diff --git a/rootfs/root/docker/setup/00-init.sh b/rootfs/root/docker/setup/00-init.sh index 2990986..c134819 100755 --- a/rootfs/root/docker/setup/00-init.sh +++ b/rootfs/root/docker/setup/00-init.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:55 PM EDT 2026 +# @@Created : Sun May 24 08:59:09 PM EDT 2026 # @@File : 00-init.sh # @@Description : script to run init # @@Changelog : newScript @@ -36,9 +36,10 @@ if [ -d "/usr/local/share/template-files/defaults" ]; then rm -Rf "/usr/local/sh # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/01-system.sh b/rootfs/root/docker/setup/01-system.sh index 69cd368..bf4343a 100755 --- a/rootfs/root/docker/setup/01-system.sh +++ b/rootfs/root/docker/setup/01-system.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:56 PM EDT 2026 +# @@Created : Sun May 24 08:59:09 PM EDT 2026 # @@File : 01-system.sh # @@Description : script to run system # @@Changelog : newScript @@ -34,9 +34,10 @@ exitCode=0 # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/02-packages.sh b/rootfs/root/docker/setup/02-packages.sh index a38409d..f85327d 100755 --- a/rootfs/root/docker/setup/02-packages.sh +++ b/rootfs/root/docker/setup/02-packages.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242139-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:56 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 02-packages.sh # @@Description : script to run packages # @@Changelog : newScript @@ -31,87 +31,20 @@ exitCode=0 # - - - - - - - - - - - - - - - - - - - - - - - - - # Main script - -# Install the latest upstream Go toolchain straight from go.dev. -# We don't use apk's `go` package because Alpine often lags upstream by -# a release. Tarballs from go.dev are HTTPS-served and we additionally -# verify the SHA256 published in the same JSON catalog. -# -# Wrapped in a subshell with `set -e` so any single step (curl, jq, -# sha256sum, tar) that fails aborts the whole installer and the -# parent script returns non-zero - the Dockerfile then fails the build -# rather than silently producing a broken image. -( - set -euo pipefail - - case "$(uname -m)" in - x86_64) GO_ARCH="amd64" ;; - aarch64) GO_ARCH="arm64" ;; - armv7l|armv6l) GO_ARCH="armv6l" ;; - i386|i686) GO_ARCH="386" ;; - ppc64le) GO_ARCH="ppc64le" ;; - s390x) GO_ARCH="s390x" ;; - riscv64) GO_ARCH="riscv64" ;; - *) - echo "Unsupported architecture for upstream Go install: $(uname -m)" >&2 - exit 1 - ;; - esac - - GO_DL_INDEX="https://go.dev/dl/?mode=json" - GO_INDEX_JSON="$(curl -fsSL "$GO_DL_INDEX")" - # `// empty` makes jq emit nothing (instead of the literal string - # "null") when the path is missing, so the [ -z ... ] check below - # actually catches resolution failures. - GO_VERSION="$(printf '%s' "$GO_INDEX_JSON" \ - | jq -r '[.[] | select(.stable == true)][0].version // empty')" - if [ -z "$GO_VERSION" ]; then - echo "Failed to resolve latest Go version from $GO_DL_INDEX" >&2 - exit 1 - fi - GO_FILE="${GO_VERSION}.linux-${GO_ARCH}.tar.gz" - GO_SHA256="$(printf '%s' "$GO_INDEX_JSON" \ - | jq -r --arg f "$GO_FILE" '[.[] | select(.stable == true)][0].files[] | select(.filename == $f) | .sha256 // empty')" - if [ -z "$GO_SHA256" ]; then - echo "Failed to resolve sha256 for $GO_FILE from $GO_DL_INDEX" >&2 - exit 1 - fi - - echo "Installing upstream ${GO_VERSION} for linux/${GO_ARCH}" - curl -fsSL "https://go.dev/dl/${GO_FILE}" -o "/tmp/${GO_FILE}" - echo "${GO_SHA256} /tmp/${GO_FILE}" | sha256sum -c - - - rm -rf /usr/local/go - tar -C /usr/local -xzf "/tmp/${GO_FILE}" - rm -f "/tmp/${GO_FILE}" - - # Expose go + gofmt on PATH (the rest of the Go-shipped tools are - # invoked through `go tool ...` and don't need symlinks). - ln -sf /usr/local/go/bin/go /usr/local/bin/go - ln -sf /usr/local/go/bin/gofmt /usr/local/bin/gofmt - - # Sanity-check the install before subsequent setup steps depend on it. - /usr/local/bin/go version - - # Trim ~70MB of test data and API definitions that aren't useful at - # build/run time. Stdlib sources stay (needed for `go build`). - rm -rf /usr/local/go/test /usr/local/go/api /usr/local/go/doc -) -__go_install_rc=$? -# Note: this is intentionally a separate statement, not `(...) || exit`. -# Bash silently disables `set -e` inside an explicit subshell when the -# subshell appears on the left of && or ||, so the form below is the -# only reliable way to propagate set -e failures from the subshell. -if [ "$__go_install_rc" -ne 0 ]; then - exit "$__go_install_rc" +if command -v update-ca-certificates >/dev/null 2>&1; then + update-ca-certificates +elif command -v update-ca-trust >/dev/null 2>&1; then + update-ca-trust extract +elif command -v trust >/dev/null 2>&1; then + trust extract-compat fi -unset __go_install_rc # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/03-files.sh b/rootfs/root/docker/setup/03-files.sh index 4b26f0f..c8e064d 100755 --- a/rootfs/root/docker/setup/03-files.sh +++ b/rootfs/root/docker/setup/03-files.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:57 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 03-files.sh # @@Description : script to run files # @@Changelog : newScript @@ -31,51 +31,55 @@ exitCode=0 if [ -d "/tmp/bin" ]; then mkdir -p "/usr/local/bin" for bin in "/tmp/bin"/*; do - name="$(basename -- "$bin")" + [ -e "$bin" ] || continue + name="${bin##*/}" echo "Installing $name to /usr/local/bin/$name" - copy "$bin" "/usr/local/bin/$name" + cp -Rf "$bin" "/usr/local/bin/$name" chmod -f +x "/usr/local/bin/$name" done fi unset bin if [ -d "/tmp/var" ]; then for var in "/tmp/var"/*; do - name="$(basename -- "$var")" + [ -e "$var" ] || continue + name="${var##*/}" echo "Installing $var to /var/$name" if [ -d "$var" ]; then mkdir -p "/var/$name" - copy "$var/." "/var/$name/" + cp -Rf "$var/." "/var/$name/" else - copy "$var" "/var/$name" + cp -Rf "$var" "/var/$name" fi done fi unset var if [ -d "/tmp/etc" ]; then for config in "/tmp/etc"/*; do - name="$(basename -- "$config")" + [ -e "$config" ] || continue + name="${config##*/}" echo "Installing $config to /etc/$name" if [ -d "$config" ]; then mkdir -p "/etc/$name" - copy "$config/." "/etc/$name/" + cp -Rf "$config/." "/etc/$name/" mkdir -p "/usr/local/share/template-files/config/$name" - copy "$config/." "/usr/local/share/template-files/config/$name/" + cp -Rf "$config/." "/usr/local/share/template-files/config/$name/" else - copy "$config" "/etc/$name" - copy "$config" "/usr/local/share/template-files/config/$name" + cp -Rf "$config" "/etc/$name" + cp -Rf "$config" "/usr/local/share/template-files/config/$name" fi done fi unset config if [ -d "/tmp/data" ]; then for data in "/tmp/data"/*; do - name="$(basename -- "$data")" + [ -e "$data" ] || continue + name="${data##*/}" echo "Installing $data to /usr/local/share/template-files/data" if [ -d "$data" ]; then mkdir -p "/usr/local/share/template-files/data/$name" - copy "$data/." "/usr/local/share/template-files/data/$name/" + cp -Rf "$data/." "/usr/local/share/template-files/data/$name/" else - copy "$data" "/usr/local/share/template-files/data/$name" + cp -Rf "$data" "/usr/local/share/template-files/data/$name" fi done fi @@ -83,35 +87,12 @@ unset data # - - - - - - - - - - - - - - - - - - - - - - - - - # Main script -# Create conventional Go project dirs. Users can mount their code into -# any of these; WORKDIR defaults to /app. -for dir in /app /work /root/app /root/project; do - mkdir -p "$dir" - chmod 0755 "$dir" -done - -# Canonical Go state dir (FHS-style: arch-independent shared data); -# declared as a Docker VOLUME for cross-rebuild persistence. The paths -# /go, /root/go, /root/.go, /root/.local/share/go are symlinks to this -# location so any of the conventional GOPATH paths resolve here. /data/go -# is symlinked at runtime by the init script (since /data is a volume). -GO_STATE_DIR="/usr/local/share/go" -mkdir -p "${GO_STATE_DIR}/bin" "${GO_STATE_DIR}/cache" "${GO_STATE_DIR}/pkg/mod" -chmod -R 0755 "${GO_STATE_DIR}" -mkdir -p /root/.local/share -for link in /go /root/go /root/.go /root/.local/share/go; do - if [ -e "$link" ] && [ ! -L "$link" ]; then - rm -rf "$link" - fi - ln -sfn "${GO_STATE_DIR}" "$link" -done -unset GO_STATE_DIR link - # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/04-users.sh b/rootfs/root/docker/setup/04-users.sh index 176881e..a6c8bc2 100755 --- a/rootfs/root/docker/setup/04-users.sh +++ b/rootfs/root/docker/setup/04-users.