage-card>
|
||||||
|
<sz-platform-services-card
|
||||||
|
.services=${dashboardData.platformServices}
|
||||||
@service-click=${(e: CustomEvent) => this.handlePlatformServiceClick(e)}
|
@service-click=${(e: CustomEvent) => this.handlePlatformServiceClick(e)}
|
||||||
></sz-dashboard-view>
|
></sz-platform-services-card>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="section">
|
||||||
|
<h2 class="section-title">Network & Traffic</h2>
|
||||||
|
<sz-status-grid-network
|
||||||
|
.traffic=${dashboardData.traffic}
|
||||||
|
.proxy=${dashboardData.proxy}
|
||||||
|
.certificates=${dashboardData.certificates}
|
||||||
|
></sz-status-grid-network>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="section">
|
||||||
|
<h2 class="section-title">Infrastructure</h2>
|
||||||
|
<sz-status-grid-infra
|
||||||
|
?dnsConfigured=${dashboardData.dnsConfigured}
|
||||||
|
?acmeConfigured=${dashboardData.acmeConfigured}
|
||||||
|
.actions=${dashboardData.quickActions}
|
||||||
|
@action-click=${(e: CustomEvent) => this.handleQuickAction(e)}
|
||||||
|
></sz-status-grid-infra>
|
||||||
|
</section>
|
||||||
|
</div>
|
||||||
`;
|
`;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user