Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
37c212d5b4 |
+24
-55
@@ -2,15 +2,12 @@
|
||||
// module's tools and anything else baserow-specific import it; nothing outside baserow does.
|
||||
//
|
||||
// Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/.
|
||||
// The standard image creates no admin from env, so the account is one a person made in Baserow: its
|
||||
// password is the module's `admin` secret, accepted from the operator, and its email and the public
|
||||
// host Baserow answers to reach the runtime config file the mesh mounts (the email from the
|
||||
// assignment's settings). Until both are there fromEnv throws and the module exposes no tools — the
|
||||
// same dormant-until-configured shape gitea uses for its token.
|
||||
// Those credentials are the mesh's own: a person signs up in Baserow (the standard image creates no
|
||||
// admin from env), and the credential is placed in the runtime config file the mesh mounts. Until
|
||||
// that happens fromEnv throws and the module simply exposes no tools — the same dormant-until-
|
||||
// configured shape gitea uses for its token.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
import { request as httpRequest } from "node:http";
|
||||
import { request as httpsRequest } from "node:https";
|
||||
|
||||
export interface BaserowApplication {
|
||||
id: number;
|
||||
@@ -71,63 +68,35 @@ export class BaserowClient {
|
||||
return h;
|
||||
}
|
||||
|
||||
/**
|
||||
* One HTTP exchange. Not `fetch`: Node's fetch drops a caller's Host header and sends the URL's
|
||||
* own, and Baserow answers only the host of its BASEROW_PUBLIC_URL — any other Host is looked up
|
||||
* as a published builder site and gets 404, `/api/_health/` included. A co-located caller reaching
|
||||
* it by container name must present the public host, so the request is made with node:http, which
|
||||
* sends the Host it is given.
|
||||
*/
|
||||
private send(path: string, method: string, headers: Record<string, string>, body?: string): Promise<{ status: number; text: string }> {
|
||||
const url = new URL(`${this.baseUrl}${path}`);
|
||||
const request = url.protocol === "https:" ? httpsRequest : httpRequest;
|
||||
// A length, never chunked: Baserow's server reads a chunked body as empty.
|
||||
const sent = body === undefined ? headers : { ...headers, "Content-Length": String(Buffer.byteLength(body)) };
|
||||
return new Promise((resolve, reject) => {
|
||||
const req = request(url, { method, headers: sent }, (res) => {
|
||||
let text = "";
|
||||
res.setEncoding("utf8");
|
||||
res.on("data", (chunk: string) => (text += chunk));
|
||||
res.on("end", () => resolve({ status: res.statusCode ?? 0, text }));
|
||||
res.on("error", reject);
|
||||
});
|
||||
req.on("error", reject);
|
||||
if (body !== undefined) req.write(body);
|
||||
req.end();
|
||||
});
|
||||
}
|
||||
|
||||
/** Exchange email + password for a JWT, caching it until Baserow refuses it. Handles both the
|
||||
/** Exchange email + password for a JWT, caching it for the client's lifetime. Handles both the
|
||||
* older `{ token }` and the newer `{ access_token }` response shapes. */
|
||||
async authenticate(): Promise<string> {
|
||||
if (this.token) return this.token;
|
||||
const res = await this.send(
|
||||
"/api/user/token-auth/",
|
||||
"POST",
|
||||
this.headers(),
|
||||
JSON.stringify({ email: this.email, password: this.password }),
|
||||
);
|
||||
if (res.status < 200 || res.status >= 300) throw new Error(`baserow auth failed: ${res.status} ${res.text}`);
|
||||
const data = JSON.parse(res.text) as { token?: string; access_token?: string };
|
||||
const res = await fetch(`${this.baseUrl}/api/user/token-auth/`, {
|
||||
method: "POST",
|
||||
headers: this.headers(),
|
||||
body: JSON.stringify({ email: this.email, password: this.password }),
|
||||
});
|
||||
if (!res.ok) throw new Error(`baserow auth failed: ${res.status} ${await res.text()}`);
|
||||
const data = (await res.json()) as { token?: string; access_token?: string };
|
||||
const token = data.access_token ?? data.token;
|
||||
if (!token) throw new Error("baserow auth returned no token");
|
||||
this.token = token;
|
||||
return token;
|
||||
}
|
||||
|
||||
/** An authenticated GET. A refused token is dropped and the call made once more with a fresh one:
|
||||
* Baserow's access tokens expire after minutes, and the runtime lives for weeks. */
|
||||
private async authed<T>(path: string): Promise<T> {
|
||||
for (let attempt = 0; ; attempt++) {
|
||||
const token = await this.authenticate();
|
||||
const res = await this.send(path, "GET", this.headers({ Authorization: `JWT ${token}` }));
|
||||
if (res.status === 401 && attempt === 0) {
|
||||
this.token = null;
|
||||
continue;
|
||||
}
|
||||
if (res.status < 200 || res.status >= 300) throw new Error(`baserow ${path}: ${res.status} ${res.text}`);
|
||||
return (res.text ? JSON.parse(res.text) : null) as T;
|
||||
}
|
||||
private async authed<T>(path: string, options: RequestInit = {}): Promise<T> {
|
||||
const token = await this.authenticate();
|
||||
const res = await fetch(`${this.baseUrl}${path}`, {
|
||||
...options,
|
||||
headers: this.headers({
|
||||
Authorization: `JWT ${token}`,
|
||||
...(options.headers as Record<string, string> | undefined),
|
||||
}),
|
||||
});
|
||||
if (!res.ok) throw new Error(`baserow ${path}: ${res.status} ${await res.text()}`);
|
||||
const text = await res.text();
|
||||
return (text ? JSON.parse(text) : null) as T;
|
||||
}
|
||||
|
||||
/** The applications (databases) the account can see, across all its workspaces. */
|
||||
|
||||
+16
-15
@@ -18,14 +18,14 @@
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"postgres-database": "${dir:state}/database.json",
|
||||
"route": "${dir:state}/route.json"
|
||||
"postgres-database": "/var/lib/baserow/database.json",
|
||||
"route": "/var/lib/baserow/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"postgres-database": "${dir:state}/database.secret"
|
||||
"postgres-database": "/var/lib/baserow/database.secret"
|
||||
},
|
||||
"own-secrets": {
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"secret-key": "/var/lib/baserow/secret-key.secret",
|
||||
"broker": "/var/lib/mesh/baserow/broker"
|
||||
},
|
||||
"listens": [
|
||||
@@ -34,7 +34,7 @@
|
||||
"port": 80,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's"
|
||||
"why": "the Baserow web UI and REST API; a public name is a route grant later"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -47,21 +47,22 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/baserow",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/baserow/data",
|
||||
"mode": "0755",
|
||||
"owner": "9999:9999"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"path": "/var/lib/baserow/server.env",
|
||||
"mode": "0600",
|
||||
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n"
|
||||
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
@@ -72,25 +73,25 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "baserow",
|
||||
"image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080",
|
||||
"image": "baserow/baserow@sha256:834424a10413798567f76428f255dc259445b7f8dcec56598c05b4073bb2a124",
|
||||
"network": "baserow",
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
"/var/lib/baserow/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"80"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:data}:/baserow/data",
|
||||
"${dir:state}/database.secret:/run/secrets/database:ro"
|
||||
]
|
||||
"/services/baserow/data:/baserow/data"
|
||||
],
|
||||
"secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/baserow/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n",
|
||||
"content": "{}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
|
||||
+41
-21
@@ -10,35 +10,35 @@
|
||||
"port": 8443,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
|
||||
"why": "the controller web UI and API, over its own self-signed tls; named through the proxy as an https route"
|
||||
},
|
||||
{
|
||||
"name": "inform",
|
||||
"port": 8080,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "device inform \u2014 how APs and switches check in and are adopted"
|
||||
"why": "device inform, how APs and switches check in and are adopted; the controller tells devices this number, so the machine must publish it on the same one"
|
||||
},
|
||||
{
|
||||
"name": "stun",
|
||||
"port": 3478,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "STUN, so managed devices can find the controller through NAT"
|
||||
"why": "STUN for managed devices; the controller tells devices this number, so the machine must publish it on the same one"
|
||||
},
|
||||
{
|
||||
"name": "discovery",
|
||||
"port": 10001,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
|
||||
"why": "device discovery broadcasts from unadopted devices and the UniFi apps"
|
||||
},
|
||||
{
|
||||
"name": "discovery-l2",
|
||||
"port": 1902,
|
||||
"port": 1900,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
|
||||
"why": "make-controller-discoverable-on-L2 (SSDP); the software listens on 1900, which machines commonly have taken by another SSDP speaker"
|
||||
},
|
||||
{
|
||||
"name": "portal-tls",
|
||||
@@ -76,10 +76,15 @@
|
||||
"path": "/var/lib/mesh/unifi",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/unifi/data",
|
||||
"mode": "0700",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
@@ -87,17 +92,17 @@
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "unifi-controller",
|
||||
"image": "lscr.io/linuxserver/unifi-controller@sha256:fcd5d8b13a77a588c79c1b49e5fc9ad08115aa3bb1a3576c589c64908a68845f",
|
||||
"image": "lscr.io/linuxserver/unifi-controller@sha256:0ae315a3a45635e443899e30e86bd507c2c48922cb27f4bc7241777885f4650e",
|
||||
"ports": [
|
||||
"8443:8443",
|
||||
"8080:8080",
|
||||
"3478:3478/udp",
|
||||
"10001:10001/udp",
|
||||
"1902:1900/udp",
|
||||
"8843:8843",
|
||||
"8880:8880",
|
||||
"6789:6789",
|
||||
"5514:5514/udp"
|
||||
"8443",
|
||||
"8080",
|
||||
"3478/udp",
|
||||
"10001/udp",
|
||||
"1900/udp",
|
||||
"8843",
|
||||
"8880",
|
||||
"6789",
|
||||
"5514/udp"
|
||||
],
|
||||
"env": {
|
||||
"PUID": "1000",
|
||||
@@ -107,7 +112,7 @@
|
||||
"MEM_STARTUP": "1024"
|
||||
},
|
||||
"volumes": [
|
||||
"/services/unifi/data:/config"
|
||||
"${dir:data}:/config"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -115,7 +120,7 @@
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/unifi/config.json",
|
||||
"mode": "0600",
|
||||
"content": "{}\n",
|
||||
"content": "{\n \"site\": \"default\",\n \"password\": \"${secret:controller}\"\n}\n",
|
||||
"merge": "json"
|
||||
},
|
||||
{
|
||||
@@ -129,7 +134,7 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_UNIFI_URL": "https://127.0.0.1:8443",
|
||||
"MESH_UNIFI_URL": "https://127.0.0.1:${port:8443}",
|
||||
"MESH_UNIFI_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
@@ -138,8 +143,23 @@
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "unifi",
|
||||
"endpoint": "web",
|
||||
"scheme": "https",
|
||||
"insecure": true
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/unifi/broker"
|
||||
"broker": "/var/lib/mesh/unifi/broker",
|
||||
"controller": "/var/lib/mesh/unifi/controller"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
|
||||
Reference in New Issue
Block a user