docker
This commit is contained in:
@@ -3,7 +3,7 @@ NODE_ENV=development
|
|||||||
API_PORT=3000
|
API_PORT=3000
|
||||||
WEB_PORT=4200
|
WEB_PORT=4200
|
||||||
PUBLIC_WEB_URL=http://localhost:4200
|
PUBLIC_WEB_URL=http://localhost:4200
|
||||||
API_BASE_URL=http://localhost:3000
|
API_BASE_URL=
|
||||||
|
|
||||||
DATABASE_URL=mysql://ldap_portal:change-me@mysql.example.com:3306/ldap_portal
|
DATABASE_URL=mysql://ldap_portal:change-me@mysql.example.com:3306/ldap_portal
|
||||||
DATABASE_SSL=false
|
DATABASE_SSL=false
|
||||||
@@ -24,7 +24,7 @@ SMTP_USER=portal@example.com
|
|||||||
SMTP_PASS=change-me
|
SMTP_PASS=change-me
|
||||||
SMTP_FROM="LDAP Portal <portal@example.com>"
|
SMTP_FROM="LDAP Portal <portal@example.com>"
|
||||||
|
|
||||||
OIDC_ISSUER=http://localhost:3000
|
OIDC_ISSUER=http://localhost:8080
|
||||||
OIDC_COOKIE_SECRET=change-me-long-random-oidc-cookie-secret
|
OIDC_COOKIE_SECRET=change-me-long-random-oidc-cookie-secret
|
||||||
OIDC_ADMIN_GROUP=client_manager
|
OIDC_ADMIN_GROUP=client_manager
|
||||||
OIDC_ADMIN_GROUP_UUID=89aa3d8d-fcbd-3ec9-b99d-901a0cfc405e
|
OIDC_ADMIN_GROUP_UUID=89aa3d8d-fcbd-3ec9-b99d-901a0cfc405e
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ WORKDIR /app
|
|||||||
ENV NODE_ENV=production
|
ENV NODE_ENV=production
|
||||||
ENV API_PORT=3000
|
ENV API_PORT=3000
|
||||||
ENV WEB_PORT=8080
|
ENV WEB_PORT=8080
|
||||||
ENV API_BASE_URL=http://localhost:3000
|
ENV API_BASE_URL=
|
||||||
|
|
||||||
RUN apk add --no-cache nginx
|
RUN apk add --no-cache nginx
|
||||||
|
|
||||||
@@ -30,5 +30,5 @@ COPY docker/start-single-container.sh /usr/local/bin/start-ldap-portal
|
|||||||
RUN chmod +x /usr/local/bin/start-ldap-portal \
|
RUN chmod +x /usr/local/bin/start-ldap-portal \
|
||||||
&& mkdir -p /run/nginx /var/log/nginx
|
&& mkdir -p /run/nginx /var/log/nginx
|
||||||
|
|
||||||
EXPOSE 3000 8080
|
EXPOSE 8080
|
||||||
CMD ["start-ldap-portal"]
|
CMD ["start-ldap-portal"]
|
||||||
|
|||||||
10
README.md
10
README.md
@@ -23,7 +23,7 @@ npm run start:api
|
|||||||
npm run start:web
|
npm run start:web
|
||||||
```
|
```
|
||||||
|
|
||||||
Die API laeuft standardmaessig auf `http://localhost:3000`, das Frontend auf `http://localhost:4200`.
|
In der lokalen Entwicklung laeuft die API standardmaessig auf `http://localhost:3000`, das Frontend auf `http://localhost:4200`.
