mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-10-06 20:45:30 +00:00
Port to Django 5.2 (#635)
* Port to Django 5.2 * Pin pluggy to 1.2.0 Any newer and the mystery importlib metadata error appears. Weird! >_> * Update for premailer changed default * Update view logic for is_ajax being changed to a template context processor * Port a few more tests to pytest proper Having two distinct test flavours is giving me a headache * Version 1 dockerfile Makes a VERY big image, I suspect we can optimise this a lot... * Optimise dockerfile a little lot a bit * fix(users): change logout link to POST request * fix(tests): fix some syntax errors in test code still got lots of failed tests :( * fix: replace deprecated Django APIs * ci: update Dockerfile * ci: update Dockerfile * fix(dependencies+tests): update EoL/vulnerable dependencies and improve test stability * Upgrade Python from 3.10 to 3.12 * Update frontend dependencies, replace node-sass with sass * chore(logging): ignore dangling obj reference warning from pypdf * ci: update compose.yml for prod deployment - Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template * style: reformat code * ci: add more sleep trying to pass tests * ci: ignore browser-based tests during ci testing * fix: create home for the new user during Dockerfile building * chore: remove heroku conf file * fix: RIGS not franken anymore * fix: restore is_ajax as a boolean and split out the context processor * test: remove Selenium interaction tests and their CI workarounds * fix: harden production settings (CSRF origins, env casts, ADMINS) and drop dead debug toolbar code * deploy: serve static files from nginx, pin PGDATA, and make cert scripts loud on failure * build: switch .dockerignore to an allowlist * build: drop unused dependencies, soft-pin the rest and target Python 3.14 * build: move image to Python 3.14 / Node 24 and force DEBUG off * ci: add dependabot config for uv, npm, docker and actions * build: narrow Sass deprecation silencing to @import and require Node 24 * build: provide placeholder env for collectstatic now that DEBUG is off in the image * deploy: add plain-HTTP nginx config for local development and use it in compose * deploy: remove self-signed cert script * build: make the image multi-arch with official node and python base images * ci: lint and test on PRs, build the image on PRs and push it to GHCR on master * docs: add local running and sample data instructions * fix: report a form error instead of crashing when big power has no Power MIC * fix: upgrade pypdf and urllib3 to patched releases * fix: apply non-breaking npm audit fixes * fix: strip whitespace in ALLOWED_HOSTS and drop misleading HSTS preload * deploy: add a pyrigs healthcheck and make nginx wait for it * build: pin the uv image version * fix: correct the check-in person picker condition and use BeautifulSoup's string argument * refactor: replace unique_together with UniqueConstraint * build: replace pycodestyle with ruff and fix what it found Removes unused imports and variables, and fixes a few real problems it surfaced: - EventCheckIn.active() referenced an undefined name and raised NameError; it now returns whether the check-in has no end time - RIGS.admin defined EventChecklistAdmin twice; the second is now PowerTestRecordAdmin - RIGS/tests/conftest.py used date/timedelta without importing them - the signal-registering imports in apps.py are kept with noqa pycodestyle config in setup.cfg is dropped. * style: format the codebase with ruff * style: normalise line endings, trailing whitespace and end-of-file newlines * ci: run ruff and file hygiene through prek, and document it --------- Co-authored-by: Hang <me@hangxu.me> Co-authored-by: Joe Banks <joe@jb3.dev>
This commit is contained in:
49
scripts/certbot-issue.sh
Normal file
49
scripts/certbot-issue.sh
Normal file
@@ -0,0 +1,49 @@
|
||||
#!/usr/bin/env bash
|
||||
# Issue the initial certificate (run as root on the deployment server)
|
||||
# Usage: sudo ./scripts/certbot-issue.sh <domain> <email>
|
||||
set -euo pipefail
|
||||
|
||||
DOMAIN="${1:?Usage: $0 <domain> <email>}"
|
||||
EMAIL="${2:?Usage: $0 <domain> <email>}"
|
||||
|
||||
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
||||
WEBROOT="$REPO_DIR/nginx/certbot"
|
||||
CERTS_DIR="$REPO_DIR/nginx/certs"
|
||||
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
|
||||
|
||||
if ! command -v certbot >/dev/null 2>&1; then
|
||||
echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy
|
||||
|
||||
# 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal)
|
||||
certbot certonly \
|
||||
--webroot -w "$WEBROOT" \
|
||||
-d "$DOMAIN" \
|
||||
-m "$EMAIL" \
|
||||
--agree-tos --no-eff-email --non-interactive
|
||||
|
||||
# 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal)
|
||||
cat > "$HOOK_PATH" <<EOF
|
||||
#!/bin/sh
|
||||
# Generated by scripts/certbot-issue.sh: copy renewed certs and reload nginx
|
||||
set -e
|
||||
cp -fL "\$RENEWED_LINEAGE/fullchain.pem" "$CERTS_DIR/fullchain.pem"
|
||||
cp -fL "\$RENEWED_LINEAGE/privkey.pem" "$CERTS_DIR/privkey.pem"
|
||||
chmod 600 "$CERTS_DIR/privkey.pem"
|
||||
if ! docker compose -f "$REPO_DIR/compose.yml" exec -T nginx nginx -s reload; then
|
||||
echo "pyrigs deploy-hook: WARNING: certificates were copied but nginx could not be reloaded (is the stack running?)" >&2
|
||||
fi
|
||||
echo "pyrigs deploy-hook: \$(date) renewed [\$RENEWED_DOMAINS] and reloaded nginx"
|
||||
EOF
|
||||
chmod +x "$HOOK_PATH"
|
||||
|
||||
# 3. Deploy the freshly issued certificate right away
|
||||
RENEWED_LINEAGE="/etc/letsencrypt/live/$DOMAIN" \
|
||||
RENEWED_DOMAINS="$DOMAIN" \
|
||||
"$HOOK_PATH"
|
||||
|
||||
echo "Done: certificate for $DOMAIN issued and deployed to $CERTS_DIR; deploy-hook installed."
