feat: 基于新的模板更新脚本及Dockerfile文件
This commit is contained in:
+44
-68
@@ -1,9 +1,8 @@
|
||||
# Ver: 1.9 by Endial Fang (endial@126.com)
|
||||
# Ver: 1.12 by Endial Fang (endial@126.com)
|
||||
#
|
||||
|
||||
# 默认变量 ========================================================================
|
||||
# 系统默认变量 ====================================================================
|
||||
# 该部分变量为系统根据编译命令默认设置
|
||||
|
||||
# `TARGETPLATFORM`:构建后的目标平台信息。如 `linux/amd64`,`linux/arm/v7`,`windows/amd64`
|
||||
# `TARGETOS`:目标平台信息(TARGETPLATFORM)中的操作系统部分,如:`linux`、`windows`
|
||||
# `TARGETARCH`:目标平台信息(TARGETPLATFORM)中的平台架构部分,如:`amd64`、`arm`
|
||||
@@ -16,18 +15,11 @@
|
||||
# 可变参数 ========================================================================
|
||||
# 该部分变量,在编译命令中通过 `--build-arg` 传入;如果未设置,则使用下面对应的默认值
|
||||
|
||||
# 设置当前应用名称及版本
|
||||
ARG APP_NAME=postgresql
|
||||
ARG APP_VER=15.4
|
||||
|
||||
# 设置默认仓库地址,默认为本地仓库;定义时需要包含末尾的`/`
|
||||
ARG REGISTRY_URL="docker.colovu.com/"
|
||||
|
||||
# 设置 apt-get 源:default / ustc / aliyun
|
||||
ARG APT_SOURCE=aliyun
|
||||
|
||||
# 编译镜像时指定用于加速的本地软件包存储服务器地址
|
||||
ARG LOCAL_URL="http://local.colovu.com/dist"
|
||||
ARG APP_NAME=postgresql # 设置当前应用名称
|
||||
ARG APP_VER=15.4 # 设置当前应用版本
|
||||
ARG REGISTRY_URL="docker.colovu.com/" # 设置默认仓库地址,默认为本地仓库;定义时需要包含末尾的`/`
|
||||
ARG APT_SOURCE=aliyun # 设置 apt-get 源:default / ustc / aliyun
|
||||
ARG LOCAL_URL="http://local.colovu.com/dist" # 编译镜像时指定用于加速的本地软件包存储服务器地址
|
||||
|
||||
# 0. 预处理 ======================================================================
|
||||
FROM --platform=${TARGETPLATFORM:-linux/amd64} ${REGISTRY_URL}colovu/dbuilder:12 as builder
|
||||
@@ -38,21 +30,18 @@ ARG APP_VER
|
||||
ARG APT_SOURCE
|
||||
ARG LOCAL_URL
|
||||
|
||||
# 选择软件包源(Optional),以加速后续软件包安装
|
||||
# 选择软件包源,加速后续软件包安装
|
||||
RUN select_source ${APT_SOURCE};
|
||||
|
||||
# 安装依赖的软件包及库(Optional)
|
||||
# 安装依赖的软件包及库
|
||||
RUN install_pkg bison flex libedit-dev libxml2-dev libxslt-dev zlib1g-dev libreadline-dev uuid-dev \
|
||||
libperl-dev libicu-dev libxslt1-dev libssl-dev libldap2-dev libkrb5-dev libpam0g-dev libselinux1-dev;
|
||||
|
||||
# 设置工作目录
|
||||
WORKDIR /tmp
|
||||
|
||||
# 下载并解压软件包
|
||||
RUN set -eux; \
|
||||
appName="${APP_NAME}-${APP_VER}.tar.gz"; \
|
||||
sha256="0e11eee723dd7e59a634052bc1bfc9be605e55c1cca3f66e9fc25d3a394fb030"; \
|
||||
[ -n ${LOCAL_URL} ] && localURL=${LOCAL_URL}/${APP_NAME}/v${APP_VER}; \
|
||||
[ -n ${LOCAL_URL} ] && localURL=${LOCAL_URL}/${APP_NAME}; \
|
||||
appUrls="${localURL:-} \
|
||||
https://ftp.postgresql.org/pub/source/v${APP_VER} \
|
||||
"; \
|
||||
@@ -62,6 +51,7 @@ RUN set -eux; \
|
||||
RUN set -eux; \
|
||||
APP_ARCH=`arch` \
|
||||
APP_SRC="/tmp/${APP_NAME}-${APP_VER}"; \
|
||||
dpkgArch="$(dpkg --print-architecture)"; \
|
||||
cd ${APP_SRC}; \
|
||||
\
|
||||
# update "DEFAULT_PGSOCKET_DIR" to "/var/run/postgresql" (matching Debian)
|
||||
@@ -107,8 +97,7 @@ RUN set -eux; \
|
||||
# --with-python \
|
||||
# --with-pam \
|
