feat: add FX Cloudron package (DevOps-Tools) [#640]
FX 0.9.48 ("poor man's function as a service") as the 13th package:
pre-compiled goreleaser release binary with sha256 pin on
cloudron/base:4.0.0. fx is a CLI with no user concept, so the package
is a workstation: pinned binary + persistent workspace
(functions/ssh/kube) driven from the Cloudron web terminal, with an
auth-proxied landing page as the only HTTP surface (httpAuth proxy).
Deploys target remote Docker hosts over key-based SSH or Kubernetes
via FX_KUBECONF. Build green; runtime smoke (landing page, workspace
seeding, fx -v) green. Docs gardened to 13 packages.
Ticket: https://projects.knownelement.com/issues/640
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
# FX Cloudron Package
|
||||
#
|
||||
# fx (metrue/fx) is "poor man's function as a service": a CLI that turns a
|
||||
# stateless function file (JavaScript, Python, Go, Ruby, Java, PHP, Perl,
|
||||
# Crystal, Rust, Julia, D) into a running HTTP service on your own Docker
|
||||
# host or Kubernetes cluster, in seconds. fx is a DRIVER-side tool: it
|
||||
# packages the function, ships it to the target over SSH (key-based) or
|
||||
# the K8s API, and the TARGET runs the container.
|
||||
#
|
||||
# Cloudron app containers have no Docker daemon, so this package is the
|
||||
# operator's fx WORKSTATION: the pinned fx binary plus a persistent
|
||||
# workspace (/app/data/functions, /app/data/ssh, /app/data/kube), driven
|
||||
# from the Cloudron web terminal. Deploy targets are remote Docker hosts
|
||||
# (--host user@host --ssh_key ...) or a Kubernetes cluster (FX_KUBECONF
|
||||
# or -C kubeconf).
|
||||
#
|
||||
# Authentication: fx has NO user concept — no web UI, no accounts, no
|
||||
# SSO hooks — so the auth-gate verdict is the proxy row (AGENTS.md
|
||||
# matrix). The manifest declares httpAuth.type = proxy: Cloudron's auth
|
||||
# proxy gates the landing page, the only HTTP surface this app has.
|
||||
# Access to the terminal/workspace itself is Cloudron's app access list.
|
||||
#
|
||||
# Upstream: https://github.com/metrue/fx
|
||||
# - Release 0.9.48-alpha.d91a7a0 (2021-06-10) is the latest published
|
||||
# release and what the official scripts/install.sh installs; the
|
||||
# binary reports version 0.9.48. Repo master (2023) has no newer
|
||||
# release.
|
||||
# - Ships goreleaser tarballs; the linux/amd64 asset is
|
||||
# fx_<tag>_Tux_64-bit.tar.gz, glibc-built -> needs an Ubuntu base.
|
||||
FROM cloudron/base:4.0.0
|
||||
|
||||
ARG FX_TAG=0.9.48-alpha.d91a7a0
|
||||
ARG FX_SHA256=1ed8a40f81038ca9e33aa09dba2184448b2efa3ed6373936e9f849f50200910f
|
||||
|
||||
# Pre-compiled-binaries pattern (JOURNAL pattern #5): pinned release
|
||||
# download behind a sha256 gate (checksum taken from the upstream
|
||||
# checksums.txt asset). Building the 2021-era codebase (go 1.12 modules
|
||||
# + packr assets) from source would buy nothing over the official
|
||||
# release binary.
|
||||
RUN curl -fsSL -o /tmp/fx.tar.gz \
|
||||
"https://github.com/metrue/fx/releases/download/${FX_TAG}/fx_${FX_TAG}_Tux_64-bit.tar.gz" \
|
||||
&& echo "${FX_SHA256} /tmp/fx.tar.gz" | sha256sum -c - \
|
||||
&& tar -xzf /tmp/fx.tar.gz -C /usr/local/bin --exclude='*.md' --exclude='LICENSE*' \
|
||||
&& chmod +x /usr/local/bin/fx \
|
||||
&& rm -f /tmp/fx.tar.gz \
|
||||
&& /usr/local/bin/fx -v
|
||||
|
||||
# Static landing page served on the Cloudron HTTP port (platform health
|
||||
# check + auth-proxied usage guide). fx itself has no daemon, so the
|
||||
# page server is the only long-running process. start.sh seeds the
|
||||
# /app/data workspace on first run; it is made executable on the host,
|
||||
# not at build time (Cloudron gotcha).
|
||||
COPY status.html /app/code/status/index.html
|
||||
COPY start.sh /app/start.sh
|
||||
|
||||
WORKDIR /app/data
|
||||
|
||||
EXPOSE 8000
|
||||
|
||||
CMD ["/bin/bash", "/app/start.sh"]
|
||||
Reference in New Issue
Block a user