mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-10-05 03:55:37 +00:00
* Port to Django 5.2 * Pin pluggy to 1.2.0 Any newer and the mystery importlib metadata error appears. Weird! >_> * Update for premailer changed default * Update view logic for is_ajax being changed to a template context processor * Port a few more tests to pytest proper Having two distinct test flavours is giving me a headache * Version 1 dockerfile Makes a VERY big image, I suspect we can optimise this a lot... * Optimise dockerfile a little lot a bit * fix(users): change logout link to POST request * fix(tests): fix some syntax errors in test code still got lots of failed tests :( * fix: replace deprecated Django APIs * ci: update Dockerfile * ci: update Dockerfile * fix(dependencies+tests): update EoL/vulnerable dependencies and improve test stability * Upgrade Python from 3.10 to 3.12 * Update frontend dependencies, replace node-sass with sass * chore(logging): ignore dangling obj reference warning from pypdf * ci: update compose.yml for prod deployment - Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template * style: reformat code * ci: add more sleep trying to pass tests * ci: ignore browser-based tests during ci testing * fix: create home for the new user during Dockerfile building * chore: remove heroku conf file * fix: RIGS not franken anymore * fix: restore is_ajax as a boolean and split out the context processor * test: remove Selenium interaction tests and their CI workarounds * fix: harden production settings (CSRF origins, env casts, ADMINS) and drop dead debug toolbar code * deploy: serve static files from nginx, pin PGDATA, and make cert scripts loud on failure * build: switch .dockerignore to an allowlist * build: drop unused dependencies, soft-pin the rest and target Python 3.14 * build: move image to Python 3.14 / Node 24 and force DEBUG off * ci: add dependabot config for uv, npm, docker and actions * build: narrow Sass deprecation silencing to @import and require Node 24 * build: provide placeholder env for collectstatic now that DEBUG is off in the image * deploy: add plain-HTTP nginx config for local development and use it in compose * deploy: remove self-signed cert script * build: make the image multi-arch with official node and python base images * ci: lint and test on PRs, build the image on PRs and push it to GHCR on master * docs: add local running and sample data instructions * fix: report a form error instead of crashing when big power has no Power MIC * fix: upgrade pypdf and urllib3 to patched releases * fix: apply non-breaking npm audit fixes * fix: strip whitespace in ALLOWED_HOSTS and drop misleading HSTS preload * deploy: add a pyrigs healthcheck and make nginx wait for it * build: pin the uv image version * fix: correct the check-in person picker condition and use BeautifulSoup's string argument * refactor: replace unique_together with UniqueConstraint * build: replace pycodestyle with ruff and fix what it found Removes unused imports and variables, and fixes a few real problems it surfaced: - EventCheckIn.active() referenced an undefined name and raised NameError; it now returns whether the check-in has no end time - RIGS.admin defined EventChecklistAdmin twice; the second is now PowerTestRecordAdmin - RIGS/tests/conftest.py used date/timedelta without importing them - the signal-registering imports in apps.py are kept with noqa pycodestyle config in setup.cfg is dropped. * style: format the codebase with ruff * style: normalise line endings, trailing whitespace and end-of-file newlines * ci: run ruff and file hygiene through prek, and document it --------- Co-authored-by: Hang <me@hangxu.me> Co-authored-by: Joe Banks <joe@jb3.dev>
50 lines
1.9 KiB
Bash
50 lines
1.9 KiB
Bash
#!/usr/bin/env bash
|
|
# Issue the initial certificate (run as root on the deployment server)
|
|
# Usage: sudo ./scripts/certbot-issue.sh <domain> <email>
|
|
set -euo pipefail
|
|
|
|
DOMAIN="${1:?Usage: $0 <domain> <email>}"
|
|
EMAIL="${2:?Usage: $0 <domain> <email>}"
|
|
|
|
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
|
WEBROOT="$REPO_DIR/nginx/certbot"
|
|
CERTS_DIR="$REPO_DIR/nginx/certs"
|
|
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
|
|
|
|
if ! command -v certbot >/dev/null 2>&1; then
|
|
echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy
|
|
|
|
# 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal)
|
|
certbot certonly \
|
|
--webroot -w "$WEBROOT" \
|
|
-d "$DOMAIN" \
|
|
-m "$EMAIL" \
|
|
--agree-tos --no-eff-email --non-interactive
|
|
|
|
# 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal)
|
|
cat > "$HOOK_PATH" <<EOF
|
|
#!/bin/sh
|
|
# Generated by scripts/certbot-issue.sh: copy renewed certs and reload nginx
|
|
set -e
|
|
cp -fL "\$RENEWED_LINEAGE/fullchain.pem" "$CERTS_DIR/fullchain.pem"
|
|
cp -fL "\$RENEWED_LINEAGE/privkey.pem" "$CERTS_DIR/privkey.pem"
|
|
chmod 600 "$CERTS_DIR/privkey.pem"
|
|
if ! docker compose -f "$REPO_DIR/compose.yml" exec -T nginx nginx -s reload; then
|
|
echo "pyrigs deploy-hook: WARNING: certificates were copied but nginx could not be reloaded (is the stack running?)" >&2
|
|
fi
|
|
echo "pyrigs deploy-hook: \$(date) renewed [\$RENEWED_DOMAINS] and reloaded nginx"
|
|
EOF
|
|
chmod +x "$HOOK_PATH"
|
|
|
|
# 3. Deploy the freshly issued certificate right away
|
|
RENEWED_LINEAGE="/etc/letsencrypt/live/$DOMAIN" \
|
|
RENEWED_DOMAINS="$DOMAIN" \
|
|
"$HOOK_PATH"
|
|
|
|
echo "Done: certificate for $DOMAIN issued and deployed to $CERTS_DIR; deploy-hook installed."
|
|
echo "Tip: for scheduled renewal, run sudo ./scripts/cron-install.sh"
|