|
|
@@ -36,6 +36,10 @@ services:
|
|
|
LOG_LEVEL: info
|
|
|
DATABASE_ADDRESS: host.docker.internal:9004
|
|
|
DATABASE_PROJECT: smartbotic-automation
|
|
|
+ # For anything that talks to OpenSSL directly. libcurl ignores it, which
|
|
|
+ # is why the bundle is also mounted over curl's default CA path below -
|
|
|
+ # see the volume comment.
|
|
|
+ SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
|
|
|
volumes:
|
|
|
# Read-only: it carries the credentials master key and the JWT secret,
|
|
|
# and nothing should be rewriting it from inside a container.
|
|
|
@@ -43,6 +47,16 @@ services:
|
|
|
# Bind-mounted rather than used from the image so a node can be edited and
|
|
|
# re-migrated without a rebuild, which is how they are worked on today.
|
|
|
- /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
|
|
|
+ # Debian's CA set plus the extra certificates in ca/ - currently mulan's
|
|
|
+ # self-signed SD.cpp cert. Regenerate with ca/build-bundle.sh.
|
|
|
+ #
|
|
|
+ # Mounted OVER curl's default CA file rather than beside it. The runner
|
|
|
+ # never sets CURLOPT_CAINFO, so libcurl uses its compiled-in default,
|
|
|
+ # which on Debian is exactly this path - and libcurl reads neither
|
|
|
+ # SSL_CERT_FILE (that is OpenSSL's) nor CURL_CA_BUNDLE (that is the curl
|
|
|
+ # command-line tool's). Pointing an environment variable at a bundle
|
|
|
+ # somewhere else looks like it should work and silently does nothing.
|
|
|
+ - /data/dev/smartbotics/smartbotic/deploy/zeus/ca/bundle.crt:/etc/ssl/certs/ca-certificates.crt:ro
|
|
|
healthcheck:
|
|
|
# bash's /dev/tcp, because a slim image carries no curl or wget.
|
|
|
#
|
|
|
@@ -83,12 +97,26 @@ services:
|
|
|
# "localhost:9011", which inside a container means the webserver's own
|
|
|
# container - it registers, reports online, and every dispatch vanishes.
|
|
|
ADVERTISE_ADDRESS: smartbotic-runner:9011
|
|
|
+ # For anything that talks to OpenSSL directly. libcurl ignores it, which
|
|
|
+ # is why the bundle is also mounted over curl's default CA path below -
|
|
|
+ # see the volume comment.
|
|
|
+ SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
|
|
|
volumes:
|
|
|
- /data/dev/smartbotics/smartbotic/config:/var/lib/smartbotic/config:ro
|
|
|
- /data/dev/smartbotics/smartbotic/nodes:/usr/share/smartbotic-automation/nodes:ro
|
|
|
# Written by imap-extract-attachments. A bind mount, so the 230 files
|
|
|
# carried over from mulan stay where the host can see them.
|
|
|
- /data/dev/smartbotics/smartbotic/data:/var/lib/smartbotic/data
|
|
|
+ # Debian's CA set plus the extra certificates in ca/ - currently mulan's
|
|
|
+ # self-signed SD.cpp cert. Regenerate with ca/build-bundle.sh.
|
|
|
+ #
|
|
|
+ # Mounted OVER curl's default CA file rather than beside it. The runner
|
|
|
+ # never sets CURLOPT_CAINFO, so libcurl uses its compiled-in default,
|
|
|
+ # which on Debian is exactly this path - and libcurl reads neither
|
|
|
+ # SSL_CERT_FILE (that is OpenSSL's) nor CURL_CA_BUNDLE (that is the curl
|
|
|
+ # command-line tool's). Pointing an environment variable at a bundle
|
|
|
+ # somewhere else looks like it should work and silently does nothing.
|
|
|
+ - /data/dev/smartbotics/smartbotic/deploy/zeus/ca/bundle.crt:/etc/ssl/certs/ca-certificates.crt:ro
|
|
|
|
|
|
networks:
|
|
|
smartbotic:
|