fix(scriberr): serve over HTTPS via the fleet TLS caddy so the browser recorder works
The in-browser recorder calls getUserMedia, which browsers refuse on http:// origins, so it sat at "Initializing recorder...". scriberr.nh3.phasefinal.com is now fronted by the fleet TLS caddy on nh3-dev (wildcard cert) and added to Scriberr's ALLOWED_ORIGINS; the Homepage link points at it. The plain http://10.251.50.54:8080 URL keeps working except for recording.
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
# Let Scriberr accept its HTTPS name (2026-10-01). The fleet TLS caddy on nh3-dev now fronts
|
||||
# https://scriberr.nh3.phasefinal.com -> fv-ml1:8080; Scriberr's server rejects requests whose
|
||||
# Origin is not in ALLOWED_ORIGINS, so the name has to be added there, then the container
|
||||
# recreated (env and labels apply only at creation). The http:// origins stay, so the old URL
|
||||
# keeps working. SECURE_COOKIES stays false for the same reason.
|
||||
# scripts/elway infra-ops@10.251.50.54 --playbook playbooks/scriberr-https-origin.yaml
|
||||
vars:
|
||||
dir: /opt/docker/compose/scriberr
|
||||
origin: https://scriberr.nh3.phasefinal.com
|
||||
|
||||
steps:
|
||||
- name: Back up .env once
|
||||
sudo: true
|
||||
shell: cp -p {{ dir }}/.env {{ dir }}/.env.bak-20261001-https
|
||||
creates: "{{ dir }}/.env.bak-20261001-https"
|
||||
|
||||
- name: Append the HTTPS origin to SCRIBERR_ALLOWED_ORIGINS
|
||||
sudo: true
|
||||
shell: sed -i '/^SCRIBERR_ALLOWED_ORIGINS=/ s#$#,{{ origin }}#' {{ dir }}/.env
|
||||
when: "! sudo -n grep -q '^SCRIBERR_ALLOWED_ORIGINS=.*{{ origin }}' {{ dir }}/.env"
|
||||
|
||||
- name: Dry-parse the stack
|
||||
sudo: true
|
||||
shell: cd {{ dir }} && docker compose config -q
|
||||
changed_when: "false"
|
||||
|
||||
- name: Recreate the scriberr service (only if the running env lacks the origin)
|
||||
sudo: true
|
||||
shell: cd {{ dir }} && docker compose up -d scriberr
|
||||
when: "! docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'"
|
||||
|
||||
verify:
|
||||
- name: Running container carries the HTTPS origin
|
||||
shell: docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'
|
||||
changed_when: "false"
|
||||
- name: .env kept its owner and mode
|
||||
sudo: true
|
||||
shell: test "$(stat -c '%U %a' {{ dir }}/.env)" = "lkraven 600"
|
||||
changed_when: "false"
|
||||
Reference in New Issue
Block a user