|
||||||
|
|
||||||
## Docker Compose
|
## Docker Compose
|
||||||
|
|
||||||
@@ -39,8 +39,8 @@ Fuer OIDC muessen zusaetzlich `OIDC_ISSUER`, `OIDC_COOKIE_SECRET`, `OIDC_ADMIN_G
|
|||||||
|
|
||||||
Das Root-`Dockerfile` baut API und Angular in ein einzelnes Image. Der Container startet:
|
Das Root-`Dockerfile` baut API und Angular in ein einzelnes Image. Der Container startet:
|
||||||
|
|
||||||
- NestJS API / IdP auf Port `3000`
|
- Nginx Web-UI und Reverse Proxy auf Port `8080`
|
||||||
- Nginx Web-UI auf Port `8080`
|
- NestJS API / IdP nur intern auf Port `3000`
|
||||||
|
|
||||||
Build und Push:
|
Build und Push:
|
||||||
|
|
||||||
@@ -54,13 +54,11 @@ Start:
|
|||||||
```bash
|
```bash
|
||||||
docker run -d --name ldap-portal-idp \
|
docker run -d --name ldap-portal-idp \
|
||||||
--env-file .env \
|
--env-file .env \
|
||||||
-e API_BASE_URL=https://id.example.com \
|
|
||||||
-p 3000:3000 \
|
|
||||||
-p 8080:8080 \
|
-p 8080:8080 \
|
||||||
registry.example.com/ldap-portal/idp:latest
|
registry.example.com/ldap-portal/idp:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
`API_BASE_URL` wird beim Containerstart in `/config.js` geschrieben und vom Angular-Frontend gelesen. Setze es auf die aus Browser-Sicht erreichbare API-/IdP-URL.
|
Standardmaessig bleibt `API_BASE_URL` leer. Das Frontend nutzt dadurch relative URLs und Nginx routet API-/OIDC-Pfade intern zur NestJS-API. Setze `API_BASE_URL` nur, wenn das Frontend bewusst eine andere API-Origin verwenden soll.
|
||||||
|
|
||||||
## Externe Dienste
|
## Externe Dienste
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
window.__LDAP_PORTAL_CONFIG__ = {
|
window.__LDAP_PORTAL_CONFIG__ = {
|
||||||
apiBaseUrl: 'http://localhost:3000'
|
apiBaseUrl: ''
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -66,6 +66,6 @@ bootstrapApplication(AppComponent, {
|
|||||||
provideRouter(routes),
|
provideRouter(routes),
|
||||||
provideHttpClient(withInterceptors([authInterceptor])),
|
provideHttpClient(withInterceptors([authInterceptor])),
|
||||||
AuthService,
|
AuthService,
|
||||||
{ provide: API_BASE_URL, useValue: window.__LDAP_PORTAL_CONFIG__?.apiBaseUrl ?? 'http://localhost:3000' },
|
{ provide: API_BASE_URL, useValue: window.__LDAP_PORTAL_CONFIG__?.apiBaseUrl ?? '' },
|
||||||
],
|
],
|
||||||
}).catch((error) => console.error(error));
|
}).catch((error) => console.error(error));
|
||||||
|
|||||||
@@ -6,5 +6,4 @@ services:
|
|||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
ports:
|
ports:
|
||||||
- "3000:3000"
|
|
||||||
- "8080:8080"
|
- "8080:8080"
|
||||||
|
|||||||
@@ -4,11 +4,48 @@ server {
|
|||||||
root /usr/share/nginx/html;
|
root /usr/share/nginx/html;
|
||||||
index index.html;
|
index index.html;
|
||||||
|
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
|
||||||
location = /config.js {
|
location = /config.js {
|
||||||
add_header Cache-Control "no-store";
|
add_header Cache-Control "no-store";
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
location /.well-known/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /oidc/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /interaction/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /auth/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /account/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /admin/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /password/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /registration/ {
|
||||||
|
proxy_pass http://127.0.0.1:3000;
|
||||||
|
}
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
try_files $uri $uri/ /index.html;
|
try_files $uri $uri/ /index.html;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ set -eu
|
|||||||
|
|
||||||
cat >/usr/share/nginx/html/config.js <<EOF
|
cat >/usr/share/nginx/html/config.js <<EOF
|
||||||
window.__LDAP_PORTAL_CONFIG__ = {
|
window.__LDAP_PORTAL_CONFIG__ = {
|
||||||
apiBaseUrl: "${API_BASE_URL:-http://localhost:3000}"
|
apiBaseUrl: "${API_BASE_URL:-}"
|
||||||
};
|
};
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user