I'm using prisma with docker and I want to protect...
# orm-help
g
I'm using prisma with docker and I want to protect my service with managementApiSecret. Here is how my dockey-compose.yml looks like - http://prntscr.com/lfebga, it contains managementApiSecret but I keep getting warning
Warning: Management API authentication is disabled. To protect your management server you should provide one (not both) of the environment variables 'CLUSTER_PUBLIC_KEY' (asymmetric, deprecated soon) or 'PRISMA_MANAGEMENT_API_JWT_SECRET' (symmetric JWT).
. What's wrong?
d
That configuration looks correct to me, are you sure you applied it?
g
@dpetrick what do you mean by 'applied it'?
d
docker-compose up -d
after you changed the config, for example
g
Nope, I didn't do this. I thought docker does everything for me 😞
d
docker compose is nothing more than convenience for starting a bunch of containers. if you change the .yml you need to apply it again, else when would docker ever know when to apply it automatically? also, the snippet you now showed me is unrelated. you don’t need to use the
Dockerfile
if you use the compose file you showed me above. So which one is it?
To be clear, on the second snippet you showed me you bake the config into the image, which is one way to achieve what you want. You’d need to rebuild the image as soon as you change the config, though, because it is statically baked in to the image, which in turn means it’s not referencing your copy on the file system.
g
@dpetrick aw, I'm completely noob in setting up Dokku and using Docker. I'm trying to set up dokku with prisma service and a server on graphql-yoga but I do not understand how to run it all inside the dokku. I followed this tutorial (and from it I get such Dockerfile) - https://www.prisma.io/docs/tutorials/deploy-prisma-servers/dokku-zie0ahhaox But it didn't work properly, so I added docker-compose.yml but haven't even run it. Now I'm completely confused with all of this. Could you, please, help me?
Maybe this will work? First I'm trying to run my server, then run the command you sent above
d
I have no experience with dokku. All I can give you is the following: If you want to run a docker image that has the config baked in and “just works” you can use the the snippet you send me, and use absolute paths for the config.
for example:
Copy code
FROM prismagraphql/prisma:1.19.3
ENV PRISMA_CONFIG_PATH /app/config.yml
COPY config.yml /app/config.yml
EXPOSE 4466
build it like this:
docker build -t prismatest .
. You can easily test if it works by running it locally with
docker run -itP prismatest
Given you have a database somewhere, of course
g
lemme try 🙂
d
I just tested a minimal example, the Dockerfile above works, the config I used is (with a mysql on my host system):
Copy code
port: 4466
managementApiSecret: "somethingsomething"
enableManagementApi: "true"
databases:
  default:
    connector: "mysql"
    active: "true"
    host: "host.docker.internal"
    port: "3306"
    user: "root"
    password: "prisma"
docker build -t prismatest .
docker run -it -p 4466:4466 prismatest
-> localhost:4466/management is reachable
g
@dpetrick okay, so I finally deployed it all to the server but now I cannot deploy my prisma service, lol
Here is how I decided to do
d
Well, make sure the server is reachable and the docker bindings are set up in a way that you can access the container from the outside.
g
And here is what I get on deploying prisma service
d
The server is not reachable, you need to make sure to expose the server correctly with whatever dokku needs.
g
@dpetrick Not sure how to check it 😄 Maybe something wrong about running the command? Here is an output of running this command.
d
If you are still using the docker compose file above, then try the following port binding:
Copy code
ports:
- "0.0.0.0:4466:4466"
g
@dpetrick still the same. Right now it used cache for this command
d
if you have shell access to the machine, see what the docker port bindings are saying
docker ps
g
same for docker-compose up -d
d
probably installed as root, fairly common.
sudo docker ps
g
d
yea, the caching probably caused the command to not be properly executed. You need to convince dokku to not use caches, if possible.