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:57 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 04-users.sh # @@Description : script to run users # @@Changelog : newScript @@ -34,9 +34,10 @@ exitCode=0 # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/05-custom.sh b/rootfs/root/docker/setup/05-custom.sh index a7d57e7..052f4b5 100755 --- a/rootfs/root/docker/setup/05-custom.sh +++ b/rootfs/root/docker/setup/05-custom.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:57 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 05-custom.sh # @@Description : script to run custom # @@Changelog : newScript @@ -32,123 +32,12 @@ exitCode=0 # - - - - - - - - - - - - - - - - - - - - - - - - - # Main script -# Install Go developer tools into /usr/local/bin so they are on PATH -# without pulling GOPATH/bin into the runtime image. CGO disabled so the -# tools themselves are fully static (matches the image default). -export GOPATH="${GOPATH:-/usr/local/share/go}" -export GOBIN="/usr/local/bin" -export PATH="${GOBIN}:${PATH}" -export CGO_ENABLED=0 -export GOTOOLCHAIN=auto -export GOMAXPROCS="${GOMAXPROCS:-2}" -export GOMEMLIMIT="${GOMEMLIMIT:-1GiB}" -export GOFLAGS="${GOFLAGS:+${GOFLAGS} }-p=1" -mkdir -p "$GOPATH" "$GOPATH/bin" "$GOPATH/cache" "$GOPATH/pkg/mod" - -if command -v go >/dev/null 2>&1; then - echo "Installing Go developer tools with $(go version)" - tool_install_count=0 - - install_go_tool() { - local tool="$1" - - echo "go install $tool" - # Best-effort: don't fail the build if a single upstream tool has - # stale deps incompatible with the current Go release. The rest of - # the kitchen-sink installs cleanly and the user can manually - # `go install` whichever tools they need at runtime against their - # own version pin. - go install "$tool" || echo " WARN: skipping $tool (install failed)" >&2 - - tool_install_count=$((tool_install_count + 1)) - if [ "$tool_install_count" -ge 5 ]; then - go clean -cache -testcache 2>/dev/null || true - tool_install_count=0 - fi - } - - for tool in \ - "github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest" \ - "golang.org/x/tools/gopls@latest" \ - "golang.org/x/tools/cmd/goimports@latest" \ - "golang.org/x/tools/cmd/stringer@latest" \ - "golang.org/x/tools/cmd/godoc@latest" \ - "golang.org/x/tools/cmd/deadcode@latest" \ - "golang.org/x/tools/cmd/callgraph@latest" \ - "golang.org/x/tools/cmd/guru@latest" \ - "golang.org/x/tools/cmd/gorename@latest" \ - "golang.org/x/lint/golint@latest" \ - "golang.org/x/perf/cmd/benchstat@latest" \ - "github.com/go-delve/delve/cmd/dlv@latest" \ - "mvdan.cc/gofumpt@latest" \ - "honnef.co/go/tools/cmd/staticcheck@latest" \ - "golang.org/x/vuln/cmd/govulncheck@latest" \ - "github.com/air-verse/air@latest" \ - "go.uber.org/mock/mockgen@latest" \ - "github.com/swaggo/swag/cmd/swag@latest" \ - "google.golang.org/protobuf/cmd/protoc-gen-go@latest" \ - "google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest" \ - "github.com/kisielk/errcheck@latest" \ - "github.com/gordonklaus/ineffassign@latest" \ - "github.com/fzipp/gocyclo/cmd/gocyclo@latest" \ - "github.com/securego/gosec/v2/cmd/gosec@latest" \ - "github.com/cweill/gotests/gotests@latest" \ - "github.com/josharian/impl@latest" \ - "github.com/fatih/gomodifytags@latest" \ - "gotest.tools/gotestsum@latest" \ - "github.com/kyoh86/richgo@latest" \ - "github.com/goreleaser/goreleaser/v2@latest" \ - "github.com/vektra/mockery/v2@latest" \ - "github.com/google/wire/cmd/wire@latest" \ - "github.com/sqlc-dev/sqlc/cmd/sqlc@latest" \ - "github.com/oapi-codegen/oapi-codegen/v2/cmd/oapi-codegen@latest" \ - "github.com/bufbuild/buf/cmd/buf@latest" \ - "github.com/go-task/task/v3/cmd/task@latest" \ - "github.com/google/ko@latest" \ - "github.com/magefile/mage@latest" \ - "github.com/pressly/goose/v3/cmd/goose@latest" \ - "github.com/mgechev/revive@latest" \ - "github.com/daixiang0/gci@latest" \ - "github.com/segmentio/golines@latest" \ - "go.uber.org/nilaway/cmd/nilaway@latest" \ - "github.com/jstemmer/go-junit-report/v2@latest" \ - "github.com/boumenot/gocover-cobertura@latest" \ - "github.com/jandelgado/gcov2lcov@latest" \ - "github.com/google/gops@latest" \ - "github.com/dmarkham/enumer@latest" \ - "github.com/mailru/easyjson/easyjson@latest" \ - "github.com/envoyproxy/protoc-gen-validate@latest" \ - "github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-grpc-gateway@latest" \ - "github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2@latest" \ - ; do - install_go_tool "$tool" - done - - # migrate: needs build tags for DB driver compilation. Limited to - # the common pure-Go drivers (postgres, pgx, mysql, sqlite) - the - # full driver set (cockroachdb, spanner, clickhouse, mongodb, - # redshift) pulls in ~2GB of transitive deps and has been observed - # to crash bash mid-compile inside resource-constrained build - # environments. Users who need those drivers can rebuild migrate at - # runtime with whatever tags they need. - echo "go install golang-migrate/migrate (pure-Go drivers)" - go install -tags 'postgres,pgx,mysql,sqlite' \ - github.com/golang-migrate/migrate/v4/cmd/migrate@latest \ - || echo " WARN: skipping migrate (install failed)" >&2 - - # Drop the module cache; it's not needed in the final image. - go clean -testcache 2>/dev/null || true - go clean -modcache 2>/dev/null || true - go clean -cache 2>/dev/null || true - rm -rf "$GOPATH/pkg" "$GOPATH/src" 2>/dev/null || true -else - echo "go binary not found; skipping Go dev tools" >&2 -fi - -# Always succeed: tool installation is best-effort, the build environment -# is functional even if some optional dev tools didn't make it. The Go -# toolchain itself was already verified by 02-packages.sh. -exit 0 +# - - - - - - - - - - - - - - - - - - - - - - - - - +# Set the exit code +exitCode=$? +# - - - - - - - - - - - - - - - - - - - - - - - - - +exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/06-post.sh b/rootfs/root/docker/setup/06-post.sh index 3d4fe16..365ee54 100755 --- a/rootfs/root/docker/setup/06-post.sh +++ b/rootfs/root/docker/setup/06-post.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:58 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 06-post.sh # @@Description : script to run post # @@Changelog : newScript @@ -34,9 +34,10 @@ exitCode=0 # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/root/docker/setup/07-cleanup.sh b/rootfs/root/docker/setup/07-cleanup.sh index 08caedd..cbf05e6 100755 --- a/rootfs/root/docker/setup/07-cleanup.sh +++ b/rootfs/root/docker/setup/07-cleanup.sh @@ -1,12 +1,12 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202604221922-git +##@Version : 202605242059-git # @@Author : CasjaysDev # @@Contact : CasjaysDev # @@License : MIT # @@Copyright : Copyright 2026 CasjaysDev -# @@Created : Wed Apr 22 07:22:58 PM EDT 2026 +# @@Created : Sun May 24 08:59:10 PM EDT 2026 # @@File : 07-cleanup.sh # @@Description : script to run cleanup # @@Changelog : newScript @@ -24,7 +24,7 @@ set -o pipefail [ "$DEBUGGER" = "on" ] && echo "Enabling debugging" && set -x$DEBUGGER_OPTIONS # - - - - - - - - - - - - - - - - - - - - - - - - - # Load functions -__find_and_remove() { [ -z "$1" ] || find "${2:-/etc}" -iname "$1" -exec rm -Rf {} \; 2>/dev/null; } +__find_and_remove() { [ -z "$1" ] || find "${2:-/etc}" -iname "$1" -exec rm -Rf {} + 2>/dev/null; } # - - - - - - - - - - - - - - - - - - - - - - - - - # Set env variables exitCode=0 @@ -38,9 +38,10 @@ if [ -d "$HOME/.cache" ]; then rm -Rf "$HOME/.cache"; fi # - - - - - - - - - - - - - - - - - - - - - - - - - # Set the exit code -#exitCode=$? +exitCode=$? # - - - - - - - - - - - - - - - - - - - - - - - - - exit $exitCode # - - - - - - - - - - - - - - - - - - - - - - - - - # ex: ts=2 sw=2 et filetype=sh # - - - - - - - - - - - - - - - - - - - - - - - - - + diff --git a/rootfs/usr/local/bin/entrypoint.sh b/rootfs/usr/local/bin/entrypoint.sh index fb48191..24576d0 100755 --- a/rootfs/usr/local/bin/entrypoint.sh +++ b/rootfs/usr/local/bin/entrypoint.sh @@ -1,15 +1,15 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202602061352-git +##@Version : 202605241245-git # @@Author : Jason Hempstead # @@Contact : jason@casjaysdev.pro # @@License : WTFPL # @@ReadME : entrypoint.sh --help # @@Copyright : Copyright: (c) 2026 Jason Hempstead, Casjays Developments -# @@Created : Wednesday, Apr 22, 2026 19:22 