Compare commits

..
8 changed files with 119 additions and 11 deletions
+39
View File
@@ -0,0 +1,39 @@
---
kind: pipeline
name: deploy to swarm-test.autonomic.zone
steps:
- name: deployment
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
settings:
host: swarm-test.autonomic.zone
stack: n8n
generate_secrets: true
purge: true
deploy_key:
from_secret: drone_ssh_swarm_test
networks:
- proxy
environment:
DOMAIN: n8n.swarm-test.autonomic.zone
STACK_NAME: n8n
LETS_ENCRYPT_ENV: production
SECRET_DB_PASSWORD_VERSION: v1
trigger:
branch:
- main
---
kind: pipeline
name: generate recipe catalogue
steps:
- name: release a new version
image: plugins/downstream
settings:
server: https://build.coopcloud.tech
token:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
trigger:
event: tag
+13
View File
@@ -8,11 +8,24 @@ LETS_ENCRYPT_ENV=production
SECRET_DB_PASSWORD_VERSION=v1 SECRET_DB_PASSWORD_VERSION=v1
# Change to `true` to enable sending "anonymous" telemetry data to n8n
# https://docs.n8n.io/reference/data-collection/
N8N_DIAGNOSTICS_ENABLED=false
# Change to `true` to enable questionnaire-based customisation of the UI
N8N_PERSONALIZATION_ENABLED=false
# "Permit users to import specific built-in modules in the Code node"
#NODE_FUNCTION_ALLOW_BUILTIN=*
COMPOSE_FILE="compose.yml" COMPOSE_FILE="compose.yml"
# SSO using traefik-forward-auth # SSO using traefik-forward-auth
#COMPOSE_FILE="$COMPOSE_FILE:compose.sso.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.sso.yml"
# Disable user management completely, useful for SSO
#N8N_USER_MANAGEMENT_DISABLED=false
# Basic auth # Basic auth
#COMPOSE_FILE="$COMPOSE_FILE:compose.basicauth.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.basicauth.yml"
#N8N_BASIC_AUTH_ACTIVE=true #N8N_BASIC_AUTH_ACTIVE=true
BIN
View File
Binary file not shown.
+5 -5
View File
@@ -6,7 +6,7 @@ Extensible environment for interactive and reproducible computing
* **Category**: Utilities * **Category**: Utilities
* **Status**: 1 * **Status**: 1
* **Image**: `n8nio/n8n` * **Image**: [`n8nio/n8n`](https://hub.docker.com/n8nio/n8n), 4, upstream
* **Healthcheck**: No * **Healthcheck**: No
* **Backups**: No * **Backups**: No
* **Email**: N/A * **Email**: N/A
@@ -21,19 +21,19 @@ Extensible environment for interactive and reproducible computing
2. Deploy [`coop-cloud/traefik`] 2. Deploy [`coop-cloud/traefik`]
3. `abra app new ${REPO_NAME} --secrets` (optionally with `--pass` if you'd like 3. `abra app new ${REPO_NAME} --secrets` (optionally with `--pass` if you'd like
to save secrets in `pass`) to save secrets in `pass`)
4. `abra app YOURAPPDOMAIN config` - be sure to change `$DOMAIN` to something that resolves to 4. `abra app config YOURAPPDOMAIN` - be sure to change `$DOMAIN` to something that resolves to
your Docker swarm box your Docker swarm box
5. `abra app YOURAPPDOMAIN deploy` 5. `abra app deploy YOURAPPDOMAIN`
6. Open the configured domain in your browser to finish set-up 6. Open the configured domain in your browser to finish set-up
Currently, you have to manually run a command to generate an initial Currently, you have to manually run a command to generate an initial
configuration (see #1): configuration (see #1):
`abra app YOURAPPDOMAIN run app jupyter notebook --generate-config` `abra app run YOURAPPDOMAIN app jupyter notebook --generate-config`
And then run this command to get a token for initial login: And then run this command to get a token for initial login:
`abra app YOURAPPDOMAIN run app jupyter notebook list` `abra app run YOURAPPDOMAIN app jupyter notebook list`
You can enter this token at the bottom of the login page to set a password You can enter this token at the bottom of the login page to set a password
instead (see #2). instead (see #2).
