fix(keyCloak): fix openresty keycloak deployment recipe (#3655)
Co-authored-by: Joe Boccanfuso <joe.boccanfuso@radicalimaging.com>
This commit is contained in:
1 parent
c49b833274
commit
2d7721cb58
15 files changed
+325
-176
No files matched your search
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
@@ -22,7 +22,7 @@ http {
|
||||
|
||||
# lua_ settings
|
||||
#
|
||||
lua_package_path '/usr/local/openresty/lualib/?.lua;;';
|
||||
lua_package_path '/usr/local/openresty/lualib/?.lua;;/usr/local/share/lua/5.4/?.lua;;';
|
||||
lua_shared_dict discovery 1m; # cache for discovery metadata documents
|
||||
lua_shared_dict jwks 1m; # cache for JWKs
|
||||
# lua_ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt;
|
||||
@@ -182,6 +182,8 @@ http {
|
||||
index index.html;
|
||||
try_files $uri $uri/ /index.html;
|
||||
add_header Cache-Control "no-store, no-cache, must-revalidate";
|
||||
add_header 'Cross-Origin-Opener-Policy' 'same-origin' always;
|
||||
add_header 'Cross-Origin-Embedder-Policy' 'require-corp' always;
|
||||
}
|
||||
|
||||
# EXAMPLE: Reverse Proxy, no auth
|
||||
|
||||
@@ -28,6 +28,8 @@ FROM node:16.15.0-slim as builder
|
||||
RUN mkdir /usr/src/app
|
||||
WORKDIR /usr/src/app
|
||||
|
||||
RUN apt-get update && apt-get install -y build-essential python3
|
||||
|
||||
ENV APP_CONFIG=config/docker_openresty-orthanc-keycloak.js
|
||||
ENV PATH /usr/src/app/node_modules/.bin:$PATH
|
||||
|
||||
@@ -44,23 +46,38 @@ RUN yarn run build
|
||||
# Stage 2: Bundle the built application into a Docker container
|
||||
# which runs openresty (nginx) using Alpine Linux
|
||||
# LINK: https://hub.docker.com/r/openresty/openresty
|
||||
FROM openresty/openresty:1.15.8.1rc1-0-alpine-fat
|
||||
FROM openresty/openresty:1.21.4.2-0-bullseye-fat
|
||||
|
||||
RUN mkdir /var/log/nginx
|
||||
RUN apk add --no-cache openssl
|
||||
RUN apk add --no-cache openssl-dev
|
||||
RUN apk add --no-cache git
|
||||
RUN apk add --no-cache gcc
|
||||
RUN apt-get update && \
|
||||
apt-get install -y openssl libssl-dev git gcc wget unzip make&& \
|
||||
apt-get clean
|
||||
|
||||
RUN apt-get install --assume-yes lua5.4 libzmq3-dev lua5.4-dev
|
||||
RUN cd /tmp && \
|
||||
wget http://luarocks.org/releases/luarocks-3.9.2.tar.gz && \
|
||||
tar zxpf luarocks-3.9.2.tar.gz && \
|
||||
cd luarocks-3.9.2 && \
|
||||
./configure && \
|
||||
make && \
|
||||
make install
|
||||
|
||||
# !!!
|
||||
RUN luarocks install lua-resty-http
|
||||
# RUN luarocks install lua-nginx-module
|
||||
RUN luarocks install lua-cjson
|
||||
RUN luarocks install lua-resty-string
|
||||
RUN luarocks install lua-resty-session
|
||||
RUN luarocks install lua-resty-jwt
|
||||
RUN luarocks install lua-resty-openidc
|
||||
|
||||
RUN apt-get clean && rm -rf /var/lib/apt/lists/*
|
||||
|
||||
#
|
||||
RUN luarocks install lua-resty-jwt
|
||||
RUN luarocks install lua-resty-session
|
||||
RUN luarocks install lua-resty-http
|
||||
# !!!
|
||||
RUN luarocks install lua-resty-openidc
|
||||
RUN luarocks install luacrypto
|
||||
RUN luarocks install lua-resty-auto-ssl
|
||||
|
||||
|
||||
# Copy build output to image
|
||||
COPY --from=builder /usr/src/app/platform/app/dist /var/www/html
|
||||
|
||||
Reference in new issue
Block a user