||||
; \
|
||||
make -j "$(nproc)" world; \
|
||||
make install-world; \
|
||||
make -j "$(nproc)" world && make install-world; \
|
||||
make -C contrib install;
|
||||
|
||||
# 删除编译生成的多余文件
|
||||
@@ -119,12 +108,9 @@ RUN set -eux; \
|
||||
# 检测并生成依赖文件记录
|
||||
RUN set -eux; \
|
||||
find /usr/local/${APP_NAME} -type f -executable -exec ldd '{}' ';' | \
|
||||
awk '/=>/ { print $(NF-1) }' | \
|
||||
sort -u | \
|
||||
xargs -r readlink -f | \
|
||||
xargs -r dpkg-query --search 2>/dev/null | \
|
||||
cut -d: -f1 | \
|
||||
sort -u >>/usr/local/${APP_NAME}/runDeps;
|
||||
awk '/=>/ { print $(NF-1) }' | xargs -r basename -a | sort -u | \
|
||||
xargs -r dpkg-query --search 2>/dev/null | cut -d: -f1 | sort -u \
|
||||
>>/usr/local/${APP_NAME}/runDeps;
|
||||
|
||||
# 1. 生成镜像 =====================================================================
|
||||
FROM --platform=${TARGETPLATFORM:-linux/amd64} ${REGISTRY_URL}colovu/debian:12
|
||||
@@ -138,12 +124,10 @@ ARG APT_SOURCE
|
||||
ENV APP_NAME=${APP_NAME} \
|
||||
APP_VER=${APP_VER} \
|
||||
APP_EXEC=postgres \
|
||||
APP_HOME_DIR=/usr/local/${APP_NAME} \
|
||||
APP_DEF_DIR=/etc/${APP_NAME}
|
||||
|
||||
# 增加应用可执行文件及库文件搜索路径
|
||||
ENV PATH="${APP_HOME_DIR}/sbin:${APP_HOME_DIR}/bin:${PATH}" \
|
||||
LD_LIBRARY_PATH="${APP_HOME_DIR}/lib"
|
||||
APP_USER=postgres \
|
||||
\
|
||||
LD_LIBRARY_PATH="/usr/local/${APP_NAME}/lib" \
|
||||
PATH="${PATH}:/usr/local/${APP_NAME}/bin"
|
||||
|
||||
LABEL \
|
||||
"Version"="v${APP_VER}" \
|
||||
@@ -151,54 +135,46 @@ LABEL \
|
||||
"Github"="https://github.com/colovu/docker-${APP_NAME}" \
|
||||
"Vendor"="Endial Fang (endial@126.com)"
|
||||
|
||||
# 从预处理过程中拷贝软件包(Optional),可以使用阶段编号或阶段命名定义来源
|
||||
# 拷贝多阶段构建结果输出及客制化脚本
|
||||
COPY --from=builder /usr/local/${APP_NAME} /usr/local/${APP_NAME}
|
||||
|
||||
# 拷贝应用使用的客制化脚本
|
||||
COPY customer /
|
||||
|
||||
RUN set -eux; \
|
||||
\
|
||||
# 创建对应的用户及数据存储目录
|
||||
prepare_env; \
|
||||
useradd -U -u 996 -d /srv/${APP_NAME} -s /usr/sbin/nologin -r ${APP_USER}; \
|
||||
mkdir -p /var/log/${APP_NAME} /var/run/${APP_NAME} /var/cache/${APP_NAME}; \
|
||||
mkdir -p /srv/${APP_NAME}/conf /srv/${APP_NAME}/data /srv/${APP_NAME}/cert /srv/${APP_NAME}/log; \
|
||||
chown -R ${APP_USER}:${APP_USER} /var/log/${APP_NAME} /var/run/${APP_NAME} /var/cache/${APP_NAME}; \
|
||||
chown -R ${APP_USER}:${APP_USER} /usr/local/${APP_NAME} /srv/${APP_NAME}; \
|
||||
\
|
||||
# 选择软件包源(Optional),以加速后续软件包安装
|
||||
/bin/bash -c "ln -sf /usr/local/${APP_NAME}/etc/${APP_NAME} /etc/"; \
|
||||
\
|
||||
# 选择软件包源,以加速后续软件包安装
|
||||
select_source ${APT_SOURCE}; \
|
||||
\
|
||||
# 安装依赖的软件包及库(Optional)
|
||||
# 安装应用依赖的软件包及库
|
||||
install_pkg `cat /usr/local/${APP_NAME}/runDeps`; \
|
||||
\
|
||||
# 执行后处理脚本,并验证安装的应用
|
||||
override_file="/usr/local/overrides/overrides-${APP_VER}.sh"; \
|
||||
[ -e "${override_file}" ] && /bin/bash "${override_file}"; \
|
||||
postgres --version ;
|
||||
# 执行后处理脚本
|
||||
