Dennis Rodewyk 1 rok temu
rodzic
commit
38883a2bdd

+ 28 - 0
data/services/ghost4/containers.sh

@@ -0,0 +1,28 @@
+ghost4_service_dockerbunker() {
+	docker run -d \
+		--name=${FUNCNAME[0]//_/-} \
+		--network dockerbunker-${SERVICE_NAME} \
+		--restart=always \
+		--env-file ${SERVICE_ENV} \
+		-e mysql__client=mysql \
+		-e database__connection__database=${MYSQL_DATABASE} \
+		-e database__connection__host=db \
+		-e database__connection__user=${MYSQL_USER} \
+		-e database__connection__password=${MYSQL_PASSWORD} \
+		-e NODE_ENV=production \
+		-v "${BASE_DIR}/data/services/${SERVICE_NAME}/themes":/var/lib/ghost/content/themes \
+		-v ${SERVICE_NAME}-data-vol-1:${volumes[${SERVICE_NAME}-data-vol-1]} \
+		${IMAGES[service]} >/dev/null
+}
+ghost4_db_dockerbunker() {
+	docker run -d \
+		--name=${FUNCNAME[0]//_/-} \
+		--restart=always \
+		--network dockerbunker-${SERVICE_NAME} --net-alias=db \
+		--env-file="${SERVICE_ENV}" \
+		-v ${SERVICE_NAME}-db-vol-1:${volumes[${SERVICE_NAME}-db-vol-1]} \
+		-v "${BASE_DIR}/data/services/${SERVICE_NAME}/mysql/":/etc/mysql/conf.d/:ro \
+		--health-cmd="mysqladmin ping --host localhost --silent" --health-interval=10s --health-retries=5 --health-timeout=30s \
+	${IMAGES[db]} >/dev/null
+}
+

+ 72 - 0
data/services/ghost4/ghost4.sh

@@ -0,0 +1,72 @@
+#!/usr/bin/env bash
+
+while true;do ls | grep -q dockerbunker.sh;if [[ $? == 0 ]];then BASE_DIR=$PWD;break;else cd ../;fi;done
+
+PROPER_NAME="Ghost4"
+SERVICE_NAME="$(echo -e "${PROPER_NAME,,}" | tr -d '[:space:]')"
+PROMPT_SSL=1
+safe_to_keep_volumes_when_reconfiguring=1
+
+declare -a environment=( "data/env/dockerbunker.env" "data/include/init.sh" )
+
+for env in "${environment[@]}";do
+	[[ -f "${BASE_DIR}"/$env ]] && source "${BASE_DIR}"/$env
+done
+
+declare -A WEB_SERVICES
+declare -a containers=( "${SERVICE_NAME}-db-dockerbunker" "${SERVICE_NAME}-service-dockerbunker" )
+declare -a add_to_network=( "${SERVICE_NAME}-service-dockerbunker" )
+declare -A volumes=( [${SERVICE_NAME}-db-vol-1]="/var/lib/mysql" [${SERVICE_NAME}-data-vol-1]="/var/lib/ghost/content" )
+declare -a networks=( "dockerbunker-${SERVICE_NAME}" )
+declare -A IMAGES=( [db]="mariadb:10.3" [service]="ghost:5-alpine" )
+
+[[ -z $1 ]] && options_menu
+
+configure() {
+	pre_configure_routine
+
+	echo -e "# \e[4mGhost Settings\e[0m"
+
+	set_domain
+
+	cat <<-EOF >> "${SERVICE_ENV}"
+	PROPER_NAME=${PROPER_NAME}
+	SERVICE_NAME=${SERVICE_NAME}
+	SSL_CHOICE=${SSL_CHOICE}
+	LE_EMAIL=${LE_EMAIL}
+	
+	# ------------------------------
+	# General Settings
+	# ------------------------------
+	
+	SERVICE_DOMAIN=${SERVICE_DOMAIN}
+	
+	# ------------------------------
+	# Ghost Settings
+	# ------------------------------
+	
+	url=https://${SERVICE_DOMAIN}/
+	NODE_ENV=production
+	
+	# ------------------------------
+	# SQL database configuration
+	# ------------------------------
+
+	MYSQL_DATABASE=ghost
+	MYSQL_USER=ghost
+	
+	# Please use long, random alphanumeric strings (A-Za-z0-9)
+	MYSQL_PASSWORD=$(tr -dc 'a-zA-Z0-9' < /dev/urandom | head -c 28)
+	MYSQL_ROOT_PASSWORD=$(tr -dc 'a-zA-Z0-9' < /dev/urandom | head -c 28)
+	EOF
+
+	post_configure_routine
+}
+
+if [[ $1 == "letsencrypt" ]];then
+	$1 $*
+else
+	$1
+fi
+
+

+ 48 - 0
data/services/ghost4/nginx/ghost4.conf

@@ -0,0 +1,48 @@
+upstream ghost4 {
+ server ghost4-service-dockerbunker:2368;
+}
+
+server {
+    listen 80;
+	server_name ${SERVICE_DOMAIN};
+    return 301 https://$host$request_uri;
+}
+
+server {
+    listen 443 ssl;
+	server_name ${SERVICE_DOMAIN};
+	ssl_certificate /etc/nginx/ssl/${SERVICE_DOMAIN}/cert.pem;
+	ssl_certificate_key /etc/nginx/ssl/${SERVICE_DOMAIN}/key.pem;
+	include /etc/nginx/includes/ssl.conf;
+
+    add_header Strict-Transport-Security "max-age=15768000; includeSubDomains";
+	add_header X-Frame-Options DENY;
+	add_header X-Content-Type-Options nosniff;
+
+	include /etc/nginx/includes/gzip.conf;
+
+    location ^~ /blog {
+        proxy_set_header X-Real-IP $remote_addr;
+        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+        proxy_set_header Host $http_host;
+        proxy_set_header X-NginX-Proxy true;
+
+        proxy_pass http://ghost4/;
+        proxy_redirect off;
+    }
+
+#    location / {
+#        proxy_pass http://ghost4/;
+#		proxy_set_header  Host              $http_host;   # required for docker client's sake
+#		proxy_set_header  X-Real-IP         $remote_addr; # pass on real client's IP
+#		proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
+#		proxy_set_header  X-Forwarded-Proto $scheme;
+#		proxy_read_timeout                  900;
+#    }
+
+	location ~ /.well-known {
+        allow all;
+		root /var/www/html;
+	}
+}
+