fix: WebSocket race conditions, Vue error handler, remove sudo podman, add container health checks
- F1: Guard connectWebSocket against concurrent calls with isWsConnecting flag - F2: Serialize mesh send operations with sendQueue to prevent fetchMessages races - F3: Add global Vue error handler with toast notification - S1: Replace sudo podman with podman across all scripts (rootless Podman) - S2: Add health-cmd to all 40 container run commands in first-boot-containers.sh Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
c299199d37
commit
38dc845f57
@@ -19,13 +19,13 @@ NETWORK="indeedhub-build_indeedhub-network"
|
||||
# Load custom images if tar exists
|
||||
if [ -f /tmp/indeedhub-images.tar ]; then
|
||||
echo "Loading custom images from tar..."
|
||||
sudo podman load < /tmp/indeedhub-images.tar 2>&1 | tail -5
|
||||
podman load < /tmp/indeedhub-images.tar 2>&1 | tail -5
|
||||
fi
|
||||
|
||||
# Verify correct images are available
|
||||
echo "Verifying images..."
|
||||
for img in "docker.io/library/redis:7-alpine" "docker.io/minio/minio:latest" "docker.io/library/postgres:16-alpine" "docker.io/scsibug/nostr-rs-relay:latest" "docker.io/searxng/searxng:latest" "localhost/indeedhub:latest" "localhost/indeedhub-build_api:latest" "localhost/indeedhub-build_ffmpeg-worker:latest"; do
|
||||
if ! sudo podman image exists "$img" 2>/dev/null; then
|
||||
if ! podman image exists "$img" 2>/dev/null; then
|
||||
echo "ERROR: Missing image $img"
|
||||
exit 1
|
||||
fi
|
||||
@@ -33,26 +33,26 @@ done
|
||||
echo "All images verified."
|
||||
|
||||
# Ensure network exists
|
||||
if ! sudo podman network exists "$NETWORK" 2>/dev/null; then
|
||||
if ! podman network exists "$NETWORK" 2>/dev/null; then
|
||||
echo "Creating network $NETWORK..."
|
||||
sudo podman network create "$NETWORK" 2>/dev/null || true
|
||||
podman network create "$NETWORK" 2>/dev/null || true
|
||||
fi
|
||||
|
||||
# Stop all affected containers
|
||||
echo "Stopping containers..."
|
||||
for c in indeedhub indeedhub-build_api_1 indeedhub-build_ffmpeg-worker_1 indeedhub-relay indeedhub-redis indeedhub-minio indeedhub-postgres searxng; do
|
||||
sudo podman stop "$c" 2>/dev/null || true
|
||||
podman stop "$c" 2>/dev/null || true
|
||||
done
|
||||
|
||||
# Remove all affected containers
|
||||
echo "Removing containers..."
|
||||
for c in indeedhub indeedhub-build_api_1 indeedhub-build_ffmpeg-worker_1 indeedhub-relay indeedhub-redis indeedhub-minio indeedhub-postgres searxng; do
|
||||
sudo podman rm -f "$c" 2>/dev/null || true
|
||||
podman rm -f "$c" 2>/dev/null || true
|
||||
done
|
||||
|
||||
# 1. PostgreSQL (must start first — others depend on it)
|
||||
echo "Creating postgres..."
|
||||
sudo podman run -d --name indeedhub-postgres \
|
||||
podman run -d --name indeedhub-postgres \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias postgres \
|
||||
-v indeedhub-postgres-data:/var/lib/postgresql/data \
|
||||
@@ -64,7 +64,7 @@ sudo podman run -d --name indeedhub-postgres \
|
||||
# Wait for postgres to be ready
|
||||
echo "Waiting for postgres..."
|
||||
for i in $(seq 1 15); do
|
||||
if sudo podman exec indeedhub-postgres pg_isready -U indeedhub 2>/dev/null; then
|
||||
if podman exec indeedhub-postgres pg_isready -U indeedhub 2>/dev/null; then
|
||||
echo "Postgres ready."
|
||||
break
|
||||
fi
|
||||
@@ -73,7 +73,7 @@ done
|
||||
|
||||
# 2. Redis
|
||||
echo "Creating redis..."