overrideShell="/usr/local/overrides/overrides-${APP_VER}.sh"; \
|
||||
[ -e "${overrideShell}" ] && /bin/bash "${overrideShell}"; \
|
||||
\
|
||||
# 验证安装的应用
|
||||
${APP_EXEC} --version ;
|
||||
|
||||
# 默认提供的数据卷
|
||||
VOLUME ["/srv/conf", "/srv/data", "/srv/datalog", "/srv/cert", "/var/log"]
|
||||
|
||||
# 默认使用gosu切换为新建用户启动,必须保证端口在1024之上
|
||||
# 配置容器的数据卷、工作目录及服务端口(必须保证端口在1024之上)
|
||||
VOLUME ["/srv/${APP_NAME}/conf", "/srv/${APP_NAME}/data", "/srv/${APP_NAME}/cert", "/srv/${APP_NAME}/log"]
|
||||
WORKDIR /srv/${APP_NAME}/data
|
||||
EXPOSE 5432
|
||||
STOPSIGNAL SIGINT
|
||||
|
||||
# 关闭基础镜像的健康检查
|
||||
#HEALTHCHECK NONE
|
||||
|
||||
# 应用健康状态检查(需要使用 EXPOSE 定义的端口)
|
||||
#HEALTHCHECK --interval=30s --timeout=30s --retries=3 \
|
||||
# CMD curl -fs http://localhost:8080/ || exit 1
|
||||
#HEALTHCHECK --interval=10s --timeout=10s --retries=3 \
|
||||
# CMD netstat -ltun | grep 8080
|
||||
#HEALTHCHECK --interval=30s --timeout=30s --retries=3 CMD curl -fs http://localhost:8080/ || exit 1
|
||||
#HEALTHCHECK --interval=10s --timeout=10s --retries=3 CMD netstat -ltun | grep 8080
|
||||
HEALTHCHECK CMD PGPASSWORD="${PG_POSTGRES_PASSWORD:-${PG_PASSWORD}}" psql -h 127.0.0.1 -d postgres -U postgres -At -c "select version();" || exit 1
|
||||
|
||||
# 使用 non-root 用户运行后续的命令
|
||||
USER 1001
|
||||
|
||||
# 设置工作目录
|
||||
WORKDIR /srv/data
|
||||
|
||||
# 容器入口命令脚本,'/usr/local/bin/entry.sh'
|
||||
ENTRYPOINT ["entry.sh"]
|
||||
|
||||
# 应用程序的启动命令,可为应用程序可执行命令或脚本
|
||||
# 必须使用非守护进程方式运行,'/usr/local/bin/run.sh'
|
||||
CMD ["run.sh"]
|
||||
# 使用 dumb-init 启动入口 Shell,确保容器可以接收控制信号;并使用前台方式启动应用程序
|
||||
ENTRYPOINT ["dumb-init", "entry.sh"]
|
||||
CMD ["run.sh"]
|
||||
|
||||
|
||||
+482
-663
File diff suppressed because it is too large
Load Diff
@@ -1,29 +1,37 @@
|
||||
#!/bin/bash
|
||||
# Ver: 1.3 by Endial Fang (endial@126.com)
|
||||
#!/usr/bin/dumb-init /bin/bash
|
||||
# Ver: 1.5 by Endial Fang (endial@126.com)
|
||||
#
|
||||
# 容器入口脚本
|
||||
# 容器入口脚本;当前脚本执行完毕时,使用默认用户执行镜像 CMD 定义的命令(默认为'/usr/local/bin/run.sh')
|
||||
|
||||
# 设置 shell 执行参数,可使用'-'(打开)'+'(关闭)控制。常用:
|
||||
# -e: 命令执行错误则报错(errexit); -u: 变量未定义则报错(nounset); -x: 打印实际待执行的命令行; -o pipefail: 设置管道中命令遇到失败则报错
|
||||
set -eu
|
||||
set -o pipefail
|
||||
set -euo pipefail
|
||||
|
||||
. /colovu/lib/libcommon.sh # 加载通用函数库
|
||||
. /colovu/lib/libcommon.sh # 加载通用函数库
|
||||
|
||||
. /usr/local/bin/environment.sh # 设置环境变量
|
||||
|
||||
LOG_I "** Processing entry.sh **"
|
||||
|
||||
if [[ "$*" = "/usr/local/bin/run.sh" ]]; then
|
||||
print_image_welcome
|
||||
# 优先处理'-'开始的版本信息、帮助信息显示命令,如果是该类命令,处理后退出容器
|
||||
[[ "${1:0:1}" == '-' ]] && set -- "${APP_EXEC:-/bin/bash}" "$@" && print_command_help "$@"
|
||||
|
||||
LOG_I "** Starting ${APP_NAME} setup **"
|
||||
# 处理 root 用户**且**使用默认启动脚本时的初始化
|
||||
if [[ "$(id -u)" == '0' ]] && [[ "$1" == "run.sh" ]]; then
|
||||
print_welcome_info
|
||||
/usr/local/bin/setup.sh
|
||||
/usr/local/bin/init.sh
|
||||
LOG_I "** ${APP_NAME} setup finished! **"
|
||||
gosu "${APP_USER}" /usr/local/bin/init.sh
|
||||
|
||||
# 执行应用启动脚本并替换当前进程
|
||||
exec gosu "${APP_USER}" "$@"
|
||||
fi
|
||||
|
||||
# 检测是否仅打印帮助信息
|
||||
[ "${1:0:1}" = '-' ] && set -- "${APP_EXEC:-/bin/bash}" "$@"
|
||||
print_command_help "$@"
|
||||
# 处理 root 用户**且**使用init.sh脚本时的初始化
|
||||
if [[ "$(id -u)" == '0' ]] && [[ "$1" == "init.sh" ]]; then
|
||||
/usr/local/bin/setup.sh
|
||||
gosu "${APP_USER}" /usr/local/bin/init.sh
|
||||
fi
|
||||
|
||||
# 处理非以上情形的自定义命令
|
||||
LOG_I "Start container with command: $@"
|
||||
exec "$@"
|
||||
|
||||
@@ -1,11 +1,10 @@
|
||||
#!/bin/bash
|
||||
# Ver: 1.1 by Endial Fang (endial@126.com)
|
||||
# Ver: 1.2 by Endial Fang (endial@126.com)
|
||||
#
|
||||
# 应用环境变量定义及初始化
|
||||
|
||||
# 通用设置
|
||||
export ENV_DEBUG=${ENV_DEBUG:-false}
|
||||
export ALLOW_ANONYMOUS_LOGIN="${ALLOW_ANONYMOUS_LOGIN:-no}"
|
||||
export ALLOW_ANONYMOUS="${ALLOW_ANONYMOUS:-no}"
|
||||
|
||||
# 通过读取变量名对应的 *_FILE 文件,获取变量值;如果对应文件存在,则通过传入参数设置的变量值会被文件中对应的值覆盖
|
||||
# 变量优先级: *_FILE > 传入变量 > 默认值
|
||||
@@ -13,7 +12,6 @@ app_env_file_lists=(
|
||||
PG_POSTGRES_PASSWORD
|
||||
PG_PASSWORD
|
||||
PG_REPLICATION_PASSWORD
|
||||
PG_LDAP_BIND_PASSWORD
|
||||
)
|
||||
for env_var in "${app_env_file_lists[@]}"; do
|
||||
file_env_var="${env_var}_FILE"
|
||||
@@ -24,96 +22,97 @@ for env_var in "${app_env_file_lists[@]}"; do
|
||||
done
|
||||
unset app_env_file_lists
|
||||
|
||||
# 应用路径参数
|
||||
export APP_HOME_DIR="/usr/local/${APP_NAME}"
|
||||
export APP_DEF_DIR="/etc/${APP_NAME}"
|
||||
export APP_CONF_DIR="/srv/conf/${APP_NAME}"
|
||||
export APP_DATA_DIR="/srv/data/${APP_NAME}"
|
||||
export APP_DATA_LOG_DIR="/srv/datalog/${APP_NAME}"
|
||||
# 应用路径参数(Dockerfile 已定义:APP_NAME、APP_VER,可能定义 APP_USER、APP_EXEC)
|
||||
export APP_EXEC="${APP_EXEC:-${APP_NAME}}"
|
||||
export APP_USER="${APP_USER:-${APP_NAME}}"
|
||||
export APP_GROUP="${APP_USER:-${APP_NAME}}"
|
||||
export APP_HOME="${APP_HOME:-/srv/${APP_NAME}}"
|
||||
export APP_BASE="${APP_BASE:-/usr/local/${APP_NAME}}"
|
||||
|
||||
export APP_DEF_DIR="${APP_BASE}/etc/${APP_NAME}"
|
||||
export APP_CONF_DIR="/srv/${APP_NAME}/conf"
|
||||
export APP_DATA_DIR="/srv/${APP_NAME}/data"
|
||||
export APP_CERT_DIR="/srv/${APP_NAME}/cert"
|
||||
export APP_LOG_DIR="/srv/${APP_NAME}/log"
|
||||
export APP_CACHE_DIR="/var/cache/${APP_NAME}"
|
||||
export APP_RUN_DIR="/var/run/${APP_NAME}"
|
||||
export APP_LOG_DIR="/var/log/${APP_NAME}"
|
||||
export APP_CERT_DIR="/srv/cert/${APP_NAME}"
|
||||
|
||||
export PG_DATA_DIR="${APP_DATA_DIR}/data"
|
||||
export PGDATA="${PGDATA:-${APP_DATA_DIR}}"
|
||||
export TZ=${TZ:-"Asia/Shanghai"}
|
||||
|
||||
export PG_CONF_FILE="${APP_CONF_DIR}/postgresql.conf"
|
||||
export PG_HBA_FILE="${APP_CONF_DIR}/pg_hba.conf"
|
||||
export PG_RECOVERY_FILE="${PG_DATA_DIR}/recovery.conf"
|
||||
export PG_IDENT_FILE="${PG_DATA_DIR}/pg_ident.conf"
|
||||
export PG_EXT_PID_FILE="${APP_RUN_DIR}/postgresql.pid"
|
||||
export PG_LOG_FILE="${APP_LOG_DIR}/postgresql.log"
|
||||
export PG_CONF_FILE="${PG_CONF_FILE:-${PGDATA}/postgresql.conf}"
|
||||
export PG_PID_FILE="${PG_PID_FILE:-${PGDATA}/postmaster.pid}"
|
||||
export PG_INIT_MAX_TIMEOUT=${PG_INIT_MAX_TIMEOUT:-60}
|
||||
export PG_REPLICATION_MODE="${PG_REPLICATION_MODE:-primary}"
|
||||
|
||||
if [[ "${PG_REPLICATION_MODE}" == "primary" ]]; then
|
||||
export PG_SYNCHRONOUS_REPLICAS_NUM="${PG_SYNCHRONOUS_REPLICAS_NUM:-0}"
|
||||
export PG_SYNCHRONOUS_REPLICAS_METHOD="${PG_SYNCHRONOUS_REPLICAS_METHOD:-}"
|
||||
export PG_SYNCHRONOUS_REPLICAS_NAMES="${PG_SYNCHRONOUS_REPLICAS_NAMES:-\*}"
|
||||
|
||||
export PG_CFG_MAX_WAL_SENDERS="${PG_CFG_MAX_WAL_SENDERS:-10}"
|
||||
export PG_CFG_WAL_LEVEL="${PG_CFG_WAL_LEVEL:-logical}"
|
||||
export PG_CFG_WAL_LOG_HINTS="${PG_CFG_WAL_LOG_HINTS:-on}"
|
||||
|
||||
elif [[ "${PG_REPLICATION_MODE}" == "standby" ]]; then
|
||||
export PG_REPLICATION_APP_NAME=${PG_REPLICATION_APP_NAME:-cvcluster}
|
||||
export PG_REPLICATION_HOST="${PG_REPLICATION_HOST:-}"
|
||||
export PG_REPLICATION_PORT="${PG_REPLICATION_PORT:-5432}"
|
||||
export PG_REPLICATION_USER="${PG_REPLICATION_USER:-}"
|
||||
export PG_REPLICATION_PASSWORD="${PG_REPLICATION_PASSWORD:-}"
|
||||
export PG_REPLICATION_CONNECT_TIMEOUT="${PG_REPLICATION_CONNECT_TIMEOUT:-10}"
|
||||
|
||||
# 配置允许从备机备份,参考:http://www.postgres.cn/docs/9.4/app-pgbasebackup.html
|
||||
export PG_CFG_FULL_PAGE_WRITES="${PG_CFG_FULL_PAGE_WRITES:-on}"
|
||||
export PG_CFG_HOT_STANDBY="${PG_CFG_HOT_STANDBY:-on}"
|
||||
export PG_CFG_MAX_WAL_SENDERS="${PG_CFG_MAX_WAL_SENDERS:-16}"
|
||||
fi
|
||||
|
||||
# 应用配置参数
|
||||
export PG_CLUSTER_APP_NAME=${PG_CLUSTER_APP_NAME:-cvcluster}
|
||||
export PG_REPLICATION_MODE="${PG_REPLICATION_MODE:-primary}"
|
||||
export PG_PRIMARY_HOST="${PG_PRIMARY_HOST:-}"
|
||||
export PG_PRIMARY_PORT="${PG_PRIMARY_PORT:-5432}"
|
||||
export PG_NUM_SYNCHRONOUS_REPLICAS="${PG_NUM_SYNCHRONOUS_REPLICAS:-0}"
|
||||
export PG_REPLICATION_USER="${PG_REPLICATION_USER:-}"
|
||||
export PG_REPLICATION_PASSWORD="${PG_REPLICATION_PASSWORD:-}"
|
||||
export PG_SYNCHRONOUS_COMMIT_MODE="${PG_SYNCHRONOUS_COMMIT_MODE:-on}"
|
||||
export PG_FSYNC="${PG_FSYNC:-on}"
|
||||
export PG_INIT_MAX_TIMEOUT=${PG_INIT_MAX_TIMEOUT:-60}
|
||||
export PG_INITDB_ARGS="${PG_INITDB_ARGS:-}"
|
||||
export PG_INITDB_WAL_DIR="${PG_INITDB_WAL_DIR:-}"
|
||||
export PG_PORT_NUMBER="${PG_PORT_NUMBER:-5432}"
|
||||
export PG_SHARED_PRELOAD_LIBRARIES="${PG_SHARED_PRELOAD_LIBRARIES:-}"
|
||||
export PG_USERNAME_CONNECTION_LIMIT="${PG_USERNAME_CONNECTION_LIMIT:-}"
|
||||
export PG_POSTGRES_CONNECTION_LIMIT="${PG_POSTGRES_CONNECTION_LIMIT:-}"
|
||||
|
||||
export PG_ENABLE_LDAP="${PG_ENABLE_LDAP:-no}"
|
||||
export PG_LDAP_URL="${PG_LDAP_URL:-}"
|
||||
export PG_LDAP_PREFIX="${PG_LDAP_PREFIX:-}"
|
||||
export PG_LDAP_SUFFIX="${PG_LDAP_SUFFIX:-}"
|
||||
export PG_LDAP_SERVER="${PG_LDAP_SERVER:-}"
|
||||
export PG_LDAP_PORT="${PG_LDAP_PORT:-}"
|
||||
export PG_LDAP_SCHEME="${PG_LDAP_SCHEME:-}"
|
||||
export PG_LDAP_TLS="${PG_LDAP_TLS:-}"
|
||||
export PG_LDAP_BASE_DN="${PG_LDAP_BASE_DN:-}"
|
||||
export PG_LDAP_BIND_DN="${PG_LDAP_BIND_DN:-}"
|
||||
export PG_LDAP_BIND_PASSWORD="${PG_LDAP_BIND_PASSWORD:-}"
|
||||
export PG_LDAP_SEARCH_ATTR="${PG_LDAP_SEARCH_ATTR:-}"
|
||||
export PG_LDAP_SEARCH_FILTER="${PG_LDAP_SEARCH_FILTER:-}"
|
||||
if [[ ${PG_ENABLE_LDAP} == yes ]]; then
|
||||
export PG_LDAP_URL="${PG_LDAP_URL:-}"
|
||||
|
||||
export PG_ENABLE_TLS="${PG_ENABLE_TLS:-no}"
|
||||
export PG_TLS_CERT_FILE="${PG_TLS_CERT_FILE:-}"
|
||||
export PG_TLS_KEY_FILE="${PG_TLS_KEY_FILE:-}"
|
||||
export PG_TLS_CA_FILE="${PG_TLS_CA_FILE:-}"
|
||||
export PG_TLS_CRL_FILE="${PG_TLS_CRL_FILE:-}"
|
||||
export PG_TLS_PREFER_SERVER_CIPHERS="${PG_TLS_PREFER_SERVER_CIPHERS:-yes}"
|
||||
export PG_LDAP_PREFIX="${PG_LDAP_PREFIX:-}"
|
||||
export PG_LDAP_SUFFIX="${PG_LDAP_SUFFIX:-}"
|
||||
export PG_LDAP_SERVER="${PG_LDAP_SERVER:-}"
|
||||
export PG_LDAP_PORT="${PG_LDAP_PORT:-}"
|
||||
export PG_LDAP_SCHEME="${PG_LDAP_SCHEME:-}"
|
||||
export PG_LDAP_TLS="${PG_LDAP_TLS:-}"
|
||||
export PG_LDAP_BASE_DN="${PG_LDAP_BASE_DN:-}"
|
||||
export PG_LDAP_BIND_DN="${PG_LDAP_BIND_DN:-}"
|
||||
export PG_LDAP_BIND_PASSWORD="${PG_LDAP_BIND_PASSWORD:-}"
|
||||
export PG_LDAP_SEARCH_ATTR="${PG_LDAP_SEARCH_ATTR:-}"
|
||||
export PG_LDAP_SEARCH_FILTER="${PG_LDAP_SEARCH_FILTER:-}"
|
||||
fi
|
||||
|
||||
export PG_PGAUDIT_LOG="${PG_PGAUDIT_LOG:-}"
|
||||
export PG_PGAUDIT_LOG_CATALOG="${PG_PGAUDIT_LOG_CATALOG:-}"
|
||||
export PG_LOG_CONNECTIONS="${PG_LOG_CONNECTIONS:-}"
|
||||
export PG_LOG_DISCONNECTIONS="${PG_LOG_DISCONNECTIONS:-}"
|
||||
export PG_LOG_HOSTNAME="${PG_LOG_HOSTNAME:-}"
|
||||
export PG_CLIENT_MIN_MESSAGES="${PG_CLIENT_MIN_MESSAGES:-error}"
|
||||
export PG_LOG_LINE_PREFIX="${PG_LOG_LINE_PREFIX:-}"
|
||||
export PG_LOG_TIMEZONE="${PG_LOG_TIMEZONE:-}"
|
||||
|
||||
export PG_MAX_CONNECTIONS="${PG_MAX_CONNECTIONS:-}"
|
||||
export PG_TCP_KEEPALIVES_IDLE="${PG_TCP_KEEPALIVES_IDLE:-}"
|
||||
export PG_TCP_KEEPALIVES_INTERVAL="${PG_TCP_KEEPALIVES_INTERVAL:-}"
|
||||
export PG_TCP_KEEPALIVES_COUNT="${PG_TCP_KEEPALIVES_COUNT:-}"
|
||||
export PG_STATEMENT_TIMEOUT="${PG_STATEMENT_TIMEOUT:-}"
|
||||
export PG_INITDB_ARGS="${PG_INITDB_ARGS:-}"
|
||||
export PG_INITDB_WAL_DIR="${PG_INITDB_WAL_DIR:-${PGDATA}/pg_wal}"
|
||||
export PG_USER_CONNECTION_LIMIT="${PG_USER_CONNECTION_LIMIT:-}"
|
||||
export PG_DB_CONNECTION_LIMIT="${PG_DB_CONNECTION_LIMIT:-}"
|
||||
export PG_USER_IP4_RANGE="${PG_IP4_RANGE:-0.0.0.0/0}"
|
||||
export PG_USER_IP6_RANGE="${PG_IP6_RANGE:-::0/0}"
|
||||
export PG_REPLICATION_IP4_RANGE="${PG_REPLICATION_IP4_RANGE:-${PG_USER_IP4_RANGE}}"
|
||||
export PG_REPLICATION_IP6_RANGE="${PG_REPLICATION_IP6_RANGE:-${PG_USER_IP6_RANGE}}"
|
||||
|
||||
export PG_USERNAME="${PG_USERNAME:-postgres}"
|
||||
export PG_PASSWORD="${PG_PASSWORD:-}"
|
||||
export PG_DATABASE="${PG_DATABASE:-postgres}"
|
||||
# 使用自定义用户名(非"postgres")时的管理员密码
|
||||
[[ "${PG_USERNAME}" = "postgres" ]] && PG_POSTGRES_PASSWORD="${PG_PASSWORD}"
|
||||
export PG_POSTGRES_PASSWORD="${PG_POSTGRES_PASSWORD:-}"
|
||||
|
||||
# 使用自定义用户名(非"postgres")时的管理员密码
|
||||
[[ "${PG_USERNAME}" == "postgres" ]] && export PG_POSTGRES_PASSWORD="${PG_PASSWORD}"
|
||||
|
||||
# 用来执行初始化数据库命令的用户名及密码
|
||||
export PG_INITSCRIPTS_USERNAME="${PG_INITSCRIPTS_USERNAME:-${PG_USERNAME}}"
|
||||
export PG_INITSCRIPTS_PASSWORD="${PG_INITSCRIPTS_PASSWORD:-${PG_PASSWORD}}"
|
||||
|
||||
export PGCONNECT_TIMEOUT="${PGCONNECT_TIMEOUT:-10}"
|
||||
|
||||
# 内部变量
|
||||
export PG_FIRST_BOOT="yes"
|
||||
|
||||
export APP_DAEMON_USER="${APP_NAME}"
|
||||
export APP_DAEMON_GROUP="${APP_NAME}"
|
||||
|
||||
# 个性化变量
|
||||
|
||||
export PG_CFG_DATA_DIRECTORY="${PGDATA}"
|
||||
export PG_CFG_HBA_FILE="${PGDATA}/pg_hba.conf"
|
||||
export PG_CFG_IDENT_FILE="${PGDATA}/pg_ident.conf"
|
||||
export PG_CFG_EXTERNAL_PID_FILE="${APP_RUN_DIR}/postgresql.pid"
|
||||
export PG_CFG_LOG_DIRECTORY="${APP_LOG_DIR}"
|
||||
|
||||
@@ -1,29 +1,25 @@
|
||||
#!/bin/bash
|
||||
# Ver: 1.2 by Endial Fang (endial@126.com)
|
||||
# Ver: 1.3 by Endial Fang (endial@126.com)
|
||||
#
|
||||
# 应用初始化脚本
|
||||
|
||||
# 设置 shell 执行参数,可使用'-'(打开)'+'(关闭)控制。常用:
|
||||
# -e: 命令执行错误则报错; -u: 变量未定义则报错; -x: 打印实际待执行的命令行; -o pipefail: 设置管道中命令遇到失败则报错
|
||||
set -eu
|
||||
set -o pipefail
|
||||
set -euo pipefail
|
||||
|
||||
. /usr/local/bin/common.sh # 应用专用函数库
|
||||
. /usr/local/bin/environment.sh # 设置环境变量
|
||||
. /usr/local/bin/common.sh # 应用专用函数库
|
||||
|
||||
LOG_I "** Processing init.sh **"
|
||||
#trap "app_stop_server" EXIT
|
||||
|
||||
trap "${APP_NAME}_stop_server" EXIT
|
||||
|
||||
${APP_NAME}_verify_minimum_env
|
||||
app_verify_minimum_env
|
||||
|
||||
# 执行应用预初始化操作
|
||||
${APP_NAME}_custom_preinit
|
||||
app_custom_preinit
|
||||
|
||||
# 执行应用初始化操作
|
||||
${APP_NAME}_default_init
|
||||
app_default_init
|
||||
|
||||
# 执行用户自定义初始化脚本
|
||||
${APP_NAME}_custom_init
|
||||
|
||||
LOG_I "** Processing init.sh finished! **"
|
||||
app_custom_init
|
||||
|
||||
@@ -1,28 +1,25 @@
|
||||
#!/bin/bash
|
||||
# Ver: 1.5 by Endial Fang (endial@126.com)
|
||||
# Ver: 1.6 by Endial Fang (endial@126.com)
|
||||
#
|
||||
# 应用启动脚本
|
||||
# 应用启动脚本;组合默认的配置参数及容器启动时传入的 CMD 参数,启动应用
|
||||
|
||||
# 设置 shell 执行参数,可使用'-'(打开)'+'(关闭)控制。常用:
|
||||
# -e: 命令执行错误则报错(errexit); -u: 变量未定义则报错(nounset); -x: 打印实际待执行的命令行; -o pipefail: 设置管道中命令遇到失败则报错
|
||||
set -eu
|
||||
set -o pipefail
|
||||
set -euo pipefail
|
||||
|
||||
. /colovu/lib/liblog.sh # 日志输出函数库
|
||||
|
||||
. /usr/local/bin/common.sh # 应用专用函数库
|
||||
. /usr/local/bin/environment.sh # 设置环境变量
|
||||
|
||||
LOG_I "** Processing run.sh **"
|
||||
|
||||
readonly START_COMMAND="$(command -v ${APP_EXEC})"
|
||||
readonly START_COMMAND="$(command -v ${APP_EXEC:-${APP_NAME}})"
|
||||
|
||||
# 配置默认启动参数(应用配置文件、前台方式启动)
|
||||
flags=("--config-file=${PG_CONF_FILE}" "--hba_file=${PG_HBA_FILE}")
|
||||
[[ -z "${APP_EXTRA_FLAGS:-}" ]] || flags+=("${APP_EXTRA_FLAGS[@]}")
