mirror of
https://codeberg.org/PostERG/xamxam.git
synced 2026-09-25 09:53:08 +02:00
Add a test environment that simulates a blank Debian trixie box (systemd + sshd container) and routes the project's real 📦 Linting CSS + JS (biome)… Checked 71 files in 140ms. No fixes applied. 📦 Building CSS bundles… 🎨 Building CSS bundles… ✓ base.min.css (22,317 bytes) ✓ admin.min.css (55,602 bytes) ✓ form.min.css (41,855 bytes) ✓ public.min.css (4,310 bytes) ✓ tfe.min.css (9,089 bytes) ✓ repertoire.min.css (13,166 bytes) ✓ content-page.min.css (3,683 bytes) ✓ not-found.min.css (672 bytes) ✓ system.min.css (7,408 bytes) ✓ file-access.min.css (3,733 bytes) ✓ form-base.min.css (19,110 bytes) ✓ partage-form.min.css (37,229 bytes) ✅ CSS bundles done — 218,174 bytes total 📦 Building JS bundles… 📦 Building JS bundles… ✓ admin.min.js (60,911 bytes) ✓ public.min.js (22,022 bytes) ✓ form.min.js (41,547 bytes) ✓ partage.min.js (42,441 bytes) ✅ JS bundles done ✅ Build complete 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=461/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=458/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=411/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=411/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=401/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=360/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=325/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=319/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=309/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=302/469) 0 0% 0.00kB/s 0:00:00 (xfr#0, to-chk=280/469) 700 0% 0.00kB/s 0:00:00 55,602 1% 52.36MB/s 0:00:00 (xfr#1, to-chk=265/469) 55,602 1% 52.36MB/s 0:00:00 (xfr#1, to-chk=250/469) 116,513 2% 110.45MB/s 0:00:00 (xfr#2, to-chk=264/469) 138,830 2% 131.73MB/s 0:00:00 (xfr#3, to-chk=263/469) 142,513 2% 135.24MB/s 0:00:00 (xfr#4, to-chk=262/469) 146,246 2% 138.80MB/s 0:00:00 (xfr#5, to-chk=261/469) 165,356 2% 157.03MB/s 0:00:00 (xfr#6, to-chk=260/469) 207,211 3% 196.94MB/s 0:00:00 (xfr#7, to-chk=259/469) 248,758 4% 236.57MB/s 0:00:00 (xfr#8, to-chk=258/469) 249,430 4% 237.21MB/s 0:00:00 (xfr#9, to-chk=257/469) 286,659 5% 272.71MB/s 0:00:00 (xfr#10, to-chk=256/469) 329,100 5% 313.19MB/s 0:00:00 (xfr#11, to-chk=255/469) 333,410 6% 317.30MB/s 0:00:00 (xfr#12, to-chk=254/469) 355,432 6% 338.30MB/s 0:00:00 (xfr#13, to-chk=253/469) 368,598 6% 350.85MB/s 0:00:00 (xfr#14, to-chk=252/469) 376,006 6% 357.92MB/s 0:00:00 (xfr#15, to-chk=251/469) 385,095 6% 366.59MB/s 0:00:00 (xfr#16, to-chk=250/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=250/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=235/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=230/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=193/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=192/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=189/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=156/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=156/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=147/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=135/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=134/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=129/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=120/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=93/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=78/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=77/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=71/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=71/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=64/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=43/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=39/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=34/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=33/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=25/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=8/469) 385,095 6% 2.96MB/s 0:00:00 (xfr#16, to-chk=0/469) 📋 Deploying nginx configuration… xamxam.conf sent 145 bytes received 125 bytes 540.00 bytes/sec total size is 10,012 speedup is 37.08 deploy-server.sh sent 1,089 bytes received 107 bytes 797.33 bytes/sec total size is 8,519 speedup is 7.12 recipes to it via safe ssh/rsync shims, so setup scripts can be validated without touching production. Includes provision-server-packages.sh, setup.sh/teardown.sh, server Dockerfile + helper, and the rendered ssh config. Validated end-to-end against the box: - provisioning (apt nginx, php8.4-fpm, composer), - scripts/setup-server.sh (group/user/dir bootstrap), - just deploy-code (transfer; surfaced the deploy-code --chown regression).
