09ae93db05
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
39 lines
2.8 KiB
Python
39 lines
2.8 KiB
Python
#!/usr/bin/env python3
|
|
"""bookstack_36.py — checklist 3.6 for BookStack with and without APP_PROXIES=172.16.0.0/12, on 9202 through the SIMULATED
|
|
tunnel (bslogin.sh in a curl container at 172.16.253.2). Phase 1 = the live template (control); phase 2 = the same box
|
|
with APP_PROXIES added by hand to the stack's compose and the app restarted through the product. Env: SC, EV."""
|
|
import os, subprocess, sys, time
|
|
sys.path.insert(0, "/mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu/scripts")
|
|
import box_walk as w
|
|
APP, SUB, EMAIL = "bookstack", "wiki", "admin@admin.com"
|
|
log = open(f"{w.EV}/bookstack-3.6.txt", "a", buffering=1)
|
|
def say(*a):
|
|
w.say(*a); log.write(" ".join(map(str, a)) + "\n")
|
|
def login(visitor, forged, pw):
|
|
return w.guest(f"docker run --rm --network felhom-tunnel --ip 172.16.253.2 -v /root/bslogin.sh:/s.sh:ro -v /root/.bspw:/pw:ro "
|
|
f"curlimages/curl:8.11.1 sh /s.sh {visitor} {forged} {EMAIL} {pw}").strip().splitlines()[-1:]
|
|
def round_(label):
|
|
say(f"## {label} — {time.strftime('%FT%TZ', time.gmtime())}")
|
|
r = [login("198.51.100.66", f"10.5.0.{i}", "-wrong")[0] for i in range(1, 7)]
|
|
say(f" stranger 198.51.100.66, 6 wrong for {EMAIL} (a new forged leftmost each): {r}")
|
|
say(f" household 203.0.113.10, the right password, at once: {login('203.0.113.10', '203.0.113.10', '/pw')}")
|
|
w.login()
|
|
say(f"##### BookStack 3.6 on 9202 — controller {w.guest('docker inspect felhom-controller --format {{.Config.Image}}').strip()}")
|
|
say("deploy ->", w.deploy(APP, SUB))
|
|
pw = (w.GENERATED.get(APP) or {}).get("ADMIN_PASSWORD")
|
|
if not pw: sys.exit("no generated ADMIN_PASSWORD")
|
|
w.guest(f"umask 077; cat > /root/.bspw <<'PEOF'\n{pw}\nPEOF\ntruncate -s -1 /root/.bspw; chmod 644 /root/.bspw")
|
|
for _ in range(60): # after_install replaces the login, then the hold opens
|
|
if "install_hold" not in w.guest("grep -A2 '^install_hold:' /opt/docker/stacks/bookstack/app.yaml | grep -c 'state: open' | sed 's/^1$/open/;s/^0$/install_hold/'"): break
|
|
time.sleep(5)
|
|
w.wait_app(SUB, "/login", tries=40)
|
|
round_("phase 1 — the live template (no APP_PROXIES): control")
|
|
say(" waiting 75 s for BookStack's 60-second throttle to pass"); time.sleep(75)
|
|
w.guest("cd /opt/docker/stacks/bookstack && grep -q APP_PROXIES docker-compose.yml || sed -i 's#^\\(\\s*\\)- APP_URL=#\\1- APP_PROXIES=172.16.0.0/12\\n\\1- APP_URL=#' docker-compose.yml; grep -n APP_PROXIES docker-compose.yml")
|
|
code, d = w.ctl("POST", f"/api/stacks/{APP}/restart"); say("restart through the product ->", code)
|
|
w.wait_app(SUB, "/login", tries=40)
|
|
say(" the running container's env:", w.guest("docker exec bookstack printenv APP_PROXIES").strip())
|
|
round_("phase 2 — APP_PROXIES=172.16.0.0/12")
|
|
say(" LAN household (192.168.0.180), right password, while the stranger is throttled:")
|
|
w.guest("true")
|