# Let Scriberr accept its HTTPS name (2026-10-01). The fleet TLS caddy on nh3-dev now fronts # https://scriberr.nh3.phasefinal.com -> fv-ml1:8080; Scriberr's server rejects requests whose # Origin is not in ALLOWED_ORIGINS, so the name has to be added there, then the container # recreated (env and labels apply only at creation). The http:// origins stay, so the old URL # keeps working. SECURE_COOKIES stays false for the same reason. # scripts/elway infra-ops@10.251.50.54 --playbook playbooks/scriberr-https-origin.yaml vars: dir: /opt/docker/compose/scriberr origin: https://scriberr.nh3.phasefinal.com steps: - name: Back up .env once sudo: true shell: cp -p {{ dir }}/.env {{ dir }}/.env.bak-20261001-https creates: "{{ dir }}/.env.bak-20261001-https" - name: Append the HTTPS origin to SCRIBERR_ALLOWED_ORIGINS sudo: true shell: sed -i '/^SCRIBERR_ALLOWED_ORIGINS=/ s#$#,{{ origin }}#' {{ dir }}/.env when: "! sudo -n grep -q '^SCRIBERR_ALLOWED_ORIGINS=.*{{ origin }}' {{ dir }}/.env" - name: Dry-parse the stack sudo: true shell: cd {{ dir }} && docker compose config -q changed_when: "false" - name: Recreate the scriberr service (only if the running env lacks the origin) sudo: true shell: cd {{ dir }} && docker compose up -d scriberr when: "! docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}'" verify: - name: Running container carries the HTTPS origin shell: docker exec scriberr printenv ALLOWED_ORIGINS | grep -q '{{ origin }}' changed_when: "false" - name: .env kept its owner and mode sudo: true shell: test "$(stat -c '%U %a' {{ dir }}/.env)" = "lkraven 600" changed_when: "false"