|
||||
echo "Tip: for scheduled renewal, run sudo ./scripts/cron-install.sh"
|
||||
34
scripts/cron-install.sh
Normal file
34
scripts/cron-install.sh
Normal file
@@ -0,0 +1,34 @@
|
||||
#!/usr/bin/env bash
|
||||
# Install system-level scheduled tasks (run as root on the deployment server)
|
||||
# Usage: sudo ./scripts/cron-install.sh
|
||||
#
|
||||
# Writes two /etc/cron.d files:
|
||||
# 1. pyrigs-certbot - certificate renewal check, daily at 03:00 / 15:00
|
||||
# 2. pyrigs-django - cleanup and reminder jobs inside the pyrigs container
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
||||
CERTBOT_CRON="/etc/cron.d/pyrigs-certbot"
|
||||
DJANGO_CRON="/etc/cron.d/pyrigs-django"
|
||||
|
||||
# 1. Certificate renewal: checked twice a day (officially recommended frequency);
|
||||
# on successful renewal the deploy-hook in the official hook dir takes over
|
||||
cat > "$CERTBOT_CRON" <<EOF
|
||||
# Generated by scripts/cron-install.sh; remove with scripts/cron-uninstall.sh
|
||||
0 3,15 * * * root certbot renew --quiet
|
||||
EOF
|
||||
|
||||
# 2. Django scheduled tasks (replacing the former Heroku Scheduler jobs, run via exec inside the container)
|
||||
cat > "$DJANGO_CRON" <<EOF
|
||||
SHELL=/bin/sh
|
||||
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
|
||||
# Generated by scripts/cron-install.sh; remove with scripts/cron-uninstall.sh
|
||||
0 0 * * * root docker compose -f $REPO_DIR/compose.yml exec -T pyrigs sh -c "python manage.py cleanupregistration && python manage.py usercleanup" >> /var/log/pyrigs-cleanup.log 2>&1
|
||||
0 8 * * * root docker compose -f $REPO_DIR/compose.yml exec -T pyrigs python manage.py send_reminders >> /var/log/pyrigs-reminders.log 2>&1
|
||||
EOF
|
||||
|
||||
chmod 644 "$CERTBOT_CRON" "$DJANGO_CRON"
|
||||
|
||||
echo "Installed:"
|
||||
echo " $CERTBOT_CRON"
|
||||
echo " $DJANGO_CRON"
|
||||
19
scripts/cron-uninstall.sh
Normal file
19
scripts/cron-uninstall.sh
Normal file
@@ -0,0 +1,19 @@
|
||||
#!/usr/bin/env bash
|
||||
# Uninstall the scheduled tasks installed by cron-install.sh (run as root on the deployment server)
|
||||
# Usage: sudo ./scripts/cron-uninstall.sh
|
||||
set -euo pipefail
|
||||
|
||||
CERTBOT_CRON="/etc/cron.d/pyrigs-certbot"
|
||||
DJANGO_CRON="/etc/cron.d/pyrigs-django"
|
||||
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
|
||||
|
||||
rm -f "$CERTBOT_CRON" "$DJANGO_CRON"
|
||||
echo "Removed scheduled tasks: $CERTBOT_CRON $DJANGO_CRON"
|
||||
|
||||
if [ -f "$HOOK_PATH" ]; then
|
||||
read -rp "Also remove the deploy-hook ($HOOK_PATH)? [y/N] " ans
|
||||
case "$ans" in
|
||||
y|Y) rm -f "$HOOK_PATH"; echo "Deploy-hook removed" ;;
|
||||
*) echo "Deploy-hook kept" ;;
|
||||
esac
|
||||
fi
|
||||
Reference in New Issue
Block a user