+1
View File
@@ -0,0 +1 @@
export DB_ENTRYPOINT_VERSION=v1
-1
View File
@@ -4,7 +4,6 @@ version: '3.8'
services: services:
app: app:
image: n8nio/n8n
environment: environment:
- N8N_BASIC_AUTH_ACTIVE=false - N8N_BASIC_AUTH_ACTIVE=false
deploy: deploy:
+17 -5
View File
@@ -1,10 +1,9 @@
--- ---
version: '3.8' version: '3.8'
services: services:
app: app:
image: n8nio/n8n:0.204.0 image: n8nio/n8n:0.237.0
environment: environment:
- DB_TYPE=postgresdb - DB_TYPE=postgresdb
- DB_POSTGRESDB_HOST=${STACK_NAME}_db - DB_POSTGRESDB_HOST=${STACK_NAME}_db
@@ -12,6 +11,9 @@ services:
- DB_POSTGRESDB_DATABASE=n8n - DB_POSTGRESDB_DATABASE=n8n
- DB_POSTGRESDB_USER=root - DB_POSTGRESDB_USER=root
- DB_POSTGRESDB_PASSWORD_FILE=/run/secrets/db_password - DB_POSTGRESDB_PASSWORD_FILE=/run/secrets/db_password
- N8N_PERSONALIZATION_ENABLED
- N8N_DIAGNOSTICS_ENABLED
- N8N_USER_MANAGEMENT_DISABLED
- N8N_BASIC_AUTH_ACTIVE=false - N8N_BASIC_AUTH_ACTIVE=false
- WEBHOOK_URL=https://${DOMAIN} - WEBHOOK_URL=https://${DOMAIN}
- NODE_FUNCTION_ALLOW_EXTERNAL=moment - NODE_FUNCTION_ALLOW_EXTERNAL=moment
@@ -38,25 +40,29 @@ services:
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect" - "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true" - "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}" - "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=0.3.0+0.204.0" - "coop-cloud.${STACK_NAME}.version=0.7.0+0.237.0"
- "backupbot.backup=true" - "backupbot.backup=true"
- "backupbot.backup.path=/home/node/.n8n" - "backupbot.backup.path=/home/node/.n8n"
db: db:
image: postgres:11 image: postgres:16
networks: networks:
- internal_network - internal_network
environment: environment:
- POSTGRES_USER=root - POSTGRES_USER=root
- POSTGRES_PASSWORD_FILE=/run/secrets/db_password - POSTGRES_PASSWORD_FILE=/run/secrets/db_password
- POSTGRES_DB=n8n - POSTGRES_DB=n8n
configs:
- source: db_entrypoint
target: /docker-entrypoint.sh
mode: 0555
secrets: secrets:
- db_password - db_password
healthcheck: healthcheck:
test: ["CMD", "pg_isready", "-U", "root", "-d", "n8n"] test: ["CMD", "pg_isready", "-U", "root", "-d", "n8n"]
volumes: volumes:
- 'postgresql_data:/var/lib/postgresql/data' - 'postgresql_data:/var/lib/postgresql/data'
# - ./init-data.sh:/docker-entrypoint-initdb.d/init-data.sh entrypoint: /docker-entrypoint.sh
deploy: deploy:
labels: labels:
backupbot.backup: "true" backupbot.backup: "true"
@@ -80,3 +86,9 @@ networks:
proxy: proxy:
external: true external: true
internal_network: internal_network:
configs:
db_entrypoint:
name: ${STACK_NAME}_db_entrypoint_${DB_ENTRYPOINT_VERSION}
file: entrypoint.postgres.sh.tmpl
template_driver: golang
+44
View File
@@ -0,0 +1,44 @@
#!/bin/bash
set -e
MIGRATION_MARKER=$PGDATA/migration_in_progress
OLDDATA=$PGDATA/old_data
NEWDATA=$PGDATA/new_data
if [ -e $MIGRATION_MARKER ]; then
echo "FATAL: migration was started but did not complete in a previous run. manual recovery necessary"
exit 1
fi
if [ -f $PGDATA/PG_VERSION ]; then
DATA_VERSION=$(cat $PGDATA/PG_VERSION)
if [ -n "$DATA_VERSION" -a "$PG_MAJOR" != "$DATA_VERSION" ]; then
echo "postgres data version $DATA_VERSION found, but need $PG_MAJOR. Starting migration"
echo "Installing postgres $DATA_VERSION"
sed -i "s/$/ $DATA_VERSION/" /etc/apt/sources.list.d/pgdg.list
apt-get update && apt-get install -y --no-install-recommends \
postgresql-$DATA_VERSION \
&& rm -rf /var/lib/apt/lists/*
echo "shuffling around"
gosu postgres mkdir $OLDDATA $NEWDATA
chmod 700 $OLDDATA $NEWDATA
mv $PGDATA/* $OLDDATA/ || true
touch $MIGRATION_MARKER
echo "running initdb"
# abuse entrypoint script for initdb by making server error out
gosu postgres bash -c "export PGDATA=$NEWDATA ; /usr/local/bin/docker-entrypoint.sh --invalid-arg || true"
echo "running pg_upgrade"
cd /tmp
gosu postgres pg_upgrade --link -b /usr/lib/postgresql/$DATA_VERSION/bin -d $OLDDATA -D $NEWDATA -U $POSTGRES_USER
cp $OLDDATA/pg_hba.conf $NEWDATA/
mv $NEWDATA/* $PGDATA
rm -rf $OLDDATA
rmdir $NEWDATA
rm $MIGRATION_MARKER
echo "migration complete"
fi
fi
/usr/local/bin/docker-entrypoint.sh postgres