Fix Docker deployment: Auto-generate JWT keys on startup

Previously, the Dockerfile tried to copy the instance/ directory which is
gitignored and doesn't exist in fresh clones. This caused deployment to fail
with "instance/: not found" error.

Changes:
- Add docker-entrypoint.sh script to auto-generate JWT keys if missing
- Install openssl in container for key generation
- Remove COPY instance/ from Dockerfile (no longer needed)
- Create instance/ directory during build
- Set ENTRYPOINT to run initialization script before starting Gunicorn

This allows the application to deploy successfully on fresh clones without
requiring manual JWT key generation.

Fixes deployment issue on production servers.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2025-11-30 12:59:18 +01:00
parent b5e642aecb
commit 73ad5ca34f
2 changed files with 50 additions and 4 deletions

View File

@ -1,10 +1,11 @@
# Multi-stage Build für OIDC Identity Provider
FROM python:3.10-slim as base
# System dependencies
# System dependencies (including openssl for JWT key generation)
RUN apt-get update && apt-get install -y \
gcc \
postgresql-client \
openssl \
&& rm -rf /var/lib/apt/lists/*
# Working directory
@ -30,12 +31,15 @@ COPY templates/ templates/
# Copy migrations directory for database schema management
COPY migrations/ migrations/
# Copy instance directory with JWT keys
COPY instance/ instance/
# Copy static directory with CSS files
COPY static/ static/
# Copy entrypoint script for initialization
COPY docker-entrypoint.sh /app/docker-entrypoint.sh
# Make entrypoint script executable and create instance directory
RUN chmod +x /app/docker-entrypoint.sh && mkdir -p /app/instance
# Create non-root user and set permissions
RUN useradd -m -u 1000 oidc && chown -R oidc:oidc /app
USER oidc
@ -47,5 +51,8 @@ EXPOSE 5000
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
CMD python -c "import requests; requests.get('http://localhost:5000/health')" || exit 1
# Set entrypoint script to handle initialization
ENTRYPOINT ["/app/docker-entrypoint.sh"]
# Start with Gunicorn (production WSGI server)
CMD ["gunicorn", "--bind", "0.0.0.0:5000", "--workers", "4", "--threads", "2", "--timeout", "60", "oidc_server:app"]

39
docker-entrypoint.sh Executable file
View File

@ -0,0 +1,39 @@
#!/bin/bash
# Docker entrypoint script for OIDC Identity Provider
# Generates JWT keys if they don't exist and starts the application
set -e
echo "========================================"
echo "OIDC IdP - Container Initialization"
echo "========================================"
# Create instance directory if it doesn't exist
mkdir -p /app/instance
# Generate JWT keys if they don't exist
if [ ! -f /app/instance/jwt_private.pem ]; then
echo "Generating JWT RSA key pair..."
# Generate private key (2048-bit RSA)
openssl genrsa -out /app/instance/jwt_private.pem 2048
# Extract public key from private key
openssl rsa -in /app/instance/jwt_private.pem -pubout -out /app/instance/jwt_public.pem
# Set proper permissions
chmod 600 /app/instance/jwt_private.pem
chmod 644 /app/instance/jwt_public.pem
echo "✓ JWT keys generated successfully"
else
echo "✓ JWT keys already exist"
fi
echo ""
echo "Starting OIDC server..."
echo "========================================"
echo ""
# Execute the CMD from Dockerfile (Gunicorn)
exec "$@"