anvilsign in

collin/anvil

1#!/usr/bin/env bash
2# (Re)start the anvil container on hagrid from an ALREADY-LOADED image.
3#
4# Build and ship the image first with deploy/build.sh on a capable machine
5# (the VPS can't compile it). This script only runs docker — no build — so it's
6# safe on the low-RAM box. Standalone: needs only docker + the loaded image.
7set -euo pipefail
8
9IMAGE="${ANVIL_IMAGE:-anvil:latest}"
10NETWORK="${ANVIL_NETWORK:-hagrid}"
11SSH_PORT="${ANVIL_SSH_PORT:-2222}"
12DOCKER_SOCK="${ANVIL_DOCKER_SOCK:-/var/run/docker.sock}"
13
14# The CI runner drives Docker via the host socket. Mount it in, and add the
15# socket's group to the non-root `anvil` user so it can actually open it.
16# NOTE: socket access = root-equivalent on the host. We accept this because
17# anvil is a single-tenant, owner-operated forge; CI only runs code the owner
18# pushed. Do not expose this instance to untrusted users.
19SOCK_GID="$(stat -c '%g' "$DOCKER_SOCK")"
20
21# Single sign-on's client secret, if this instance uses one (docs/oidc.md).
22# Passed only when set: an empty value would override the config file with
23# "no secret" and turn a confidential client into a public one.
24OIDC_ENV=()
25if [[ -n "${ANVIL_OIDC_CLIENT_SECRET:-}" ]]; then
26 OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${ANVIL_OIDC_CLIENT_SECRET}")
27fi
28
29docker rm -f anvil 2>/dev/null || true
30docker run -d \
31 --name anvil \
32 --network "$NETWORK" \
33 --restart unless-stopped \
34 -p "${SSH_PORT}:2222" \
35 -v anvil-data:/data \
36 -v "${DOCKER_SOCK}:/var/run/docker.sock" \
37 --group-add "$SOCK_GID" \
38 "${OIDC_ENV[@]}" \
39 "$IMAGE"
40
41echo "==> anvil (re)started from $IMAGE (web: anvil:3000 via Caddy, ssh: host :${SSH_PORT}, docker.sock gid ${SOCK_GID})"