Skip to content

feat(console): run the demo in a container with one command - #218

Merged
kannandreams merged 1 commit into
mainfrom
feat/console-demo-in-container
Oct 2, 2026
Merged

kannandreams merged 1 commit into
mainfrom
feat/console-demo-in-container

Conversation

@kannandreams

Copy link
Copy Markdown
Owner

docker run --rm -p 127.0.0.1:7474:7474 ghcr.io/kannandreams/tuff-console --demo now starts the demo. Two changes make that work:

  • A demo needs no publish credential on a non-loopback address. check_bind skips the credential check when --demo is set. The server already requires a credential for every publish on a non-loopback address, so with none configured every POST /api/v1/reports gets 401 and the demo is read only. --public-read is still required.
  • TUFF_CONSOLE_DATA sets the data folder when --data is not given, for serve and the key commands. It is read in code rather than by clap, so it does not trip the --demo/--data conflict. The Dockerfile sets TUFF_CONSOLE_DATA=/data and drops --data /data from the entry point. The volume path is unchanged.

Also: the release smoke test now runs the image as tuff-console:test --demo and checks that a publish gets 401. The Console page, the self-hosting guide, and the changelog are updated; the guide keeps the long form for the 0.15.0 image.

Testing

  • Unit test for the demo bind rule; integration tests in console_demo.rs: public demo starts with no credential and refuses publishing, still needs --public-read, TUFF_CONSOLE_DATA does not conflict with --demo, and key create/list use it.
  • Built the arm64 image from this branch: docker run <image> --demo serves, /healthz ok, publish → 401; guide flow (key create without --data, start with --trust, docker exec ... key list); a volume created by the published 0.15.0 image is read by the new image.
  • mise run check passes.

A demo on a non-loopback address no longer needs a publish credential: its data is generated and in memory, and with no credential every publish is refused, so it is read only. --public-read is still required.

TUFF_CONSOLE_DATA sets the data folder when --data is not given. The image sets it to /data instead of passing --data, so docker run <image> --demo works and docker exec <container> tuff console key list needs no --data. The volume stays at /data.
@kannandreams
kannandreams merged commit f7f02c4 into main Oct 2, 2026
2 checks passed
@kannandreams
kannandreams deleted the feat/console-demo-in-container branch October 2, 2026 22:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant