# Mbin 1.10.1: the threadiverse in Symfony (magazines, threads, comments, microblog posts, votes up and down), from its # own image: FrankenPHP serving plain HTTP behind Caddy, and a messenger worker for its queues, on the shared Postgres # (database mbin) and Redis (db 12), with a RabbitMQ of its own (its transports carry AMQP options). Symfony's HTTP # client trusts the system bundle, so the pasture's is mounted over it. Its admin is mbuser, made by its console; its # API takes an OAuth2 token, which mbin_settle gets through the authorization-code flow as mbuser (a client-credentials # client acts as a bot, which may not vote). MBIN_IMAGE=${MBIN_IMAGE:-ghcr.io/mbinorg/mbin:v1.10.1} MBIN_RABBITMQ_IMAGE=${MBIN_RABBITMQ_IMAGE:-docker.io/library/rabbitmq:4-alpine} MBIN_PASSWORD=Mbin-Pasture-Pass-1 . "$here/peers/shared.sh" mbin_env() { local dir="$here/.state/mbin" [ -s "$dir/secret" ] || head -c 32 /dev/urandom | od -An -tx1 | tr -d ' \n' > "$dir/secret" [ -s "$dir/mercure" ] || head -c 32 /dev/urandom | od -An -tx1 | tr -d ' \n' > "$dir/mercure" [ -s "$dir/oauth-key" ] || head -c 16 /dev/urandom | od -An -tx1 | tr -d ' \n' > "$dir/oauth-key" cat </dev/null openssl rsa -in "$here/.state/mbin/oauth2/private.pem" -passin "pass:$MBIN_PASSWORD" -pubout -out "$here/.state/mbin/oauth2/public.pem" 2>/dev/null chmod 644 "$here/.state/mbin/oauth2/"*.pem fi mbin_env > "$here/.state/mbin/env" # its API's own limits (two threads every six minutes) would throttle a scripted run: the same file, every limit raised podman run --rm --entrypoint cat "$MBIN_IMAGE" config/packages/rate_limiter.yaml \ | sed -E 's/^( +limit:) [0-9]+$/\1 100000/' > "$here/.state/mbin/rate_limiter.yaml" # (as its own user on a volume it owns: started as root, it writes an .erlang.cookie it then cannot read) podman volume exists pasture-mbin-rabbitmq || podman volume create --label pasture=1 pasture-mbin-rabbitmq >/dev/null podman run -d --replace --name pasture-mbin-rabbitmq --network $net --label pasture=1 --user rabbitmq -v pasture-mbin-rabbitmq:/var/lib/rabbitmq:U \ "$MBIN_RABBITMQ_IMAGE" >/dev/null for _ in $(seq 1 60); do podman exec pasture-mbin-rabbitmq rabbitmq-diagnostics -q ping >/dev/null 2>&1 && break; sleep 2; done podman volume exists pasture-mbin-media || podman volume create --label pasture=1 pasture-mbin-media >/dev/null local common=(--network $net --label pasture=1 --env-file "$here/.state/mbin/env" -v pasture-mbin-media:/app/public/media -v "$here/.state/mbin/oauth2:/oauth2:z,ro" -v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" -v "$here/.state/mbin/rate_limiter.yaml:/app/config/packages/rate_limiter.yaml:z,ro") podman run -d --replace --name pasture-mbin "${common[@]}" "$MBIN_IMAGE" >/dev/null # the web container runs the migrations as it starts; the worker waits for them for _ in $(seq 1 120); do podman logs pasture-mbin 2>&1 | grep -q "PHP app ready" && break sleep 2 done podman run -d --replace --name pasture-mbin-worker "${common[@]}" "$MBIN_IMAGE" \ php bin/console messenger:consume scheduler_default old async outbox deliver inbox resolve receive failed --time-limit=86400 >/dev/null for _ in $(seq 1 60); do site mbin.test -s -o /dev/null -w '%{http_code}' https://mbin.test:6443/api/instance 2>/dev/null | grep -q 200 && break sleep 2 done mbin_settle echo "mbin: https://mbin.test:6443" } mbin_console() { podman exec pasture-mbin php bin/console "$@"; } # mbuser (admin, verified), the instance's keys, and mbuser's OAuth token from the authorization-code flow mbin_settle() { mbin_console mbin:ap:keys:update >/dev/null 2>&1 || true mbin_console mbin:user:create mbuser mbuser@mbin.test "$MBIN_PASSWORD" >/dev/null 2>&1 || true mbin_console mbin:user:admin mbuser >/dev/null 2>&1 || true mbin_console mbin:user:verify mbuser >/dev/null 2>&1 || true python3 "$here/peers/mbin_token.py" "$MBIN_PASSWORD" "$here/.state/mbin/client.json" > "$here/.state/mbin.token" 2>"$here/.state/mbin/token.log" || true }