Files
deploy_home/ansible/roles/podman/tasks/containers/home/rsvp.yml
T
Bastian de BylandClaude Opus 5 f59ade748b feat(rsvp): deploy rsvp.debyl.io, the invite-only party RSVP app
A single Go binary with SQLite, built and loaded as localhost/rsvpd:<VERSION>
by make deploy-remote in ~/src/rsvp-debylio. Both of its listeners are
published on 127.0.0.1 only: Caddy proxies the public one to everyone and the
admin one (/admin, no login) only to caddy_local_networks. A Caddyfile mistake
alone cannot expose admin, and neither can a port mistake alone.

Guests' invite links are the credential and they sit in the URL path, which
shapes the vhost:

- It does not import common_headers. That snippet sets Referrer-Policy
  same-origin, which would replace the app's no-referrer and let a token leak
  in a Referer header.
- Its access log rewrites request>uri to /i/REDACTED and drops the Location
  response header, since every POST 303s back to /i/<token>.
- Caddy's error logger is separate from the site's and wrote the raw URI to
  caddy.log when the upstream was down. The global log now excludes
  http.log.error.rsvp and a filtered rsvp-errors logger takes it instead.
  Verified with zero token occurrences in both logs, locally and live.

The data directory is owned directly by the host uid of the container's uid
10001 (subuid + 10000). Setting it to the podman user and chowning back each run
flipped ownership on every deploy and briefly locked the app out of its
database.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 23:14:46 -04:00

52 lines
1.6 KiB
YAML

---
# The image runs as uid 10001 (scratch, no passwd file). Rootless podman maps
# container uid N to host uid subuid_start + N - 1, so own the directory as
# that host uid directly. Setting the podman user here and chowning back
# afterwards would flip ownership on every deploy and briefly lock the running
# app out of its own database directory.
- name: create rsvp host directory volumes
become: true
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: "{{ podman_subuid.stdout | int + 10000 }}"
group: "{{ podman_subuid.stdout | int + 10000 }}"
mode: 0750
notify: restorecon podman
loop:
- "{{ rsvp_path }}/data"
- name: flush handlers
ansible.builtin.meta: flush_handlers
- import_tasks: podman/podman-check.yml
vars:
container_name: rsvp
container_image: "{{ image }}"
- name: create rsvp container
become: true
become_user: "{{ podman_user }}"
containers.podman.podman_container:
name: rsvp
image: "{{ image }}"
restart_policy: on-failure:3
log_driver: journald
env:
RSVP_DB_PATH: /data/rsvp.db
RSVP_BASE_URL: "https://{{ rsvp_server_name }}"
RSVP_TZ: America/New_York
# Client IPs for the invite-link miss limiter come from Caddy's
# X-Forwarded-For. Safe only because both ports are loopback-only.
RSVP_TRUST_FORWARDED: "1"
volumes:
- "{{ rsvp_path }}/data:/data"
ports:
- "127.0.0.1:{{ rsvp_public_port }}:8080"
- "127.0.0.1:{{ rsvp_admin_port }}:8081"
- name: create systemd startup job for rsvp
include_tasks: podman/systemd-generate.yml
vars:
container_name: rsvp