Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.
Our SPA ships as a static file in the altinity/acm image docroot, served same-origin at a concrete path (e.g. /sql/), opened in a new tab from acm-ui.
Our repo (altinity-sql-browser)
- Build the artifact so it runs under ACM (see CSP below): either keep the single inline-
<script> file and rely on a scoped ACM <Location> CSP, or add a build mode emitting external JS from 'self' (no inline/eval).
- Select ACM cookie-auth mode at runtime (URL context) rather than a separate bundle if practical.
- Decide artifact delivery to ACM: committed asset, pinned GitHub release download, or built in acm-ui's pipeline.
acm repo (backend/distrib)
distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).
- vhost: add a
<Location /sql/> CSP block (mirror the existing /api/ CSP: 'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle.
- Serve as a real file at a concrete path (
FallbackResource /index.html would otherwise return the Angular shell).
acm-ui repo
- Add a link on the cluster/explore page →
/sql/?cluster=<id>&node=<n> (target=_blank).
Do NOT
vX.Y.Z-sup tag — release.yml fires on v* and docker.yml on v*.*.* (+latest); a -sup tag would enter public GitHub Release / Helm / Docker latest. Deployment here is via the ACM image, not this repo's public tags.
Acceptance
Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.
Our SPA ships as a static file in the
altinity/acmimage docroot, served same-origin at a concrete path (e.g./sql/), opened in a new tab from acm-ui.Our repo (altinity-sql-browser)
<script>file and rely on a scoped ACM<Location>CSP, or add a build mode emitting external JS from'self'(no inline/eval).acm repo (backend/distrib)
distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).<Location /sql/>CSP block (mirror the existing/api/CSP:'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle.FallbackResource /index.htmlwould otherwise return the Angular shell).acm-ui repo
/sql/?cluster=<id>&node=<n>(target=_blank).Do NOT
—vX.Y.Z-suptagrelease.ymlfires onv*anddocker.ymlonv*.*.*(+latest); a-suptag would enter public GitHub Release / Helm / Dockerlatest. Deployment here is via the ACM image, not this repo's public tags.Acceptance
/sql/; cookie auth works end-to-end in the console.<Location /sql/>CSP allows the app; page loads with no CSP violations.FallbackResource).