diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml new file mode 100644 index 0000000..d188978 --- /dev/null +++ b/.github/workflows/build.yaml @@ -0,0 +1,63 @@ +name: Build + +on: + push: + branches: [main] + # Publish semver tags as releases. + tags: ['v*.*.*'] + pull_request: + branches: [main] + +env: + # Use docker.io for Docker Hub if empty + REGISTRY: ghcr.io + # github.repository as / + IMAGE_NAME: ${{ github.repository }} + + +jobs: + build: + + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + + steps: + - name: Checkout repository + uses: actions/checkout@v3 + + # Login against a Docker registry except on PR + # https://github.com/docker/login-action + - name: Log into registry ${{ env.REGISTRY }} + if: github.event_name != 'pull_request' + uses: docker/login-action@v2 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + # Extract metadata (tags, labels) for Docker + # https://github.com/docker/metadata-action + - name: Extract Docker metadata + id: meta + uses: docker/metadata-action@v4 + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=semver,pattern=v{{version}} + type=semver,pattern=v{{major}}.{{minor}} + type=semver,pattern=v{{major}} + type=ref,event=branch + type=ref,event=pr + type=sha + + # Build and push Docker image with Buildx (don't push on PR) + # https://github.com/docker/build-push-action + - name: Build and push Docker image + uses: docker/build-push-action@v4 + with: + context: . + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..ad1caf8 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,16 @@ +FROM debian:12 +RUN apt update +RUN apt install -y apache2 +RUN apt install -y libapache2-mod-wsgi-py3 +RUN apt install -y libapache2-mod-auth-openidc +RUN a2enmod wsgi +RUN a2enmod proxy +RUN a2enmod proxy_http +RUN a2enmod headers +RUN a2enmod ssl +RUN a2enmod rewrite +RUN a2enmod auth_openidc +RUN a2ensite default-ssl +COPY files/apache2-foreground /usr/bin/apache2-foreground +RUN chmod 755 /usr/bin/apache2-foreground +CMD /usr/bin/apache2-foreground diff --git a/files/apache2-foreground b/files/apache2-foreground new file mode 100644 index 0000000..dd758cc --- /dev/null +++ b/files/apache2-foreground @@ -0,0 +1,10 @@ +#!/bin/sh +set -e + +export APACHE_RUN_DIR=/var/run/apache2 +export APACHE_ARGUMENTS="-DFOREGROUND $@" + +# Apache gets grumpy about PID files pre-existing +rm -f ${APACHE_RUN_DIR}/apache2.pid + +exec /usr/sbin/apachectl start