feat: jpa, messaging, notification, mongo, graphql 어댑터터 리펙토링
This commit is contained in:
Executable
+37
@@ -0,0 +1,37 @@
|
||||
#!/bin/sh
|
||||
# =============================================================================
|
||||
# Installs the server certificate where PostgreSQL will accept it, then hands over.
|
||||
#
|
||||
# PostgreSQL refuses to start if the private key is group- or world-readable, and it reads the key
|
||||
# as the `postgres` user — uid 70 in the Alpine image. The certificate is generated on the host by
|
||||
# the qualification wrapper, so it arrives owned by whoever ran the script; a bind mount preserves
|
||||
# that ownership, and the two facts together mean a mounted key is either unreadable by postgres or
|
||||
# too permissive for it. Neither is fixable from the outside.
|
||||
#
|
||||
# So the key is copied, once, at the only moment this container is still root: before the official
|
||||
# entrypoint gosu's down to postgres. The copy lives on the container filesystem, not on the mount,
|
||||
# and the mount stays read-only.
|
||||
#
|
||||
# The same problem, the same shape as the Keycloak client secret and the MinIO smoke client. It is
|
||||
# worth stating plainly: bind-mounted credentials and per-image uids do not compose, and every
|
||||
# service that needs one has to say how it bridges them.
|
||||
# =============================================================================
|
||||
set -eu
|
||||
|
||||
TLS_SOURCE="${POSTGRES_TLS_DIR:-/opt/postgres-tls}"
|
||||
TLS_TARGET=/etc/postgresql-tls
|
||||
|
||||
if [ -f "${TLS_SOURCE}/server.key" ] && [ -f "${TLS_SOURCE}/server.crt" ]; then
|
||||
mkdir -p "${TLS_TARGET}"
|
||||
cp "${TLS_SOURCE}/server.key" "${TLS_TARGET}/server.key"
|
||||
cp "${TLS_SOURCE}/server.crt" "${TLS_TARGET}/server.crt"
|
||||
chown -R postgres:postgres "${TLS_TARGET}"
|
||||
chmod 0700 "${TLS_TARGET}"
|
||||
chmod 0600 "${TLS_TARGET}/server.key"
|
||||
chmod 0644 "${TLS_TARGET}/server.crt"
|
||||
else
|
||||
echo "postgres-entrypoint: no certificate at ${TLS_SOURCE}; refusing to start a TLS lane without one" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
exec docker-entrypoint.sh "$@"
|
||||
Reference in New Issue
Block a user