File size: 2,991 Bytes
6d60378
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
#!/bin/sh
# WorkBuddy2API Panel — Hugging Face Spaces 入口脚本
#
# 持久化模型:
#   HF Storage Bucket(私有)  ->  挂载到容器 /app/storage
#     /app/storage/config.json        运行配置(含 api_key,私有卷上,不进公开仓库)
#     /app/storage/auths/*.json       账号凭证
#     /app/storage/data/*.json        水位/用量/模型探测/请求归档
#
# 容器根文件系统是 ephemeral 的:重启、休眠唤醒、重新构建都会重置。
# 所以配置和账号必须待在卷上,否则每次重启都要重新登录账号。
set -eu

PERSIST="${WB2A_PERSIST_DIR:-/app/storage}"
TEMPLATE=/app/config.json
CFG="$TEMPLATE"

echo "[entrypoint] boot at $(date -u '+%Y-%m-%dT%H:%M:%SZ')"

if [ -d "$PERSIST" ]; then
  echo "[entrypoint] persistent volume detected at $PERSIST"
  mkdir -p "$PERSIST/auths" "$PERSIST/data"

  # 落盘自检:程序全部走「写 .tmp 再 rename」,rename 不可用的话持久化是假的
  if echo probe > "$PERSIST/.wb2a-write-probe" 2>/dev/null \
     && mv "$PERSIST/.wb2a-write-probe" "$PERSIST/.wb2a-rename-probe" 2>/dev/null \
     && rm -f "$PERSIST/.wb2a-rename-probe"; then
    echo "[entrypoint] storage self-test: write+rename OK"
  else
    echo "[entrypoint] storage self-test: FAILED — write or rename unsupported on $PERSIST" >&2
    rm -f "$PERSIST/.wb2a-write-probe" "$PERSIST/.wb2a-rename-probe" 2>/dev/null || true
  fi

  if [ ! -f "$PERSIST/config.json" ]; then
    if [ -f "$TEMPLATE" ]; then
      echo "[entrypoint] no config.json on the volume -> seeding from image template"
      cp "$TEMPLATE" "$PERSIST/config.json"
    else
      echo "[entrypoint] no config.json on the volume and no image template" >&2
    fi
  fi
  [ -f "$PERSIST/config.json" ] && CFG="$PERSIST/config.json"
else
  echo "[entrypoint] WARNING: no persistent volume at $PERSIST — everything written will be LOST on restart" >&2
  mkdir -p /app/auths /app/data
fi

# 安全闸门:api_key 为空 == 完全不鉴权(httpauth.VerifyBearer 语义)。
# 空间是公网可达的,绝不允许以裸奔状态启动。
if [ -n "${WB2A_API_KEY:-}" ]; then
  echo "[entrypoint] api_key supplied via WB2A_API_KEY env"
else
  KEY=$(python3 -c 'import json,sys

try:

    print(json.load(open(sys.argv[1])).get("api_key") or "")

except Exception:

    print("")' "$CFG" 2>/dev/null || true)
  if [ -z "$KEY" ]; then
    echo "[entrypoint] FATAL: api_key is empty in $CFG and WB2A_API_KEY is not set." >&2
    echo "[entrypoint] Refusing to start: an empty api_key disables authentication on a public Space." >&2
    echo "[entrypoint] Fix: write a config.json containing an api_key onto the bucket, or set the WB2A_API_KEY secret." >&2
    exit 1
  fi
  echo "[entrypoint] api_key loaded from config file"
fi

echo "[entrypoint] config: $CFG"
echo "[entrypoint] auth_dir: $(dirname "$CFG")/auths (see config)"
exec /app/wb2api -config "$CFG"