anvilsign in

collin/anvil

1#!/usr/bin/env bash
2# (Re)start the anvil container on hagrid from an ALREADY-LOADED image.
3#
4# Build and ship the image first with deploy/build.sh on a capable machine
5# (the VPS can't compile it). This script only runs docker — no build — so it's
6# safe on the low-RAM box. Standalone: needs only docker + the loaded image.
7set -euo pipefail
8
9IMAGE="${ANVIL_IMAGE:-anvil:latest}"
10NETWORK="${ANVIL_NETWORK:-hagrid}"
11SSH_PORT="${ANVIL_SSH_PORT:-2222}"
12DOCKER_SOCK="${ANVIL_DOCKER_SOCK:-/var/run/docker.sock}"
13
14# The CI runner drives Docker via the host socket. Mount it in, and add the
15# socket's group to the non-root `anvil` user so it can actually open it.
16# NOTE: socket access = root-equivalent on the host. We accept this because
17# anvil is a single-tenant, owner-operated forge; CI only runs code the owner
18# pushed. Do not expose this instance to untrusted users.
19SOCK_GID="$(stat -c '%g' "$DOCKER_SOCK")"
20
21# Single sign-on's client secret, if this instance uses one (docs/oidc.md).
22#
23# Read from a file on the host by default, because deploy/deploy.sh pipes this
24# script over ssh (`ssh host 'bash -s' < run.sh`) and no environment travels
25# with it — an env var alone would silently vanish on exactly the path that
26# matters. ANVIL_OIDC_CLIENT_SECRET still wins when running this by hand.
27#
28# Passed only when non-empty: an empty value would override the baked config
29# with "no secret" and turn a confidential client into a public one.
30OIDC_SECRET_FILE="${ANVIL_OIDC_SECRET_FILE:-$HOME/.config/anvil/oidc-client-secret}"
31OIDC_SECRET="${ANVIL_OIDC_CLIENT_SECRET:-}"
32if [[ -z "$OIDC_SECRET" && -r "$OIDC_SECRET_FILE" ]]; then
33 OIDC_SECRET="$(tr -d '[:space:]' <"$OIDC_SECRET_FILE")"
34fi
35
36OIDC_ENV=()
37if [[ -n "$OIDC_SECRET" ]]; then
38 OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${OIDC_SECRET}")
39 echo "==> single sign-on: client secret loaded"
40else
41 echo "==> single sign-on: no client secret found (${OIDC_SECRET_FILE})"
42fi
43
44docker rm -f anvil 2>/dev/null || true
45docker run -d \
46 --name anvil \
47 --network "$NETWORK" \
48 --restart unless-stopped \
49 -p "${SSH_PORT}:2222" \
50 -v anvil-data:/data \
51 -v "${DOCKER_SOCK}:/var/run/docker.sock" \
52 --group-add "$SOCK_GID" \
53 "${OIDC_ENV[@]}" \
54 "$IMAGE"
55
56echo "==> anvil (re)started from $IMAGE (web: anvil:3000 via Caddy, ssh: host :${SSH_PORT}, docker.sock gid ${SOCK_GID})"