81 lines
2.4 KiB
Bash
81 lines
2.4 KiB
Bash
#!/bin/sh
|
|
|
|
set -eu
|
|
|
|
prefix="memrelay-vault-stage0"
|
|
network="${prefix}-network"
|
|
vault="${prefix}-server"
|
|
tls="${prefix}-tls"
|
|
cli="${prefix}-cli"
|
|
config_volume="${prefix}-config"
|
|
npm_volume="${prefix}-npm"
|
|
email="stage0@memrelay.local"
|
|
password="MemRelay-Stage0-2026!"
|
|
script_dir="$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)"
|
|
script_source="${MEMRELAY_SCRIPT_SOURCE:-$script_dir}"
|
|
|
|
cleanup() {
|
|
docker rm -f "$cli" "$tls" "$vault" >/dev/null 2>&1 || true
|
|
docker volume rm "$config_volume" "$npm_volume" >/dev/null 2>&1 || true
|
|
docker network rm "$network" >/dev/null 2>&1 || true
|
|
}
|
|
trap cleanup EXIT INT TERM
|
|
cleanup
|
|
|
|
docker network create "$network" >/dev/null
|
|
docker volume create "$config_volume" >/dev/null
|
|
docker volume create "$npm_volume" >/dev/null
|
|
|
|
docker run -d --name "$vault" --network "$network" \
|
|
-e I_REALLY_WANT_VOLATILE_STORAGE=true \
|
|
-e SIGNUPS_ALLOWED=true \
|
|
-e DOMAIN="https://$tls" \
|
|
vaultwarden/server:1.37.1 >/dev/null
|
|
|
|
docker run -d --name "$tls" --network "$network" \
|
|
-e HTTP_PROXY= -e HTTPS_PROXY= -e http_proxy= -e https_proxy= \
|
|
caddy:2-alpine caddy reverse-proxy \
|
|
--from "https://$tls" \
|
|
--to "http://$vault:80" \
|
|
--internal-certs >/dev/null
|
|
|
|
docker run -d --name "$cli" --network "$network" \
|
|
-e HTTP_PROXY= -e HTTPS_PROXY= -e http_proxy= -e https_proxy= \
|
|
-v "$config_volume:/root/.config" \
|
|
-v "$npm_volume:/root/.npm" \
|
|
--mount "type=bind,source=$script_source,target=/opt/memrelay-tests,readonly" \
|
|
node:22-bookworm-slim sh -lc \
|
|
"npm install -g @bitwarden/cli@2026.7.0 >/tmp/npm-install.log 2>&1 && touch /tmp/ready && sleep infinity" \
|
|
>/dev/null
|
|
|
|
attempt=0
|
|
until docker exec "$cli" test -f /tmp/ready; do
|
|
attempt=$((attempt + 1))
|
|
if [ "$attempt" -ge 120 ]; then
|
|
docker logs "$cli" >&2
|
|
exit 1
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
docker exec "$cli" node /opt/memrelay-tests/create_test_vault_account.mjs \
|
|
"http://$vault" "$email" "$password" >/dev/null
|
|
|
|
docker exec \
|
|
-e NODE_TLS_REJECT_UNAUTHORIZED=0 \
|
|
-e BW_SERVER="https://$tls" \
|
|
-e BW_EMAIL="$email" \
|
|
-e BW_PASSWORD="$password" \
|
|
"$cli" sh /opt/memrelay-tests/validate_bitwarden_cli.sh
|
|
|
|
docker stop "$tls" >/dev/null
|
|
docker exec \
|
|
-e NODE_TLS_REJECT_UNAUTHORIZED=0 \
|
|
-e BW_SERVER="https://$tls" \
|
|
-e BW_EMAIL="$email" \
|
|
-e BW_PASSWORD="$password" \
|
|
-e BW_OFFLINE_ONLY=1 \
|
|
"$cli" sh /opt/memrelay-tests/validate_bitwarden_cli.sh
|
|
|
|
echo "Vault integration validation passed"
|