mirror of
https://codeberg.org/PostERG/xamxam.git
synced 2026-09-25 01:53:03 +02:00
test-env: podman-compose fresh-Debian harness + ssh/rsync deploy shims
Add a test environment that simulates a blank Debian trixie box (systemd + sshd container) and routes the project's real 📦 Linting CSS + JS (biome)… Checked 71 files in 140ms. No fixes applied. 📦 Building CSS bundles… 🎨 Building CSS bundles… ✓ base.min.css (22,317 bytes) ✓ admin.min.css (55,602 bytes) ✓ form.min.css (41,855 bytes) ✓ public.min.css (4,310 bytes) ✓ tfe.min.css (9,089 bytes) ✓ repertoire.min.css (13,166 bytes) ✓ content-page.min.css (3,683 bytes) ✓ not-found.min.css (672 bytes) ✓ system.min.css (7,408 bytes) ✓ file-access.min.css (3,733 bytes) ✓ form-base.min.css (19,110 bytes) ✓ partage-form.min.css (37,229 bytes) ✅ CSS bundles done — 218,174 bytes total 📦 Building JS bundles… 📦 Building JS bundles… ✓ admin.min.js (60,911 bytes) ✓ public.min.js (22,022 bytes) ✓ form.min.js (41,547 bytes) ✓ partage.min.js (42,441 bytes) ✅ JS bundles done ✅ Build complete 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=461/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=458/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=411/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=411/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=401/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=360/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=325/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=319/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=309/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=302/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=280/469) 700 0% 0.00kB/s 0:00:00 55,602 1% 52.36MB/s 0:00:00 (xfr#1, to-chk=265/469) 55,602 1% 52.36MB/s 0:00:00 (xfr#1, to-chk=250/469) 116,513 2% 110.45MB/s 0:00:00 (xfr#2, to-chk=264/469) 138,830 2% 131.73MB/s 0:00:00 (xfr#3, to-chk=263/469) 142,513 2% 135.24MB/s 0:00:00 (xfr#4, to-chk=262/469) 146,246 2% 138.80MB/s 0:00:00 (xfr#5, to-chk=261/469) 165,356 2% 157.03MB/s 0:00:00 (xfr#6, to-chk=260/469) 207,211 3% 196.94MB/s 0:00:00 (xfr#7, to-chk=259/469) 248,758 4% 236.57MB/s 0:00:00 (xfr#8, to-chk=258/469) 249,430 4% 237.21MB/s 0:00:00 (xfr#9, to-chk=257/469) 286,659 5% 272.71MB/s 0:00:00 (xfr#10, to-chk=256/469) 329,100 5% 313.19MB/s 0:00:00 (xfr#11, to-chk=255/469) 333,410 6% 317.30MB/s 0:00:00 (xfr#12, to-chk=254/469) 355,432 6% 338.30MB/s 0:00:00 (xfr#13, to-chk=253/469) 368,598 6% 350.85MB/s 0:00:00 (xfr#14, to-chk=252/469) 376,006 6% 357.92MB/s 0:00:00 (xfr#15, to-chk=251/469) 385,095 6% 366.59MB/s 0:00:00 (xfr#16, to-chk=250/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=250/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=235/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=230/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=193/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=192/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=189/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=156/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=156/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=147/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=135/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=134/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=129/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=120/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=93/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=78/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=77/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=71/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=71/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=64/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=43/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=39/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=34/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=33/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=25/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=8/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=0/469) 📋 Deploying nginx configuration… xamxam.conf sent 145 bytes received 125 bytes 540.00 bytes/sec total size is 10,012 speedup is 37.08 deploy-server.sh sent 1,089 bytes received 107 bytes 797.33 bytes/sec total size is 8,519 speedup is 7.12 recipes to it via safe ssh/rsync shims, so setup scripts can be validated without touching production. Includes provision-server-packages.sh, setup.sh/teardown.sh, server Dockerfile + helper, and the rendered ssh config. Validated end-to-end against the box: - provisioning (apt nginx, php8.4-fpm, composer), - scripts/setup-server.sh (group/user/dir bootstrap), - just deploy-code (transfer; surfaced the deploy-code --chown regression).
