JB/postgres-entrypoint.sh
JobsBoard Deployer bb4c93b11c fix(db): derive DATABASE_URL from POSTGRES_PASSWORD and harden credential sync
Stop web/scraper containers from using a stray literal DATABASE_URL in the
root .env (which desynced the postgres role password and caused persistent
'password authentication failed' errors). DATABASE_URL is now always computed
from POSTGRES_USER/POSTGRES_PASSWORD.

Also harden postgres-entrypoint.sh: log to stderr, retry on failure, and run
ALTER ROLE unconditionally so the stored password always matches the env.
2026-09-07 13:06:42 -04:00

40 lines
1.2 KiB
Bash
Executable file

#!/bin/sh
set -e
# Re-align the Postgres role password with POSTGRES_PASSWORD on every boot.
# Connects via the local unix socket (pg_hba "trust"), so it works even when
# TCP password auth is currently broken. Runs in the background so it does not
# block server startup, but retries until it succeeds.
sync_credentials() {
until pg_isready -q -h /var/run/postgresql; do
sleep 0.5
done
USER="${POSTGRES_USER:-postgres}"
PASS="${POSTGRES_PASSWORD:-postgres}"
for i in $(seq 1 30); do
if psql -v ON_ERROR_STOP=1 -h /var/run/postgresql -U postgres -d postgres <<-EOSQL 2>/dev/null
DO \$\$
BEGIN
IF NOT EXISTS (SELECT FROM pg_catalog.pg_roles WHERE rolname = '$USER') THEN
CREATE ROLE "$USER" WITH LOGIN SUPERUSER PASSWORD '$PASS';
END IF;
ALTER ROLE "$USER" WITH LOGIN SUPERUSER PASSWORD '$PASS';
END
\$\$;
EOSQL
then
echo "[entrypoint] Synchronized '$USER' role password." >&2
return 0
fi
echo "[entrypoint] Credential sync attempt $i failed, retrying..." >&2
sleep 1
done
echo "[entrypoint] WARNING: could not synchronize credentials." >&2
}
sync_credentials &
exec docker-entrypoint.sh "$@"