Add @mieweb/os-cloud-provider: mieweb deploy --target mieweb (#475) - #484
runleveldev wants to merge 13 commits into
Conversation
… service deletes (#475)
|
| Consumer pnpm | This package pins packageManager |
Result |
|---|---|---|
| 10.17.1 | no | ❌ prepared with npm → contract missing → tsc fails |
| 10.17.1 | yes | ❌ pnpm 10 ignores the pin; still npm |
| 12.8.1 | no | ❌ still npm; also blocked by blockExoticSubdeps (on by default in 12) |
| 12.8.1 | yes | ✅ prepared with pnpm install, dist/ built, createProvider(env) imports, supports('mieweb') === true |
Fix for this PR — pin the package manager in packages/os-cloud-provider/package.json:
{
"name": "@mieweb/os-cloud-provider",
"version": "0.1.0",
"packageManager": "pnpm@12.8.1",
// …
}Consumer side (worth a note in the package README until the contract is on npm). The app installing the provider needs pnpm ≥ 12 and, in pnpm-workspace.yaml:
blockExoticSubdeps: false # this package has a git-hosted subdependency (the contract)
allowBuilds:
"@mieweb/os-cloud-provider@https://codeload.github.com/mieweb/opensource-server/tar.gz/<sha>#path:/packages/os-cloud-provider": trueAfter mieweb/cloud#14 merges and @mieweb/deploy-contract is published, switching the dependency to ^0.2.1 removes the git-hosted subdependency, and with it the blockExoticSubdeps exception. The pin is still required as long as this package is consumed from git.
…GitHub Packages, publish PR previews (#475)
…475) Uses the only visible site, otherwise prompts on the terminal; non-interactive runs error with the list. MIEWEB_OS_SITE_ID overrides targets.mieweb.siteId.
| const state = url.searchParams.get('state')!; | ||
| const frag = new URLSearchParams({ ...this.nextKey, state }); | ||
| this.tokens.set(this.nextKey.key, { user: this.nextKey.user, keyId: this.nextKey.id }); | ||
| res.writeHead(303, { Location: `http://127.0.0.1:${port}/callback#${frag}` }); |
Closes #475. Stacked on #476 (volumes, #421). This PR targets
421-volumesand should be retargeted tomainonce #476 merges.What's in it
packages/os-cloud-provider: the@mieweb/deploy-contractDeployProviderfor os.mieweb.org. It's written in TypeScript: Node runs the sources directly in development, andtscbuildsdist/for publishing. The contract is installed with pnpm's git subdirectory syntax, pinned to the mieweb/cloud#14 commit.deploywrangler.jsoncname), then creates or updates it. A 409 from a concurrent create is retried as an update.rw/mnt/datavolume is kept across the recreate./opt/app/srcover the container's SSH port, then restartsapp.service. It honors.gitignorefiles (nested ones too) and skips.git/; staged/committed status doesn't matter.ssh2,ignore,tar-stream), so no localsshorrsyncis needed.sudo tar -x. Files deleted locally are deleted remotely; gitignored remote paths are left alone.~/.sshkeys (with a passphrase prompt), then a password prompt. Host keys are trusted on first use and pinned in~/.mieweb/known_hosts.destroy,whoami,login,logout: token fromMIEWEB_OS_TOKEN, or the per-instance cache in~/.mieweb/os.jsonwritten bylogin.logoutrevokes the key on the Manager.devandtailare intentionally omitted.Manager
GET/POST /api/v1/auth/cli/callback: the loopback login handoff (§4.3).127.0.0.1and the CLI'sstatevalue is echoed back. The key is returned in the URL fragment, so it never appears in a request line.GET /sites/:id/containers/new, which any container creator can call, returned the fullExternalDomainrows, includingcloudflareApiKey/cloudflareApiEmail. It now returns only{id, name, siteId}.onDelete: CASCADE, matching the migrations. Without it, deleting a service in an update failed with a foreign-key error on SQLite.LoginPagedoes a full page load for same-origin/api/...redirects, so sign-in can return to the CLI route.images/cloud: built onnodejs. MinIO (built from source at a pinned release, since MinIO no longer publishes binaries),sqld(checksum-verified download), and Valkey run as systemd units bound to 127.0.0.1, with their data under/mnt/data.app.serviceinstalls dependencies only whenpackage.jsonor the lockfile changed, runsbuildif present, then starts the app on$PORT. The image is added to the bake file andbuild-images.yml.Docs:
docs/users/mieweb-cli-deploy.md, the image docs, the package README, andexamples/mieweb.jsonc.Testing
pnpm test): 67 tests.ssh2server: password fallback, key login, host-key pinning.cli-authandcontainers.self-servicesuites.agents.checkin.test.jscrashes the same way on the unmodified421-volumesbranch, so that crash wasn't introduced here.make dev(SQLite + simulated hypervisor): create, update, recreate on image change, destroy, live conformance, and the browser login → whoami → logout round trip.registry.os.mieweb.org/opensource-server/cloud:provider-test):Follow-ups
ghcr.io/mieweb/opensource-server/cloudpublic.:latestonly exists after a release.@mieweb/deploy-contractto^0.2.1once it's published to npm.