56 lines
2.8 KiB
Bash
56 lines
2.8 KiB
Bash
# Mastodon: web (puma) and sidekiq from one image, on the shared Postgres and Redis. Streaming is not needed.
|
|||
|
|
MASTODON_IMAGE=ghcr.io/mastodon/mastodon:v4.7.3
|
||
|
|
. "$here/peers/shared.sh"
|
||
|
|
|
||
|
|
mastodon_env() {
|
||
|
|
cat <<ENV
|
||
|
|
LOCAL_DOMAIN=mastodon.test
|
||
|
|
RAILS_ENV=production
|
||
|
|
NODE_ENV=production
|
||
|
|
DB_HOST=postgres
|
||
|
|
DB_USER=pasture
|
||
|
|
DB_PASS=pasture
|
||
|
|
DB_NAME=mastodon
|
||
|
|
REDIS_URL=redis://redis:6379/1
|
||
|
|
SECRET_KEY_BASE=pasture0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
|
||
|
|
OTP_SECRET=pasture000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
|
||
|
|
ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY=pasturedeterministickey0000000000
|
||
|
|
ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT=pasturederivationsalt000000000000
|
||
|
|
ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY=pastureprimarykey0000000000000000
|
||
|
|
ALLOWED_PRIVATE_ADDRESSES=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
|
||
|
|
SSL_CERT_FILE=/pasture/ca/bundle.pem
|
||
|
|
SKIP_POST_DEPLOYMENT_MIGRATIONS=false
|
||
|
|
WEB_CONCURRENCY=0
|
||
|
|
MAX_THREADS=8
|
||
|
|
RAILS_LOG_LEVEL=warn
|
||
|
|
${MASTODON_EXTRA_ENV:-}
|
||
|
|
ENV
|
||
|
|
}
|
||
|
|
|
||
|
|
mastodon_up() {
|
||
|
|
shared_postgres_up
|
||
|
|
shared_redis_up
|
||
|
|
mastodon_env > "$here/.ca/mastodon.env"
|
||
|
|
local common=(--network $net --env-file "$here/.ca/mastodon.env" -v "$ca:/pasture/ca:z,ro")
|
||
|
|
podman run --rm "${common[@]}" -e SAFETY_ASSURED=1 $MASTODON_IMAGE bundle exec rails db:prepare >/dev/null
|
||
|
|
podman run -d --replace --name pasture-mastodon "${common[@]}" -p 127.0.0.1:6973:3000 $MASTODON_IMAGE bundle exec puma -C config/puma.rb >/dev/null
|
||
|
|
podman run -d --replace --name pasture-mastodon-sidekiq "${common[@]}" $MASTODON_IMAGE bundle exec sidekiq >/dev/null
|
||
|
|
wait_http http://127.0.0.1:6973/health 90
|
||
|
|
podman exec pasture-mastodon bin/tootctl accounts create mastouser --email mastouser@mastodon.test --confirmed --role Owner >/dev/null 2>&1 || true
|
||
|
|
podman exec pasture-mastodon bin/tootctl accounts approve mastouser >/dev/null 2>&1 || true
|
||
|
|
echo "mastodon: https://mastodon.test:6443"
|
||
|
|
}
|
||
|
|
|
||
|
|
# mastodon_token [user]: a token for a Mastodon user, made directly (Mastodon offers no password grant). Owners get
|
||
|
|
# admin:read too, for reading reports.
|
||
|
|
mastodon_token() {
|
||
|
|
podman exec pasture-mastodon bin/rails runner '
|
||
|
|
app = Doorkeeper::Application.find_or_create_by!(name: "pasture") { |a| a.redirect_uri = "urn:ietf:wg:oauth:2.0:oob"; a.scopes = "read write follow admin:read" }
|
||
|
|
user = Account.find_local("'"${1:-mastouser}"'").user
|
||
|
|
puts Doorkeeper::AccessToken.create!(application_id: app.id, resource_owner_id: user.id, scopes: "read write follow admin:read").token' 2>/dev/null | tail -1
|
||
|
|
}
|
||
|
|
|
||
|
|
mastodon_user() { # name
|
||
|
|
podman exec pasture-mastodon bin/tootctl accounts create "$1" --email "$1@mastodon.test" --confirmed >/dev/null 2>&1 || true
|
||
|
|
podman exec pasture-mastodon bin/tootctl accounts approve "$1" >/dev/null 2>&1 || true
|
||
|
|
}
|