Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow advanced customization of nginx parameters in addon #3874

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

Ten0
Copy link

@Ten0 Ten0 commented Dec 28, 2024

My use-case is that I want to setup mTLS, except for webhooks endpoints.

Because nginx's ssl_verify_client cannot be set at the location level but needs to be set at the server level, and then whether we are authenticated should be checked at the location level, this requires modifying the location / directive of the configuration.

It follows that the template is not customizable enough.

To give full flexibility to the user to patch the server config however they like, we allow them to execute arbitrary commands or scripts from within the container before starting nginx, similarly to what is done by the SSH addon and appdaemon.

Summary by CodeRabbit

  • New Features

    • Added support for custom initialization commands in NGINX proxy configuration.
    • Enhanced startup script to execute user-defined initialization commands before starting the server.
  • Improvements

    • Expanded configuration options to allow more flexible initialization process.
    • Updated documentation to include new optional configuration for initialization commands.
    • Added translation for the new initialization commands feature.

My use-case is that I want to setup mTLS, except for webhooks endpoints.

Because ssl_verify_client cannot be set at the `location` level but needs to be set at the `server` level, and then whether we are authenticated should be checked at the location level, this requires modifying the `location /` directive of the configuration.

It follows that [the template](https://github.com/home-assistant/addons/blob/91160e1b5d00e13091b0537d85a3b3112e4a3f60/nginx_proxy/rootfs/etc/nginx/nginx.conf.gtpl) is not customizable enough.

To give full flexibility to the user to patch the server config however they like, we allow them to execute arbitrary commands or scripts from within the container before starting nginx, similarly to what is done by the SSH addon and appdaemon.
Copy link

@home-assistant home-assistant bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @Ten0

It seems you haven't yet signed a CLA. Please do so here.

Once you do that we will be able to review and accept this pull request.

Thanks!

@home-assistant home-assistant bot marked this pull request as draft December 28, 2024 15:16
@home-assistant
Copy link

Please take a look at the requested changes, and use the Ready for review button when you are done, thanks 👍

Learn more about our pull request process.

@Ten0 Ten0 marked this pull request as ready for review December 28, 2024 15:18
Copy link
Contributor

coderabbitai bot commented Dec 28, 2024

Warning

Rate limit exceeded

@Ten0 has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 22 minutes and 1 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 2e3d246 and ef8535a.

📒 Files selected for processing (1)
  • nginx_proxy/DOCS.md (1 hunks)
📝 Walkthrough

Walkthrough

The pull request introduces enhancements to the NGINX Home Assistant SSL proxy configuration by adding support for initialization commands. The changes include updating the config.yaml file to include a new init_commands option, modifying the startup script to execute these commands before launching the nginx server, and updating the documentation and translation files to reflect this new feature. This modification allows users to specify custom initialization commands that will run during the container's startup process.

Changes

File Change Summary
nginx_proxy/config.yaml - Added init_commands: [] to options section
- Updated schema to include init_commands: - str
nginx_proxy/rootfs/etc/s6-overlay/s6-rc.d/nginx/run - Added logic to execute user-configured initialization commands
- Implements error handling for command execution
nginx_proxy/DOCS.md - Documented new optional configuration option init_commands
nginx_proxy/translations/en.yaml - Added init_commands section with name and description

Sequence Diagram

sequenceDiagram
    participant Config as Configuration
    participant Script as Startup Script
    participant Nginx as Nginx Server

    Config->>Script: Provide init_commands
    Script->>Script: Validate init_commands
    alt Commands exist
        Script->>Script: Execute each command
        alt Command fails
            Script-->>Config: Log error
            Script->>Script: Exit with failure
        else All commands succeed
            Script->>Nginx: Start server
        end
    else No init_commands
        Script->>Nginx: Start server directly
    end
Loading

Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR. (Beta)
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai or @coderabbitai title anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 91160e1 and 9865d93.

📒 Files selected for processing (2)
  • nginx_proxy/config.yaml (2 hunks)
  • nginx_proxy/rootfs/etc/s6-overlay/s6-rc.d/nginx/run (1 hunks)
🧰 Additional context used
📓 Path-based instructions (1)
nginx_proxy/config.yaml (6)

Pattern */**(html|markdown|md): - For instructional content in documentation, use a direct and authoritative tone. Avoid expressions of politeness such as 'may' or 'please', and ensure the goal of the instruction is fronted.

  • Apply the Microsoft Style Guide to ensure documentation maintains clarity and conciseness.
  • In step-by-step instructions, front the location phrase in the instructional sentence.
  • In step-by-step instructions, front the 'goal' in the instructional sentence.
  • In step-by-step instructions, if in doubt what to front, front the 'goal' before the location phrase in the instructional sentence.
  • do not hyphenate terms like 'top-right' or 'bottom-left' with 'corner'

Pattern */**(html|markdown|md): - Use bold to mark UI strings.

  • If "" are used to mark UI strings, replace them by bold.

Pattern */**(html|markdown|md): - Be brief in your replies and don't add fluff like "thank you for..." and "Please let me know if"


Pattern */**(html|markdown|md): - Use sentence-style capitalization also in headings.


Pattern */**(html|markdown|md): do not comment on HTML used for icons


Pattern */**(html|markdown|md): Avoid flagging inline HTML for embedding videos in future reviews for this repository.

🔇 Additional comments (2)
nginx_proxy/config.yaml (2)

30-30: Good default for optional commands.

Providing an empty list (init_commands: []) as the default ensures that no commands are executed unless explicitly specified, which is a safe and clear approach for new users.


46-47: Schema aligns with the new feature.

Defining init_commands as a list of strings properly reflects the new functionality and ensures valid user input for each command. This is consistent and well-integrated with the rest of the schema.

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 9865d93 and 2e3d246.

📒 Files selected for processing (2)
  • nginx_proxy/DOCS.md (1 hunks)
  • nginx_proxy/translations/en.yaml (1 hunks)
🧰 Additional context used
📓 Path-based instructions (1)
nginx_proxy/DOCS.md (6)

Pattern */**(html|markdown|md): - For instructional content in documentation, use a direct and authoritative tone. Avoid expressions of politeness such as 'may' or 'please', and ensure the goal of the instruction is fronted.

  • Apply the Microsoft Style Guide to ensure documentation maintains clarity and conciseness.
  • In step-by-step instructions, front the location phrase in the instructional sentence.
  • In step-by-step instructions, front the 'goal' in the instructional sentence.
  • In step-by-step instructions, if in doubt what to front, front the 'goal' before the location phrase in the instructional sentence.
  • do not hyphenate terms like 'top-right' or 'bottom-left' with 'corner'

Pattern */**(html|markdown|md): - Use bold to mark UI strings.

  • If "" are used to mark UI strings, replace them by bold.

Pattern */**(html|markdown|md): - Be brief in your replies and don't add fluff like "thank you for..." and "Please let me know if"


Pattern */**(html|markdown|md): - Use sentence-style capitalization also in headings.


Pattern */**(html|markdown|md): do not comment on HTML used for icons


Pattern */**(html|markdown|md): Avoid flagging inline HTML for embedding videos in future reviews for this repository.

nginx_proxy/translations/en.yaml Show resolved Hide resolved
nginx_proxy/DOCS.md Outdated Show resolved Hide resolved
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant