Fetch templates over HTTP instead of shelling out to git
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

The runtime image is distroless and has no git binary, so every sync
failed and bootapi silently served the stale embedded templates.

- fetch the branch tarball (<repo>/archive/<branch>.tar.gz) and extract
  it into an in-memory FS; no checkout, no writable volume
- digest the extracted tree, not the archive bytes, so a recompressed
  identical archive is not a change
- skip entries that would escape the tree
- log the source commit from Gitea's immutable Link header
This commit is contained in:
2026-09-26 18:59:07 +10:00
parent ca86d9cedc
commit a414918350
7 changed files with 351 additions and 166 deletions
+3 -2
View File
@@ -46,14 +46,15 @@ type Config struct {
DefaultTemplate string
// --- template git-sync (preferred over TemplateDir) ---
// TemplateGitURL, when set, makes bootapi clone a templates repo and re-pull
// TemplateGitURL, when set, makes bootapi fetch a templates repo's branch
// tarball over HTTP (<repo>/archive/<branch>.tar.gz) and re-fetch
// it every TemplateGitInterval, atomically swapping the loaded set on change
// and keeping the last-good set on a parse failure.
TemplateGitURL string
TemplateGitBranch string
TemplateGitInterval time.Duration
// TemplateGitToken is an optional token for a private templates repo,
// injected into the HTTPS clone URL. Empty for a public repo.
// sent as a Gitea token header. Empty for a public repo.
TemplateGitToken string
// BaseURL is the http:// base PXE clients use to reach bootapi. It is baked