Commit Graph
4 Commits
Author SHA1 Message Date
jekkos de21fdb682 fix(install): always set app.allowedHostnames so the app starts in production
The shipped .env has no app.allowedHostnames line, so the previous sed was a
silent no-op. Since the installer sets CI_ENVIRONMENT=production, the app then
fails fast on first load (App.php throws when the whitelist is empty). Append
the key if it's missing, or substitute it if present.
2026-09-30 14:22:42 +00:00
jekkos 6b83e0f108 fix(install): make cleanup EXIT trap return 0 under set -e
The cleanup used '[ -n ... ] && rm -f ...', which returns non-zero when the
temp file is unset (the no-root-password default). Under the installer's
'set -e', that non-zero status becomes the script's exit code, failing the CI
step even though the install completed. Rewrite as an if-statement so it
always exits 0.
2026-09-30 15:52:54 +02:00
jekkos 9baa396445 fix(install): address CodeRabbit review round 2
- Workflow: use github.ref for the concurrency group so distinct PRs from the
  same source branch don't cancel each other
- Workflow: extract the generated DB password from the installer's 'Password:'
  output and verify the 'ospos' account can authenticate with DB_PASS
- Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session,
  pass the root password via a private 0600 defaults file (no argv exposure),
  and scope the SQL account to the 'localhost' client host
- Docs: interactive mode requires a tty (download-then-run, not a pipe);
  clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
2026-09-30 15:52:54 +02:00
jekkos 4170ed4028 feat(install): add one-line Ubuntu installer with CI test and docs
- Add scripts/install-ubuntu.sh: installs Apache/MariaDB/PHP, downloads the
  latest stable release, configures the DB + Apache, and optionally sets up
  Let's Encrypt SSL (interactive or via env vars).
- Add .github/workflows/install-script-test.yml: runs the installer in a fresh
  Ubuntu container and sanity-checks the result.
- Document the installer in INSTALL.md.
- Harden the script: identifier-safe DB_NAME, quote/pipe rejection in
  passwords, correct 'Candidate: (none)' PPA detection, keep unix_socket root
  auth when no root password is set, select the .zip release asset, and use the
  SSL domain as the public hostname for allowedHostnames.

Based on the latest master CI (build-release.yml / deploy-pr.yml left as-is).
2026-09-30 15:52:54 +02:00