diff --git a/seed/base-machine/manual/install/install_machines b/seed/base-machine/manual/install/install_machines
index f053a5f4..82388f32 100755
--- a/seed/base-machine/manual/install/install_machines
+++ b/seed/base-machine/manual/install/install_machines
@@ -14,7 +14,7 @@ for image in *; do
if [ -f "host/configurations/$HOST_NAME/etc/systemd/nspawn/$osname.nspawn" ]; then
MACHINES="$MACHINES$osname "
fi
- echo
+ echo
echo "Install machine $image"
./install_machine "$HOST_NAME" "$image" "$osname"
fi
@@ -23,5 +23,39 @@ for image in *; do
done
machinectl enable $MACHINES
machinectl start $MACHINES
+STARTED=""
+DEGRADED=""
+found=true
+idx=0
+while [ $found = true ]; do
+ found=false
+ echo "tentative $idx"
+ for machine in $MACHINES; do
+ if ! echo $STARTED | grep -q " $machine "; then
+ status=$(machinectl -q shell $machine /usr/bin/systemctl is-system-running || true)
+ if echo "$status" | grep -q degraded; then
+ STARTED="$STARTED $machine "
+ DEGRADED="$DEGRADED $machine"
+ elif echo "$status" | grep -q running; then
+ STARTED="$STARTED $machine "
+ else
+ found=true
+ echo "status actuel de $machine : $status"
+ fi
+ fi
+ done
+ sleep 2
+ idx=$((idx+1))
+ if [ $idx = 60 ]; then
+ break
+ fi
+done
+retcode=0
+for machine in $DEGRADED; do
+ echo
+ echo "========= $machine"
+ machinectl -q shell $machine /usr/bin/systemctl --state=failed --no-legend --no-pager
+ retcode=1
+done
-exit 0
+exit $retcode
diff --git a/seed/dovecot/dictionaries/26_dovecot.xml b/seed/dovecot/dictionaries/26_dovecot.xml
index 05e555eb..89a55027 100644
--- a/seed/dovecot/dictionaries/26_dovecot.xml
+++ b/seed/dovecot/dictionaries/26_dovecot.xml
@@ -18,7 +18,7 @@
- /etc/nginx/conf.d/autoconfig.conf
+ /etc/nginx/default.d/autoconfig.conf
well_known_filenames
@@ -90,8 +90,8 @@
-
- False
+
+ /var/www/html
diff --git a/seed/dovecot/templates/autoconfig.conf b/seed/dovecot/templates/autoconfig.conf
index 8be4082e..c4faeebb 100644
--- a/seed/dovecot/templates/autoconfig.conf
+++ b/seed/dovecot/templates/autoconfig.conf
@@ -1,12 +1,2 @@
-server {
- listen 443 ssl;
- server_name %%domain_name_eth0;
-
- ssl_client_certificate %%revprox_ca_file;
- ssl_certificate %%revprox_cert_file;
- ssl_certificate_key %%revprox_key_file;
-
- root /var/www/html/;
- # To allow POST on static pages
- error_page 405 =200 $uri;
-}
+# To allow POST on static pages
+error_page 405 =200 $uri;
diff --git a/seed/lemonldap/dictionaries/70_lemonldap_ng.xml b/seed/lemonldap/dictionaries/70_lemonldap_ng.xml
index 37b7de86..d5b9eea9 100644
--- a/seed/lemonldap/dictionaries/70_lemonldap_ng.xml
+++ b/seed/lemonldap/dictionaries/70_lemonldap_ng.xml
@@ -25,10 +25,10 @@
+
False
-
diff --git a/seed/lemonldap/templates/wget.pl b/seed/lemonldap/templates/wget.pl
index b46dc4b7..ca4eda78 100644
--- a/seed/lemonldap/templates/wget.pl
+++ b/seed/lemonldap/templates/wget.pl
@@ -1,7 +1,6 @@
%echo "#!/usr/bin/env perl"
use HTTP::Tiny;
-use JSON qw(from_json to_json);
my $response = HTTP::Tiny->new->get('https://%%domain_name_eth0/.well-known/openid-configuration');
