Repository navigation
feat(console): run the demo in a container with one command - #218
Merged
Merged
Conversation
A demo on a non-loopback address no longer needs a publish credential: its data is generated and in memory, and with no credential every publish is refused, so it is read only. --public-read is still required. TUFF_CONSOLE_DATA sets the data folder when --data is not given. The image sets it to /data instead of passing --data, so docker run <image> --demo works and docker exec <container> tuff console key list needs no --data. The volume stays at /data.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
docker run --rm -p 127.0.0.1:7474:7474 ghcr.io/kannandreams/tuff-console --demonow starts the demo. Two changes make that work:check_bindskips the credential check when--demois set. The server already requires a credential for every publish on a non-loopback address, so with none configured everyPOST /api/v1/reportsgets401and the demo is read only.--public-readis still required.TUFF_CONSOLE_DATAsets the data folder when--datais not given, forserveand thekeycommands. It is read in code rather than by clap, so it does not trip the--demo/--dataconflict. The Dockerfile setsTUFF_CONSOLE_DATA=/dataand drops--data /datafrom the entry point. The volume path is unchanged.Also: the release smoke test now runs the image as
tuff-console:test --demoand checks that a publish gets401. The Console page, the self-hosting guide, and the changelog are updated; the guide keeps the long form for the 0.15.0 image.Testing
console_demo.rs: public demo starts with no credential and refuses publishing, still needs--public-read,TUFF_CONSOLE_DATAdoes not conflict with--demo, andkey create/listuse it.docker run <image> --demoserves,/healthzok, publish → 401; guide flow (key createwithout--data, start with--trust,docker exec ... key list); a volume created by the published 0.15.0 image is read by the new image.mise run checkpasses.