Files
truf-server/deploy/edge/entrypoint.sh
T
2026-09-30 20:30:56 +03:00

72 lines
2.6 KiB
Bash

#!/bin/sh
set -eu
fail() {
echo "edge configuration rejected: $1" >&2
exit 64
}
host=${TRUF_EDGE_HOST:-}
prefix=${TRUF_ADMIN_PREFIX:-}
user=${TRUF_ADMIN_USER:-}
password_hash=${TRUF_ADMIN_PASSWORD_HASH:-}
edge_marker=${TRUF_ADMIN_EDGE_MARKER:-}
edge_mode=${TRUF_EDGE_MODE:-standalone-edge-v1}
ingress_marker=${TRUF_SHARED_INGRESS_MARKER:-}
tls_include=${TRUF_EDGE_TLS_INCLUDE:-}
case "$edge_mode" in
standalone-edge-v1) caddyfile=/etc/caddy/Caddyfile ;;
shared-host-edge-v1)
caddyfile=/etc/caddy/Caddyfile.shared-host
[ "${#ingress_marker}" -eq 64 ] || fail "TRUF_SHARED_INGRESS_MARKER must encode 256 random bits"
printf '%s' "$ingress_marker" | grep -Eq '^[0-9a-f]{64}$' \
|| fail "TRUF_SHARED_INGRESS_MARKER must encode 256 random bits"
;;
*) fail "TRUF_EDGE_MODE is unsupported" ;;
esac
if [ "$host" = localhost ]; then
[ -n "$tls_include" ] || fail "localhost requires an explicit static TLS include"
else
case "$host" in
''|*://*|*/*|*:*|.*|*..*|*.) fail "TRUF_EDGE_HOST must be one DNS hostname" ;;
esac
printf '%s' "$host" | awk -F. '
length($0) > 253 || NF < 2 { exit 1 }
{ for (i = 1; i <= NF; i++) if (length($i) > 63 || $i !~ /^[A-Za-z0-9-]+$/ || $i ~ /^-/ || $i ~ /-$/) exit 1 }
' \
|| fail "TRUF_EDGE_HOST must be one DNS hostname"
fi
if [ -n "$tls_include" ]; then
case "$tls_include" in
/etc/caddy/tls/*.caddy) ;;
*) fail "TRUF_EDGE_TLS_INCLUDE must be an absolute Caddy TLS include" ;;
esac
[ -f "$tls_include" ] && [ ! -L "$tls_include" ] \
|| fail "TRUF_EDGE_TLS_INCLUDE must be a regular non-link file"
fi
[ "${#prefix}" -eq 64 ] || fail "TRUF_ADMIN_PREFIX must encode 256 random bits"
printf '%s' "$prefix" | grep -Eq '^[0-9a-f]{64}$' \
|| fail "TRUF_ADMIN_PREFIX must encode 256 random bits"
printf '%s' "$user" | grep -Eq '^[A-Za-z0-9_.-]{1,64}$' \
|| fail "TRUF_ADMIN_USER has an unsupported form"
printf '%s' "$password_hash" | grep -Eq '^\$2[aby]\$(0[4-9]|[12][0-9]|3[01])\$[./A-Za-z0-9]{53}$' \
|| fail "TRUF_ADMIN_PASSWORD_HASH must be a supported bcrypt hash"
[ "${#edge_marker}" -eq 64 ] || fail "TRUF_ADMIN_EDGE_MARKER must encode 256 random bits"
printf '%s' "$edge_marker" | grep -Eq '^[0-9a-f]{64}$' \
|| fail "TRUF_ADMIN_EDGE_MARKER must encode 256 random bits"
[ -f /etc/caddy/denylist/admin-denylist.caddy ] \
|| fail "the managed admin denylist snippet is missing"
[ ! -L /etc/caddy/denylist/admin-denylist.caddy ] \
|| fail "the managed admin denylist snippet must not be a link"
[ -d /var/log/caddy ] && [ -w /var/log/caddy ] \
|| fail "the authentication log directory is not writable"
umask 077
exec caddy run --config "$caddyfile" --adapter caddyfile