diff --git a/seed/mailman/applicationservice.yml b/seed/mailman/applicationservice.yml
index 769c5867..17e1ec58 100644
--- a/seed/mailman/applicationservice.yml
+++ b/seed/mailman/applicationservice.yml
@@ -5,5 +5,5 @@ depends:
- postgresql-client
- relay-lmtp-client
- reverse-proxy-client
- - nginx-common
+ - nginx-https
- oauth2-client
diff --git a/seed/mailman/dictionaries/31_mailman.xml b/seed/mailman/dictionaries/31_mailman.xml
index b7055029..3bf09da9 100644
--- a/seed/mailman/dictionaries/31_mailman.xml
+++ b/seed/mailman/dictionaries/31_mailman.xml
@@ -11,7 +11,7 @@
/etc/postorius/gunicorn_config.py
/sysusers.d/0postorius.conf
- /etc/nginx/conf.d/postorius.conf
+ /etc/nginx/default.d/postorius.conf
/etc/mailman3.d/postorius.py
@@ -47,6 +47,11 @@
+
+
+ /usr/share/webapps/postorius
+
+
mailman
diff --git a/seed/mailman/templates/config-nginx.conf b/seed/mailman/templates/config-nginx.conf
index 5c928d74..56b07475 100644
--- a/seed/mailman/templates/config-nginx.conf
+++ b/seed/mailman/templates/config-nginx.conf
@@ -1,42 +1,31 @@
-server {
- listen 443 ssl;
- server_name %%domain_name_eth0;
-
- ssl_client_certificate %%revprox_ca_file;
- ssl_certificate %%revprox_cert_file;
- ssl_certificate_key %%revprox_key_file;
-
- charset utf-8;
- client_max_body_size 75M;
- root /usr/share/webapps/postorius;
-
- location /mailman/postorius_static {
- alias /usr/lib/python3.10/site-packages/postorius/static;
- }
- #FIXME user-profile seems to be in hyperkitty redirect in existing page
- location /mailman/user-profile {
- proxy_pass http://127.0.0.1:8002/postorius/users;
- proxy_set_header Host $http_host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-Host $host;
- proxy_set_header X-Forwarded-Port $server_port;
- proxy_set_header X-Forwarded-Server $host;
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- }
-%for %%location in ['accounts', 'admin', 'postorius']
- location /mailman/%%location {
- proxy_pass http://127.0.0.1:8002/%%location;
- proxy_set_header Host $http_host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-Host $host;
- proxy_set_header X-Forwarded-Port $server_port;
- proxy_set_header X-Forwarded-Server $host;
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- }
-%end for
- location /mailman {
- rewrite ^(/mailman/.*)$ /mailman/postorius/ permanent;
- }
+charset utf-8;
+client_max_body_size 75M;
+location /mailman/postorius_static {
+ alias /usr/lib/python3.10/site-packages/postorius/static;
+}
+#FIXME user-profile seems to be in hyperkitty redirect in existing page
+location /mailman/user-profile {
+ proxy_pass http://127.0.0.1:8002/postorius/users;
+ proxy_set_header Host $http_host;
+ proxy_set_header X-Real-IP $remote_addr;
+ proxy_set_header X-Forwarded-Host $host;
+ proxy_set_header X-Forwarded-Port $server_port;
+ proxy_set_header X-Forwarded-Server $host;
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+ proxy_set_header X-Forwarded-Proto $scheme;
+}
+%for %%location in ['accounts', 'admin', 'postorius']
+location /mailman/%%location {
