mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-08-22 12:53:32 +02:00
* feat(portainer_be): add Portainer Business Edition add-on Adds a new `portainer_be` add-on based on the existing Portainer (CE) add-on, requested in #873. Business Edition has no public GitHub release tarball like CE, so the binary and web assets are pulled from the official multi-arch `portainer/portainer-ee` image via a multi-stage build and placed under /opt/portainer, mirroring CE's layout exactly. All runtime scripts, nginx/ingress config, options schema, SSL and password handling are unchanged from CE, so behaviour is identical apart from the edition. Users obtain a free (up to 3 nodes) Business Edition license key by registering with Portainer and enter it in the web UI on first launch. - config.yaml: slug portainer_be, BE image name, BE description/name - Dockerfile: multi-stage COPY from portainer/portainer-ee (no CE tarball) - updater.json: dockerhub source tracking portainer/portainer-ee - apparmor.txt: unique profile name (portainer_be_addon) - CHANGELOG/README/DOCS: BE-specific, documents the license-key step Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(portainer_be): address PR review feedback - nginx finish: move shebang to byte 0 (leading blank line prevented S6 from recognising the interpreter, so the finish hook could fail to tear down the supervision tree) [Codex P2] - ingress: tighten CSP to `frame-ancestors 'self'` to match the adjacent X-Frame-Options SAMEORIGIN; HA ingress embeds same-origin so the panel keeps working [CodeRabbit] - README: correct login note (password is the configured option value, never printed to logs); drop MD012 consecutive blank lines [CodeRabbit] - DOCS: fix "environement" -> "environment" typo [CodeRabbit] Skipped: nginx SSL "idempotency" finding — /etc/nginx lives in the read-only image layer and cont-init re-renders from the pristine template on every container start, so in-place sed edits never accumulate or need restoring. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * revert(portainer_be): keep CSP frame-ancestors * for ingress compatibility Reverts the frame-ancestors 'self' change from the previous commit. The wildcard is required for the Home Assistant ingress iframe to embed the Portainer UI; tightening it breaks the ingress panel. Matches the CE add-on. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
36 lines
1.2 KiB
Bash
Executable File
36 lines
1.2 KiB
Bash
Executable File
#!/usr/bin/with-contenv bashio
|
|
# shellcheck shell=bash
|
|
set -e
|
|
|
|
#################
|
|
# NGINX SETTING #
|
|
#################
|
|
|
|
#declare admin_port
|
|
declare portainer_protocol=http
|
|
|
|
# Generate Ingress configuration
|
|
if bashio::config.true 'ssl'; then
|
|
bashio::config.require.ssl
|
|
portainer_protocol=https
|
|
sed -i "s|9000|9443|g" /etc/nginx/includes/upstream.conf
|
|
sed -i "s|9000|9443|g" /etc/services.d/nginx/run
|
|
sed -i "s|9099 default_server|9099 ssl|g" /etc/nginx/templates/ingress.gtpl
|
|
sed -i '8 i ssl_certificate /ssl/{{ .certfile }};' /etc/nginx/templates/ingress.gtpl
|
|
sed -i '8 i ssl_certificate_key /ssl/{{ .keyfile }};' /etc/nginx/templates/ingress.gtpl
|
|
bashio::log.info "Ssl enabled, please use https for connection"
|
|
else
|
|
sed -i '/connection_upgrade/a\proxy_set_header Origin "";' /etc/nginx/templates/ingress.gtpl
|
|
fi
|
|
|
|
bashio::var.json \
|
|
interface "$(bashio::addon.ip_address)" \
|
|
port "^$(bashio::addon.ingress_port)" \
|
|
protocol "${portainer_protocol}" \
|
|
certfile "$(bashio::config 'certfile')" \
|
|
keyfile "$(bashio::config 'keyfile')" \
|
|
ssl "^$(bashio::config 'ssl')" \
|
|
| tempio \
|
|
-template /etc/nginx/templates/ingress.gtpl \
|
|
-out /etc/nginx/servers/ingress.conf
|