diff --git a/.github/workflows/pr-batch-test-deploy.yml b/.github/workflows/pr-batch-test-deploy.yml index d745eb97..ad31ee33 100644 --- a/.github/workflows/pr-batch-test-deploy.yml +++ b/.github/workflows/pr-batch-test-deploy.yml @@ -143,6 +143,27 @@ jobs: cache-from: type=gha,scope=manual-test-server cache-to: type=gha,mode=max,scope=manual-test-server + - name: Resolve frontend runtime defaults + id: web-runtime + env: + PUBLIC_URL: ${{ inputs.public_url }} + WEB_BASE_PATH: ${{ inputs.web_base_path }} + run: | + public_url="${PUBLIC_URL%/}" + web_base_path="${WEB_BASE_PATH}" + api_base_url="" + + if [[ -n "${web_base_path}" && "${web_base_path}" != "/" ]]; then + case "${web_base_path}" in + /*/) api_base_url="${web_base_path%/}" ;; + /*) api_base_url="${web_base_path}" ;; + *) api_base_url="/${web_base_path%/}" ;; + esac + fi + + echo "public_url=${public_url}" >> "${GITHUB_OUTPUT}" + echo "api_base_url=${api_base_url}" >> "${GITHUB_OUTPUT}" + - name: Build and push frontend image uses: docker/build-push-action@v6 with: @@ -151,6 +172,8 @@ jobs: platforms: ${{ env.DOCKER_PLATFORM }} build-args: | VITE_BASE_PATH=${{ inputs.web_base_path || '/__SKILLHUB_WEB_BASE_PATH__/' }} + SKILLHUB_PUBLIC_BASE_URL=${{ steps.web-runtime.outputs.public_url }} + SKILLHUB_WEB_API_BASE_URL=${{ steps.web-runtime.outputs.api_base_url }} push: true provenance: false sbom: false diff --git a/scripts/deploy-test-runtime.sh b/scripts/deploy-test-runtime.sh index 95c8feab..645997b7 100755 --- a/scripts/deploy-test-runtime.sh +++ b/scripts/deploy-test-runtime.sh @@ -209,13 +209,17 @@ if [[ -n "${public_url}" || -n "${web_base_path}" ]]; then if ! grep -Fq -- "--public-url" <<<"${helper_help}" || \ ! grep -Fq -- "--web-base-path" <<<"${helper_help}"; then if [[ -n "${remote_helper_path}" && -f "${remote_helper_path}" ]]; then - echo "HK deploy helper is outdated; installing bundled helper from ${remote_helper_path}." >&2 - sudo install -m 0755 "${remote_helper_path}" /usr/local/bin/skillhub-test-deploy - helper_help="$(sudo /usr/local/bin/skillhub-test-deploy --help 2>&1 || true)" - if ! grep -Fq -- "--public-url" <<<"${helper_help}" || \ - ! grep -Fq -- "--web-base-path" <<<"${helper_help}"; then + echo "HK deploy helper is outdated; trying to install bundled helper from ${remote_helper_path}." >&2 + if sudo -n install -m 0755 "${remote_helper_path}" /usr/local/bin/skillhub-test-deploy; then + helper_help="$(sudo /usr/local/bin/skillhub-test-deploy --help 2>&1 || true)" + if ! grep -Fq -- "--public-url" <<<"${helper_help}" || \ + ! grep -Fq -- "--web-base-path" <<<"${helper_help}"; then + helper_supports_sub_path=false + echo "Bundled HK deploy helper still does not support sub-path options." >&2 + fi + else helper_supports_sub_path=false - echo "Bundled HK deploy helper still does not support sub-path options." >&2 + echo "Cannot install bundled HK deploy helper without passwordless sudo; falling back to the existing helper." >&2 fi else helper_supports_sub_path=false diff --git a/web/Dockerfile b/web/Dockerfile index 241d6996..ca1454ee 100644 --- a/web/Dockerfile +++ b/web/Dockerfile @@ -14,8 +14,16 @@ ENV SKILLHUB_TRUST_FORWARDED_PROTO=false # to it and generates matching Nginx routing without repeating the value at runtime. # Placeholder builds (the default) intentionally write no file and default to '/'. ARG VITE_BASE_PATH=/__SKILLHUB_WEB_BASE_PATH__/ +ARG SKILLHUB_PUBLIC_BASE_URL= +ARG SKILLHUB_WEB_API_BASE_URL= RUN if [ "$VITE_BASE_PATH" != "/__SKILLHUB_WEB_BASE_PATH__/" ]; then \ mkdir -p /etc/skillhub && printf '%s' "$VITE_BASE_PATH" > /etc/skillhub/baked-base-path; \ + fi; \ + if [ -n "$SKILLHUB_PUBLIC_BASE_URL" ]; then \ + mkdir -p /etc/skillhub && printf '%s' "$SKILLHUB_PUBLIC_BASE_URL" > /etc/skillhub/baked-public-base-url; \ + fi; \ + if [ -n "$SKILLHUB_WEB_API_BASE_URL" ]; then \ + mkdir -p /etc/skillhub && printf '%s' "$SKILLHUB_WEB_API_BASE_URL" > /etc/skillhub/baked-api-base-url; \ fi COPY --from=build /app/dist /usr/share/nginx/html COPY --from=build /app/src/docs/skill.md.template /usr/share/nginx/html/registry/skill.md.template diff --git a/web/docker-entrypoint.d/30-runtime-config.sh b/web/docker-entrypoint.d/30-runtime-config.sh index a8bf88a4..608ccdd1 100644 --- a/web/docker-entrypoint.d/30-runtime-config.sh +++ b/web/docker-entrypoint.d/30-runtime-config.sh @@ -6,6 +6,17 @@ set -eu : "${SKILLHUB_WEB_AUTH_DIRECT_ENABLED:=false}" : "${SKILLHUB_WEB_AUTH_DIRECT_PROVIDER:=}" +baked_api_base_url_file="${SKILLHUB_WEB_BAKED_API_BASE_URL_FILE:-/etc/skillhub/baked-api-base-url}" +baked_public_base_url_file="${SKILLHUB_WEB_BAKED_PUBLIC_BASE_URL_FILE:-/etc/skillhub/baked-public-base-url}" + +if [ -z "$SKILLHUB_WEB_API_BASE_URL" ] && [ -f "$baked_api_base_url_file" ]; then + SKILLHUB_WEB_API_BASE_URL=$(cat "$baked_api_base_url_file") +fi + +if [ -z "$SKILLHUB_PUBLIC_BASE_URL" ] && [ -f "$baked_public_base_url_file" ]; then + SKILLHUB_PUBLIC_BASE_URL=$(cat "$baked_public_base_url_file") +fi + # Session-bootstrap variables are defaulted here so envsubst writes # `authSessionBootstrapEnabled: "false"` into runtime-config.js instead of leaving # the literal `${...}` placeholder. They are intentionally NOT exposed in