route-proxy: the trust gate retries with a timeout and checks for a certificate; its images are declared artifacts (ADRs 0096, 0097, 0098)
This commit is contained in:
@@ -74,7 +74,6 @@
|
|||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "route-proxy-trust",
|
"name": "route-proxy-trust",
|
||||||
"run-once": true,
|
"run-once": true,
|
||||||
"image": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b",
|
|
||||||
"network": "host",
|
"network": "host",
|
||||||
"env-file": [
|
"env-file": [
|
||||||
"/var/lib/route-proxy/acme.env"
|
"/var/lib/route-proxy/acme.env"
|
||||||
@@ -85,7 +84,7 @@
|
|||||||
"args": [
|
"args": [
|
||||||
"sh",
|
"sh",
|
||||||
"-c",
|
"-c",
|
||||||
"wget -q --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && test -s /ca/root.crt"
|
"for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -112,6 +111,18 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"build": {
|
"build": {
|
||||||
|
"artifacts": [
|
||||||
|
{
|
||||||
|
"name": "server",
|
||||||
|
"kind": "image",
|
||||||
|
"from": "Dockerfile"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "trust",
|
||||||
|
"kind": "upstream",
|
||||||
|
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b"
|
||||||
|
}
|
||||||
|
],
|
||||||
"on": [
|
"on": [
|
||||||
{
|
{
|
||||||
"arg": "GO_BASE",
|
"arg": "GO_BASE",
|
||||||
|
|||||||
Reference in New Issue
Block a user