mirror of
https://github.com/openziti/ziti.git
synced 2026-10-09 06:11:34 +00:00
rev2 on getting the docker-compose env up to speed with the other quickstarts policy-wise and 'editable'
This commit is contained in:
@@ -17,6 +17,22 @@ services:
|
||||
- ziti-fs:/openziti
|
||||
entrypoint:
|
||||
- "/openziti/scripts/run-controller.sh"
|
||||
-
|
||||
ziti-controller-init-container:
|
||||
image: "${ZITI_IMAGE}:${ZITI_VERSION}"
|
||||
env_file:
|
||||
- ./.env
|
||||
networks:
|
||||
zitiblue:
|
||||
aliases:
|
||||
- ziti-edge-controller-init-container
|
||||
zitired:
|
||||
aliases:
|
||||
- ziti-edge-controller-init-container
|
||||
volumes:
|
||||
- ziti-fs:/openziti
|
||||
entrypoint:
|
||||
- "/openziti/scripts/access-control.sh"
|
||||
|
||||
ziti-edge-router:
|
||||
image: "${ZITI_IMAGE}:${ZITI_VERSION}"
|
||||
|
||||
@@ -25,7 +25,7 @@ COPY --chown=ziti ziti.ignore "${ZITI_BIN_DIR}"
|
||||
COPY --chown=ziti ziti-cli-functions.sh "${ZITI_SCRIPTS}/"
|
||||
COPY --chown=ziti run-controller.sh "${ZITI_SCRIPTS}/"
|
||||
COPY --chown=ziti run-router.sh "${ZITI_SCRIPTS}/"
|
||||
COPY --chown=ziti run-router.sh "${ZITI_SCRIPTS}/"
|
||||
COPY --chown=ziti access-control.sh "${ZITI_SCRIPTS}/"
|
||||
|
||||
RUN /bin/bash -c "source ${ZITI_SCRIPTS}/ziti-cli-functions.sh; ziti_createEnvFile; echo source ${ZITI_HOME}/ziti.env >> ~/.bashrc"
|
||||
|
||||
|
||||
@@ -3,6 +3,14 @@
|
||||
# Should we execute?
|
||||
initFile="/openziti/access-control.init"
|
||||
if [[ -f "${initFile}" ]]; then
|
||||
echo " "
|
||||
echo "*****************************************************"
|
||||
echo " docker-compose init file has been detected"
|
||||
echo " the initialization of the docker-compose environment has already happened"
|
||||
echo " if you wish to allow this volume to be re-initialized, delete the file"
|
||||
echo " located at ${initFile}"
|
||||
echo "*****************************************************"
|
||||
echo " "
|
||||
exit 0
|
||||
fi
|
||||
|
||||
@@ -22,14 +30,16 @@ until $(curl -s -o /dev/null --fail -k "https://${ZITI_EDGE_CTRL_ADVERTISED_HOST
|
||||
sleep 2
|
||||
done
|
||||
|
||||
echo " "
|
||||
echo "*****************************************************"
|
||||
#### Add service policies
|
||||
|
||||
# Allow all identities to use any edge router with the "public" attribute
|
||||
ziti edge delete edge-router-policy all-endpoints-public-routers
|
||||
ziti edge create edge-router-policy all-endpoints-public-routers --edge-router-roles "#public" --identity-roles "#all"
|
||||
|
||||
# Allow all edge-routers to access all services
|
||||
ziti edge delete service-edge-router-policy all-routers-all-services
|
||||
ziti edge create service-edge-router-policy all-routers-all-services --edge-router-roles "#all" --service-roles "#all"
|
||||
|
||||
touch "${initFile}"
|
||||
touch "${initFile}"
|
||||
|
||||
This docker volume has been initialized.
|
||||
@@ -1,5 +1,7 @@
|
||||
#!/bin/bash
|
||||
|
||||
ziti_controller_cfg='/openziti/ziti-edge-controller.yaml'
|
||||
|
||||
export ZITI_CONTROLLER_RAWNAME=ziti-controller
|
||||
export ZITI_EDGE_CONTROLLER_RAWNAME=ziti-edge-controller
|
||||
|
||||
@@ -11,8 +13,17 @@ generateEnvFile
|
||||
# create pki
|
||||
createPki
|
||||
|
||||
# generates the config file for the controller
|
||||
createControllerConfig
|
||||
if [ ! -f "${ziti_controller_cfg}" ]; then
|
||||
echo " "
|
||||
echo "${ziti_controller_cfg} doesn't exist. Generating config file"
|
||||
echo " "
|
||||
# generates the config file for the controller
|
||||
createControllerConfig
|
||||
else
|
||||
echo " "
|
||||
echo "${ziti_controller_cfg} exists. Not overwriting"
|
||||
echo " "
|
||||
fi
|
||||
|
||||
# initialize the database with the admin user:
|
||||
"${ZITI_BIN_DIR}/ziti-controller" edge init "${ZITI_HOME}/ziti-edge-controller.yaml" -u "${ZITI_USER}" -p "${ZITI_PWD}"
|
||||
|
||||
Reference in New Issue
Block a user