diff --git a/docker-compose.yml b/docker-compose.yml index 93703e1..86cad3a 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -34,7 +34,7 @@ services: ports: - "${WEB_PORT:-3000}:3000" environment: - DATABASE_URL: "${DATABASE_URL:-postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public}" + DATABASE_URL: "postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public" NEXTAUTH_SECRET: "${NEXTAUTH_SECRET:-jobsboard-secret-key-for-auth-sessions}" NEXTAUTH_URL: "${NEXTAUTH_URL:-http://localhost:3000}" NODE_ENV: "production" @@ -55,7 +55,7 @@ services: container_name: jobsboard_scraper restart: always environment: - DATABASE_URL: "${DATABASE_URL:-postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public}" + DATABASE_URL: "postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@db:5432/${POSTGRES_DB:-jobsboard}?schema=public" SCRAPE_INTERVAL_MINUTES: "30" SOCKS5_PROXY: "${SOCKS5_PROXY:-}" PROXY_URL: "${PROXY_URL:-}" diff --git a/postgres-entrypoint.sh b/postgres-entrypoint.sh index 80e562d..f67f5db 100755 --- a/postgres-entrypoint.sh +++ b/postgres-entrypoint.sh @@ -1,7 +1,10 @@ #!/bin/sh set -e -# Run background synchronization once PostgreSQL is up on local unix socket +# Re-align the Postgres role password with POSTGRES_PASSWORD on every boot. +# Connects via the local unix socket (pg_hba "trust"), so it works even when +# TCP password auth is currently broken. Runs in the background so it does not +# block server startup, but retries until it succeeds. sync_credentials() { until pg_isready -q -h /var/run/postgresql; do sleep 0.5 @@ -10,17 +13,26 @@ sync_credentials() { USER="${POSTGRES_USER:-postgres}" PASS="${POSTGRES_PASSWORD:-postgres}" - psql -v ON_ERROR_STOP=0 -h /var/run/postgresql -U postgres -d postgres <<-EOSQL >/dev/null 2>&1 - DO \$\$ - BEGIN - IF NOT EXISTS (SELECT FROM pg_catalog.pg_roles WHERE rolname = '$USER') THEN - CREATE ROLE "$USER" WITH LOGIN SUPERUSER PASSWORD '$PASS'; - ELSE + for i in $(seq 1 30); do + if psql -v ON_ERROR_STOP=1 -h /var/run/postgresql -U postgres -d postgres <<-EOSQL 2>/dev/null + DO \$\$ + BEGIN + IF NOT EXISTS (SELECT FROM pg_catalog.pg_roles WHERE rolname = '$USER') THEN + CREATE ROLE "$USER" WITH LOGIN SUPERUSER PASSWORD '$PASS'; + END IF; ALTER ROLE "$USER" WITH LOGIN SUPERUSER PASSWORD '$PASS'; - END IF; - END - \$\$; + END + \$\$; EOSQL + then + echo "[entrypoint] Synchronized '$USER' role password." >&2 + return 0 + fi + echo "[entrypoint] Credential sync attempt $i failed, retrying..." >&2 + sleep 1 + done + + echo "[entrypoint] WARNING: could not synchronize credentials." >&2 } sync_credentials &