ops: add ZSpace NAS deployment
CI / config (push) Canceled after 0s
CI / test-frontend (push) Canceled after 0s
CI / test-rust (push) Canceled after 0s
CI / test-e2e (push) Canceled after 0s
CI / test-e2e-release (push) Canceled after 0s
CI / build (push) Canceled after 0s
CI / release (push) Canceled after 0s
CI / docker (push) Canceled after 0s
CI / docker-website (push) Canceled after 0s
CI / config (push) Canceled after 0s
CI / test-frontend (push) Canceled after 0s
CI / test-rust (push) Canceled after 0s
CI / test-e2e (push) Canceled after 0s
CI / test-e2e-release (push) Canceled after 0s
CI / build (push) Canceled after 0s
CI / release (push) Canceled after 0s
CI / docker (push) Canceled after 0s
CI / docker-website (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
# Build the customized Plainleaf client and Rust server for an amd64 NAS.
|
||||
FROM node:24.13.0-bookworm-slim AS client-builder
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates git \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
WORKDIR /src
|
||||
COPY . .
|
||||
|
||||
ARG GITHUB_SHA=unknown
|
||||
RUN npm ci \
|
||||
&& npm run build
|
||||
|
||||
FROM rust:bookworm AS server-builder
|
||||
|
||||
WORKDIR /src
|
||||
COPY --from=client-builder /src /src
|
||||
|
||||
RUN cargo build --locked --release -p silverbullet \
|
||||
&& strip target/release/silverbullet
|
||||
|
||||
FROM debian:bookworm-slim
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates curl git openssh-client tini \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
ENV SB_HOSTNAME=0.0.0.0 \
|
||||
SB_FOLDER=/space \
|
||||
SB_PORT=3000 \
|
||||
SB_NAME=Plainleaf \
|
||||
SB_SHELL_BACKEND=off
|
||||
|
||||
COPY --from=server-builder /src/target/release/silverbullet /usr/local/bin/plainleaf
|
||||
|
||||
EXPOSE 3000
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=5 \
|
||||
CMD curl --fail "http://127.0.0.1:${SB_PORT}/.instance" || exit 1
|
||||
|
||||
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/plainleaf"]
|
||||
CMD ["--single"]
|
||||
@@ -0,0 +1,26 @@
|
||||
# Plainleaf on ZSpace NAS
|
||||
|
||||
This deployment builds the customized Plainleaf source on an amd64 ZSpace NAS.
|
||||
It keeps deployment files and Markdown data separate:
|
||||
|
||||
- Deployment: `个人空间/docker/plainleaf`
|
||||
- Markdown space: `个人空间/笔记管理/Plainleaf`
|
||||
|
||||
The server listens on NAS port `3000`, runs as the NAS account's UID/GID, and
|
||||
has SilverBullet shell execution disabled. Authentication is supplied through a
|
||||
deployment-local `.env` file that must not be committed.
|
||||
|
||||
The intended `.env` keys are:
|
||||
|
||||
```dotenv
|
||||
PLAINLEAF_GIT_SHA=94d310d71211de57339724a9ad5cb21f214e101a
|
||||
PLAINLEAF_IMAGE_TAG=94d310d7
|
||||
PLAINLEAF_UID=1001
|
||||
PLAINLEAF_GID=1001
|
||||
PLAINLEAF_PORT=3000
|
||||
PLAINLEAF_SPACE_PATH=/tmp/zfsv3/sata11/13616066635/data/笔记管理/Plainleaf
|
||||
PLAINLEAF_USER=your-user:your-password
|
||||
```
|
||||
|
||||
Do not commit the real `.env` file. Do not expose the service publicly until a
|
||||
separate HTTPS reverse-proxy configuration has been verified.
|
||||
@@ -0,0 +1,41 @@
|
||||
name: plainleaf
|
||||
|
||||
services:
|
||||
plainleaf:
|
||||
build:
|
||||
context: ../..
|
||||
dockerfile: Dockerfile.nas
|
||||
args:
|
||||
GITHUB_SHA: ${PLAINLEAF_GIT_SHA:-unknown}
|
||||
image: plainleaf:${PLAINLEAF_IMAGE_TAG:-local}
|
||||
container_name: plainleaf
|
||||
restart: unless-stopped
|
||||
user: "${PLAINLEAF_UID:-1001}:${PLAINLEAF_GID:-1001}"
|
||||
environment:
|
||||
SB_HOSTNAME: 0.0.0.0
|
||||
SB_PORT: 3000
|
||||
SB_FOLDER: /space
|
||||
SB_NAME: Plainleaf
|
||||
SB_USER: ${PLAINLEAF_USER:?Set PLAINLEAF_USER in the NAS deployment .env file}
|
||||
SB_SHELL_BACKEND: "off"
|
||||
ports:
|
||||
- "${PLAINLEAF_PORT:-3000}:3000"
|
||||
volumes:
|
||||
- "${PLAINLEAF_SPACE_PATH:?Set PLAINLEAF_SPACE_PATH in the NAS deployment .env file}:/space"
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop:
|
||||
- ALL
|
||||
init: false
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "--fail", "http://127.0.0.1:3000/.instance"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
start_period: 20s
|
||||
retries: 5
|
||||
networks:
|
||||
- plainleaf
|
||||
|
||||
networks:
|
||||
plainleaf:
|
||||
name: plainleaf_network
|
||||
Reference in New Issue
Block a user