beszel/compose.yaml

65 lines
3.3 KiB
YAML

services:
beszel:
image: henrygd/beszel:0.19.0
container_name: beszel
restart: always
environment:
APP_URL: http://10.1.1.111:8090
BESZEL_HUB_USER_EMAIL: ${BESZEL_ADMIN_EMAIL}
BESZEL_HUB_USER_PASSWORD: ${BESZEL_ADMIN_PASSWORD}
ports:
- "8090:8090"
volumes:
- /app-config/beszel/hub:/beszel_data
- /app-config/beszel/socket:/beszel_socket
- ./config.yml:/beszel_data/config.yml:ro
healthcheck:
test: ["CMD", "/beszel", "health", "--url", "http://localhost:8090"]
interval: 60s
timeout: 5s
start_period: 15s
retries: 3
beszel-password-changer:
image: python:3.11-alpine
container_name: beszel-password-changer
restart: "no"
depends_on:
beszel:
condition: service_healthy
environment:
BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL}
BESZEL_OLD_PASSWORD: ${BESZEL_OLD_PASSWORD}
BESZEL_NEW_PASSWORD: ${BESZEL_NEW_PASSWORD}
command:
- python
- -c
- |
import json, os, urllib.request
base = "http://beszel:8090"
email = os.environ["BESZEL_EMAIL"]
old = os.environ["BESZEL_OLD_PASSWORD"]
new = os.environ["BESZEL_NEW_PASSWORD"]
def auth(password):
body = json.dumps({"identity": email, "password": password}).encode()
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
with urllib.request.urlopen(req, timeout=10) as response:
return json.load(response)
user_session = auth(old)
super_body = json.dumps({"identity": email, "password": old}).encode()
super_req = urllib.request.Request(base + "/api/collections/_superusers/auth-with-password", data=super_body, headers={"Content-Type": "application/json"})
with urllib.request.urlopen(super_req, timeout=10) as response:
super_session = json.load(response)
update = json.dumps({"password": new, "passwordConfirm": new}).encode()
user_req = urllib.request.Request(base + "/api/collections/users/records/" + user_session["record"]["id"], data=update, method="PATCH", headers={"Authorization": super_session["token"], "Content-Type": "application/json"})
with urllib.request.urlopen(user_req, timeout=10) as response:
user_updated = json.load(response)
super_req = urllib.request.Request(base + "/api/collections/_superusers/records/" + super_session["record"]["id"], data=update, method="PATCH", headers={"Authorization": super_session["token"], "Content-Type": "application/json"})
with urllib.request.urlopen(super_req, timeout=10) as response:
super_updated = json.load(response)
user_verified = auth(new)
super_body = json.dumps({"identity": email, "password": new}).encode()
super_req = urllib.request.Request(base + "/api/collections/_superusers/auth-with-password", data=super_body, headers={"Content-Type": "application/json"})
with urllib.request.urlopen(super_req, timeout=10) as response:
super_verified = json.load(response)
print(json.dumps({"user_changed": bool(user_updated.get("id")), "superuser_changed": bool(super_updated.get("id")), "user_login_ok": bool(user_verified.get("token")), "superuser_login_ok": bool(super_verified.get("token"))}), flush=True)