Enable web-based configuration updates

This commit is contained in:
2026-08-25 12:45:21 +00:00
parent ff17c46b2c
commit 00b71e0f1f
3 changed files with 51 additions and 11 deletions
+1 -2
View File
@@ -33,7 +33,7 @@ RUN --mount=type=cache,target=/root/.cache/pip \
FROM debian:trixie-slim AS runtime FROM debian:trixie-slim AS runtime
RUN apt-get update \ RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates iproute2 \ && apt-get install -y --no-install-recommends ca-certificates gosu iproute2 \
&& rm -rf /var/lib/apt/lists/* \ && rm -rf /var/lib/apt/lists/* \
&& groupadd --system --gid 10001 drivershub \ && groupadd --system --gid 10001 drivershub \
&& useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub && useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub
@@ -44,7 +44,6 @@ COPY --from=builder --chown=drivershub:drivershub /build/dist/ ./
COPY --from=builder --chown=drivershub:drivershub /build/src/external_plugins/ ./external_plugins/ COPY --from=builder --chown=drivershub:drivershub /build/src/external_plugins/ ./external_plugins/
COPY --chown=root:root docker/entrypoint.sh /usr/local/bin/drivershub-entrypoint COPY --chown=root:root docker/entrypoint.sh /usr/local/bin/drivershub-entrypoint
USER drivershub
EXPOSE 7777 8700 EXPOSE 7777 8700
ENTRYPOINT ["drivershub-entrypoint"] ENTRYPOINT ["drivershub-entrypoint"]
+43 -6
View File
@@ -107,16 +107,35 @@ configure it as follows:
2. Copy the application ID to `discord_client_id` in 2. Copy the application ID to `discord_client_id` in
`config/config.json`. `config/config.json`.
3. Create a client secret and copy it to `discord_client_secret`. 3. Create a client secret and copy it to `discord_client_secret`.
4. Add a bot to the application and copy its token to `discord_bot_token`.
5. Copy the ID of the Discord server to `discord_guild_id`.
6. Install the bot in that server.
The callback URL points to the frontend. Do not add `/api` to it. The frontend The callback URL points to the frontend. Do not add `/api` to it. The frontend
requests the `identify`, `email`, and `role_connections.write` OAuth scopes. requests the `identify`, `email`, and `role_connections.write` OAuth scopes.
Give the bot only the permissions that your configuration needs. It needs This configuration is sufficient for Discord sign-in and account connections.
access to channels where it sends messages. Give it **Manage Roles** if the Hub A Discord bot is optional. Create and install a bot only if the Hub must check
must change roles. Put the bot role above every role that it must manage. The server membership, use server nicknames, manage roles, or send messages and
direct notifications. For these functions:
1. Add a bot to the Discord application and copy its token to
`discord_bot_token`.
2. Copy the ID of the Discord server to `discord_guild_id`.
3. Install the bot in that server.
Give the bot only the permissions that these functions need. It needs access to
channels where it sends messages. Give it **Manage Roles** if the Hub must
change roles. Put the bot role above every role that it must manage.
If you do not install a bot, use these settings:
```json
"must_join_guild": false,
"use_server_nickname": false,
"discord_guild_id": "",
"discord_bot_token": ""
```
The external `discord-member` plugin also requires the bot, but the built-in
functions listed above do not depend on that plugin. The
[Discord OAuth2 documentation](https://docs.discord.com/developers/topics/oauth2) [Discord OAuth2 documentation](https://docs.discord.com/developers/topics/oauth2)
explains application installation and OAuth2 settings. explains application installation and OAuth2 settings.
@@ -164,6 +183,24 @@ connect. Add `truckersmp` if a TruckersMP connection is mandatory. For example:
Restart the backend after you change these settings. You do not have to rebuild Restart the backend after you change these settings. You do not have to rebuild
an image for changes in `config/config.json`. an image for changes in `config/config.json`.
## Edit the configuration in the Hub
The administration interface can save and apply application configuration
changes. The container sets the owner of the bind-mounted `config/` directory
to its internal user, UID and GID `10001`, when it starts. It then runs the
backend as that unprivileged user. This lets the backend create
`config.json.saved` and replace `config.json`. Both files stay in the project
directory on the host.
The administrator needs the `update_config` permission to save changes and the
`reload_config` permission to apply them. The default `administrator`
permission also grants access to these operations. The administrator must
enable MFA before applying a saved configuration.
The start process can change the numeric owner of files in `config/` to
`10001:10001` on the host. Use an account with sufficient permissions when you
edit these files directly. Do not make the directory writable by all users.
## Start the deployment ## Start the deployment
```bash ```bash
+7 -3
View File
@@ -2,6 +2,10 @@
# Start a compiled program. # Start a compiled program.
set -eu set -eu
if [ "$(id -u)" = "0" ] && [ -d /app/config ]; then
chown -R drivershub:drivershub /app/config
fi
if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then
proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)" proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)"
if [ -z "$proxy_ip" ]; then if [ -z "$proxy_ip" ]; then
@@ -13,12 +17,12 @@ fi
if [ "${1:-}" = "drivershub" ]; then if [ "${1:-}" = "drivershub" ]; then
shift shift
exec /app/drivershub "$@" exec gosu drivershub /app/drivershub "$@"
fi fi
if [ "${1:-}" = "bannergen" ]; then if [ "${1:-}" = "bannergen" ]; then
shift shift
exec /app/bannergen "$@" exec gosu drivershub /app/bannergen "$@"
fi fi
exec "$@" exec gosu drivershub "$@"