56 lines
1.6 KiB
JavaScript
56 lines
1.6 KiB
JavaScript
/**
|
|
* tls-server.cjs — production HTTPS entrypoint for TradeAC.
|
|
*
|
|
* Serves the compiled Next.js app (tac-app/.next) over HTTPS with the
|
|
* self-signed certificate generated by the container entrypoint
|
|
* (entrypoint.sh) when SERVER_TLS=true.
|
|
*
|
|
* It reuses Next's normal production server (next({ dev: false }) +
|
|
* getRequestHandler()), so middleware, server actions, and all routes behave
|
|
* exactly like `next start` — just over TLS.
|
|
*/
|
|
"use strict";
|
|
|
|
const fs = require("node:fs");
|
|
const https = require("node:https");
|
|
const path = require("node:path");
|
|
const next = require("next");
|
|
|
|
const port = Number(process.env.PORT || 3000);
|
|
const host = process.env.HOSTNAME || "0.0.0.0";
|
|
const tlsKeyPath = process.env.TLS_KEY || "/tmp/tls/key.pem";
|
|
const tlsCertPath = process.env.TLS_CERT || "/tmp/tls/cert.pem";
|
|
const tlsHost = process.env.TLS_HOST || "localhost";
|
|
|
|
async function main() {
|
|
const app = next({
|
|
dev: false,
|
|
dir: path.join(__dirname, "tac-app"),
|
|
hostname: host,
|
|
port,
|
|
});
|
|
const handle = app.getRequestHandler();
|
|
|
|
await app.prepare();
|
|
|
|
const key = fs.readFileSync(tlsKeyPath);
|
|
const cert = fs.readFileSync(tlsCertPath);
|
|
|
|
const server = https.createServer({ key, cert }, (req, res) => handle(req, res));
|
|
server.listen(port, host, () => {
|
|
console.log(`> TradeAC HTTPS (self-signed) ready on https://${tlsHost}:${port}`);
|
|
});
|
|
|
|
const shutdown = () => {
|
|
server.close(() => process.exit(0));
|
|
setTimeout(() => process.exit(0), 2000).unref();
|
|
};
|
|
process.on("SIGTERM", shutdown);
|
|
process.on("SIGINT", shutdown);
|
|
}
|
|
|
|
main().catch((err) => {
|
|
console.error("Failed to start HTTPS server:", err);
|
|
process.exit(1);
|
|
});
|