From ec4ca97af403b5d0ffbd41decf35206307743e66 Mon Sep 17 00:00:00 2001 From: William Mantly Date: Tue, 28 Jul 2026 15:46:40 -0400 Subject: [PATCH] =?UTF-8?q?Fix:=20Redis=20had=20zero=20persistence=20?= =?UTF-8?q?=E2=80=94=20every=20rebuild=20wiped=20sessions,=20(#18)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit in-flight OAuth logins, and any admin-created API token redis-server ran with --save '' --appendonly no (deliberately ephemeral, per the original "audit/metrics/session storage" framing). That stopped being a safe assumption once API tokens (PATs) lived in this same Redis -- a PAT is supposed to be a stable, long-lived credential, not disposable session state, but every `docker rm -f jump-host` + rebuild silently invalidated every one that existed. Matches proxy's existing pattern exactly: AOF + periodic RDB persisted to $REDIS_DATA_DIR (default /data), which the deployment mounts as a volume (see the companion theta-env change). Verified against a live container: minted a real PAT, force-recreated the container (docker rm -f + rebuild), confirmed the same token still authenticates afterward. Co-authored-by: Claude Sonnet 5 --- docker-entrypoint.sh | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh index afb763e..bdfc8dc 100644 --- a/docker-entrypoint.sh +++ b/docker-entrypoint.sh @@ -12,9 +12,17 @@ if [[ -f /config/jump-secrets.js ]]; then info "Loaded config from /config/jump-secrets.js" fi -# Redis for audit/metrics/session storage (app connects to 127.0.0.1:6379). -info "Starting redis..." -redis-server --daemonize yes --save '' --appendonly no +# Redis for audit/metrics/session AND api-token storage (app connects to +# 127.0.0.1:6379). Persisted (AOF + periodic RDB) to /data, which the +# deployment should mount as a volume -- without this, every container +# recreation silently wiped every session, in-flight OAuth login, and any +# admin-created API token, which is especially bad for the last one since a +# PAT is meant to be a stable, long-lived credential, not session state. +REDIS_DATA_DIR="${REDIS_DATA_DIR:-/data}" +mkdir -p "$REDIS_DATA_DIR" +info "Starting redis (AOF persisted to $REDIS_DATA_DIR)..." +redis-server --daemonize yes --dir "$REDIS_DATA_DIR" --appendonly yes \ + --appendfilename appendonly.aof --save 900 1 --save 300 10 --save 60 10000 # Wait for redis to answer before starting the app. for _ in $(seq 1 20); do