EDT +# @@Created : Sunday, May 24, 2026 20:59 EDT # @@File : entrypoint.sh -# @@Description : Entrypoint file for go +# @@Description : Entrypoint file for alpine # @@Changelog : New script # @@TODO : Better documentation # @@Other : @@ -21,17 +21,25 @@ # shellcheck disable=SC1001,SC1003,SC2001,SC2003,SC2016,SC2031,SC2090,SC2115,SC2120,SC2155,SC2199,SC2229,SC2317,SC2329 # - - - - - - - - - - - - - - - - - - - - - - - - - # run trap command on exit -trap 'retVal=$?;[ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ] && rm -Rf "$SERVICE_PID_FILE";exit $retVal' INT TERM PWR +trap 'retVal=$?;[ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ] && rm -Rf "$SERVICE_PID_FILE";exit $retVal' INT TERM +trap 'retVal=$?;[ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ] && rm -Rf "$SERVICE_PID_FILE";exit $retVal' SIGPWR 2>/dev/null || true # - - - - - - - - - - - - - - - - - - - - - - - - - # setup debugging - https://www.gnu.org/software/bash/manual/html_node/The-Set-Builtin.html [ -f "/config/.debug" ] && [ -z "$DEBUGGER_OPTIONS" ] && export DEBUGGER_OPTIONS="$(<"/config/.debug")" || DEBUGGER_OPTIONS="${DEBUGGER_OPTIONS:-}" -{ [ "$DEBUGGER" = "on" ] || [ -f "/config/.debug" ]; } && echo "Enabling debugging" && set -o pipefail -x$DEBUGGER_OPTIONS && export DEBUGGER="on" || set -o pipefail +if [ "$DEBUGGER" = "on" ] || [ -f "/config/.debug" ]; then + echo "Enabling debugging" + set -o pipefail + [ -n "$DEBUGGER_OPTIONS" ] && set -"$DEBUGGER_OPTIONS" + export DEBUGGER="on" +else + set -o pipefail +fi # - - - - - - - - - - - - - - - - - - - - - - - - - PATH="/usr/local/etc/docker/bin:/usr/local/bin:/usr/bin:/usr/sbin:/bin:/sbin" # - - - - - - - - - - - - - - - - - - - - - - - - - # Set bash options SCRIPT_FILE="$0" -CONTAINER_NAME="go" +CONTAINER_NAME="alpine" SCRIPT_NAME="${SCRIPT_FILE##*/}" CONTAINER_NAME="${ENV_CONTAINER_NAME:-$CONTAINER_NAME}" # - - - - - - - - - - - - - - - - - - - - - - - - - @@ -54,7 +62,7 @@ case "$1" in -h | --help) shift 1 echo 'Docker container for '$CONTAINER_NAME'' - echo "Usage: $CONTAINER_NAME [help tail cron exec start init shell certbot ssl procs ports healthcheck backup command]" + echo "Usage: $CONTAINER_NAME [help tail cron exec start init shell procs ports healthcheck backup command]" echo "" exit 0 ;; @@ -87,8 +95,8 @@ SERVICE_UID="${SERVICE_UID:-0}" SERVICE_GID="${SERVICE_GID:-0}" # - - - - - - - - - - - - - - - - - - - - - - - - - # User and group in which the service switches to - IE: nginx,apache,mysql,postgres -#SERVICE_USER="${SERVICE_USER:-go}" # execute command as another user -#SERVICE_GROUP="${SERVICE_GROUP:-go}" # Set the service group +#SERVICE_USER="${SERVICE_USER:-alpine}" # execute command as another user +#SERVICE_GROUP="${SERVICE_GROUP:-alpine}" # Set the service group # - - - - - - - - - - - - - - - - - - - - - - - - - # Secondary ports # specifiy other ports @@ -143,7 +151,7 @@ export DOMAINNAME="$(hostname -d)" # - - - - - - - - - - - - - - - - - - - - - - - - - # Default directories export SSL_DIR="${SSL_DIR:-/config/ssl}" -export SSL_CA="${SSL_CERT:-/config/ssl/ca.crt}" +export SSL_CA="${SSL_CA:-/config/ssl/ca.crt}" export SSL_KEY="${SSL_KEY:-/config/ssl/localhost.pem}" export SSL_CERT="${SSL_CERT:-/config/ssl/localhost.crt}" export LOCAL_BIN_DIR="${LOCAL_BIN_DIR:-/usr/local/bin}" @@ -164,7 +172,7 @@ export NGINX_CONFIG_FILE="${NGINX_CONFIG_FILE:-$(__find_nginx_conf)}" export MYSQL_CONFIG_FILE="${MYSQL_CONFIG_FILE:-$(__find_mysql_conf)}" export PGSQL_CONFIG_FILE="${PGSQL_CONFIG_FILE:-$(__find_pgsql_conf)}" export MONGODB_CONFIG_FILE="${MONGODB_CONFIG_FILE:-$(__find_mongodb_conf)}" -export ENTRYPOINT_PID_FILE="${ENTRYPOINT_PID_FILE:-$ENTRYPOINT_PID_FILE}" +export ENTRYPOINT_PID_FILE="${ENTRYPOINT_PID_FILE:-/run/.entrypoint.pid}" export ENTRYPOINT_INIT_FILE="${ENTRYPOINT_INIT_FILE:-/config/.entrypoint.done}" export ENTRYPOINT_DATA_INIT_FILE="${ENTRYPOINT_DATA_INIT_FILE:-/data/.docker_has_run}" export ENTRYPOINT_CONFIG_INIT_FILE="${ENTRYPOINT_CONFIG_INIT_FILE:-/config/.docker_has_run}" @@ -214,8 +222,6 @@ SERVER_PORTS="${SERVER_PORTS//,/ }" # SERVER_PORTS="${SERVER_PORTS//\/*/}" # # - - - - - - - - - - - - - - - - - - - - - - - - - # clean WEB_SERVER_PORTS variables -WEB_SERVER_PORTS="${WEB_SERVER_PORT//\/*/}" # -WEB_SERVER_PORTS="${WEB_SERVER_PORTS//\/*/}" # WEB_SERVER_PORTS="${WEB_SERVER_PORT//,/ } ${ENV_WEB_SERVER_PORTS//,/ }" # # - - - - - - - - - - - - - - - - - - - - - - - - - # rewrite and merge variables @@ -288,7 +294,7 @@ fi if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then if [ "$CONFIG_DIR_INITIALIZED" = "no" ] || [ "$DATA_DIR_INITIALIZED" = "no" ]; then if [ "$ENTRYPOINT_MESSAGE" = "yes" ]; then - echo "Executing entrypoint script for go" + echo "Executing entrypoint script for alpine" fi fi # - - - - - - - - - - - - - - - - - - - - - - - - - @@ -357,7 +363,7 @@ if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then fi # - - - - - - - - - - - - - - - - - - - - - - - - - if [ -f "/etc/hostname" ]; then - if [ -n "$(type -P hostname 2>/dev/null)" ]; then + if command -v hostname &>/dev/null; then hostname -F "/etc/hostname" 2>/dev/null || true else HOSTNAME="$(<"/etc/hostname")" 2>/dev/null || true @@ -372,7 +378,7 @@ if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then # - - - - - - - - - - - - - - - - - - - - - - - - - # import resolv.conf file into container if [ "$CUSTOM_DNS" != "yes" ] && [ -f "/usr/local/etc/resolv.conf" ] && [ "$UPDATE_FILE_RESOLV" = "yes" ]; then - cat "/usr/local/etc/resolv.conf" >"/etc/resolv.conf" 2>/dev/null || true + cp -f "/usr/local/etc/resolv.conf" "/etc/resolv.conf" 2>/dev/null || true fi # - - - - - - - - - - - - - - - - - - - - - - - - - if [ -n "$HOME" ] && [ -d "/usr/local/etc/skel" ]; then @@ -383,12 +389,13 @@ if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then # - - - - - - - - - - - - - - - - - - - - - - - - - fi # - - - - - - - - - - - - - - - - - - - - - - - - - -# Delete any .gitkeep files +# Delete any .gitkeep files (bash * does not match dotfiles by default, +# so the explicit /.gitkeep path is required at each depth) if [ -d "/data" ]; then - rm -Rf "/data/.gitkeep" "/data"/*/*.gitkeep 2>/dev/null || true + rm -Rf "/data/.gitkeep" "/data"/*/.gitkeep 2>/dev/null || true fi if [ -d "/config" ]; then - rm -Rf "/config/.gitkeep" "/config"/*/*.gitkeep 2>/dev/null || true + rm -Rf "/config/.gitkeep" "/config"/*/.gitkeep 2>/dev/null || true fi if [ -f "/usr/local/bin/.gitkeep" ]; then rm -Rf "/usr/local/bin/.gitkeep" 2>/dev/null || true @@ -442,7 +449,7 @@ fi # if no pid assume container restart - clean stale files on restart if [ -f "$ENTRYPOINT_PID_FILE" ]; then # Check if the PID in the file is still running - entrypoint_pid=$(cat "$ENTRYPOINT_PID_FILE" 2>/dev/null || echo "") + entrypoint_pid=$(<"$ENTRYPOINT_PID_FILE") 2>/dev/null if [ -n "$entrypoint_pid" ] && kill -0 "$entrypoint_pid" 2>/dev/null; then # Process is still running, don't restart services START_SERVICES="no" @@ -482,7 +489,7 @@ __set_user_group_id $SERVICE_USER ${SERVICE_UID:-} ${SERVICE_GID:-} __run_message # - - - - - - - - - - - - - - - - - - - - - - - - - # Just start services -START_SERVICES="${START_SERVICES:-SYSTEM_INIT}" +START_SERVICES="${START_SERVICES:-yes}" # - - - - - - - - - - - - - - - - - - - - - - - - - # Determine if we should start services based on command # Only skip service start for the 'init' command @@ -540,10 +547,10 @@ logs) tail -Fq /data/logs/*/* ;; clean) - log_files="$(find "/data/logs" -type f)" + mapfile -t log_files < <(find "/data/logs" -type f 2>/dev/null) for log in "${log_files[@]}"; do __log_info "Clearing log file: $log" - printf '' >$log + printf '' >"$log" done ;; *) @@ -578,16 +585,16 @@ healthcheck) healthPorts="${WEB_SERVER_PORTS:-}" healthEndPoints="${HEALTH_ENDPOINTS:-}" SERVICES_LIST="${arguments:-$SERVICES_LIST}" - services="$(echo "${SERVICES_LIST//,/ }")" + services="${SERVICES_LIST//,/ }" healthMessage="Everything seems to be running" [ "$healthEnabled" = "yes" ] || exit 0 - if [ -d "/run/healthcheck" ] && [ "$(ls -A "/run/healthcheck" | wc -l)" -ne 0 ]; then + if [ -d "/run/healthcheck" ] && ! __is_dir_empty "/run/healthcheck"; then for service in /run/healthcheck/*; do name="${service##*/}" services+="$name " done fi - services="$(echo "$services" | tr ' ' '\n' | sort -u | grep -v '^$')" + services="$(printf '%s\n' $services | sort -u | grep -v '^$')" for proc in $services; do if [ -n "$proc" ]; then if ! __pgrep "$proc"; then @@ -596,8 +603,8 @@ healthcheck) fi fi done - for port in $ports; do - if [ -n "$(type -P netstat)" ] && [ -n "$port" ]; then + for port in $healthPorts; do + if command -v netstat &>/dev/null && [ -n "$port" ]; then if ! netstat -taupln | grep -q ":$port "; then echo "$port isn't open" >&2 healthStatus=$((healthStatus + 1)) @@ -621,38 +628,17 @@ healthcheck) # show open ports ports) shift 1 - ports="$(__netstat -taupln | awk -F ' ' '{print $4}' | awk -F ':' '{print $2}' | sort --unique --version-sort | grep -v '^$' | grep '^' || echo '')" + ports="$(__netstat -taupln 2>/dev/null | awk '{ split($4, a, ":"); if (a[2] != "") print a[2] }' | sort -uV)" [ -n "$ports" ] && printf '%s\n%s\n' "The following are servers:" "$ports" | tr '\n' ' ' exit $? ;; # show running processes procs) shift 1 - ps="$(__ps axco command | grep -vE 'COMMAND|grep|ps' | sort -u || grep '^' || echo '')" + ps="$(__ps axco command 2>/dev/null | grep -vE '^(COMMAND|grep|ps)$' | sort -u)" [ -n "$ps" ] && printf '%s\n%s\n' "Found the following processes" "$ps" | tr '\n' ' ' exit $? ;; - # setup ssl -ssl) - shift 1 - __create_ssl_cert - exit $? - ;; -# manage ssl certificate -certbot) - shift 1 - CERT_BOT_ENABLED="yes" - if [ "$1" = "create" ]; then - shift 1 - __certbot "create" - elif [ "$1" = "renew" ]; then - shift 1 - __certbot "renew certonly --force-renew" - else - __exec_command "certbot" "$@" - fi - exit $? - ;; # Launch shell */bin/sh | */bin/bash | bash | sh | shell) shift 1 diff --git a/rootfs/usr/local/bin/pkmgr b/rootfs/usr/local/bin/pkmgr index fbd269a..bebefdb 100755 --- a/rootfs/usr/local/bin/pkmgr +++ b/rootfs/usr/local/bin/pkmgr @@ -103,7 +103,7 @@ install) [ -n "$1" ] || exit 0 [ "$USER_UID" -eq 0 ] || [ "$USER" = "root" ] || pkmgr_install_cmd="sudo $pkmgr_install_cmd" if [ -f "$1" ]; then - install_list="$(cat "$1")" + install_list="$(tr '\n' ' ' < "$1")" else install_list="$*" fi @@ -140,3 +140,4 @@ clean) esac # - - - - - - - - - - - - - - - - - - - - - - - - - # end + diff --git a/rootfs/usr/local/etc/docker/functions/entrypoint.sh b/rootfs/usr/local/etc/docker/functions/entrypoint.sh index 240469b..e83485d 100644 --- a/rootfs/usr/local/etc/docker/functions/entrypoint.sh +++ b/rootfs/usr/local/etc/docker/functions/entrypoint.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash # shellcheck shell=bash # - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202602061352-git +##@Version : 202605241245-git # @@Author : Jason Hempstead # @@Contact : git-admin@casjaysdev.pro # @@License : LICENSE.md @@ -25,13 +25,14 @@ if [ -f "/config/.debug" ] && [ -z "$DEBUGGER_OPTIONS" ]; then export DEBUGGER_OPTIONS="$(<"/config/.debug")" fi if [ "$DEBUGGER" = "on" ] || [ -f "/config/.debug" ]; then - set -xo pipefail -x$DEBUGGER_OPTIONS + set -o pipefail + [ -n "$DEBUGGER_OPTIONS" ] && set -"$DEBUGGER_OPTIONS" export DEBUGGER="on" else set -o pipefail fi # - - - - - - - - - - - - - - - - - - - - - - - - - -__remove_extra_spaces() { sed 's/\( \)*/\1/g;s|^ ||g'; } +__remove_extra_spaces() { sed -E 's/ +/ /g; s|^ ||'; } # - - - - - - - - - - - - - - - - - - - - - - - - - __log_debug() { [ "$DEBUGGER" = "on" ] && echo "[DEBUG] $*" >&2 @@ -76,201 +77,121 @@ __rm() { fi return 0 } -__grep_test() { - if grep -sh "$1" "$2" 2>/dev/null | grep -qwF "${3:-$1}"; then - return 0 - else - return 1 - fi -} +__grep_test() { grep -sh "$1" "$2" 2>/dev/null | grep -qwF "${3:-$1}"; } __netstat() { - if [ -n "$(command -v netstat 2>/dev/null)" ]; then - netstat "$@" 2>/dev/null - else + command -v netstat &>/dev/null || { [ "$DEBUGGER" = "on" ] && echo "Warning: netstat command not found" >&2 return 10 - fi + } + netstat "$@" 2>/dev/null } __cd() { - if [ ! -d "$1" ]; then - mkdir -p "$1" 2>/dev/null || return 1 - fi + [ -d "$1" ] || mkdir -p "$1" 2>/dev/null || return 1 builtin cd "$1" || return 1 } -__is_in_file() { - if [ -e "$2" ] && grep -Rsq "$1" "$2" 2>/dev/null; then - return 0 - else - return 1 - fi -} -__curl() { - if curl -q -sfI --max-time 3 -k -o /dev/null "$@" 2>/dev/null; then - return 0 - else - return 10 - fi -} +__is_in_file() { [ -e "$2" ] && grep -Rsq "$1" "$2" 2>/dev/null; } +__curl() { curl -q -sfI --max-time 3 -k -o /dev/null "$@" 2>/dev/null || return 10; } __find() { - if find "$1" -mindepth 1 -type ${2:-f,d} 2>/dev/null | grep '.'; then - return 0 - else - return 10 - fi + local result + result=$(find "$1" -mindepth 1 -type "${2:-f,d}" 2>/dev/null) + [ -n "$result" ] || return 10 + printf '%s\n' "$result" } __pcheck() { - if [ -n "$(which pgrep 2>/dev/null)" ] && pgrep -x "$1" &>/dev/null; then - return 0 - else - return 10 - fi -} -__file_exists_with_content() { - if [ -n "$1" ] && [ -f "$1" ] && [ -s "$1" ]; then - return 0 - else - return 2 - fi -} -__sed() { - if sed -i 's|'$1'|'$2'|g' "$3" 2>/dev/null; then - return 0 - elif sed -i "s|$1|$2|g" "$3" 2>/dev/null; then - return 0 - else - return 0 - fi + command -v pgrep &>/dev/null && pgrep -x "$1" &>/dev/null || return 10 } +__file_exists_with_content() { [ -n "$1" ] && [ -f "$1" ] && [ -s "$1" ] || return 2; } +__sed() { sed -i "s|$1|$2|g" "$3" 2>/dev/null || return 1; } __ps() { - if [ -f "$(type -P ps 2>/dev/null)" ]; then - if ps "$@" 2>/dev/null | sed 's|:||g' | grep -Fw " ${1:-$SERVICE_NAME}$"; then - return 0 - else - return 10 - fi - else - return 10 - fi + command -v ps &>/dev/null || return 10 + ps "$@" 2>/dev/null | sed 's|:||g' | grep -Fw " ${1:-$SERVICE_NAME}$" || return 10 } __is_dir_empty() { - if [ -n "$1" ]; then - if [ "$(ls -A "$1" 2>/dev/null | wc -l)" -eq 0 ]; then - return 0 - else - return 1 - fi - else - return 1 - fi + [ -n "$1" ] && [ -d "$1" ] || return 1 + [ -z "$(ls -A "$1" 2>/dev/null)" ] } __get_ip6() { - local ip6 - ip6="$(ip a 2>/dev/null | grep -w 'inet6' | awk '{print $2}' | grep -vE '^::1|^fe' | sed 's|/.*||g' | head -n1 | grep '.')" - if [ -n "$ip6" ]; then - echo "$ip6" - else - echo '' - fi + ip a 2>/dev/null | awk '/^[[:space:]]*inet6 / { + split($2, a, "/"); ip = a[1] + if (ip !~ /^::1$/ && ip !~ /^fe/) { print ip; exit } + }' } __get_ip4() { local ip4 - ip4="$(ip a 2>/dev/null | grep -w 'inet' | awk '{print $2}' | grep -vE '^127.0.0' | sed 's|/.*||g' | head -n1 | grep '.')" - if [ -n "$ip4" ]; then - echo "$ip4" - else - echo '127.0.0.1' - fi + ip4=$(ip a 2>/dev/null | awk '/^[[:space:]]*inet / { + split($2, a, "/"); ip = a[1] + if (ip !~ /^127\.0\.0/) { print ip; exit } + }') + echo "${ip4:-127.0.0.1}" } __find_and_remove() { find "${2:-/etc}" -iname "$1" -exec rm -Rfv {} \; 2>/dev/null || true } # - - - - - - - - - - - - - - - - - - - - - - - - - __pgrep() { - local count=3 - local srvc="${1:-SERVICE_NAME}" - local found=0 - if [ -z "$srvc" ] || [ "$srvc" = "SERVICE_NAME" ]; then - return 10 - fi + local srvc="$1" count=3 + [ -z "$srvc" ] && return 10 while [ $count -ge 0 ]; do - if pgrep -x "$srvc" >/dev/null 2>&1; then - found=1 - break - elif pgrep -f "$srvc" >/dev/null 2>&1; then - found=1 - break - elif ps -ef 2>/dev/null | grep -v grep | grep -qw "$srvc"; then - found=1 - break - fi - if [ $count -gt 0 ]; then - sleep 1 - fi + pgrep -x "$srvc" &>/dev/null && return 0 + pgrep -f "$srvc" &>/dev/null && return 0 + ps -eo comm 2>/dev/null | grep -qxF "$srvc" && return 0 + [ $count -gt 0 ] && sleep 1 count=$((count - 1)) done - if [ $found -eq 1 ]; then - return 0 - else - return 10 - fi + return 10 } # - - - - - - - - - - - - - - - - - - - - - - - - - __find_file_relative() { - if [ ! -e "$1" ]; then - return 0 - fi - find "$1"/* -not -path '*env/*' -not -path '.git*' -type f 2>/dev/null | sed 's|'$1'/||g' | sort -u | grep -v '^$' | grep '.' || true + [ -e "$1" ] || return 0 + find "$1"/* -not -path '*env/*' -not -path '*/.git/*' -not -name '.git' -type f 2>/dev/null \ + | sort -u \ + | sed "s|^$1/||" || true } # - - - - - - - - - - - - - - - - - - - - - - - - - __find_directory_relative() { - if [ ! -d "$1" ]; then - return 0 - fi - find "$1"/* -not -path '*env/*' -not -path '.git*' -type d 2>/dev/null | sed 's|'$1'/||g' | sort -u | grep -v '^$' | grep '.' || true + [ -d "$1" ] || return 0 + find "$1"/* -not -path '*env/*' -not -path '*/.git/*' -not -name '.git' -type d 2>/dev/null \ + | sort -u \ + | sed "s|^$1/||" || true } # - - - - - - - - - - - - - - - - - - - - - - - - - -__pid_exists() { - local result="" - result="$(ps -ax --no-header 2>/dev/null | sed 's/^[[:space:]]*//g' | awk -F' ' '{print $1}' | sed 's|:||g' | grep '[0-9]' | sort -uV | grep "^$1$" 2>/dev/null || echo '')" - if [ -n "$result" ]; then - return 0 - else - return 1 - fi -} +__pid_exists() { [ -n "$1" ] && [ -d "/proc/$1" ]; } __is_running() { - local result="" - result="$(ps -eo args --no-header 2>/dev/null | awk '{print $1,$2,$3}' | sed 's|:||g' | sort -u | grep -vE 'grep|COMMAND|awk|tee|ps|sed|sort|tail' | grep "$1" | grep "${2:-^}" 2>/dev/null || echo '')" - if [ -n "$result" ]; then - return 0 + local pat="$1" + [ -n "$2" ] && pat="$pat.*$2" + if command -v pgrep &>/dev/null; then + pgrep -f "$pat" &>/dev/null else - return 1 + ps -eo args 2>/dev/null | grep -v grep | grep -Eq "$pat" fi } __get_pid() { - local result="" if [ -z "$1" ]; then [ "$DEBUGGER" = "on" ] && echo "Warning: __get_pid called without process name" >&2 return 1 fi - result="$(ps -ax --no-header 2>/dev/null | sed 's/^[[:space:]]*//g;s|;||g;s|:||g' | awk '{print $1,$5}' | sed 's|:||g' | grep "$1$" | grep -v 'grep' | awk -F' ' '{print $1}' | grep '[0-9]' | sort -uV | head -n1 | grep '.' 2>/dev/null || echo '')" - if [ -n "$result" ]; then - echo "$result" + local pid + pid=$(pgrep -x -n "$1" 2>/dev/null) + if [ -n "$pid" ]; then + echo "$pid" return 0 - else - [ "$DEBUGGER" = "on" ] && echo "Debug: No PID found for process: $1" >&2 - return 1 fi + [ "$DEBUGGER" = "on" ] && echo "Debug: No PID found for process: $1" >&2 + return 1 } # - - - - - - - - - - - - - - - - - - - - - - - - - -__format_variables() { printf '%s\n' "${@//,/ }" | tr ' ' '\n' | sort -RVu | grep -v '^$' | tr '\n' ' ' | __clean_variables | grep '.' || return 0; } +__format_variables() { + local input="${*//,/ }" + [ -z "$input" ] && return 0 + printf '%s\n' $input | sort -Ru | tr '\n' ' ' +} # - - - - - - - - - - - - - - - - - - - - - - - - - __clean_variables() { local var="$*" - var="${var#"${var%%[![:space:]]*}"}" # remove leading whitespace characters - var="${var%"${var##*[![:space:]]}"}" # remove trailing whitespace characters - var="$(printf '%s\n' "$var" | sed 's/\( \)*/\1/g;s|^ ||g')" - printf '%s' "$var" | grep -v '^$' + var="${var#"${var%%[![:space:]]*}"}" + var="${var%"${var##*[![:space:]]}"}" + while [[ $var == *" "* ]]; do var="${var// / }"; done + [ -n "$var" ] && printf '%s' "$var" } # - - - - - - - - - - - - - - - - - - - - - - - - - __no_exit() { @@ -280,45 +201,57 @@ __no_exit() { local failed_services="" local failure_count=0 - [ -f "/run/.no_exit.pid" ] && return 0 + # only return early if the recorded PID is still alive; a leftover + # pid file from a prior container life (docker restart) would otherwise + # cause us to exit instead of entering the monitor loop. + if [ -f "/run/.no_exit.pid" ]; then + local no_exit_pid + no_exit_pid=$(<"/run/.no_exit.pid") 2>/dev/null + if [ -n "$no_exit_pid" ] && kill -0 "$no_exit_pid" 2>/dev/null; then + return 0 + fi + rm -f /run/.no_exit.pid 2>/dev/null || true + fi exec bash -c " trap 'echo \"Container shutdown requested\"; rm -f /run/.no_exit.pid /run/*.pid; exit 0' TERM INT echo \$\$ > /run/.no_exit.pid + failed_services=\"\" + failure_count=0 while true; do if [ -n \"$monitor_services\" ] && [ \"$monitor_services\" != \"tini\" ]; then for service in \$(echo \"$monitor_services\" | tr ',' ' '); do if [ \"\$service\" != \"tini\" ] && ! pgrep -x \"\$service\" >/dev/null 2>&1; then - echo \"⚠️ Service \$service is not running\" >&2 + echo \"WARNING: Service \$service is not running\" >&2 failed_services=\"\$failed_services \$service\" failure_count=\$((failure_count + 1)) fi done if [ \$failure_count -ge $failure_threshold ]; then - echo \"❌ Too many service failures (\$failure_count), exiting container\" >&2 + echo \"ERROR: Too many service failures (\$failure_count), exiting container\" >&2 exit 1 fi if [ -n \"\$failed_services\" ]; then - echo \"⚠️ Failed services:\$failed_services\" >&2 + echo \"WARNING: Failed services:\$failed_services\" >&2 failed_services=\"\" + failure_count=0 fi fi - sleep $monitor_interval - done & - wait + sleep $monitor_interval & wait \$! + done " } # - - - - - - - - - - - - - - - - - - - - - - - - - __trim() { local var="${*//;/ }" - var="${var#"${var%%[![:space:]]*}"}" # remove leading whitespace characters - var="${var%"${var##*[![:space:]]}"}" # remove trailing whitespace characters - var="$(echo "$var" | __remove_extra_spaces | sed "s| |; |g;s|;$| |g" | __remove_extra_spaces)" - printf '%s' "$var" | sed 's|;||g' | grep -v '^$' + var="${var#"${var%%[![:space:]]*}"}" + var="${var%"${var##*[![:space:]]}"}" + while [[ $var == *" "* ]]; do var="${var// / }"; done + [ -n "$var" ] && printf '%s' "$var" } # - - - - - - - - - - - - - - - - - - - - - - - - - __banner() { @@ -340,17 +273,21 @@ __service_banner() { printf '# - - - %s %-*s %s - - - #\n' "$icon" "$text_width" "$full_message" "$icon" } # - - - - - - - - - - - - - - - - - - - - - - - - - -__find_php_bin() { find -L '/usr'/*bin -maxdepth 4 -name 'php-fpm*' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_php_ini() { find -L '/etc' -maxdepth 4 -name 'php.ini' 2>/dev/null | head -n1 | sed 's|/php.ini||g' | grep '.' || echo ''; } +__find_php_bin() { find -L '/usr'/*bin -maxdepth 4 -name 'php-fpm*' 2>/dev/null | head -n1; } +__find_php_ini() { + local f + f=$(find -L '/etc' -maxdepth 4 -name 'php.ini' 2>/dev/null | head -n1) + [ -n "$f" ] && printf '%s\n' "${f%/php.ini}" +} # - - - - - - - - - - - - - - - - - - - - - - - - - -__find_nginx_conf() { find -L '/etc' -maxdepth 4 -name 'nginx.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_caddy_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'caddy.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_lighttpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'lighttpd.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_cherokee_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'cherokee.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_httpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'httpd.conf' -o -iname 'apache2.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } +__find_nginx_conf() { find -L '/etc' -maxdepth 4 -name 'nginx.conf' 2>/dev/null | head -n1; } +__find_caddy_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'caddy.conf' 2>/dev/null | head -n1; } +__find_lighttpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'lighttpd.conf' 2>/dev/null | head -n1; } +__find_cherokee_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'cherokee.conf' 2>/dev/null | head -n1; } +__find_httpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'httpd.conf' -o -iname 'apache2.conf' 2>/dev/null | head -n1; } # - - - - - - - - - - - - - - - - - - - - - - - - - -__find_mysql_conf() { find -L '/etc' -maxdepth 4 -type f -name 'my.cnf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_pgsql_conf() { find -L '/var/lib' '/etc' -maxdepth 8 -type f -name 'postgresql.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } +__find_mysql_conf() { find -L '/etc' -maxdepth 4 -type f -name 'my.cnf' 2>/dev/null | head -n1; } +__find_pgsql_conf() { find -L '/var/lib' '/etc' -maxdepth 8 -type f -name 'postgresql.conf' 2>/dev/null | head -n1; } __find_couchdb_conf() { return; } __find_mongodb_conf() { return; } # - - - - - - - - - - - - - - - - - - - - - - - - - @@ -400,7 +337,7 @@ __exec_service() { eval "$@" 2>>/dev/stderr >>/data/logs/start.log & while [ $count -ne 0 ]; do sleep 3 - if __pgrep $1; then + if __pgrep "$1"; then touch "/run/init.d/$1.pid" break else @@ -419,105 +356,32 @@ __update_ssl_certs() { fi } # - - - - - - - - - - - - - - - - - - - - - - - - - -__certbot() { - [ -n "$(type -P 'certbot')" ] || return 1 - local options="$1" - local statusCode=0 - local domain_list="" - local certbot_key_opts="" - local ADD_CERTBOT_DOMAINS="" - local CERTBOT_DOMAINS="${CERTBOT_DOMAINS:-$HOSTNAME}" - local CERT_BOT_MAIL="${CERT_BOT_MAIL:-ssl-admin@$CERTBOT_DOMAINS}" - local certbot_key_opts="--key-path $SSL_KEY --fullchain-path $SSL_CERT" - mkdir -p "/config/letsencrypt" - __symlink "/etc/letsencrypt" "/config/letsencrypt" - is_renewal="$(find /etc/letsencrypt/renewal -type f 2>/dev/null || false)" - [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" - [ -f "/config/certbot/env.sh" ] && . "/config/certbot/env.sh" - if [ -n "$SSL_KEY" ]; then - mkdir -p "$(dirname "$SSL_KEY")" 2>/dev/null || true - else - echo "The variable SSL_KEY is not set" >&2 - return 1 - fi - if [ -n "$SSL_CERT" ]; then - mkdir -p "$(dirname "$SSL_CERT")" 2>/dev/null || true - else - echo "The variable SSL_CERT is not set" >&2 - return 1 - fi - domain_list="$CERTBOT_DOMAINS www.$CERTBOT_DOMAINS mail.$CERTBOT_DOMAINS" - domain_list="$(echo "$domain_list" | tr ' ' '\n' | sort -u | tr '\n' ' ')" - if [ "$CERT_BOT_ENABLED" != "true" ]; then - export CERT_BOT_ENABLED="" - return 10 - fi - if [ -z "$CERT_BOT_MAIL" ]; then - echo "The variable CERT_BOT_MAIL is not set" >&2 - return 1 - fi - if [ -z "$CERTBOT_DOMAINS" ]; then - echo "The variable CERTBOT_DOMAINS is not set" >&2 - return 1 - fi - for domain in $CERTBOT_DOMAINS; do - [ -n "$domain" ] && ADD_CERTBOT_DOMAINS+="-d $domain " - done - if [ -n "$is_renewal" ]; then - options="renew" - ADD_CERTBOT_DOMAINS="" - else - options="certonly" - fi - certbot_key_opts="$certbot_key_opts $ADD_CERTBOT_DOMAINS" - if [ -f "/config/certbot/setup.sh" ]; then - eval "/config/certbot/setup.sh" - statusCode=$? - elif [ -f "/etc/named/certbot.sh" ]; then - eval "/etc/named/certbot.sh" - statusCode=$? - elif [ -f "/config/certbot/dns.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts - fi - statusCode=$? - elif [ -f "/config/certbot/certbot.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts - fi - statusCode=$? - elif [ -f "/config/named/certbot-update.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts - fi - statusCode=$? - else - certbot_key_opts="$certbot_key_opts --webroot ${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" - if [ -n "$ADD_CERTBOT_DOMAINS" ]; then - certbot $options --agree-tos -m $CERT_BOT_MAIL certonly --webroot "${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" $certbot_key_opts - statusCode=$? - else - statusCode=1 - fi - fi - [ $statusCode -eq 0 ] && __update_ssl_certs - return $statusCode -} -# - - - - - - - - - - - - - - - - - - - - - - - - - __display_user_info() { if [ -n "$user_name" ] || [ -n "$user_pass" ] || [ -n "$root_user_name" ] || [ -n "$root_user_pass" ]; then __banner "User info" - [ -n "$user_name" ] && __printf_space "40" "username:" "$user_name" && echo "$user_name" - [ -n "$user_pass" ] && __printf_space "40" "password:" "saved to ${USER_FILE_PREFIX}/${SERVICE_NAME}_pass" && echo "$user_pass" - [ -n "$root_user_name" ] && __printf_space "40" "root username:" "$root_user_name" && echo "$root_user_name" - [ -n "$root_user_pass" ] && __printf_space "40" "root password:" "saved to ${ROOT_FILE_PREFIX}/${SERVICE_NAME}_pass" && echo "$root_user_pass" + [ -n "$user_name" ] && __printf_space "40" "username:" "$user_name" + if [ -n "$user_pass" ]; then + if [ "${SHOW_PASSWORDS:-no}" = "yes" ]; then + __printf_space "40" "password:" "$user_pass" + else + __printf_space "40" "password:" "saved to ${USER_FILE_PREFIX}/${SERVICE_NAME}_pass" + fi + fi + [ -n "$root_user_name" ] && __printf_space "40" "root username:" "$root_user_name" + if [ -n "$root_user_pass" ]; then + if [ "${SHOW_PASSWORDS:-no}" = "yes" ]; then + __printf_space "40" "root password:" "$root_user_pass" + else + __printf_space "40" "root password:" "saved to ${ROOT_FILE_PREFIX}/${SERVICE_NAME}_pass" + fi + fi __banner "" fi } # - - - - - - - - - - - - - - - - - - - - - - - - - __init_config_etc() { local copy="no" - local name="$(find "/etc/$SERVICE_NAME" -maxdepth 0 2>/dev/null | head -n1)" + local name="$SERVICE_NAME" local etc_dir="${ETC_DIR:-/etc/$name}" local conf_dir="${CONF_DIR:-/config/$name}" __is_dir_empty "$conf_dir" && copy=yes @@ -533,29 +397,26 @@ __init_config_etc() { } __create_ssl_cert() { local SSL_DIR="${SSL_DIR:-/etc/ssl}" - if ! __certbot certonly; then - [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" - if [ -z "$SSL_DIR" ]; then - echo "SSL_DIR is unset" - return 1 - fi - [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" - if [ -n "$FORCE_SSL" ] || [ ! -f "$SSL_CERT" ] || [ ! -f "$SSL_KEY" ]; then - echo "Setting Country to $COUNTRY and Setting State/Province to $STATE and Setting City to $CITY" - echo "Setting OU to $UNIT and Setting ORG to $ORG and Setting server to $CN" - echo "All variables can be overwritten by creating a /config/.ssl.env and setting the variables there" - echo "Creating ssl key and certificate in $SSL_DIR and will be valid for $((VALID_FOR / 365)) year[s]" - # - openssl req \ - -new \ - -newkey rsa:$RSA \ - -days $VALID_FOR \ - -nodes \ - -x509 \ - -subj "/C=${COUNTRY// /\\ }/ST=${STATE// /\\ }/L=${CITY// /\\ }/O=${ORG// /\\ }/OU=${UNIT// /\\ }/CN=${CN// /\\ }" \ - -keyout "$SSL_KEY" \ - -out "$SSL_CERT" - fi + [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" + if [ -z "$SSL_DIR" ]; then + echo "SSL_DIR is unset" >&2 + return 1 + fi + [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" + if [ -n "$FORCE_SSL" ] || [ ! -f "$SSL_CERT" ] || [ ! -f "$SSL_KEY" ]; then + echo "Setting Country to $COUNTRY and Setting State/Province to $STATE and Setting City to $CITY" + echo "Setting OU to $UNIT and Setting ORG to $ORG and Setting server to $CN" + echo "All variables can be overwritten by creating a /config/.ssl.env and setting the variables there" + echo "Creating ssl key and certificate in $SSL_DIR and will be valid for $((VALID_FOR / 365)) year[s]" + openssl req \ + -new \ + -newkey rsa:$RSA \ + -days $VALID_FOR \ + -nodes \ + -x509 \ + -subj "/C=${COUNTRY// /\\ }/ST=${STATE// /\\ }/L=${CITY// /\\ }/O=${ORG// /\\ }/OU=${UNIT// /\\ }/CN=${CN// /\\ }" \ + -keyout "$SSL_KEY" \ + -out "$SSL_CERT" fi if [ -f "$SSL_CERT" ] && [ -f "$SSL_KEY" ]; then __update_ssl_certs @@ -627,7 +488,6 @@ __init_couchdb() { # Show available init functions __init_help() { echo ' -__certbot __update_ssl_certs __create_ssl_cert ' @@ -635,7 +495,7 @@ __create_ssl_cert } # - - - - - - - - - - - - - - - - - - - - - - - - - __run_once() { - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] || [ "$DATA_DIR_INITIALIZED" = "false" ] || [ ! -f "/config/.docker_has_run" ]; then + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] || [ "$DATA_DIR_INITIALIZED" = "no" ] || [ ! -f "/config/.docker_has_run" ]; then return 0 else return 1 @@ -644,7 +504,7 @@ __run_once() { # - - - - - - - - - - - - - - - - - - - - - - - - - # run program ever n minutes __cron() { - trap 'retVal=$?;[ -f "/run/cron/$bin.run" ] && rm -Rf "/run/cron/$bin.run";[ -f "/run/cron/$bin.pid" ] && rm -Rf "/run/cron/$bin.pid";exit ${retVal:-0}' SIGINT ERR EXIT + local bin="" if [ "$1" = "--pid" ]; then pid="$2" shift 2 @@ -659,11 +519,13 @@ __cron() { fi [ $# -eq 0 ] && echo "Usage: cron [interval] [command]" && exit 1 local command="$*" - local bin="${CRON_NAME:-$1}"; bin="${bin##*/}" + bin="${CRON_NAME:-$1}"; bin="${bin##*/}" + trap 'retVal=$?;[ -f "/run/cron/$bin.run" ] && rm -Rf "/run/cron/$bin.run";[ -f "/run/cron/$bin.pid" ] && rm -Rf "/run/cron/$bin.pid";exit ${retVal:-0}' SIGINT ERR EXIT [ -d "/run/cron" ] || mkdir -p "/run/cron" echo "$pid" >"/run/cron/$bin.pid" echo "$command" >"/run/cron/$bin.run" echo "Log is saved to /data/logs/cron.log" + # eval is intentional: $command is operator-controlled input from this container's init while :; do eval "$command" sleep $interval @@ -680,15 +542,15 @@ __replace() { __find_replace() { local search="$1" replace="$2" file="${3:-$2}" [ -e "$file" ] || return 1 - find "$file" -type f -not -path '.git*' -exec sed -i "s|$search|$replace|g" {} \; 2>/dev/null + find "$file" -type f -not -path '*/.git/*' -not -name '.git' -exec sed -i "s|$search|$replace|g" {} + 2>/dev/null } # - - - - - - - - - - - - - - - - - - - - - - - - - # /config > /etc __copy_templates() { - local from="$1" to="$2" - is_link="$(ls -la "$dest" 2>/dev/null | awk '{print $NF}')" + local from="$1" to="$2" is_link="" + [ -L "$to" ] && is_link="$(readlink "$to")" [ "$from" != "$is_link" ] || return 0 - if [ -e "$from" ] && __is_dir_empty "$to"; then + if [ -e "$from" ] && (! [ -d "$to" ] || __is_dir_empty "$to"); then __file_copy "$from" "$to" fi } @@ -696,16 +558,18 @@ __copy_templates() { # /config/file > /etc/file __symlink() { local from="$1" to="$2" - if [ -e "$to" ]; then - [ -e "$from" ] && __rm "$from" - ln -sf "$to" "$from" && echo "Created symlink to $from > $to" - fi + [ -e "$to" ] || return 0 + [ "$from" = "$to" ] && return 0 + __rm "$from" + [ -d "${from%/*}" ] || mkdir -p "${from%/*}" 2>/dev/null + ln -sf "$to" "$from" && echo "Created symlink to $from > $to" } # - - - - - - - - - - - - - - - - - - - - - - - - - __file_copy() { local from="$1" local dest="$2" - is_link="$(ls -la "$dest" 2>/dev/null | awk '{print $NF}')" + local is_link="" + [ -L "$dest" ] && is_link="$(readlink "$dest")" if [ "$from" != "$is_link" ]; then if [ -n "$from" ] && [ -e "$from" ] && [ -n "$dest" ]; then if [ -d "$from" ]; then @@ -733,7 +597,7 @@ __file_copy() { } # - - - - - - - - - - - - - - - - - - - - - - - - - __generate_random_uids() { - local set_random_uid="$(seq 100 999 | sort -R | head -n 1)" + local set_random_uid=$((100 + RANDOM % 900)) while :; do if grep -shq "x:.*:$set_random_uid:" "/etc/group" && ! grep -shq "x:$set_random_uid:.*:" "/etc/passwd"; then set_random_uid=$((set_random_uid + 1)) @@ -802,12 +666,12 @@ __fix_permissions() { fi } # - - - - - - - - - - - - - - - - - - - - - - - - - -__get_gid() { grep "^$1:" /etc/group 2>/dev/null | awk -F ':' '{print $3}' || return 1; } -__get_uid() { grep "^$1:" /etc/passwd 2>/dev/null | awk -F ':' '{print $3}' || return 1; } -__check_for_uid() { awk -F ':' '{print $3}' /etc/passwd 2>/dev/null | sort -u | grep -q "^$1$" || return 1; } -__check_for_guid() { awk -F ':' '{print $3}' /etc/group 2>/dev/null | sort -u | grep -q "^$1$" || return 1; } -__check_for_user() { awk -F ':' '{print $1}' /etc/passwd 2>/dev/null | sort -u | grep -q "^$1$" || return 1; } -__check_for_group() { awk -F ':' '{print $1}' /etc/group 2>/dev/null | sort -u | grep -q "^$1$" || return 1; } +__get_gid() { awk -F: -v n="$1" '$1==n {print $3; found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } +__get_uid() { awk -F: -v n="$1" '$1==n {print $3; found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_uid() { awk -F: -v n="$1" '$3==n {found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_guid() { awk -F: -v n="$1" '$3==n {found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } +__check_for_user() { awk -F: -v n="$1" '$1==n {found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_group() { awk -F: -v n="$1" '$1==n {found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } # - - - - - - - - - - - - - - - - - - - - - - - - - # check if process is already running __proc_check() { @@ -828,14 +692,14 @@ __proc_check() { check_result=0 elif [ -f "$SERVICE_PID_FILE" ]; then local pid_from_file - pid_from_file="$(cat "$SERVICE_PID_FILE" 2>/dev/null || echo "")" + pid_from_file=$(<"$SERVICE_PID_FILE") 2>/dev/null if [ -n "$pid_from_file" ] && kill -0 "$pid_from_file" 2>/dev/null; then check_result=0 fi fi if [ $check_result -eq 0 ]; then SERVICE_IS_RUNNING="yes" - touch "$SERVICE_PID_FILE" 2>/dev/null || true + pgrep -x -n "$cmd_name" >"$SERVICE_PID_FILE" 2>/dev/null || true return 0 else return 1 @@ -1012,28 +876,26 @@ __create_env_file() { dir="$(dirname "$create_env")" [ -d "$dir" ] || mkdir -p "$dir" if [ -n "$create_env" ] && [ ! -f "$create_env" ]; then - cat </dev/null -$(<"$sample_file") -EOF + cp -f "$sample_file" "$create_env" fi [ -f "$create_env" ] || envStatus=$((1 + envStatus)) done - rm -f "$sample_file" + [ "$envStatus" -eq 0 ] && rm -f "$sample_file" return $envStatus } # - - - - - - - - - - - - - - - - - - - - - - - - - __exec_command() { - local bin="" local arg=("$@") - local exitCode="0" + local exitCode=0 local cmdExec="${arg:-}" local pre_exec="--login -c" - local shell="$(type -P bash 2>/dev/null || type -P dash 2>/dev/null || type -P ash 2>/dev/null || type -P sh 2>/dev/null)" - bin="$(echo "${arg[*]}" | tr ' ' '\n' | grep -v '^$' | head -n1 | sed 's| ||g' || echo 'bash')" + local shell bin prog + shell=$(type -P bash || type -P dash || type -P ash || type -P sh) 2>/dev/null + bin="${arg[0]:-bash}" prog="$(type -P "$bin" 2>/dev/null || echo "$bin")" - if type -t $bin >/dev/null 2>&1; then + if type -t "$bin" &>/dev/null; then echo "${exec_message:-Executing command: $cmdExec}" - eval $shell $pre_exec "$cmdExec" || exitCode=1 + "$shell" $pre_exec "$cmdExec" exitCode=$? elif [ -f "$prog" ]; then echo "$prog is not executable" @@ -1050,7 +912,8 @@ __start_init_scripts() { [ "$1" = " " ] && shift 1 if [ "$DEBUGGER" = "on" ]; then echo "Enabling debugging" - set -o pipefail -x$DEBUGGER_OPTIONS + set -o pipefail + [ -n "$DEBUGGER_OPTIONS" ] && set -"$DEBUGGER_OPTIONS" else set -o pipefail fi @@ -1062,7 +925,9 @@ __start_init_scripts() { local critical_failures="0" local pidFile="/run/.start_init_scripts.pid" local init_dir="${1:-/usr/local/etc/docker/init.d}" - local init_count="$(ls -A "$init_dir"/* 2>/dev/null | grep -v '\.sample' | wc -l)" + local init_files=("$init_dir"/*.sh) + local init_count=0 + [ -e "${init_files[0]}" ] && init_count=${#init_files[@]} local exit_on_failure="${EXIT_ON_SERVICE_FAILURE:-true}" # Clean stale PID files from previous runs @@ -1078,8 +943,11 @@ __start_init_scripts() { while :; do echo "Running: $(date)" >"/data/logs/init/keep_alive" && sleep 3600; done & else if [ -d "$init_dir" ]; then - [ -f "$init_dir/service.sample" ] && __rm "$init_dir"/*.sample - chmod -Rf 755 "$init_dir"/*.sh + local sample + for sample in "$init_dir"/*.sample; do + [ -e "$sample" ] && __rm "$sample" + done + (shopt -s nullglob; chmod -Rf 755 "$init_dir"/*.sh 2>/dev/null || true) echo "🚀 Starting container services initialization" echo "📂 Init directory: $init_dir" @@ -1091,10 +959,10 @@ __start_init_scripts() { if [ -x "$init" ]; then touch "$pidFile" name="${init##*/}" - service="$(printf '%s' "$name" | sed 's/^[^-]*-//;s|.sh$||g')" + service="${name#*-}"; service="${service%.sh}" __service_banner "🔧" "Executing service script:" "${init##*/}" - # Execute the init script and capture the exit code - if source "$init"; then + # Execute the init script and capture the exit code (subshell isolates exit calls) + if ( source "$init" ); then # Check if service was disabled first if [ -n "$SERVICE_DISABLED" ]; then initStatus="0" @@ -1120,7 +988,7 @@ __start_init_scripts() { retPID="" local found_process="" # Try multiple name variants to find the process - for name_variant in "$service" "${service}84" "${service}d" "$(echo "$service" | sed 's/-//g')" "$(echo "$service" | tr -d '-')"; do + for name_variant in "$service" "${service}d" "${service//-/}"; do if [ -z "$retPID" ]; then retPID=$(__get_pid "$name_variant" 2>/dev/null || echo "") if [ -n "$retPID" ] && [ "$retPID" != "0" ]; then @@ -1135,7 +1003,7 @@ __start_init_scripts() { __service_banner "✅" "Service $service started successfully -" "PID: ${retPID} ($found_process)" elif [ -f "$expected_pid_file" ]; then # No running process but PID file exists - verify PID is valid - file_pid="$(cat "$expected_pid_file" 2>/dev/null || echo "")" + file_pid=$(<"$expected_pid_file") 2>/dev/null if [ -n "$file_pid" ] && kill -0 "$file_pid" 2>/dev/null; then initStatus="0" __service_banner "✅" "Service $service started successfully -" "PID: $file_pid (from file)" @@ -1194,14 +1062,14 @@ __setup_mta() { local local_hostname="${FULL_DOMAIN_NAME:-}" local account_user="${SERVER_ADMIN//@*/}" local account_domain="${EMAIL_DOMAIN//*@/}" - echo "$EMAIL_RELAY" | grep '[0-9][0-9]' || relay_port="465" + [[ $EMAIL_RELAY == *[0-9][0-9]* ]] || relay_port="465" ################# sSMTP relay setup - if [ -n "$(type -P 'ssmtp')" ]; then + if command -v ssmtp &>/dev/null; then [ -d "/config/ssmtp" ] || mkdir -p "/config/ssmtp" [ -f "/etc/ssmtp/ssmtp.conf" ] && __rm "/etc/ssmtp/ssmtp.conf" symlink_files="$(__find_file_relative "/config/ssmtp")" if [ ! -f "/config/ssmtp/ssmtp.conf" ]; then - cat </dev/null + cat >"/config/ssmtp/ssmtp.conf" </dev/null; then [ -d "/etc/postfix" ] || mkdir -p "/etc/postfix" [ -d "/config/postfix" ] || mkdir -p "/config/postfix" [ -f "/etc/postfix/main.cf" ] && __rm "/etc/postfix/main.cf" symlink_files="$(__find_file_relative "/config/postfix")" if [ ! -f "/config/postfix/main.cf" ]; then - cat </dev/null + cat >"/config/postfix/main.cf" </dev/null - postmap "/config/mydomains.pcre" "/config/mydomains" "/config/virtual" &>/dev/null + postmap "/config/postfix/aliases" "/config/postfix/mynetworks" "/config/postfix/transport" &>/dev/null + postmap "/config/postfix/mydomains.pcre" "/config/postfix/mydomains" "/config/postfix/virtual" &>/dev/null fi if [ -f "/etc/postfix/main.cf" ] && [ ! -f "/run/init.d/postfix.pid" ]; then SERVICES_LIST+="postfix " @@ -1389,11 +1257,11 @@ __initialize_db_users() { __initialize_system_etc() { local conf_dir="$1" local