|
||||
sudo podman run -d --name indeedhub-redis \
|
||||
podman run -d --name indeedhub-redis \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias redis \
|
||||
-v indeedhub-redis-data:/data \
|
||||
@@ -82,7 +82,7 @@ sudo podman run -d --name indeedhub-redis \
|
||||
|
||||
# 3. MinIO
|
||||
echo "Creating minio..."
|
||||
sudo podman run -d --name indeedhub-minio \
|
||||
podman run -d --name indeedhub-minio \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias minio \
|
||||
-v indeedhub-minio-data:/data \
|
||||
@@ -93,7 +93,7 @@ sudo podman run -d --name indeedhub-minio \
|
||||
|
||||
# 4. Nostr Relay
|
||||
echo "Creating relay..."
|
||||
sudo podman run -d --name indeedhub-relay \
|
||||
podman run -d --name indeedhub-relay \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias relay \
|
||||
-v indeedhub-relay-data:/usr/src/app/db \
|
||||
@@ -101,7 +101,7 @@ sudo podman run -d --name indeedhub-relay \
|
||||
|
||||
# 5. API
|
||||
echo "Creating api..."
|
||||
sudo podman run -d --name indeedhub-build_api_1 \
|
||||
podman run -d --name indeedhub-build_api_1 \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias api \
|
||||
-e ENVIRONMENT=production \
|
||||
@@ -142,7 +142,7 @@ sudo podman run -d --name indeedhub-build_api_1 \
|
||||
|
||||
# 6. FFmpeg Worker
|
||||
echo "Creating ffmpeg-worker..."
|
||||
sudo podman run -d --name indeedhub-build_ffmpeg-worker_1 \
|
||||
podman run -d --name indeedhub-build_ffmpeg-worker_1 \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" --network-alias ffmpeg-worker \
|
||||
-e ENVIRONMENT=production \
|
||||
@@ -166,7 +166,7 @@ sudo podman run -d --name indeedhub-build_ffmpeg-worker_1 \
|
||||
|
||||
# 7. IndeedHub Frontend
|
||||
echo "Creating indeedhub frontend..."
|
||||
sudo podman run -d --name indeedhub \
|
||||
podman run -d --name indeedhub \
|
||||
--restart unless-stopped \
|
||||
--network "$NETWORK" \
|
||||
-p 7777:7777 \
|
||||
@@ -179,48 +179,48 @@ sudo podman run -d --name indeedhub \
|
||||
|
||||
# Fix IndeedHub for iframe: remove X-Frame-Options, inject nostr-provider, hardcode container IPs
|
||||
sleep 3
|
||||
if sudo podman ps --format '{{.Names}}' 2>/dev/null | grep -q "^indeedhub$"; then
|
||||
sudo podman exec indeedhub sed -i "/X-Frame-Options/d" /etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
if podman ps --format '{{.Names}}' 2>/dev/null | grep -q "^indeedhub$"; then
|
||||
podman exec indeedhub sed -i "/X-Frame-Options/d" /etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
|
||||
# Inject nostr-provider.js if available
|
||||
if [ -f /opt/archipelago/web-ui/nostr-provider.js ]; then
|
||||
sudo podman cp /opt/archipelago/web-ui/nostr-provider.js indeedhub:/usr/share/nginx/html/nostr-provider.js 2>/dev/null || true
|
||||
podman cp /opt/archipelago/web-ui/nostr-provider.js indeedhub:/usr/share/nginx/html/nostr-provider.js 2>/dev/null || true
|
||||
fi
|
||||
|
||||
# Add nostr-provider location block + sub_filter
|
||||
if ! sudo podman exec indeedhub grep -q "nostr-provider" /etc/nginx/conf.d/default.conf 2>/dev/null; then
|
||||
sudo podman exec indeedhub cat /etc/nginx/conf.d/default.conf > /tmp/ih-nginx.conf 2>/dev/null
|
||||
if ! podman exec indeedhub grep -q "nostr-provider" /etc/nginx/conf.d/default.conf 2>/dev/null; then
|
||||
podman exec indeedhub cat /etc/nginx/conf.d/default.conf > /tmp/ih-nginx.conf 2>/dev/null
|
||||