+ proxy_pass http://127.0.0.1:8002/%%location;
+ proxy_set_header Host $http_host;
+ proxy_set_header X-Real-IP $remote_addr;
+ proxy_set_header X-Forwarded-Host $host;
+ proxy_set_header X-Forwarded-Port $server_port;
+ proxy_set_header X-Forwarded-Server $host;
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+ proxy_set_header X-Forwarded-Proto $scheme;
+}
+%end for
+location /mailman {
+ rewrite ^(/mailman/.*)$ /mailman/postorius/ permanent;
}
diff --git a/seed/nginx-common/dictionaries/20_nginx.xml b/seed/nginx-common/dictionaries/21_nginx.xml
similarity index 98%
rename from seed/nginx-common/dictionaries/20_nginx.xml
rename to seed/nginx-common/dictionaries/21_nginx.xml
index 2279a56b..0ab1a528 100644
--- a/seed/nginx-common/dictionaries/20_nginx.xml
+++ b/seed/nginx-common/dictionaries/21_nginx.xml
@@ -13,6 +13,7 @@
revprox_ca_file
/etc/pki/tls/certs/nginx.crt
/etc/pki/tls/private/nginx.key
+ /tests/nginx-common.yml
diff --git a/seed/nginx-common/templates/nginx-common.yml b/seed/nginx-common/templates/nginx-common.yml
new file mode 100644
index 00000000..4680042f
--- /dev/null
+++ b/seed/nginx-common/templates/nginx-common.yml
@@ -0,0 +1,13 @@
+address: %%ip_eth0
+nginx_default_http: %slurp
+%if %%getVar('nginx_default_http', False) and not %%getVar('revprox_client_external_domainnames', None)
+true
+%else
+false
+%end if
+nginx_default_https: %slurp
+%if %%getVar('nginx_default_https', False) and not %%getVar('revprox_client_external_domainnames', None)
+true
+%else
+false
+%end if
diff --git a/seed/nginx-common/templates/nginx.conf b/seed/nginx-common/templates/nginx.conf
index 758cb4de..b8cf4220 100644
--- a/seed/nginx-common/templates/nginx.conf
+++ b/seed/nginx-common/templates/nginx.conf
@@ -76,14 +76,24 @@ http {
%if %%nginx_default_https
server {
listen 443 ssl http2;
- server_name %%domain_name_eth0;
+ %if %%getVar('revprox_client_external_domainnames', None)
+ %for %%domain in %%revprox_client_external_domainnames
+ server_name %%domain;
+ %end for
+ %else
+ server_name _;
+ %end if
root %%nginx_root;
# ssl_certificate "/etc/pki/nginx/server.crt";
# ssl_certificate_key "/etc/pki/nginx/private/server.key";
ssl_certificate /etc/pki/tls/certs/nginx.crt;
ssl_certificate_key /etc/pki/tls/private/nginx.key;
- ssl_client_certificate /etc/pki/ca-trust/source/anchors/ca_InternalReverseProxy.crt;
+ %if %%getVar('revprox_client_external_domainnames', None)
+ ssl_client_certificate %%revprox_ca_file;
+ %else
+ ssl_client_certificate /etc/pki/ca-trust/source/anchors/ca_HTTP.crt;
+ %end if
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 10m;
@@ -105,5 +115,7 @@ http {
%else
include /etc/nginx/sites-enabled/*;
%end if
-
+%if not %%getVar('revprox_client_external_domainnames', None)
+ include /etc/nginx/sites-enabled/*;
+%end if
}
diff --git a/seed/nginx-common/tests/test_nginx_commmon.py b/seed/nginx-common/tests/test_nginx_commmon.py
new file mode 100644
index 00000000..efbfc866
--- /dev/null
+++ b/seed/nginx-common/tests/test_nginx_commmon.py
