diff --git a/Dockerfile b/Dockerfile index aebc8e6..87d3b00 100644 --- a/Dockerfile +++ b/Dockerfile @@ -33,7 +33,7 @@ RUN --mount=type=cache,target=/root/.cache/pip \ FROM debian:trixie-slim AS runtime RUN apt-get update \ - && apt-get install -y --no-install-recommends ca-certificates iproute2 \ + && apt-get install -y --no-install-recommends ca-certificates gosu iproute2 \ && rm -rf /var/lib/apt/lists/* \ && groupadd --system --gid 10001 drivershub \ && useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub @@ -44,7 +44,6 @@ COPY --from=builder --chown=drivershub:drivershub /build/dist/ ./ COPY --from=builder --chown=drivershub:drivershub /build/src/external_plugins/ ./external_plugins/ COPY --chown=root:root docker/entrypoint.sh /usr/local/bin/drivershub-entrypoint -USER drivershub EXPOSE 7777 8700 ENTRYPOINT ["drivershub-entrypoint"] diff --git a/README.md b/README.md index 44b8bd9..4b3b65a 100644 --- a/README.md +++ b/README.md @@ -107,16 +107,35 @@ configure it as follows: 2. Copy the application ID to `discord_client_id` in `config/config.json`. 3. Create a client secret and copy it to `discord_client_secret`. -4. Add a bot to the application and copy its token to `discord_bot_token`. -5. Copy the ID of the Discord server to `discord_guild_id`. -6. Install the bot in that server. The callback URL points to the frontend. Do not add `/api` to it. The frontend requests the `identify`, `email`, and `role_connections.write` OAuth scopes. -Give the bot only the permissions that your configuration needs. It needs -access to channels where it sends messages. Give it **Manage Roles** if the Hub -must change roles. Put the bot role above every role that it must manage. The +This configuration is sufficient for Discord sign-in and account connections. +A Discord bot is optional. Create and install a bot only if the Hub must check +server membership, use server nicknames, manage roles, or send messages and +direct notifications. For these functions: + +1. Add a bot to the Discord application and copy its token to + `discord_bot_token`. +2. Copy the ID of the Discord server to `discord_guild_id`. +3. Install the bot in that server. + +Give the bot only the permissions that these functions need. It needs access to +channels where it sends messages. Give it **Manage Roles** if the Hub must +change roles. Put the bot role above every role that it must manage. + +If you do not install a bot, use these settings: + +```json +"must_join_guild": false, +"use_server_nickname": false, +"discord_guild_id": "", +"discord_bot_token": "" +``` + +The external `discord-member` plugin also requires the bot, but the built-in +functions listed above do not depend on that plugin. The [Discord OAuth2 documentation](https://docs.discord.com/developers/topics/oauth2) explains application installation and OAuth2 settings. @@ -164,6 +183,24 @@ connect. Add `truckersmp` if a TruckersMP connection is mandatory. For example: Restart the backend after you change these settings. You do not have to rebuild an image for changes in `config/config.json`. +## Edit the configuration in the Hub + +The administration interface can save and apply application configuration +changes. The container sets the owner of the bind-mounted `config/` directory +to its internal user, UID and GID `10001`, when it starts. It then runs the +backend as that unprivileged user. This lets the backend create +`config.json.saved` and replace `config.json`. Both files stay in the project +directory on the host. + +The administrator needs the `update_config` permission to save changes and the +`reload_config` permission to apply them. The default `administrator` +permission also grants access to these operations. The administrator must +enable MFA before applying a saved configuration. + +The start process can change the numeric owner of files in `config/` to +`10001:10001` on the host. Use an account with sufficient permissions when you +edit these files directly. Do not make the directory writable by all users. + ## Start the deployment ```bash diff --git a/docker/entrypoint.sh b/docker/entrypoint.sh index 2893a28..af566fa 100755 --- a/docker/entrypoint.sh +++ b/docker/entrypoint.sh @@ -2,6 +2,10 @@ # Start a compiled program. set -eu +if [ "$(id -u)" = "0" ] && [ -d /app/config ]; then + chown -R drivershub:drivershub /app/config +fi + if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)" if [ -z "$proxy_ip" ]; then @@ -13,12 +17,12 @@ fi if [ "${1:-}" = "drivershub" ]; then shift - exec /app/drivershub "$@" + exec gosu drivershub /app/drivershub "$@" fi if [ "${1:-}" = "bannergen" ]; then shift - exec /app/bannergen "$@" + exec gosu drivershub /app/bannergen "$@" fi -exec "$@" +exec gosu drivershub "$@"