feat: complete CreatorHub gateway review fixes
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
ARG BROWSER_BASE_IMAGE
|
||||
FROM ${BROWSER_BASE_IMAGE}
|
||||
|
||||
COPY --chmod=0755 docker-entrypoint.sh /usr/local/bin/creatorhub-browser-entrypoint.sh
|
||||
ENTRYPOINT ["/usr/local/bin/creatorhub-browser-entrypoint.sh"]
|
||||
@@ -0,0 +1,12 @@
|
||||
# CreatorHub browser wrapper
|
||||
|
||||
这是浏览器运行时的受管理入口,不包含 Chromium 本体。构建时必须传入已登记的 immutable base image digest,禁止使用 tag 或 `latest`:
|
||||
|
||||
```bash
|
||||
docker build \
|
||||
--build-arg BROWSER_BASE_IMAGE=git.ipao.vip/rogee/fingerprint-chromium@sha256:<base-digest> \
|
||||
-t git.ipao.vip/rogee/creatorhub-browser-wrapper@sha256:<published-digest> \
|
||||
docker/browser-wrapper
|
||||
```
|
||||
|
||||
发布记录必须同时保存 base image 仓库、base digest、构建提交、此目录 Dockerfile 和发布 digest。入口会等待 Xvfb、检查 x11vnc、绑定容器地址上的 CDP 端口,再启动 `/opt/chromium/chrome`。
|
||||
@@ -0,0 +1,32 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
Xvfb :99 -screen 0 "${SCREEN_SIZE:-1920x1080x24}" -nolisten tcp -ac &
|
||||
xvfb_pid=$!
|
||||
i=0
|
||||
while [ "$i" -lt 300 ]; do
|
||||
[ -S /tmp/.X11-unix/X99 ] && break
|
||||
kill -0 "$xvfb_pid" 2>/dev/null || exit 1
|
||||
i=$((i + 1))
|
||||
sleep 0.1
|
||||
done
|
||||
[ -S /tmp/.X11-unix/X99 ] || {
|
||||
echo "Xvfb did not become ready" >&2
|
||||
exit 1
|
||||
}
|
||||
export DISPLAY=:99
|
||||
x11vnc -display :99 -listen "$(hostname -i)" -rfbport 5900 -forever -nopw -nevershared -dontdisconnect -noclipboard -nosetclipboard -noprimary -nosetprimary -quiet &
|
||||
rfb_pid=$!
|
||||
kill -0 "$rfb_pid" 2>/dev/null || {
|
||||
echo "RFB service did not start" >&2
|
||||
exit 1
|
||||
}
|
||||
remote_debugging_port=${REMOTE_DEBUGGING_PORT:-9222}
|
||||
case "$remote_debugging_port" in
|
||||
'' | *[!0-9]*)
|
||||
echo "REMOTE_DEBUGGING_PORT must be numeric" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
socat "TCP-LISTEN:${remote_debugging_port},fork,reuseaddr,bind=$(hostname -i)" "TCP:127.0.0.1:${remote_debugging_port}" &
|
||||
exec /opt/chromium/chrome --disable-dev-shm-usage --no-sandbox --no-default-browser-check --no-first-run --remote-debugging-port="$remote_debugging_port" --user-data-dir=/data "$@"
|
||||
Reference in New Issue
Block a user