@@ -0,0 +1,50 @@
+from yaml import load, SafeLoader
+from os import environ
+from pytest import raises
+
+import warnings
+import socket
+from requests import get
+from requests.exceptions import SSLError
+
+
+def req(url, ip, verify=True):
+ # Monkey patch to force IPv4 resolution
+ old_getaddrinfo = socket.getaddrinfo
+ def new_getaddrinfo(*args, **kwargs):
+ ret = old_getaddrinfo(*args, **kwargs)
+ dns = list(ret[0])
+ dns[-1] = (ip, dns[-1][1])
+ return [dns]
+ socket.getaddrinfo = new_getaddrinfo
+ if not verify:
+ with warnings.catch_warnings():
+ warnings.simplefilter("ignore")
+ ret = get(url, verify=verify)
+ else:
+ ret = get(url, verify=verify)
+ ret_code = ret.status_code
+ content = ret.content
+ socket.getaddrinfo = old_getaddrinfo
+ return ret_code, content.decode()
+
+
+def test_revprox():
+ conf_file = f'{environ["MACHINE_TEST_DIR"]}/nginx-common.yml'
+ with open(conf_file) as yaml:
+ data = load(yaml, Loader=SafeLoader)
+ # test unknown domain
+ url = 'google.fr'
+ protocols = []
+ if data['nginx_default_http']:
+ protocols.append('http')
+ if data['nginx_default_https']:
+ protocols.append('https')
+ # test certificate
+ with raises(SSLError):
+ # not certificat problem for https://{url}
+ req(f'https://{url}', data['address'])
+ for protocol in protocols:
+ ret_code, content = req(f'{protocol}://{url}', data['address'], verify=False)
+ assert ret_code == 200, f'{protocol}://{url} do not returns code 200 but {ret_code}'
+ assert "Test Page for the HTTP Server on Fedora" in content, f'{protocol}://{url} do not returns default fedora page'
diff --git a/seed/nginx-https/dictionaries/25_nginx.xml b/seed/nginx-https/dictionaries/25_nginx.xml
index f908f0b5..1f24bfaf 100644
--- a/seed/nginx-https/dictionaries/25_nginx.xml
+++ b/seed/nginx-https/dictionaries/25_nginx.xml
@@ -1,22 +1,16 @@
-
-
- /etc/nginx/default.d/risotto.conf
-
-
-
+
+ False
+
+
True
nginx
-
-
- /
-
@@ -29,11 +23,4 @@
-
-
-
- nginx_default_risotto
- nginx_locations
-
-
diff --git a/seed/nginx-reverse-proxy/dictionaries/20_nginx.xml b/seed/nginx-reverse-proxy/dictionaries/20_nginx.xml
new file mode 100644
index 00000000..85ac9c5a
--- /dev/null
+++ b/seed/nginx-reverse-proxy/dictionaries/20_nginx.xml
@@ -0,0 +1,8 @@
+
+
+
+
+ /etc/pki/ca-trust/source/anchors/ca_HTTP.crt
+
+
+
diff --git a/seed/nginx-reverse-proxy/dictionaries/25_nginx.xml b/seed/nginx-reverse-proxy/dictionaries/25_nginx.xml
index 3ed3d35b..e4aa3699 100644
--- a/seed/nginx-reverse-proxy/dictionaries/25_nginx.xml
+++ b/seed/nginx-reverse-proxy/dictionaries/25_nginx.xml
@@ -4,7 +4,7 @@
/etc/nginx/conf.d/options-rp.conf
- /etc/nginx/conf.d/risotto.conf
+ /etc/nginx/sites-enabled/risotto.conf
nginx.nginx_certificate_filename
nginx.nginx_private_key_filename
/tests/reverse-proxy.yml
@@ -22,6 +22,9 @@
True
+
+ True
+
diff --git a/seed/nginx-reverse-proxy/templates/ca_HTTP.crt b/seed/nginx-reverse-proxy/templates/ca_HTTP.crt
new file mode 100644
index 00000000..dcbc3aa3
--- /dev/null
+++ b/seed/nginx-reverse-proxy/templates/ca_HTTP.crt
@@ -0,0 +1,3 @@