This commit is contained in:
@@ -0,0 +1,69 @@
|
||||
# XAMXAM test server — simulates a FRESH Debian machine with nothing preinstalled.
|
||||
#
|
||||
# This image intentionally installs ONLY the bare minimum needed to SSH in and
|
||||
# run systemd services (nginx/php-fpm are brought up later by the provisioning
|
||||
# step, so the apt-installs in scripts genuinely mirror a greenfield server).
|
||||
#
|
||||
# Name of image : debian trixie (ships PHP 8.4 — required by the project).
|
||||
# systemd : enabled so `systemctl start nginx` / php-fpm work.
|
||||
# sshd : a throwaway test keypair is baked in so the `cli` service
|
||||
# can reach us as the `xamxam` SSH alias.
|
||||
#
|
||||
# Build: podman build -t xamxam-test-server ./server
|
||||
|
||||
FROM debian:trixie-slim
|
||||
|
||||
# Systemd needs the container to run as PID 1 with a cgroup namespace.
|
||||
ENV container=docker
|
||||
|
||||
# 1. Base: systemd, an SSH server, sudo, and proc/ps for systemctl helpers.
|
||||
RUN apt-get update \
|
||||
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
||||
systemd \
|
||||
systemd-sysv \
|
||||
systemd-container \
|
||||
openssh-server \
|
||||
sudo \
|
||||
ca-certificates \
|
||||
curl \
|
||||
rsync \
|
||||
procps \
|
||||
iproute2 \
|
||||
sed \
|
||||
grep \
|
||||
coreutils \
|
||||
&& apt-get clean \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# 2. Prevent systemd from starting extra junk / writing to read-only paths.
|
||||
RUN rm -f /etc/systemd/system/*.target.wants/* \
|
||||
&& rm -f /etc/systemd/system/multi-user.target.wants/* \
|
||||
&& rm -f /etc/systemd/system/getty@.service \
|
||||
&& rm -rf /lib/systemd/system/sysinit.target.wants \
|
||||
&& rm -rf /lib/systemd/system/local-fs.target.wants \
|
||||
&& rm -rf /lib/systemd/system/slices.target.wants \
|
||||
&& ln -s /lib/systemd/system/systemd-timedated.service /etc/systemd/system/dbus-org.freedesktop.timedate1.service 2>/dev/null || true
|
||||
|
||||
# 3. SSH: allow root login for initial provisioning convenience, drop in a
|
||||
# throwaway host key + authorized key (regenerated per-run by the entrypoint).
|
||||
RUN mkdir -p /root/.ssh /run/sshd \
|
||||
&& touch /root/.ssh/authorized_keys \
|
||||
&& chmod 700 /root/.ssh \
|
||||
&& chmod 600 /root/.ssh/authorized_keys \
|
||||
&& echo 'PermitRootLogin prohibit-password' >> /etc/ssh/sshd_config \
|
||||
&& echo 'PubkeyAuthentication yes' > /etc/ssh/sshd_config.d/test.conf \
|
||||
&& echo 'PasswordAuthentication no' >> /etc/ssh/sshd_config.d/test.conf
|
||||
|
||||
# The provisioning work expects a non-root deploy user; /root is used only to
|
||||
# bootstrap, then `scripts/setup-server.sh` creates the real accounts.
|
||||
|
||||
EXPOSE 22
|
||||
|
||||
# Bootstrap helper: `podman compose run --rm server add-key "<pub>"` and a few
|
||||
# tiny admin commands. Installed as /usr/local/bin/helper.
|
||||
COPY scripts/server-helper.sh /usr/local/bin/helper
|
||||
RUN chmod +x /usr/local/bin/helper
|
||||
|
||||
# Boot systemd as PID 1. The entrypoint regenerates the ssh host keys so each
|
||||
# container start is fresh (and the `cli` hops with StrictHostKeyChecking=no).
|
||||
ENTRYPOINT ["/lib/systemd/systemd"]
|
||||
Reference in New Issue
Block a user