diff --git a/Dockerfile b/Dockerfile index 7b00256..feaf5f0 100644 --- a/Dockerfile +++ b/Dockerfile @@ -31,10 +31,15 @@ COPY haproxy_manager.py /haproxy/ COPY scripts /haproxy/scripts COPY trusted_ips.list /etc/haproxy/trusted_ips.list COPY trusted_ips.map /etc/haproxy/trusted_ips.map -COPY cloudflare_ips.list /etc/haproxy/cloudflare_ips.list -COPY trusted_proxies.list /etc/haproxy/trusted_proxies.list # /etc/haproxy is a named volume in deployed containers, so baked-in files -# under that path get shadowed by the volume on existing deployments. +# under that path get shadowed by the volume on existing deployments. The +# trusted_ips.* pair above predates that discovery and is handled by the +# older start-up.sh guard (out of scope here). cloudflare_ips.list and +# trusted_proxies.list are staged under /haproxy/defaults instead, so +# start-up.sh can always read the image's baked copy regardless of what the +# volume shadows /etc/haproxy with. +COPY cloudflare_ips.list /haproxy/defaults/cloudflare_ips.list +COPY trusted_proxies.list /haproxy/defaults/trusted_proxies.list # Place errorfiles outside the volumed path; the HAProxy config references # them by absolute path. COPY errors /haproxy/errors diff --git a/VERSION b/VERSION index 39af2d4..feaba9e 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -2026.08.2 +2026.08.3 diff --git a/scripts/start-up.sh b/scripts/start-up.sh index fc648c9..975bd73 100755 --- a/scripts/start-up.sh +++ b/scripts/start-up.sh @@ -21,8 +21,31 @@ set -eo pipefail mkdir -p /etc/haproxy [ -f /etc/haproxy/trusted_ips.list ] || : > /etc/haproxy/trusted_ips.list [ -f /etc/haproxy/trusted_ips.map ] || : > /etc/haproxy/trusted_ips.map -[ -f /etc/haproxy/cloudflare_ips.list ] || : > /etc/haproxy/cloudflare_ips.list -[ -f /etc/haproxy/trusted_proxies.list ] || : > /etc/haproxy/trusted_proxies.list + +# cloudflare_ips.list is SHIPPED DATA: it must always match what this image +# bakes in (/haproxy/defaults), so a Cloudflare range refresh actually reaches +# existing hosts instead of being permanently shadowed by the volume. +# Overwrite it from the baked copy on every start. +# +# trusted_proxies.list is OPERATOR DATA: operators add entries directly on +# the server and those must survive restarts/recreates. Seed it from the +# baked copy only when it's missing; never overwrite an existing one. +# +# Both branches fall back to an empty file if the baked default is somehow +# absent, because "acl ... -f " is a fatal HAProxy config +# error -- the list files must exist unconditionally by the time HAProxy starts. +if [ -f /haproxy/defaults/cloudflare_ips.list ]; then + cp /haproxy/defaults/cloudflare_ips.list /etc/haproxy/cloudflare_ips.list +else + [ -f /etc/haproxy/cloudflare_ips.list ] || : > /etc/haproxy/cloudflare_ips.list +fi +if [ ! -f /etc/haproxy/trusted_proxies.list ]; then + if [ -f /haproxy/defaults/trusted_proxies.list ]; then + cp /haproxy/defaults/trusted_proxies.list /etc/haproxy/trusted_proxies.list + else + : > /etc/haproxy/trusted_proxies.list + fi +fi cron &