Skip to content

Containerise the verifier UI, and bring over gfour's attestation types and gov.gr branding - #1

Merged
ligouras merged 11 commits into
grnetfrom
feat/docker
Sep 30, 2026
Merged

ligouras merged 11 commits into
grnetfrom
feat/docker

Conversation

@ligouras

@ligouras ligouras commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Adds a build workflow that publishes to GHCR and a deployment for the EC2 box, and brings over five of gfour's commits that were not on grnet. The deploy workflow is manually triggered, never on push, so merging this cannot change what is running.

gfour's commits

These are the only source changes. They come from older GRNET branches such as okeanos-v6, and keep gfour as the author:

  • b500e6a Brand Verifier UI with gov.gr logo
  • 20828f1 Add EducationalID support
  • 80b22e6 Add support for AllianceID
  • 8bee9ca Add support for MyAcademicID
  • be755b6 Add support for European Vocational Education and Training Microcredential

The four attestation types are added as mso_mdoc only.

The deployment

.github/workflows/docker-build.yml publishes the image. .github/workflows/docker-deploy.yml and deploy/ hold the deployment: compose file, stack.env, and the ssh config and host keys. The only repository secret is SSH_KEY.

This is the simplest stack in the set: a static SPA behind nginx, with no database, volumes or keys. Only the browser calls the backend, so the UI runs as its own stack and HOST_API is the public URL. One benefit is that redeploying the UI does not touch the container that holds the verifier's certificates.

Routing and the base href

The UI is at demo.eudiw.grnet.gr/verifier-ui/. The backend already holds /verifier/ui, /verifier/wallet and /verifier/utilities, so the UI could not take /verifier/. Moving the backend instead was not an option, because its public URL is signed into every request object it has issued.

Angular emits relative asset paths and <base href="/">, so behind a prefix every asset was fetched from the host root and the page rendered blank. The proxy rewrites the base href to /verifier-ui/ using a sub_filter in grnet/eudi-srv-wallet-provider (grnet/eudi-srv-wallet-provider#2). The Dockerfile and nginx.conf.template here stay byte-identical to upstream's. I tested two alternatives, a build argument and a second sub_filter in the image. Both work, but each changes upstream files, and the build argument ties the image to one path.

As a result, the wallet provider has to be deployed before this stack, or the UI serves a page whose assets all 404. The rule's filename carries sha1("/verifier-ui/"), and nginx-proxy silently ignores a wrong hash.

HOST_API replaces the http://localhost:8080 that the build bakes in. It lands in a lazy-loaded chunk-*.js, not in main-*.js.

What the verify step checks

The container is running, nginx -t passes, and /verifier-ui/ returns 200 through the proxy with <base href="/verifier-ui/"> in the HTML. It also checks that the six sibling services on the hostname still return 200. The base href check matters most, because a wrong base href still serves a 200 and only fails in a browser.

@ligouras
ligouras requested a review from gfour September 28, 2026 19:44

@gfour gfour left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can merge this.

@ligouras
ligouras merged commit bb64c32 into grnet Sep 30, 2026
5 checks passed
@ligouras
ligouras deleted the feat/docker branch September 30, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants