baserow: placed directories, the database password from a file, and the build ace runs #170

Merged
mesh-admin merged 1 commits from feat/baserow-for-ace into main 2026-09-30 15:32:14 +00:00
2 changed files with 70 additions and 40 deletions
+55 -24
View File
@@ -2,12 +2,15 @@
// module's tools and anything else baserow-specific import it; nothing outside baserow does. // module's tools and anything else baserow-specific import it; nothing outside baserow does.
// //
// Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/. // Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/.
// Those credentials are the mesh's own: a person signs up in Baserow (the standard image creates no // The standard image creates no admin from env, so the account is one a person made in Baserow: its
// admin from env), and the credential is placed in the runtime config file the mesh mounts. Until // password is the module's `admin` secret, accepted from the operator, and its email and the public
// that happens fromEnv throws and the module simply exposes no tools — the same dormant-until- // host Baserow answers to reach the runtime config file the mesh mounts (the email from the
// configured shape gitea uses for its token. // assignment's settings). Until both are there fromEnv throws and the module exposes no tools — the
// same dormant-until-configured shape gitea uses for its token.
import { readFileSync } from "node:fs"; import { readFileSync } from "node:fs";
import { request as httpRequest } from "node:http";
import { request as httpsRequest } from "node:https";
export interface BaserowApplication { export interface BaserowApplication {
id: number; id: number;
@@ -68,35 +71,63 @@ export class BaserowClient {
return h; return h;
} }
/** Exchange email + password for a JWT, caching it for the client's lifetime. Handles both the /**
* One HTTP exchange. Not `fetch`: Node's fetch drops a caller's Host header and sends the URL's
* own, and Baserow answers only the host of its BASEROW_PUBLIC_URL — any other Host is looked up
* as a published builder site and gets 404, `/api/_health/` included. A co-located caller reaching
* it by container name must present the public host, so the request is made with node:http, which
* sends the Host it is given.
*/
private send(path: string, method: string, headers: Record<string, string>, body?: string): Promise<{ status: number; text: string }> {
const url = new URL(`${this.baseUrl}${path}`);
const request = url.protocol === "https:" ? httpsRequest : httpRequest;
// A length, never chunked: Baserow's server reads a chunked body as empty.
const sent = body === undefined ? headers : { ...headers, "Content-Length": String(Buffer.byteLength(body)) };
return new Promise((resolve, reject) => {
const req = request(url, { method, headers: sent }, (res) => {
let text = "";
res.setEncoding("utf8");
res.on("data", (chunk: string) => (text += chunk));
res.on("end", () => resolve({ status: res.statusCode ?? 0, text }));
res.on("error", reject);
});
req.on("error", reject);
if (body !== undefined) req.write(body);
req.end();
});
}
/** Exchange email + password for a JWT, caching it until Baserow refuses it. Handles both the
* older `{ token }` and the newer `{ access_token }` response shapes. */ * older `{ token }` and the newer `{ access_token }` response shapes. */
async authenticate(): Promise<string> { async authenticate(): Promise<string> {
if (this.token) return this.token; if (this.token) return this.token;
const res = await fetch(`${this.baseUrl}/api/user/token-auth/`, { const res = await this.send(
method: "POST", "/api/user/token-auth/",
headers: this.headers(), "POST",
body: JSON.stringify({ email: this.email, password: this.password }), this.headers(),
}); JSON.stringify({ email: this.email, password: this.password }),
if (!res.ok) throw new Error(`baserow auth failed: ${res.status} ${await res.text()}`); );
const data = (await res.json()) as { token?: string; access_token?: string }; if (res.status < 200 || res.status >= 300) throw new Error(`baserow auth failed: ${res.status} ${res.text}`);
const data = JSON.parse(res.text) as { token?: string; access_token?: string };
const token = data.access_token ?? data.token; const token = data.access_token ?? data.token;
if (!token) throw new Error("baserow auth returned no token"); if (!token) throw new Error("baserow auth returned no token");
this.token = token; this.token = token;
return token; return token;
} }
private async authed<T>(path: string, options: RequestInit = {}): Promise<T> { /** An authenticated GET. A refused token is dropped and the call made once more with a fresh one:
const token = await this.authenticate(); * Baserow's access tokens expire after minutes, and the runtime lives for weeks. */
const res = await fetch(`${this.baseUrl}${path}`, { private async authed<T>(path: string): Promise<T> {
...options, for (let attempt = 0; ; attempt++) {
headers: this.headers({ const token = await this.authenticate();
Authorization: `JWT ${token}`, const res = await this.send(path, "GET", this.headers({ Authorization: `JWT ${token}` }));
...(options.headers as Record<string, string> | undefined), if (res.status === 401 && attempt === 0) {
}), this.token = null;
}); continue;
if (!res.ok) throw new Error(`baserow ${path}: ${res.status} ${await res.text()}`); }
const text = await res.text(); if (res.status < 200 || res.status >= 300) throw new Error(`baserow ${path}: ${res.status} ${res.text}`);
return (text ? JSON.parse(text) : null) as T; return (res.text ? JSON.parse(res.text) : null) as T;
}
} }
/** The applications (databases) the account can see, across all its workspaces. */ /** The applications (databases) the account can see, across all its workspaces. */
+15 -16
View File
@@ -18,14 +18,14 @@
} }
}, },
"binds": { "binds": {
"postgres-database": "/var/lib/baserow/database.json", "postgres-database": "${dir:state}/database.json",
"route": "/var/lib/baserow/route.json" "route": "${dir:state}/route.json"
}, },
"secrets": { "secrets": {
"postgres-database": "/var/lib/baserow/database.secret" "postgres-database": "${dir:state}/database.secret"
}, },
"own-secrets": { "own-secrets": {
"secret-key": "/var/lib/baserow/secret-key.secret", "admin": "${dir:state}/admin.secret",
"broker": "/var/lib/mesh/baserow/broker" "broker": "/var/lib/mesh/baserow/broker"
}, },
"listens": [ "listens": [
@@ -34,7 +34,7 @@
"port": 80, "port": 80,
"protocol": "tcp", "protocol": "tcp",
"from": "mesh", "from": "mesh",
"why": "the Baserow web UI and REST API; a public name is a route grant later" "why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's"
} }
], ],
"resources": [ "resources": [
@@ -47,22 +47,21 @@
{ {
"id": "state", "id": "state",
"type": "directory", "type": "directory",
"path": "/var/lib/baserow", "mode": "0700",
"mode": "0700" "place": "."
}, },
{ {
"id": "data", "id": "data",
"type": "directory", "type": "directory",
"path": "/services/baserow/data",
"mode": "0755", "mode": "0755",
"owner": "9999:9999" "owner": "9999:9999"
}, },
{ {
"id": "server-env", "id": "server-env",
"type": "file", "type": "file",
"path": "/var/lib/baserow/server.env", "path": "${dir:state}/server.env",
"mode": "0600", "mode": "0600",
"content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n" "content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n"
}, },
{ {
"id": "net", "id": "net",
@@ -73,25 +72,25 @@
"id": "server", "id": "server",
"type": "container", "type": "container",
"name": "baserow", "name": "baserow",
"image": "baserow/baserow@sha256:834424a10413798567f76428f255dc259445b7f8dcec56598c05b4073bb2a124", "image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080",
"network": "baserow", "network": "baserow",
"env-file": [ "env-file": [
"/var/lib/baserow/server.env" "${dir:state}/server.env"
], ],
"ports": [ "ports": [
"80" "80"
], ],
"volumes": [ "volumes": [
"/services/baserow/data:/baserow/data" "${dir:data}:/baserow/data",
], "${dir:state}/database.secret:/run/secrets/database:ro"
"secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible" ]
}, },
{ {
"id": "runtime-config", "id": "runtime-config",
"type": "file", "type": "file",
"path": "/var/lib/mesh/baserow/config.json", "path": "/var/lib/mesh/baserow/config.json",
"mode": "0600", "mode": "0600",
"content": "{}\n", "content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n",
"merge": "json" "merge": "json"
}, },
{ {