+%for %%idx in %%range(%%len(%%zones_list))
+%%get_chain(authority_cn=%%getVar('domain_name_eth' + %%str(%%idx)), authority_name="HTTP", hide=%%hide_secret)
+%end for
diff --git a/seed/nginx-reverse-proxy/templates/nginx.crt b/seed/nginx-reverse-proxy/templates/nginx.crt
new file mode 100644
index 00000000..de2a8a1d
--- /dev/null
+++ b/seed/nginx-reverse-proxy/templates/nginx.crt
@@ -0,0 +1,2 @@
+%%get_certificate(%%nginx_default, authority_cn=%%domain_name_eth0, authority_name='HTTP', type="server", hide=%%hide_secret)
+%%get_chain(%%nginx_default, 'HTTP', hide=%%hide_secret)
diff --git a/seed/nginx-reverse-proxy/templates/nginx.key b/seed/nginx-reverse-proxy/templates/nginx.key
new file mode 100644
index 00000000..4d393c67
--- /dev/null
+++ b/seed/nginx-reverse-proxy/templates/nginx.key
@@ -0,0 +1 @@
+%%get_private_key(%%nginx_default, authority_cn=%%domain_name_eth0, authority_name='HTTP', type='server', hide=%%hide_secret)
diff --git a/seed/nginx-reverse-proxy/templates/revprox-nginx.conf b/seed/nginx-reverse-proxy/templates/revprox-nginx.conf
index c1c7ff68..0f48e774 100644
--- a/seed/nginx-reverse-proxy/templates/revprox-nginx.conf
+++ b/seed/nginx-reverse-proxy/templates/revprox-nginx.conf
@@ -41,7 +41,7 @@ server {
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Destination $dest;
%end if
- proxy_ssl_trusted_certificate /etc/pki/ca-trust/source/anchors/ca_InternalReverseProxy.crt;
+ proxy_ssl_trusted_certificate %%revprox_ca_file;
proxy_ssl_verify on;
proxy_ssl_verify_depth 2;
proxy_ssl_session_reuse on;
diff --git a/seed/nginx-reverse-proxy/tests/test_revprox.py b/seed/nginx-reverse-proxy/tests/test_revprox.py
index d48cc788..592807d8 100644
--- a/seed/nginx-reverse-proxy/tests/test_revprox.py
+++ b/seed/nginx-reverse-proxy/tests/test_revprox.py
@@ -32,19 +32,8 @@ def test_revprox():
conf_file = f'{environ["MACHINE_TEST_DIR"]}/reverse-proxy.yml'
with open(conf_file) as yaml:
data = load(yaml, Loader=SafeLoader)
- # test unknown domain
- url = 'google.fr'
- ret_code, content = req(f'https://{url}', data['address'], verify=False)
- assert ret_code == 200, f'https://{url} do not returns code 200 but {ret_code}'
- assert "
Test Page for the HTTP Server on Fedora" in content, f'https://{url} returns default fedora page'
- # test certificate
- try:
- req(f'https://{url}', data['address'])
- raise Exception(f'not certificat problem for https://{url}')
- except SSLError:
- pass
# test known domains
for url in data['urls']:
ret_code, content = req(f'https://{url}', data['address'])
assert ret_code == 200, f'https://{url} do not returns code 200 but {ret_code}'
- assert "Test Page for the HTTP Server on Fedora" not in content, f'https://{url} returns default fedora page'
+ assert "Test Page for the HTTP Server on Fedora" not in content, f'https://{url} do returns default fedora page'
diff --git a/seed/peertube/applicationservice.yml b/seed/peertube/applicationservice.yml
index 6ae8b4b7..1aa97aba 100644
--- a/seed/peertube/applicationservice.yml
+++ b/seed/peertube/applicationservice.yml
