Files
ghglance/compose.yml
T
tiennm99 2def27f49a feat(web): require GitHub sign-in to generate cards
The web UI now runs every job on an OAuth token from "Sign in with
GitHub". The ticked options decide the requested scopes (read:user, plus
repo for private repos, plus read:org for org repos); a grant wider than
requested is refused. The token lives only on the job and is revoked when
the job ends, on every path including shutdown.

The server no longer holds a GitHub token of its own, and the pasted-token
field and /generate are gone. -serve requires -oauth-client-id,
-oauth-client-secret and -public-url (GHGLANCE_OAUTH_* and
GHGLANCE_PUBLIC_URL), and compose.yml requires them too. The CLI and the
Action keep -token unchanged.
2026-10-07 17:50:33 +07:00

30 lines
1.1 KiB
YAML

# ghglance web UI, built from this repo's Dockerfile.
services:
ghglance:
build: .
entrypoint: ["ghglance"]
command: ["-serve", ":8080", "-data-dir", "/data", "-retention", "24h"]
restart: unless-stopped
# Tells Coolify's proxy which container port to route to, even when the
# domain is entered without a ":8080" suffix.
expose:
- "8080"
environment:
- SERVICE_FQDN_GHGLANCE_8080
# "Sign in with GitHub" (a GitHub OAuth App) is required: every
# generation runs on the visitor's own sign-in token.
- GHGLANCE_OAUTH_CLIENT_ID=${GHGLANCE_OAUTH_CLIENT_ID:?set the GitHub OAuth App client ID}
- GHGLANCE_OAUTH_CLIENT_SECRET=${GHGLANCE_OAUTH_CLIENT_SECRET:?set the GitHub OAuth App client secret}
- GHGLANCE_PUBLIC_URL=${GHGLANCE_PUBLIC_URL:?set the external origin, e.g. https://ghglance.example.com}
volumes:
- ghglance-data:/data
healthcheck:
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
volumes:
ghglance-data: