chore: add restart-server.sh helper for fast minerva restarts
One-line wrapper around docker compose ... restart plus a /api/health poll, useful after editing users.toml/settings.toml/.env on minerva (boot-time read). docs/deployment.md updated (user-mgmt, troubleshooting, TLS-proxy sections) to reference the wrapper instead of the inline ssh+docker command.
This commit is contained in:
+10
-8
@@ -100,12 +100,15 @@ Adding or rotating a user means editing `users.toml` on minerva and
|
|||||||
restarting the container so the boot-time parser picks up the change:
|
restarting the container so the boot-time parser picks up the change:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ssh minerva.lan
|
ssh minerva.lan 'docker run --rm -i doctate-server:latest hash-password'
|
||||||
docker run --rm -i doctate-server:latest hash-password # silent prompt, prints hash
|
ssh minerva.lan 'nano /opt/stacks/doctate-server/config/users.toml'
|
||||||
nano /opt/stacks/doctate-server/config/users.toml # paste the hash
|
./scripts/restart-server.sh
|
||||||
docker compose -f /opt/stacks/doctate-server/compose.yaml restart doctate-server
|
|
||||||
```
|
```
|
||||||
|
|
||||||
|
`scripts/restart-server.sh` wraps the `docker compose ... restart` plus
|
||||||
|
a `/api/health` poll, so you see in one line whether the new config is
|
||||||
|
actually live or whether the server hit a boot-time error.
|
||||||
|
|
||||||
The `users.toml` mount is read-only by design — the container is not
|
The `users.toml` mount is read-only by design — the container is not
|
||||||
allowed to modify the auth file. Edits happen on the host.
|
allowed to modify the auth file. Edits happen on the host.
|
||||||
|
|
||||||
@@ -133,7 +136,7 @@ rollback — only the binary swaps.
|
|||||||
| Login refused on HTTPS | `COOKIE_SECURE` and TLS-proxy mismatch — see "TLS" section below |
|
| Login refused on HTTPS | `COOKIE_SECURE` and TLS-proxy mismatch — see "TLS" section below |
|
||||||
| File missing inside container | `docker compose -f /opt/stacks/doctate-server/compose.yaml exec doctate-server ls /app` |
|
| File missing inside container | `docker compose -f /opt/stacks/doctate-server/compose.yaml exec doctate-server ls /app` |
|
||||||
| Health-check status | `ssh minerva.lan 'docker inspect --format "{{.State.Health.Status}}" doctate-server'` |
|
| Health-check status | `ssh minerva.lan 'docker inspect --format "{{.State.Health.Status}}" doctate-server'` |
|
||||||
| Config edit not picked up | `docker compose ... restart doctate-server` — most config is read on boot, not per request |
|
| Config edit not picked up | `./scripts/restart-server.sh` — most config is read on boot, not per request |
|
||||||
| Stale image tag on minerva | `docker images --filter dangling=true` — retag or `docker image prune` |
|
| Stale image tag on minerva | `docker images --filter dangling=true` — retag or `docker image prune` |
|
||||||
|
|
||||||
## TLS / nginx reverse proxy
|
## TLS / nginx reverse proxy
|
||||||
@@ -145,9 +148,8 @@ to `http://minerva.lan:3000`, set the cookie flag accordingly so
|
|||||||
browsers actually accept the session cookie:
|
browsers actually accept the session cookie:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ssh minerva.lan
|
ssh minerva.lan "echo 'COOKIE_SECURE=true' >> /opt/stacks/doctate-server/config/.env"
|
||||||
echo 'COOKIE_SECURE=true' >> /opt/stacks/doctate-server/config/.env
|
./scripts/restart-server.sh
|
||||||
docker compose -f /opt/stacks/doctate-server/compose.yaml restart doctate-server
|
|
||||||
```
|
```
|
||||||
|
|
||||||
Without this override under a TLS proxy, the login flow looks like it
|
Without this override under a TLS proxy, the login flow looks like it
|
||||||
|
|||||||
Executable
+32
@@ -0,0 +1,32 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Restart doctate-server on a remote Docker host (default: minerva.lan).
|
||||||
|
# Use after editing /opt/stacks/doctate-server/config/{users,settings}.toml
|
||||||
|
# or .env — the server reads those at boot, not per request.
|
||||||
|
#
|
||||||
|
# Usage: ./scripts/restart-server.sh [host]
|
||||||
|
# host default: minerva.lan
|
||||||
|
#
|
||||||
|
# Exit code 0 on healthy server, 1 on health-check timeout.
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
HOST="${1:-minerva.lan}"
|
||||||
|
REMOTE="/opt/stacks/doctate-server"
|
||||||
|
|
||||||
|
echo ">>> Restarting doctate-server on $HOST"
|
||||||
|
ssh "$HOST" "docker compose -f $REMOTE/compose.yaml restart doctate-server"
|
||||||
|
|
||||||
|
echo ">>> Waiting for /api/health"
|
||||||
|
for i in $(seq 1 20); do
|
||||||
|
if curl -fsS "http://$HOST:3000/api/health" >/dev/null 2>&1; then
|
||||||
|
echo " OK after ${i} attempt(s)"
|
||||||
|
curl -s "http://$HOST:3000/api/health"
|
||||||
|
echo
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
|
||||||
|
echo ">>> TIMEOUT (40s) — last 50 lines of container logs:" >&2
|
||||||
|
ssh "$HOST" "docker logs --tail 50 doctate-server" >&2 || true
|
||||||
|
exit 1
|
||||||
Reference in New Issue
Block a user