sed -i "/location = \/sw.js {/i\\ location = /nostr-provider.js {\n add_header Cache-Control \"no-cache, no-store, must-revalidate\";\n expires off;\n }\n" /tmp/ih-nginx.conf
|
||||
sed -i "/try_files.*index.html/a\\ sub_filter_once on;\n sub_filter '</head>' '<script src=\"/nostr-provider.js\"></script></head>';" /tmp/ih-nginx.conf
|
||||
sudo podman cp /tmp/ih-nginx.conf indeedhub:/etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
podman cp /tmp/ih-nginx.conf indeedhub:/etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
rm -f /tmp/ih-nginx.conf
|
||||
fi
|
||||
|
||||
# Replace DNS-based upstream resolution with hardcoded container IPs
|
||||
# (podman DNS resolver 127.0.0.11 is unreliable, causing 502 errors)
|
||||
API_IP=$(sudo podman inspect indeedhub-build_api_1 --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
MINIO_IP=$(sudo podman inspect indeedhub-minio --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
RELAY_IP=$(sudo podman inspect indeedhub-relay --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
API_IP=$(podman inspect indeedhub-build_api_1 --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
MINIO_IP=$(podman inspect indeedhub-minio --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
RELAY_IP=$(podman inspect indeedhub-relay --format "{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}" 2>/dev/null)
|
||||
|
||||
if [ -n "$API_IP" ] && [ -n "$MINIO_IP" ] && [ -n "$RELAY_IP" ]; then
|
||||
sudo podman exec indeedhub cat /etc/nginx/conf.d/default.conf > /tmp/ih-nginx.conf 2>/dev/null
|
||||
podman exec indeedhub cat /etc/nginx/conf.d/default.conf > /tmp/ih-nginx.conf 2>/dev/null
|
||||
sed -i "s|resolver 127.0.0.11 valid=30s ipv6=off;||g" /tmp/ih-nginx.conf
|
||||
sed -i "s|set \$api_upstream http://api:4000;|set \$api_upstream http://$API_IP:4000;|g" /tmp/ih-nginx.conf
|
||||
sed -i "s|set \$minio_upstream http://minio:9000;|set \$minio_upstream http://$MINIO_IP:9000;|g" /tmp/ih-nginx.conf
|
||||
sed -i "s|set \$relay_upstream http://relay:8080;|set \$relay_upstream http://$RELAY_IP:8080;|g" /tmp/ih-nginx.conf
|
||||
sed -i "s|proxy_set_header Host \$host;|proxy_set_header Host \$http_host;|g" /tmp/ih-nginx.conf
|
||||
sudo podman cp /tmp/ih-nginx.conf indeedhub:/etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
podman cp /tmp/ih-nginx.conf indeedhub:/etc/nginx/conf.d/default.conf 2>/dev/null || true
|
||||
rm -f /tmp/ih-nginx.conf
|
||||
echo "Patched IndeedHub nginx with container IPs (API=$API_IP MINIO=$MINIO_IP RELAY=$RELAY_IP)"
|
||||
fi
|
||||
|
||||
sudo podman exec indeedhub nginx -s reload 2>/dev/null || true
|
||||
podman exec indeedhub nginx -s reload 2>/dev/null || true
|
||||
echo "Applied IndeedHub iframe fix."
|
||||
fi
|
||||
|
||||
# 8. SearXNG (standalone — no cap-drop ALL, searxng needs write access to /etc/searxng/)
|
||||
echo "Creating searxng..."
|
||||
sudo podman run -d --name searxng \
|
||||
podman run -d --name searxng \
|
||||
--restart unless-stopped \
|
||||
-p 8888:8080 \
|
||||
docker.io/searxng/searxng:latest
|
||||
@@ -228,6 +228,6 @@ sudo podman run -d --name searxng \
|
||||
echo ""
|
||||
echo "=== Verifying container status ==="
|
||||
sleep 5
|
||||
sudo podman ps -a --filter name=indeedhub --filter name=searxng --format "table {{.Names}}\t{{.Status}}" 2>&1
|
||||
podman ps -a --filter name=indeedhub --filter name=searxng --format "table {{.Names}}\t{{.Status}}" 2>&1
|
||||
echo ""
|
||||
echo "=== FIX COMPLETE ==="
|
||||
|
||||
Reference in New Issue
Block a user