70 lines
2.8 KiB
Docker
70 lines
2.8 KiB
Docker
# XAMXAM test server — simulates a FRESH Debian machine with nothing preinstalled.
|
|
#
|
|
# This image intentionally installs ONLY the bare minimum needed to SSH in and
|
|
# run systemd services (nginx/php-fpm are brought up later by the provisioning
|
|
# step, so the apt-installs in scripts genuinely mirror a greenfield server).
|
|
#
|
|
# Name of image : debian trixie (ships PHP 8.4 — required by the project).
|
|
# systemd : enabled so `systemctl start nginx` / php-fpm work.
|
|
# sshd : a throwaway test keypair is baked in so the `cli` service
|
|
# can reach us as the `xamxam` SSH alias.
|
|
#
|
|
# Build: podman build -t xamxam-test-server ./server
|
|
|
|
FROM debian:trixie-slim
|
|
|
|
# Systemd needs the container to run as PID 1 with a cgroup namespace.
|
|
ENV container=docker
|
|
|
|
# 1. Base: systemd, an SSH server, sudo, and proc/ps for systemctl helpers.
|
|
RUN apt-get update \
|
|
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
|
|
systemd \
|
|
systemd-sysv \
|
|
systemd-container \
|
|
openssh-server \
|
|
sudo \
|
|
ca-certificates \
|
|
curl \
|
|
rsync \
|
|
procps \
|
|
iproute2 \
|
|
sed \
|
|
grep \
|
|
coreutils \
|
|
&& apt-get clean \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# 2. Prevent systemd from starting extra junk / writing to read-only paths.
|
|
RUN rm -f /etc/systemd/system/*.target.wants/* \
|
|
&& rm -f /etc/systemd/system/multi-user.target.wants/* \
|
|
&& rm -f /etc/systemd/system/getty@.service \
|
|
&& rm -rf /lib/systemd/system/sysinit.target.wants \
|
|
&& rm -rf /lib/systemd/system/local-fs.target.wants \
|
|
&& rm -rf /lib/systemd/system/slices.target.wants \
|
|
&& ln -s /lib/systemd/system/systemd-timedated.service /etc/systemd/system/dbus-org.freedesktop.timedate1.service 2>/dev/null || true
|
|
|
|
# 3. SSH: allow root login for initial provisioning convenience, drop in a
|
|
# throwaway host key + authorized key (regenerated per-run by the entrypoint).
|
|
RUN mkdir -p /root/.ssh /run/sshd \
|
|
&& touch /root/.ssh/authorized_keys \
|
|
&& chmod 700 /root/.ssh \
|
|
&& chmod 600 /root/.ssh/authorized_keys \
|
|
&& echo 'PermitRootLogin prohibit-password' >> /etc/ssh/sshd_config \
|
|
&& echo 'PubkeyAuthentication yes' > /etc/ssh/sshd_config.d/test.conf \
|
|
&& echo 'PasswordAuthentication no' >> /etc/ssh/sshd_config.d/test.conf
|
|
|
|
# The provisioning work expects a non-root deploy user; /root is used only to
|
|
# bootstrap, then `scripts/setup-server.sh` creates the real accounts.
|
|
|
|
EXPOSE 22
|
|
|
|
# Bootstrap helper: `podman compose run --rm server add-key "<pub>"` and a few
|
|
# tiny admin commands. Installed as /usr/local/bin/helper.
|
|
COPY scripts/server-helper.sh /usr/local/bin/helper
|
|
RUN chmod +x /usr/local/bin/helper
|
|
|
|
# Boot systemd as PID 1. The entrypoint regenerates the ssh host keys so each
|
|
# container start is fresh (and the `cli` hops with StrictHostKeyChecking=no).
|
|
ENTRYPOINT ["/lib/systemd/systemd"]
|