mirror of
https://github.com/nestriness/nestri.git
synced 2026-09-29 06:02:25 +03:00
feat(api): serve the host installer and its downloads
GET /install.sh serves a POSIX script, embedded in the API at build time so the script and the routes that redeem its token ship together. It checks the platform, asks where box images should live, downloads the host agent at a pinned version, verifies it against SHA256SUMS, installs it for the calling user and hands over with the token in the environment rather than argv. GET /install/:component/:version/:asset redirects to a one-minute signed URL on a private S3-compatible bucket, so every download passes through a route that can be logged or switched off. The SigV4 signer is written against Web Crypto and checked against AWS's published example.
This commit is contained in:
@@ -51,6 +51,18 @@ export namespace Env {
|
||||
POLAR_FREE_PRODUCT_ID: z.string().optional(),
|
||||
POLAR_SERVER: z.enum(['sandbox', 'production']).optional(),
|
||||
|
||||
/**
|
||||
* Where installable binaries are kept: an S3-compatible bucket that is
|
||||
* never public. Downloads are answered with a short-lived signed URL,
|
||||
* so every one passes through a route that can be logged or turned off.
|
||||
* Scope the key to this bucket and to reads.
|
||||
*/
|
||||
RELEASES_BUCKET: z.string().optional(),
|
||||
RELEASES_ENDPOINT: z.string().optional(),
|
||||
RELEASES_REGION: z.string().default('us-east-1'),
|
||||
RELEASES_ACCESS_KEY_ID: z.string().optional(),
|
||||
RELEASES_SECRET_ACCESS_KEY: z.string().optional(),
|
||||
|
||||
DATABASE_URL: z.string().optional()
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user