|
||||
# 增加 "@" 以使用用户在命令行添加的扩展标识
|
||||
flags=()
|
||||
[[ -n "${PGDATA:-}" ]] && flags+=("-D" "${PGDATA}")
|
||||
[[ -n "${PG_CONF_FILE:-}" ]] && flags+=("--config-file=${PG_CONF_FILE}")
|
||||
[[ -n "${APP_EXTRA_FLAGS:-}" ]] && flags+=("${APP_EXTRA_FLAGS[@]}")
|
||||
flags+=("$@")
|
||||
|
||||
LOG_I "** Starting ${APP_NAME} **"
|
||||
#is_root && flags=("-u" "$APP_DAEMON_USER" "${flags[@]}")
|
||||
|
||||
LOG_I "Command: ${START_COMMAND[@]} ${flags[@]}"
|
||||
exec "${START_COMMAND[@]}" "${flags[@]}"
|
||||
LOG_I "Start ${APP_NAME} with command: ${START_COMMAND} ${flags[@]}"
|
||||
exec "${START_COMMAND}" "${flags[@]}"
|
||||
|
||||
@@ -1,46 +1,26 @@
|
||||
#!/bin/bash
|
||||
# Ver: 1.2 by Endial Fang (endial@126.com)
|
||||
# Ver: 1.3 by Endial Fang (endial@126.com)
|
||||
#
|
||||
# 应用环境及依赖文件设置脚本
|
||||
# 应用环境及依赖文件设置脚本;当前脚本以‘root’用户执行
|
||||
|
||||
# 设置 shell 执行参数,可使用'-'(打开)'+'(关闭)控制。常用:
|
||||
# -e: 命令执行错误则报错(errexit); -u: 变量未定义则报错(nounset); -x: 打印实际待执行的命令行; -o pipefail: 设置管道中命令遇到失败则报错
|
||||
set -eu
|
||||
set -o pipefail
|
||||
set -euo pipefail
|
||||
|
||||
. /colovu/lib/libcommon.sh # 加载通用函数库
|
||||
. /colovu/lib/libfs.sh # 加载文件操作函数库
|
||||
. /colovu/lib/libos.sh # 加载系统管理函数库
|
||||
|
||||
. /usr/local/bin/environment.sh # 设置环境变量
|
||||
. /usr/local/bin/common.sh # 应用专用函数库
|
||||
|
||||
LOG_I "** Processing setup.sh **"
|
||||
|
||||
APP_DIRS="${APP_CONF_DIR:-} ${APP_DATA_DIR:-} ${APP_LOG_DIR:-} ${APP_CERT_DIR:-} ${APP_DATA_LOG_DIR:-}"
|
||||
APP_DIRS="${APP_DIRS} ${PG_DATA_DIR:-} ${PG_INITDB_WAL_DIR:-}"
|
||||
APP_DIRS=(/var/log/${APP_NAME} /var/run/${APP_NAME} /var/cache/${APP_NAME} ${APP_HOME})
|
||||
APP_DIRS+=(${APP_HOME}/conf ${APP_HOME}/data ${APP_HOME}/cert ${APP_HOME}/log)
|
||||
APP_DIRS+=(${PGDATA})
|
||||
|
||||
LOG_I "Ensure directory exists: ${APP_DIRS}"
|
||||
for dir in ${APP_DIRS}; do
|
||||
ensure_dir_exists ${dir}
|
||||
LOG_I "Ensure directory exists: ${APP_DIRS[@]}"
|
||||
for dir in ${APP_DIRS[@]}; do
|
||||
ensure_dir_exists ${dir} ${APP_USER}
|
||||
done
|
||||
|
||||
# 检测指定文件是否在配置文件存储目录存在,如果不存在则拷贝(新挂载数据卷、手动删除都会导致不存在)
|
||||
# PG 将使用默认模板生成配置文件,并放置在PGDATA目录
|
||||
#LOG_I "Check config files in: ${APP_CONF_DIR}"
|
||||
#if [[ ! -z "$(ls -A "${APP_DEF_DIR}")" ]]; then
|
||||
# ensure_config_file_exist "${APP_DEF_DIR}" $(ls -A "${APP_DEF_DIR}")
|
||||
# :
|
||||
#fi
|
||||
|
||||
#LOG_I "Ensure directory ownership: ${APP_USER}"
|
||||
#for dir in ${APP_DIRS}; do
|
||||
# configure_permissions_ownership "$dir" -u "${APP_USER}" -g "${APP_USER}"
|
||||
#done
|
||||
|
||||
# 解决 PostgreSQL 目录权限过于开放,无法初始化问题:FATAL: data directory "/srv/data/postgresql" has group or world access
|
||||
LOG_D "Lack of permissions on data directory: ${PG_DATA_DIR}"
|
||||
chmod 0700 ${PG_DATA_DIR}
|
||||
|
||||
is_root && ensure_user_exists "$APP_DAEMON_USER" -g "$APP_DAEMON_GROUP"
|
||||
|
||||
LOG_I "** Processing setup.sh finished! **"
|
||||
|
||||
Reference in New Issue
Block a user