Containerise the verifier UI, and bring over gfour's attestation types and gov.gr branding - #1
Merged
Merged
Conversation
…emove redundant environment variable
… of static assets and WSGI SCRIPT_NAME
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a build workflow that publishes to GHCR and a deployment for the EC2 box, and brings over five of gfour's commits that were not on
grnet. The deploy workflow is manually triggered, never on push, so merging this cannot change what is running.gfour's commits
These are the only source changes. They come from older GRNET branches such as
okeanos-v6, and keep gfour as the author:b500e6aBrand Verifier UI with gov.gr logo20828f1Add EducationalID support80b22e6Add support for AllianceID8bee9caAdd support for MyAcademicIDbe755b6Add support for European Vocational Education and Training MicrocredentialThe four attestation types are added as
mso_mdoconly.The deployment
.github/workflows/docker-build.ymlpublishes the image..github/workflows/docker-deploy.ymlanddeploy/hold the deployment: compose file,stack.env, and the ssh config and host keys. The only repository secret isSSH_KEY.This is the simplest stack in the set: a static SPA behind nginx, with no database, volumes or keys. Only the browser calls the backend, so the UI runs as its own stack and
HOST_APIis the public URL. One benefit is that redeploying the UI does not touch the container that holds the verifier's certificates.Routing and the base href
The UI is at
demo.eudiw.grnet.gr/verifier-ui/. The backend already holds/verifier/ui,/verifier/walletand/verifier/utilities, so the UI could not take/verifier/. Moving the backend instead was not an option, because its public URL is signed into every request object it has issued.Angular emits relative asset paths and
<base href="/">, so behind a prefix every asset was fetched from the host root and the page rendered blank. The proxy rewrites the base href to/verifier-ui/using asub_filteringrnet/eudi-srv-wallet-provider(grnet/eudi-srv-wallet-provider#2). TheDockerfileandnginx.conf.templatehere stay byte-identical to upstream's. I tested two alternatives, a build argument and a secondsub_filterin the image. Both work, but each changes upstream files, and the build argument ties the image to one path.As a result, the wallet provider has to be deployed before this stack, or the UI serves a page whose assets all 404. The rule's filename carries
sha1("/verifier-ui/"), and nginx-proxy silently ignores a wrong hash.HOST_APIreplaces thehttp://localhost:8080that the build bakes in. It lands in a lazy-loadedchunk-*.js, not inmain-*.js.What the verify step checks
The container is running,
nginx -tpasses, and/verifier-ui/returns 200 through the proxy with<base href="/verifier-ui/">in the HTML. It also checks that the six sibling services on the hostname still return 200. The base href check matters most, because a wrong base href still serves a 200 and only fails in a browser.