# Evolving Edge — edge node
#
# Three settings below exist to keep this container's node identity stable, and
# they only work together: HOME=/data persists the encrypted enrollment config,
# while the fixed hostname and the machine ID persisted in edge-identity are the
# two inputs getMachineSecret() uses to derive the key that decrypts it. Persist
# the config without pinning the key inputs and it cannot be decrypted; pin the
# key inputs without persisting the config and there is nothing to decrypt.
# Remove any one of them, or delete either volume, and recreating the container
# enrolls a brand new node whose Active Node Hours start again from zero.
services:
  edge-node:
    image: docker.io/eecdn/ee-cdn-edge:latest
    restart: unless-stopped
    hostname: edge-node
    ports:
      - "8080:8080"
    volumes:
      - edge-data:/data
      - edge-identity:/var/lib/dbus
    environment:
      - PORT=8080
      - HOST=0.0.0.0
      - HEARTBEAT_SECONDS=30
      - EE_INSTALL_METHOD=docker
      # Without this the node still re-enrolls on every recreate. os.UserHomeDir()
      # decides where the encrypted enrollment config, the mTLS cert/key and
      # settings.json live ($HOME/.ee-cdn/...), and none of those paths can be
      # overridden individually. Docker defaults root's HOME to /root, which is on
      # no volume, so the config survived exactly as long as the container did.
      # Pointing HOME at /data puts all of it on the edge-data volume below.
      - HOME=/data
      - CONTROL_PLANE_URL=https://cp.3dge.app
      # Set via 'edge-node login' or manually:
      # - NODE_ID=<your-node-id>
      # - NODE_KEY=<your-api-key>
    # Generates a persistent machine ID on first run, then hands off to the
    # image's own entrypoint unchanged. Never blocks startup: exec runs whatever
    # happened above, and a failure is reported rather than passed off as
    # success.
    #
    # The ID comes from the kernel rather than being assembled in a pipeline.
    # An earlier version piped /dev/urandom through od and tr, and a pipeline
    # reports only its LAST command's status -- so any middle stage failing
    # produced an empty file while the "generated" message still printed, which
    # is the one outcome worse than failing loudly. /proc/sys/kernel/random/uuid
    # is present in every Linux container and a UUID without its dashes is
    # exactly the 32-hex-character machine-id format.
    entrypoint:
      - /bin/sh
      - -c
      - |
        if [ ! -s /var/lib/dbus/machine-id ]; then
          mkdir -p /var/lib/dbus 2>/dev/null
          tr -d '-' < /proc/sys/kernel/random/uuid > /var/lib/dbus/machine-id 2>/dev/null
          if [ -s /var/lib/dbus/machine-id ]; then
            echo "[identity] generated persistent machine ID"
          else
            rm -f /var/lib/dbus/machine-id 2>/dev/null
            echo "[identity] WARNING: could not write a machine ID; this node will re-enroll if the container is recreated" >&2
          fi
        fi
        exec /app/docker-entrypoint.sh "$$@"
      - --

volumes:
  edge-data:
  edge-identity:
