diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index e3f30bb..1ef6a46 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -1,5 +1,6 @@ name: Publish Docker on: + workflow_dispatch: push: branches: - 'staging' diff --git a/Dockerfile b/Dockerfile index b839f1f..9e19925 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,33 +1,50 @@ -# Use a stable Python base image (Debian 12 based) -FROM python:3.14-slim +# --- Build Stage for Webhook --- +# Use Alpine for the builder to maintain consistency +FROM golang:1.26-alpine AS builder + +# Install git to fetch dependencies +RUN apk add --no-cache git + +# Clone and build webhook as a static binary (CGO_ENABLED=0) +# This ensures it runs on Alpine's musl libc +RUN git clone https://github.com/adnanh/webhook.git /build \ + && cd /build \ + && CGO_ENABLED=0 go build -o webhook . + +# --- Final Stage --- +FROM python:3.13-alpine # Set environment variables ENV WEBHOOK_URL_PREFIX="wiki/hooks" # Install system dependencies -RUN apt update && apt install -y --no-install-recommends \ - unzip apache2 build-essential python3-dev python3-pip \ - python3-setuptools python3-wheel python3-cffi libcairo2 \ - libpango-1.0-0 libpangocairo-1.0-0 libgdk-pixbuf-2.0-0 \ - libffi-dev shared-mime-info git wget curl ca-certificates \ - && apt clean && rm -rf /var/lib/apt/lists/* +# apache2 = Apache, util-linux = for 'flock' in update.sh +RUN apk add --no-cache \ + apache2 \ + git \ + ca-certificates \ + util-linux -# Copy and install Python dependencies -ADD requirements.txt . -RUN pip install --no-cache-dir -r requirements.txt +# Create required directories +# Alpine's httpd uses /var/www/localhost/htdocs by default, +# but we'll keep your custom paths. +RUN mkdir -p /var/webhook /srv_root/docs /var/www/html/wiki /run/httpd /var/log/httpd -# Install webhook binary -RUN wget -qO- https://github.com/adnanh/webhook/releases/download/2.8.1/webhook-linux-amd64.tar.gz \ - | tar xzv --strip 1 -C /usr/local/bin +# Copy and install Python dependencies +# We use --no-cache-dir to keep the image slim +COPY requirements.txt . +RUN pip install --no-cache-dir --upgrade pip && \ + pip install --no-cache-dir -r requirements.txt -# Create required directories -RUN mkdir -p /var/webhook /srv_root/docs /var/www/html/wiki +# Copy the statically built webhook binary from the builder stage +COPY --from=builder /build/webhook /usr/local/bin/webhook # Copy your scripts and config files -ADD update.sh /usr/local/bin/update.sh +COPY update.sh /usr/local/bin/update.sh COPY config/hooks.json /usr/local/bin/hooks.json -COPY config/apache2.conf /etc/apache2/apache2.conf -ADD start.sh /usr/local/bin/start.sh +# Apache config path changes from /etc/apache2 to /etc/httpd in Alpine +COPY config/apache2.conf /etc/httpd/httpd.conf +COPY start.sh /usr/local/bin/start.sh # Ensure shell scripts are executable RUN chmod +x /usr/local/bin/start.sh /usr/local/bin/update.sh @@ -35,3 +52,6 @@ RUN chmod +x /usr/local/bin/start.sh /usr/local/bin/update.sh # Set container entrypoint ENTRYPOINT ["/usr/local/bin/start.sh"] + + + diff --git a/config/apache2.conf b/config/apache2.conf index e4c4e7f..1ca1e06 100644 --- a/config/apache2.conf +++ b/config/apache2.conf @@ -1,230 +1,56 @@ -# This is the main Apache server configuration file. It contains the -# configuration directives that give the server its instructions. -# See http://httpd.apache.org/docs/2.4/ for detailed information about -# the directives and /usr/share/doc/apache2/README.Debian about Debian specific -# hints. -# -# -# Summary of how the Apache 2 configuration works in Debian: -# The Apache 2 web server configuration in Debian is quite different to -# upstream's suggested way to configure the web server. This is because Debian's -# default Apache2 installation attempts to make adding and removing modules, -# virtual hosts, and extra configuration directives as flexible as possible, in -# order to make automating the changes and administering the server as easy as -# possible. - -# It is split into several files forming the configuration hierarchy outlined -# below, all located in the /etc/apache2/ directory: -# -# /etc/apache2/ -# |-- apache2.conf -# | `-- ports.conf -# |-- mods-enabled -# | |-- *.load -# | `-- *.conf -# |-- conf-enabled -# | `-- *.conf -# `-- sites-enabled -# `-- *.conf -# -# -# * apache2.conf is the main configuration file (this file). It puts the pieces -# together by including all remaining configuration files when starting up the -# web server. -# -# * ports.conf is always included from the main configuration file. It is -# supposed to determine listening ports for incoming connections which can be -# customized anytime. -# -# * Configuration files in the mods-enabled/, conf-enabled/ and sites-enabled/ -# directories contain particular configuration snippets which manage modules, -# global configuration fragments, or virtual host configurations, -# respectively. -# -# They are activated by symlinking available configuration files from their -# respective *-available/ counterparts. These should be managed by using our -# helpers a2enmod/a2dismod, a2ensite/a2dissite and a2enconf/a2disconf. See -# their respective man pages for detailed information. -# -# * The binary is called apache2. Due to the use of environment variables, in -# the default configuration, apache2 needs to be started/stopped with -# /etc/init.d/apache2 or apache2ctl. Calling /usr/bin/apache2 directly will not -# work with the default configuration. - - # Global configuration -# - -# -# ServerRoot: The top of the directory tree under which the server's -# configuration, error, and log files are kept. -# -# NOTE! If you intend to place this on an NFS (or otherwise network) -# mounted filesystem then please read the Mutex documentation (available -# at ); -# you will save yourself a lot of trouble. -# -# Do NOT add a slash at the end of the directory path. -# -#ServerRoot "/etc/apache2" - -# -# The accept serialization lock file MUST BE STORED ON A LOCAL DISK. -# -#Mutex file:${APACHE_LOCK_DIR} default - -# -# The directory where shm and other runtime files will be stored. -# - -DefaultRuntimeDir ${APACHE_RUN_DIR} - -# -# PidFile: The file in which the server should record its process -# identification number when it starts. -# This needs to be set in /etc/apache2/envvars -# -PidFile ${APACHE_PID_FILE} - -# -# Timeout: The number of seconds before receives and sends time out. -# +ServerRoot "/etc/httpd" +Listen 80 + +# Load Modules from absolute path /usr/lib/apache2/ +LoadModule mpm_event_module /usr/lib/apache2/mod_mpm_event.so +LoadModule authn_core_module /usr/lib/apache2/mod_authn_core.so +LoadModule authz_core_module /usr/lib/apache2/mod_authz_core.so +LoadModule alias_module /usr/lib/apache2/mod_alias.so +LoadModule dir_module /usr/lib/apache2/mod_dir.so +LoadModule mime_module /usr/lib/apache2/mod_mime.so +LoadModule unixd_module /usr/lib/apache2/mod_unixd.so +LoadModule log_config_module /usr/lib/apache2/mod_log_config.so + +User apache +Group apache + +# Basic Settings +ServerName localhost Timeout 300 - -# -# KeepAlive: Whether or not to allow persistent connections (more than -# one request per connection). Set to "Off" to deactivate. -# KeepAlive On - -# -# MaxKeepAliveRequests: The maximum number of requests to allow -# during a persistent connection. Set to 0 to allow an unlimited amount. -# We recommend you leave this number high, for maximum performance. -# MaxKeepAliveRequests 100 - -# -# KeepAliveTimeout: Number of seconds to wait for the next request from the -# same client on the same connection. -# KeepAliveTimeout 5 - -# These need to be set in /etc/apache2/envvars -User ${APACHE_RUN_USER} -Group ${APACHE_RUN_GROUP} - -# -# HostnameLookups: Log the names of clients or just their IP addresses -# e.g., www.apache.org (on) or 204.62.129.132 (off). -# The default is off because it'd be overall better for the net if people -# had to knowingly turn this feature on, since enabling it means that -# each client request will result in AT LEAST one lookup request to the -# nameserver. -# -HostnameLookups Off - -# ErrorLog: The location of the error log file. -# If you do not specify an ErrorLog directive within a -# container, error messages relating to that virtual host will be -# logged here. If you *do* define an error logfile for a -# container, that host's errors will be logged there and not here. -# -ErrorLog ${APACHE_LOG_DIR}/error.log - -# -# LogLevel: Control the severity of messages logged to the error_log. -# Available values: trace8, ..., trace1, debug, info, notice, warn, -# error, crit, alert, emerg. -# It is also possible to configure the log level for particular modules, e.g. -# "LogLevel info ssl:warn" -# +ErrorLog /var/log/httpd/error_log LogLevel warn -# Include module configuration: -IncludeOptional mods-enabled/*.load -IncludeOptional mods-enabled/*.conf - -# Include list of ports to listen on -Include ports.conf +# Document Root +DocumentRoot "/var/www/html" - -# Sets the default security model of the Apache2 HTTPD server. It does -# not allow access to the root filesystem outside of /usr/share and /var/www. -# The former is used by web applications packaged in Debian, -# the latter may be used for local directories served by the web server. If -# your system is serving content from a sub-directory in /srv you must allow -# access here, or in any related virtual host. - - Options FollowSymLinks - AllowOverride None - Require all denied + + Options FollowSymLinks + AllowOverride None + Require all granted - - AllowOverride None - Require all granted - +# Wiki specific settings +Alias /wiki "/var/www/html/wiki" - - Options FollowSymLinks - AllowOverride None - Require all granted + + Options Indexes FollowSymLinks + AllowOverride None + Require all granted ErrorDocument 404 /wiki/404.html ErrorDocument 403 /wiki/404.html -# -# Options Indexes FollowSymLinks -# AllowOverride None -# Require all granted -# - - - -# AccessFileName: The name of the file to look for in each directory -# for additional configuration directives. See also the AllowOverride -# directive. -# -AccessFileName .htaccess +# Logs +CustomLog /var/log/httpd/access_log combined +LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined -# -# The following lines prevent .htaccess and .htpasswd files from being -# viewed by Web clients. -# +# Defaults - Require all denied + Require all denied - - -# -# The following directives define some format nicknames for use with -# a CustomLog directive. -# -# These deviate from the Common Log Format definitions in that they use %O -# (the actual bytes sent including headers) instead of %b (the size of the -# requested file), because the latter makes it impossible to detect partial -# requests. -# -# Note that the use of %{X-Forwarded-For}i instead of %h is not recommended. -# Use mod_remoteip instead. -# -LogFormat "%v:%p %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined -LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined -LogFormat "%h %l %u %t \"%r\" %>s %O" common -LogFormat "%{Referer}i -> %U" referer -LogFormat "%{User-agent}i" agent - -# Include of directories ignores editors' and dpkg's backup files, -# see README.Debian for details. - -# Include generic snippets of statements -IncludeOptional conf-enabled/*.conf - -# Include the virtual host configurations: -IncludeOptional sites-enabled/*.conf - -# vim: syntax=apache ts=4 sw=4 sts=4 sr noet - diff --git a/renovate.json b/renovate.json index cc58df3..4551509 100644 --- a/renovate.json +++ b/renovate.json @@ -1,37 +1,47 @@ { "extends": [ - "config:base", - ":automergePatch" + "config:recommended", + "helpers:pinGitHubActionDigests" ], "packageRules": [ { - "updateTypes": ["major"], + "matchUpdateTypes": [ + "major" + ], "addLabels": ["major"] }, { - "updateTypes": ["minor"], + "matchUpdateTypes": [ + "minor" + ], "addLabels": ["minor"] }, { - "updateTypes": ["patch"], + "matchUpdateTypes": [ + "patch" + ], "addLabels": ["patch"] }, { - "updateTypes": ["pin"], + "matchUpdateTypes": [ + "pin" + ], "addLabels": ["pin"] } ], "vulnerabilityAlerts": { "labels": ["security"] }, - "baseBranches": ["dev"], + "baseBranchPatterns": [ + "dev" + ], "reviewers": ["team:portal-dev"], "labels": ["dependencies"], "assignees": ["team:portal-dev"], "branchPrefix": "deps/", "bumpVersion": "minor", "rebaseWhen": "behind-base-branch", - "commitBodyTable": "true", + "commitBodyTable": true, "prHourlyLimit": 0, "commitMessagePrefix": "feat(Dependencies):" } diff --git a/requirements.txt b/requirements.txt index 4c69b10..e8daa95 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,6 +3,6 @@ mkdocs-glightbox==0.5.2 mkdocs==1.6.1 mkdocs-htmlproofer-plugin==1.5.0 pygments==2.20.0 -pymdown-extensions==10.21.3 +pymdown-extensions==11.0.0 mkdocs-git-revision-date-localized-plugin==1.5.3 mkdocs-macros-plugin==1.5.0 diff --git a/start.sh b/start.sh index ab42746..3d7d3ba 100755 --- a/start.sh +++ b/start.sh @@ -1,5 +1,5 @@ #!/bin/sh webhook -urlprefix "${WEBHOOK_URL_PREFIX}" -hooks /usr/local/bin/hooks.json -verbose & update.sh -apachectl -d /etc/apache2 -f apache2.conf -DFOREGROUND +httpd -D FOREGROUND -f /etc/httpd/httpd.conf diff --git a/update.sh b/update.sh index 6697edc..363d4fc 100755 --- a/update.sh +++ b/update.sh @@ -1,6 +1,6 @@ #!/bin/sh -BRANCH=${BRANCH:-master} +BRANCH=${BRANCH:-main} ( flock -n 9 || exit 1