Previously, database migrations and seeding had to be run manually after deployment, causing 500 errors on fresh deployments. This commit automates the entire database setup process. Changes to docker-entrypoint.sh: - Wait for PostgreSQL to be ready before proceeding - Run 'flask db upgrade' automatically on startup - Check if database is already seeded (admin user exists) - Run 'flask seed' only if needed (idempotent) - Provides clear console output for each step Changes to docker-compose.prod.yml: - Bind to 0.0.0.0:5000 instead of 127.0.0.1:5000 - Allows access from reverse proxy on different machines - Necessary for production deployments with external proxies Benefits: - Zero manual intervention required after 'docker-compose up' - Idempotent: Safe to restart containers without data loss - Works on fresh clones and existing deployments - Clear logging for troubleshooting Fixes: - "relation users does not exist" error on login - Manual migration/seeding requirement - Network accessibility from external proxies 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
78 lines
2.0 KiB
Bash
Executable File
78 lines
2.0 KiB
Bash
Executable File
#!/bin/bash
|
|
# Docker entrypoint script for OIDC Identity Provider
|
|
# Generates JWT keys if they don't exist and starts the application
|
|
|
|
set -e
|
|
|
|
echo "========================================"
|
|
echo "OIDC IdP - Container Initialization"
|
|
echo "========================================"
|
|
|
|
# Create instance directory if it doesn't exist
|
|
mkdir -p /app/instance
|
|
|
|
# Generate JWT keys if they don't exist
|
|
if [ ! -f /app/instance/jwt_private.pem ]; then
|
|
echo "Generating JWT RSA key pair..."
|
|
|
|
# Generate private key (2048-bit RSA)
|
|
openssl genrsa -out /app/instance/jwt_private.pem 2048
|
|
|
|
# Extract public key from private key
|
|
openssl rsa -in /app/instance/jwt_private.pem -pubout -out /app/instance/jwt_public.pem
|
|
|
|
# Set proper permissions
|
|
chmod 600 /app/instance/jwt_private.pem
|
|
chmod 644 /app/instance/jwt_public.pem
|
|
|
|
echo "✓ JWT keys generated successfully"
|
|
else
|
|
echo "✓ JWT keys already exist"
|
|
fi
|
|
|
|
echo ""
|
|
echo "Database Initialization..."
|
|
echo "========================================"
|
|
|
|
# Wait for PostgreSQL to be ready
|
|
echo "Waiting for PostgreSQL..."
|
|
for i in {1..30}; do
|
|
if python3 -c "import psycopg2; psycopg2.connect('$DATABASE_URL')" 2>/dev/null; then
|
|
echo "✓ PostgreSQL is ready"
|
|
break
|
|
fi
|
|
if [ $i -eq 30 ]; then
|
|
echo "✗ PostgreSQL connection timeout"
|
|
exit 1
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
# Run database migrations
|
|
echo "Running database migrations..."
|
|
export FLASK_APP=oidc_server.py
|
|
flask db upgrade
|
|
|
|
# Check if database needs seeding (check if admin user exists)
|
|
if ! python3 -c "
|
|
from oidc_server import app, db
|
|
from models import User
|
|
with app.app_context():
|
|
admin = User.query.filter_by(username='admin').first()
|
|
exit(0 if admin else 1)
|
|
" 2>/dev/null; then
|
|
echo "Seeding database with initial data..."
|
|
flask seed
|
|
echo "✓ Database seeded successfully"
|
|
else
|
|
echo "✓ Database already seeded"
|
|
fi
|
|
|
|
echo ""
|
|
echo "Starting OIDC server..."
|
|
echo "========================================"
|
|
echo ""
|
|
|
|
# Execute the CMD from Dockerfile (Gunicorn)
|
|
exec "$@"
|