test: expand server protocol scenario coverage
This commit is contained in:
@@ -4,12 +4,10 @@ This directory is intentionally separate from the development/toolchain Compose
|
||||
files. It starts only the Linux server and nginx TLS terminator; Windows clients
|
||||
connect through nginx at `/v1/agent`.
|
||||
|
||||
Before the first start, create `server.toml` from the authoritative example and
|
||||
prepare writable state directories for the runtime image UID/GID `65532`:
|
||||
Before the first start, create `server.toml` from the authoritative example:
|
||||
|
||||
```sh
|
||||
cp ../../docs/examples/server.toml server.toml
|
||||
install -d -m 0700 -o 65532 -g 65532 state run
|
||||
chmod 0640 server.toml
|
||||
```
|
||||
|
||||
@@ -22,7 +20,8 @@ docker compose -f compose.yaml config
|
||||
docker compose -f compose.yaml up -d
|
||||
```
|
||||
|
||||
Only `state/` and `run/` are persistent/owned deployment data. Back up the
|
||||
whole `state/` directory while the server is stopped; `run/` contains only the
|
||||
ephemeral local control socket. Do not publish, proxy, or enable JSON-RPC except
|
||||
for intentional loopback debugging.
|
||||
The stack's `init` container creates the two named volumes with the runtime
|
||||
ownership required by the non-root server. `server-data` is the sole persistent
|
||||
data volume and must be backed up as a whole while the server is stopped;
|
||||
`server-run` contains only the ephemeral local control socket. Do not publish,
|
||||
proxy, or enable JSON-RPC except for intentional loopback debugging.
|
||||
|
||||
@@ -6,6 +6,25 @@
|
||||
name: rvbox-server
|
||||
|
||||
services:
|
||||
init:
|
||||
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
|
||||
user: "0:0"
|
||||
entrypoint: ["/bin/sh", "-ec"]
|
||||
command: >-
|
||||
mkdir -p /var/lib/rvbox-server /run/rvbox &&
|
||||
chown 65532:65532 /var/lib/rvbox-server /run/rvbox &&
|
||||
chmod 0700 /var/lib/rvbox-server /run/rvbox
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp:mode=1777,size=8m
|
||||
volumes:
|
||||
- server-data:/var/lib/rvbox-server
|
||||
- server-run:/run/rvbox
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop: ["ALL"]
|
||||
cap_add: ["CHOWN", "FOWNER"]
|
||||
|
||||
server:
|
||||
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
|
||||
restart: unless-stopped
|
||||
@@ -18,11 +37,11 @@ services:
|
||||
source: ./server.toml
|
||||
target: /etc/rvbox/server.toml
|
||||
read_only: true
|
||||
- type: bind
|
||||
source: ./state
|
||||
- type: volume
|
||||
source: server-data
|
||||
target: /var/lib/rvbox-server
|
||||
- type: bind
|
||||
source: ./run
|
||||
- type: volume
|
||||
source: server-run
|
||||
target: /run/rvbox
|
||||
expose:
|
||||
- "6899"
|
||||
@@ -36,6 +55,9 @@ services:
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop: ["ALL"]
|
||||
depends_on:
|
||||
init:
|
||||
condition: service_completed_successfully
|
||||
|
||||
nginx:
|
||||
image: nginx:1.27.5-alpine
|
||||
@@ -66,3 +88,7 @@ services:
|
||||
- no-new-privileges:true
|
||||
cap_drop: ["ALL"]
|
||||
cap_add: ["NET_BIND_SERVICE"]
|
||||
|
||||
volumes:
|
||||
server-data:
|
||||
server-run:
|
||||
|
||||
@@ -1,34 +0,0 @@
|
||||
[Unit]
|
||||
Description=RVBox server
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=rvbox
|
||||
Group=rvbox
|
||||
ExecStartPre=/usr/local/bin/rvbox-server --check-config --config /etc/rvbox/server.toml
|
||||
ExecStart=/usr/local/bin/rvbox-server --config /etc/rvbox/server.toml
|
||||
Restart=on-failure
|
||||
RestartSec=5s
|
||||
TimeoutStopSec=35s
|
||||
WorkingDirectory=/var/lib/rvbox-server
|
||||
StateDirectory=rvbox-server
|
||||
RuntimeDirectory=rvbox
|
||||
RuntimeDirectoryMode=0750
|
||||
UMask=0077
|
||||
LimitNOFILE=65536
|
||||
NoNewPrivileges=yes
|
||||
PrivateTmp=yes
|
||||
ProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
ProtectKernelTunables=yes
|
||||
ProtectKernelModules=yes
|
||||
ProtectControlGroups=yes
|
||||
RestrictSUIDSGID=yes
|
||||
LockPersonality=yes
|
||||
MemoryDenyWriteExecute=yes
|
||||
ReadWritePaths=/var/lib/rvbox-server /run/rvbox
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user