cloudunity commited on
Commit
2f9dfdb
·
verified ·
1 Parent(s): 610aab7

Update Dockerfile

Browse files
Files changed (1) hide show
  1. Dockerfile +13 -2
Dockerfile CHANGED
@@ -121,18 +121,29 @@ SECRETS_FILE=/app/data/generated-secrets.env
121
  mkdir -p /app/data
122
 
123
  # Generate persistent secrets on first boot so restarts keep sessions valid.
 
 
124
  if [ ! -f "$SECRETS_FILE" ]; then
125
  echo "[entrypoint] first boot - generating secrets"
126
  {
127
  echo "PDS_JWT_SECRET=$(node -e 'console.log(require("crypto").randomBytes(16).toString("hex"))')"
128
  echo "PDS_ADMIN_PASSWORD=$(node -e 'console.log(require("crypto").randomBytes(16).toString("hex"))')"
129
- echo "PDS_PLC_ROTATION_KEY_K256_PRIVATE_KEY_HEX=$(node -e 'const k=require("@atproto/crypto");k.Secp256k1Keypair.create({exportable:true}).then(kp=>kp.export()).then(j=>console.log(Buffer.from(Object.values(j)).toString("hex")))')"
130
  } > "$SECRETS_FILE"
131
  chmod 600 "$SECRETS_FILE" || true
132
  fi
133
  . "$SECRETS_FILE"
134
  export PDS_JWT_SECRET PDS_ADMIN_PASSWORD PDS_PLC_ROTATION_KEY_K256_PRIVATE_KEY_HEX
135
 
 
 
 
 
 
 
 
 
 
136
  echo "================================================================"
137
  echo " Generated secrets (saved in $SECRETS_FILE):"
138
  echo " PDS_ADMIN_PASSWORD: $PDS_ADMIN_PASSWORD"
@@ -173,7 +184,7 @@ ENV PDS_EMAIL_DISABLE_CONFIRMATION_LINK=true
173
  # variable named PDS_HOSTNAME) so the PDS advertises the right endpoint:
174
  # https://<owner>-<space>.hf.space
175
  # Users' handles will be <name>.<that hostname>.
176
- ENV PDS_HOSTNAME=https://cloudunity-gemma-api1.hf.space
177
 
178
  EXPOSE 7860
179
 
 
121
  mkdir -p /app/data
122
 
123
  # Generate persistent secrets on first boot so restarts keep sessions valid.
124
+ # NOTE: a secp256k1 (K256) private key is just 32 random bytes, so no
125
+ # @atproto/crypto import is needed (it is not resolvable under pnpm layout).
126
  if [ ! -f "$SECRETS_FILE" ]; then
127
  echo "[entrypoint] first boot - generating secrets"
128
  {
129
  echo "PDS_JWT_SECRET=$(node -e 'console.log(require("crypto").randomBytes(16).toString("hex"))')"
130
  echo "PDS_ADMIN_PASSWORD=$(node -e 'console.log(require("crypto").randomBytes(16).toString("hex"))')"
131
+ echo "PDS_PLC_ROTATION_KEY_K256_PRIVATE_KEY_HEX=$(node -e 'console.log(require("crypto").randomBytes(32).toString("hex"))')"
132
  } > "$SECRETS_FILE"
133
  chmod 600 "$SECRETS_FILE" || true
134
  fi
135
  . "$SECRETS_FILE"
136
  export PDS_JWT_SECRET PDS_ADMIN_PASSWORD PDS_PLC_ROTATION_KEY_K256_PRIVATE_KEY_HEX
137
 
138
+ # PDS_HOSTNAME must be a bare hostname (no scheme, no trailing slash).
139
+ # did:web is built from it; normalize common full-URL mistakes.
140
+ PDS_HOSTNAME=$(node -e '
141
+ let h = process.env.PDS_HOSTNAME || ""
142
+ h = h.trim().replace(/^https?:\/\//, "").replace(/\/+$/, "").replace(/:.*$/, "")
143
+ console.log(h)
144
+ ')
145
+ export PDS_HOSTNAME
146
+
147
  echo "================================================================"
148
  echo " Generated secrets (saved in $SECRETS_FILE):"
149
  echo " PDS_ADMIN_PASSWORD: $PDS_ADMIN_PASSWORD"
 
184
  # variable named PDS_HOSTNAME) so the PDS advertises the right endpoint:
185
  # https://<owner>-<space>.hf.space
186
  # Users' handles will be <name>.<that hostname>.
187
+ ENV PDS_HOSTNAME=https://cloudunity-gemmapi1.hf.space
188
 
189
  EXPOSE 7860
190