mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-10-03 19:15:39 +00:00
* Port to Django 5.2 * Pin pluggy to 1.2.0 Any newer and the mystery importlib metadata error appears. Weird! >_> * Update for premailer changed default * Update view logic for is_ajax being changed to a template context processor * Port a few more tests to pytest proper Having two distinct test flavours is giving me a headache * Version 1 dockerfile Makes a VERY big image, I suspect we can optimise this a lot... * Optimise dockerfile a little lot a bit * fix(users): change logout link to POST request * fix(tests): fix some syntax errors in test code still got lots of failed tests :( * fix: replace deprecated Django APIs * ci: update Dockerfile * ci: update Dockerfile * fix(dependencies+tests): update EoL/vulnerable dependencies and improve test stability * Upgrade Python from 3.10 to 3.12 * Update frontend dependencies, replace node-sass with sass * chore(logging): ignore dangling obj reference warning from pypdf * ci: update compose.yml for prod deployment - Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template * style: reformat code * ci: add more sleep trying to pass tests * ci: ignore browser-based tests during ci testing * fix: create home for the new user during Dockerfile building * chore: remove heroku conf file * fix: RIGS not franken anymore * fix: restore is_ajax as a boolean and split out the context processor * test: remove Selenium interaction tests and their CI workarounds * fix: harden production settings (CSRF origins, env casts, ADMINS) and drop dead debug toolbar code * deploy: serve static files from nginx, pin PGDATA, and make cert scripts loud on failure * build: switch .dockerignore to an allowlist * build: drop unused dependencies, soft-pin the rest and target Python 3.14 * build: move image to Python 3.14 / Node 24 and force DEBUG off * ci: add dependabot config for uv, npm, docker and actions * build: narrow Sass deprecation silencing to @import and require Node 24 * build: provide placeholder env for collectstatic now that DEBUG is off in the image * deploy: add plain-HTTP nginx config for local development and use it in compose * deploy: remove self-signed cert script * build: make the image multi-arch with official node and python base images * ci: lint and test on PRs, build the image on PRs and push it to GHCR on master * docs: add local running and sample data instructions * fix: report a form error instead of crashing when big power has no Power MIC * fix: upgrade pypdf and urllib3 to patched releases * fix: apply non-breaking npm audit fixes * fix: strip whitespace in ALLOWED_HOSTS and drop misleading HSTS preload * deploy: add a pyrigs healthcheck and make nginx wait for it * build: pin the uv image version * fix: correct the check-in person picker condition and use BeautifulSoup's string argument * refactor: replace unique_together with UniqueConstraint * build: replace pycodestyle with ruff and fix what it found Removes unused imports and variables, and fixes a few real problems it surfaced: - EventCheckIn.active() referenced an undefined name and raised NameError; it now returns whether the check-in has no end time - RIGS.admin defined EventChecklistAdmin twice; the second is now PowerTestRecordAdmin - RIGS/tests/conftest.py used date/timedelta without importing them - the signal-registering imports in apps.py are kept with noqa pycodestyle config in setup.cfg is dropped. * style: format the codebase with ruff * style: normalise line endings, trailing whitespace and end-of-file newlines * ci: run ruff and file hygiene through prek, and document it --------- Co-authored-by: Hang <me@hangxu.me> Co-authored-by: Joe Banks <joe@jb3.dev>
111 lines
3.2 KiB
YAML
111 lines
3.2 KiB
YAML
services:
|
|
db:
|
|
image: postgres:18.6
|
|
restart: unless-stopped
|
|
environment:
|
|
POSTGRES_DB: ${DATABASE_NAME}
|
|
POSTGRES_USER: ${DATABASE_USERNAME}
|
|
POSTGRES_PASSWORD: ${DATABASE_PASSWORD}
|
|
# postgres 18+ defaults PGDATA to a versioned subdirectory; pin it so the volume below holds the data
|
|
PGDATA: /var/lib/postgresql/data
|
|
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
|
|
healthcheck:
|
|
test: [ "CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}" ]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
pyrigs:
|
|
build: .
|
|
restart: unless-stopped
|
|
environment:
|
|
SECRET_KEY: ${SECRET_KEY}
|
|
DJANGO_ALLOWED_HOSTS: ${DJANGO_ALLOWED_HOSTS}
|
|
DOMAIN: ${DOMAIN:-example.com}
|
|
DEBUG: ${DEBUG:-false}
|
|
STAGING: ${STAGING:-false}
|
|
SESSION_COOKIE_SECURE_ENABLED: ${SESSION_COOKIE_SECURE_ENABLED:-true}
|
|
CSRF_COOKIE_SECURE_ENABLED: ${CSRF_COOKIE_SECURE_ENABLED:-true}
|
|
FORUM_WEBHOOK_SECRET: ${FORUM_WEBHOOK_SECRET}
|
|
DATABASE_ENGINE: ${DATABASE_ENGINE:-postgresql}
|
|
DATABASE_NAME: ${DATABASE_NAME}
|
|
DATABASE_USERNAME: ${DATABASE_USERNAME}
|
|
DATABASE_PASSWORD: ${DATABASE_PASSWORD}
|
|
DATABASE_HOST: ${DATABASE_HOST:-db}
|
|
DATABASE_PORT: ${DATABASE_PORT:-5432}
|
|
EMAIL_HOST: ${EMAIL_HOST}
|
|
EMAIL_PORT: ${EMAIL_PORT:-25}
|
|
EMAIL_HOST_USER: ${EMAIL_HOST_USER}
|
|
EMAIL_HOST_PASSWORD: ${EMAIL_HOST_PASSWORD}
|
|
EMAIL_USE_TLS: ${EMAIL_USE_TLS:-false}
|
|
EMAIL_USE_SSL: ${EMAIL_USE_SSL:-false}
|
|
EMAIL_FROM: ${EMAIL_FROM}
|
|
HCAPTCHA_SITEKEY: ${HCAPTCHA_SITEKEY:-10000000-ffff-ffff-ffff-000000000001}
|
|
HCAPTCHA_SECRET: ${HCAPTCHA_SECRET:-0x0000000000000000000000000000000000000000}
|
|
SENTRY_DSN: ${SENTRY_DSN:-}
|
|
expose:
|
|
- "8000"
|
|
|
|
healthcheck:
|
|
# gunicorn only starts listening once migrations and collectstatic have finished
|
|
test: [ "CMD", "python", "-c", "import socket; socket.create_connection(('127.0.0.1', 8000), 2).close()" ]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 60s
|
|
|
|
volumes:
|
|
# shared with nginx, which serves /static/ directly
|
|
- static_files:/app/static
|
|
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
|
|
command:
|
|
- sh
|
|
- -c
|
|
- |
|
|
python manage.py migrate --noinput &&
|
|
python manage.py collectstatic --noinput &&
|
|
gunicorn \
|
|
--bind 0.0.0.0:8000 \
|
|
--workers 2 \
|
|
PyRIGS.wsgi
|
|
|
|
develop:
|
|
# Create a `watch` configuration to update the app
|
|
watch:
|
|
# Sync the working directory with the `/app` directory in the container
|
|
- action: sync
|
|
path: .
|
|
target: /app
|
|
# Exclude the project virtual environment
|
|
ignore:
|
|
- .venv/
|
|
|
|
# Rebuild the image on changes to the `pyproject.toml`
|
|
- action: rebuild
|
|
path: ./pyproject.toml
|
|
|
|
nginx:
|
|
image: nginx:stable-alpine
|
|
restart: unless-stopped
|
|
ports:
|
|
- "80:80"
|
|
|
|
volumes:
|
|
- ./nginx/default.dev.conf:/etc/nginx/conf.d/default.conf:ro
|
|
- static_files:/var/www/static:ro
|
|
|
|
depends_on:
|
|
pyrigs:
|
|
condition: service_healthy
|
|
|
|
volumes:
|
|
postgres_data:
|
|
static_files:
|