mirror of
https://github.com/migatu/conjurer.git
synced 2026-07-21 09:12:09 +00:00
33ec1c0e35
The Python half of the short-lived share links lived in the repo; the Apache config and the cron entries that make it work were hand-placed on the host, so the feature could not be rebuilt from a checkout. This adds the missing half. Scripts (defaults unchanged, so existing bare-metal cron keeps working): * scan_shares.py / revoke_shares.py take their paths from CONJURER_SHARE_* instead of hardcoding the Pi layout, and create their parent dirs; * the revoke TTL is now CONJURER_SHARE_TTL_SECONDS. Its --help claimed "2min" while the code used a hardcoded 3600 - the help text now reports the real, configured value. New share service: * docker/Dockerfile.share - Apache + the two jobs, reusing the same scripts rather than forking copies; * docker/share-vhost.conf.tpl - the previously undocumented Apache half. Three settings are load-bearing and commented as such: +FollowSymLinks (the shares ARE symlinks), -Indexes (a listing would expose every live token), and a deny rule for dotfiles (revoke_shares.py keeps .downloads.json - a map of every live token - inside the served directory); * docker/entrypoint.share.sh - renders the vhost, seeds the index on first run, then runs scanner/revoker in sleep loops beside Apache (no cron, so their output shows up in docker logs); * compose + env example, incl. the two volumes that MUST be shared with the musician (it creates the links and reads the index). docs/deployment/FILE_SHARING.md documents the mechanism, both deployment routes (docker and existing host Apache), the Discord command, why each Apache setting matters, verification commands, and the known limitations - notably that a link nobody ever downloads is never revoked, since the TTL starts at first download. Verified: scanner and revoker exercised end-to-end against temp dirs (index built; token recorded from a combined-format log line and the symlink unlinked). Compose file not validated - no docker on this machine. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
44 lines
1.8 KiB
YAML
44 lines
1.8 KiB
YAML
# Share VM/host: Apache publishing short-lived file links + the scan/revoke jobs.
|
|
# Run from the repository root:
|
|
# cp docker/env/share.env.example docker/env/share.env # then edit
|
|
# docker compose -f docker/compose.share.yaml up -d --build
|
|
#
|
|
# IMPORTANT - this service shares two paths with the musician, which is the
|
|
# process that actually creates the links:
|
|
#
|
|
# /srv/share/links -> the symlinks (musician writes, Apache reads)
|
|
# /srv/share/db -> share_scan.json (this service writes, musician reads)
|
|
#
|
|
# So the musician must mount the same two host paths (see the CONJURER_SHARE_*
|
|
# block in docker/env/musician.env.example). If the musician runs on a different
|
|
# machine, put both on shared storage - otherwise it will happily create links
|
|
# that this container cannot see.
|
|
#
|
|
# The media library must be mounted here at the SAME absolute path that the
|
|
# index recorded, because the symlink targets are absolute. Default: /mnt/shares.
|
|
services:
|
|
conjurer-share:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/Dockerfile.share
|
|
image: conjurer-share:latest
|
|
container_name: conjurer-share
|
|
restart: unless-stopped
|
|
env_file:
|
|
- env/share.env
|
|
ports:
|
|
# Plain HTTP. Terminate TLS for czernobog.pl on your existing reverse
|
|
# proxy and forward /share here.
|
|
- "8081:80"
|
|
volumes:
|
|
# Media library the links point at. Read-only: this service only ever
|
|
# serves these files, it never writes them.
|
|
- /srv/share/media:/mnt/shares:ro
|
|
# The published symlinks - shared with the musician.
|
|
- /srv/share/links:/var/www/html/share
|
|
# The search index - shared with the musician.
|
|
- /srv/share/db:/srv/share/db
|
|
# Access log the revoker tails; kept on the host so link history survives
|
|
# a container rebuild.
|
|
- /srv/share/logs:/var/log/apache2
|