services: beszel: image: henrygd/beszel:0.19.0 container_name: beszel restart: always environment: APP_URL: http://10.1.1.111:8090 BESZEL_HUB_USER_EMAIL: ${BESZEL_ADMIN_EMAIL} BESZEL_HUB_USER_PASSWORD: ${BESZEL_ADMIN_PASSWORD} ports: - "8090:8090" volumes: - /app-config/beszel/hub:/beszel_data - /app-config/beszel/socket:/beszel_socket - ./config.yml:/beszel_data/config.yml:ro healthcheck: test: ["CMD", "/beszel", "health", "--url", "http://localhost:8090"] interval: 60s timeout: 5s start_period: 15s retries: 3 beszel-password-changer: image: python:3.11-alpine container_name: beszel-password-changer restart: "no" depends_on: beszel: condition: service_healthy environment: BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL} BESZEL_OLD_PASSWORD: ${BESZEL_OLD_PASSWORD} BESZEL_NEW_PASSWORD: ${BESZEL_NEW_PASSWORD} command: - python - -c - | import json, os, urllib.request base = "http://beszel:8090" email = os.environ["BESZEL_EMAIL"] old = os.environ["BESZEL_OLD_PASSWORD"] new = os.environ["BESZEL_NEW_PASSWORD"] def auth(password): body = json.dumps({"identity": email, "password": password}).encode() req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"}) with urllib.request.urlopen(req, timeout=10) as response: return json.load(response) session = auth(old) record_id = session["record"]["id"] body = json.dumps({"password": new, "passwordConfirm": new}).encode() req = urllib.request.Request(base + "/api/collections/users/records/" + record_id, data=body, method="PATCH", headers={"Authorization": session["token"], "Content-Type": "application/json"}) with urllib.request.urlopen(req, timeout=10) as response: updated = json.load(response) verified = auth(new) print(json.dumps({"password_changed": updated.get("id") == record_id, "new_login_ok": bool(verified.get("token"))}), flush=True)