#!/bin/sh # Trusts the pasture's CA, writes the config on first start, migrates, and runs Pleroma in the foreground. set -e cp /pasture/ca/root.crt /usr/local/share/ca-certificates/pasture.crt && update-ca-certificates >/dev/null # Mint and Gun read the bundles shipped in the release (CAStore, certifi), never the system's for bundle in /opt/pleroma/lib/castore-*/priv/cacerts.pem /opt/pleroma/lib/certifi-*/priv/cacerts.pem; do [ -f "$bundle" ] || continue grep -q "pasture" "$bundle" || { echo "# pasture"; cat /pasture/ca/root.crt; } >> "$bundle" done if [ ! -f /etc/pleroma/config.exs ]; then # pleroma_ctl passes its arguments on unquoted, so no value may contain a space env -u PLEROMA_CONFIG_PATH /opt/pleroma/bin/pleroma_ctl instance gen --force --output /etc/pleroma/config.exs --output-psql /tmp/setup.psql \ --domain pleroma.test --instance-name PasturePleroma --admin-email admin@pleroma.test --notify-email admin@pleroma.test \ --dbhost postgres --dbname pleroma --dbuser pasture --dbpass pasture --rum N --indexable N --db-configurable N \ --uploads-dir /var/lib/pleroma/uploads --static-dir /var/lib/pleroma/static --listen-ip 0.0.0.0 --listen-port 4000 \ --strip-uploads-location N --read-uploads-description Y --anonymize-uploads N --dedupe-uploads N \ > /etc/pleroma/config.exs <<'EOF' # pasture: system CA bundle config :pleroma, :http, adapter: [ssl_options: [cacertfile: "/etc/ssl/certs/ca-certificates.crt"]] EOF /opt/pleroma/bin/pleroma_ctl migrate exec /opt/pleroma/bin/pleroma start