dir="" - local file=() + local files="" local directories="" if [ -n "$conf_dir" ] && [ -e "$conf_dir" ]; then - files="$(find "$conf_dir"/* -not -path '*/env/*' -type f 2>/dev/null | sed 's|'/config/'||g' | sort -u | grep -v '^$' | grep '.' || false)" - directories="$(find "$conf_dir"/* -not -path '*/env/*' -type d 2>/dev/null | sed 's|'/config/'||g' | sort -u | grep -v '^$' | grep '.' || false)" + files=$(find "$conf_dir"/* -not -path '*/env/*' -type f 2>/dev/null | sort -u | sed 's|/config/||') + directories=$(find "$conf_dir"/* -not -path '*/env/*' -type d 2>/dev/null | sort -u | sed 's|/config/||') echo "Copying config files to system: $conf_dir > /etc/${conf_dir//\/config\//}" if [ -n "$directories" ]; then for d in $directories; do @@ -1434,7 +1302,7 @@ __initialize_custom_bin_dir() { __initialize_default_templates() { local errors=0 if [ -n "$DEFAULT_TEMPLATE_DIR" ]; then - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] && [ -d "/config" ]; then + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] && [ -d "/config" ]; then __log_info "Copying default config files $DEFAULT_TEMPLATE_DIR > /config" if [ ! -d "$DEFAULT_TEMPLATE_DIR" ]; then __log_warn "Template directory not found: $DEFAULT_TEMPLATE_DIR" @@ -1471,7 +1339,7 @@ __initialize_default_templates() { __initialize_config_dir() { local errors=0 if [ -n "$DEFAULT_CONF_DIR" ]; then - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] && [ -d "/config" ]; then + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] && [ -d "/config" ]; then __log_info "Copying custom config files: $DEFAULT_CONF_DIR > /config" if [ ! -d "$DEFAULT_CONF_DIR" ]; then __log_warn "Config directory not found: $DEFAULT_CONF_DIR" @@ -1506,8 +1374,9 @@ __initialize_config_dir() { } # - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_data_dir() { + [ "$DATA_DIR_INITIALIZED" = "no" ] || return 0 if [ -d "/data" ]; then - if [ "$DATA_DIR_INITIALIZED" = "false" ] && [ -n "$DEFAULT_DATA_DIR" ]; then + if [ -n "$DEFAULT_DATA_DIR" ]; then __log_info "Copying data files $DEFAULT_DATA_DIR > /data" for create_data_template in "$DEFAULT_DATA_DIR"/*; do create_data_name="${create_data_template##*/}" @@ -1520,7 +1389,7 @@ __initialize_data_dir() { fi fi done - unset create_template + unset create_data_template fi fi } @@ -1550,13 +1419,13 @@ __is_htdocs_mounted() { unset IMPORT_FROM_GIT fi fi - if [ -n "$IMPORT_FROM_GIT" ] && [ "$(command -v "git" 2>/dev/null)" ]; then + if [ -n "$IMPORT_FROM_GIT" ] && command -v git &>/dev/null; then if __is_dir_empty "$WWW_ROOT_DIR"; then echo "Importing project from $IMPORT_FROM_GIT to $WWW_ROOT_DIR" git clone -q "$IMPORT_FROM_GIT" "$WWW_ROOT_DIR" elif [ -d "$WWW_ROOT_DIR" ]; then echo "Updating the project in $WWW_ROOT_DIR" - git -C pull -q "$WWW_ROOT_DIR" + git -C "$WWW_ROOT_DIR" pull -q fi elif [ -d "/app" ]; then WWW_ROOT_DIR="/app" @@ -1574,27 +1443,16 @@ __is_htdocs_mounted() { } # - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_ssl_certs() { - [ "$SSL_ENABLED" = "yes" ] && __certbot - if [ -d "/config/letsencrypt" ]; then - mkdir -p "/etc/letsencrypt" - __file_copy "/config/letsencrypt" "/etc/letsencrypt/" - elif [ -d "/etc/letsencrypt" ] && [ ! -d "/config/letsencrypt" ]; then - mkdir -p "/config/letsencrypt" - __file_copy "/etc/letsencrypt" "/config/letsencrypt/" - else - [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" - if [ "$SSL_ENABLED" = "true" ] || [ "$SSL_ENABLED" = "yes" ]; then - if [ -f "$SSL_CERT" ] && [ -f "$SSL_KEY" ]; then - SSL_ENABLED="true" - if [ -n "$SSL_CA" ] && [ -f "$SSL_CA" ]; then - mkdir -p "$SSL_DIR/certs" - cat "$SSL_CA" >>"/etc/ssl/certs/ca-certificates.crt" - cp -Rf "/." "$SSL_DIR/" - fi - else - [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" - __create_ssl_cert + [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" + if [ "$SSL_ENABLED" = "yes" ]; then + if [ -f "$SSL_CERT" ] && [ -f "$SSL_KEY" ]; then + if [ -n "$SSL_CA" ] && [ -f "$SSL_CA" ]; then + mkdir -p "$SSL_DIR/certs" + cat "$SSL_CA" >>"/etc/ssl/certs/ca-certificates.crt" fi + __update_ssl_certs + else + __create_ssl_cert fi fi type update-ca-certificates &>/dev/null && update-ca-certificates &>/dev/null @@ -1627,16 +1485,16 @@ __switch_to_user() { if [ "$switch_user" = "root" ]; then su_exec="" su_cmd() { eval "$@" || return 1; } - elif [ "$(builtin type -P gosu)" ]; then + elif command -v gosu &>/dev/null; then su_exec="gosu $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P runuser)" ]; then + elif command -v runuser &>/dev/null; then su_exec="runuser -u $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P sudo)" ]; then + elif command -v sudo &>/dev/null; then su_exec="sudo -u $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P su)" ]; then + elif command -v su &>/dev/null; then su_exec="su -s /bin/sh - $switch_user" su_cmd() { $su_exec -c "$@" || return 1; } else @@ -1682,8 +1540,13 @@ __backup() { [ -z "$dirs" ] && echo "BACKUP_DIR is unset" >&2 && return 1 [ -f "$pidFile" ] && echo "A backup job is already running" >&2 && return 1 echo "$$" >"$pidFile" + trap "rm -f '$pidFile'" EXIT INT TERM echo "Starting backup in $(date)" >>"$logDir/$CONTAINER_NAME" - tar --exclude $backup_exclude cfvz "$backup_dir/$backup_name" $dirs 2>/dev/stderr >>"$logDir/$CONTAINER_NAME" || exitCodeP=1 + local tar_excludes=() + for excl in $backup_exclude; do + tar_excludes+=("--exclude=$excl") + done + tar "${tar_excludes[@]}" -cfvz "$backup_dir/$backup_name" $dirs 2>/dev/stderr >>"$logDir/$CONTAINER_NAME" || exitCodeP=1 if [ $exitCodeP -eq 0 ]; then echo "Backup has completed and saved to: $backup_dir/$backup_name" printf '%s\n\n' "Backup has completed on $(date)" >>"$logDir/$CONTAINER_NAME" @@ -1694,7 +1557,7 @@ __backup() { exitStatus=1 fi [ -f "$pidFile" ] && __rm "$pidFile" - [ -n "$maxDays" ] && find "$BACKUP_DIR"* -mtime +$maxDays -exec rm -Rf {} \; >/dev/null 2>&1 + [ -n "$maxDays" ] && find "$BACKUP_DIR" -mtime +"$maxDays" -exec rm -Rf {} \; >/dev/null 2>&1 if [ -n "$cronTime" ]; then runTime=$((cronTime * 3600)) else @@ -1708,8 +1571,8 @@ export INIT_DATE="${INIT_DATE:-$(date)}" export START_SERVICES="${START_SERVICES:-yes}" export ENTRYPOINT_MESSAGE="${ENTRYPOINT_MESSAGE:-yes}" export ENTRYPOINT_FIRST_RUN="${ENTRYPOINT_FIRST_RUN:-yes}" -export DATA_DIR_INITIALIZED="${DATA_DIR_INITIALIZED:-false}" -export CONFIG_DIR_INITIALIZED="${CONFIG_DIR_INITIALIZED:-false}" +export DATA_DIR_INITIALIZED="${DATA_DIR_INITIALIZED:-no}" +export CONFIG_DIR_INITIALIZED="${CONFIG_DIR_INITIALIZED:-no}" # - - - - - - - - - - - - - - - - - - - - - - - - - # System export LANG="${LANG:-C.UTF-8}" @@ -1719,7 +1582,7 @@ export HOSTNAME="${FULL_DOMAIN_NAME:-${SERVER_HOSTNAME:-$HOSTNAME}}" # - - - - - - - - - - - - - - - - - - - - - - - - - # Default directories export SSL_DIR="${SSL_DIR:-/config/ssl}" -export SSL_CA="${SSL_CERT:-/config/ssl/ca.crt}" +export SSL_CA="${SSL_CA:-/config/ssl/ca.crt}" export SSL_KEY="${SSL_KEY:-/config/ssl/localhost.pem}" export SSL_CERT="${SSL_CERT:-/config/ssl/localhost.crt}" export LOCAL_BIN_DIR="${LOCAL_BIN_DIR:-/usr/local/bin}" @@ -1756,29 +1619,29 @@ export ENTRYPOINT_CONFIG_INIT_FILE="${ENTRYPOINT_CONFIG_INIT_FILE:-/config/.dock # is already Initialized if [ -z "$DATA_DIR_INITIALIZED" ]; then if [ -f "$ENTRYPOINT_DATA_INIT_FILE" ]; then - DATA_DIR_INITIALIZED="true" + DATA_DIR_INITIALIZED="yes" else - DATA_DIR_INITIALIZED="false" + DATA_DIR_INITIALIZED="no" fi fi if [ -z "$CONFIG_DIR_INITIALIZED" ]; then if [ -f "$ENTRYPOINT_CONFIG_INIT_FILE" ]; then - CONFIG_DIR_INITIALIZED="true" + CONFIG_DIR_INITIALIZED="yes" else - CONFIG_DIR_INITIALIZED="false" + CONFIG_DIR_INITIALIZED="no" fi fi if [ -z "$ENTRYPOINT_FIRST_RUN" ]; then if [ -f "$ENTRYPOINT_PID_FILE" ] || [ -f "$ENTRYPOINT_INIT_FILE" ]; then ENTRYPOINT_FIRST_RUN="no" else - ENTRYPOINT_FIRST_RUN="true" + ENTRYPOINT_FIRST_RUN="yes" fi fi export ENTRYPOINT_DATA_INIT_FILE DATA_DIR_INITIALIZED ENTRYPOINT_CONFIG_INIT_FILE CONFIG_DIR_INITIALIZED export ENTRYPOINT_PID_FILE ENTRYPOINT_INIT_FILE ENTRYPOINT_FIRST_RUN # - - - - - - - - - - - - - - - - - - - - - - - - - # export the functions -export -f __get_pid __start_init_scripts __is_running __certbot __update_ssl_certs __create_ssl_cert +export -f __get_pid __start_init_scripts __is_running __update_ssl_certs __create_ssl_cert # - - - - - - - - - - - - - - - - - - - - - - - - - # end of functions