@@ -7,5 +7,5 @@ depends:
- relay-mail-client
- reverse-proxy-client
- redis-client
- - nginx-common
+ - nginx-https
- oauth2-client
diff --git a/seed/peertube/dictionaries/30_peertube.xml b/seed/peertube/dictionaries/30_peertube.xml
index 47aa5482..6e627f15 100644
--- a/seed/peertube/dictionaries/30_peertube.xml
+++ b/seed/peertube/dictionaries/30_peertube.xml
@@ -6,7 +6,8 @@
/sysusers.d/0peertube.conf
/tmpfiles.d/0peertube.conf
/etc/peertube/production.yaml
- /etc/nginx/conf.d/peertube.conf
+ /etc/nginx/default.d/peertube.conf
+ /etc/nginx/conf.d/peertube.conf
@@ -45,6 +46,9 @@
+
+ /usr/share/peertube
+
/
diff --git a/seed/peertube/templates/nginx.peertube.conf b/seed/peertube/templates/nginx.peertube.conf
index 145eee6f..0f1fcf99 100644
--- a/seed/peertube/templates/nginx.peertube.conf
+++ b/seed/peertube/templates/nginx.peertube.conf
@@ -16,15 +16,14 @@
# GNUNUX location / { return 301 https://$host$request_uri; }
# GNUNUX }
-upstream %%domain_name_eth0 {
-# GNUNUX server ${PEERTUBE_HOST};
- server localhost:9000;
-}
+# GNUNUX upstream %%domain_name_eth0 {
+# GNUNUX server ${PEERTUBE_HOST};
+# GNUNUX }
-server {
- listen 443 ssl http2;
- listen [::]:443 ssl http2;
- server_name %%domain_name_eth0;
+# GNUNUX server {
+# GNUNUX listen 443 ssl http2;
+# GNUNUX listen [::]:443 ssl http2;
+# GNUNUX server_name %%domain_name_eth0;
# GNUNUX access_log /var/log/nginx/peertube.access.log; # reduce I/0 with buffer=10m flush=5m
# GNUNUX error_log /var/log/nginx/peertube.error.log;
@@ -35,11 +34,6 @@ server {
##
# GNUNUX ssl_certificate /etc/letsencrypt/live/${WEBSERVER_HOST}/fullchain.pem;
# GNUNUX ssl_certificate_key /etc/letsencrypt/live/${WEBSERVER_HOST}/privkey.pem;
-#>GNUNUX
- ssl_client_certificate %%revprox_ca_file;
- ssl_certificate %%revprox_cert_file;
- ssl_certificate_key %%revprox_key_file;
-#/etc/piwigo/database.inc.php
/sbin/piwigo.sh
/etc/php-fpm.d/piwigo.conf
+ /etc/nginx/default.d/piwigo.conf
-
-
- /usr/local/share/piwigo
-
-
+
Album photographique
@@ -53,7 +50,7 @@
piwigo_users
- nginx_locations
+ piwigo_locations
diff --git a/seed/nginx-https/templates/risotto.conf b/seed/piwigo/templates/piwigo.nginx.conf
similarity index 82%
rename from seed/nginx-https/templates/risotto.conf
rename to seed/piwigo/templates/piwigo.nginx.conf
index e7d34a48..1ba02a33 100644
--- a/seed/nginx-https/templates/risotto.conf
+++ b/seed/piwigo/templates/piwigo.nginx.conf
@@ -1,3 +1,5 @@
+# To allow POST on static pages
+error_page 405 =200 $uri;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
@@ -6,18 +8,15 @@ add_header X-Download-Options noopen;
add_header X-Permitted-Cross-Domain-Policies none;
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains;';
add_header Referrer-Policy no-referrer always;
-
-%for %%location in %%nginx_locations
+
+%for %%location in %%piwigo_locations
location %%location {
-%if %%location == '/'
+ %if %%location == '/'
root %slurp
-%else
+ %else
alias %slurp
-%end if
-%%nginx_root_directory;
-%if not %%getVar('php_fpm_installed', False)
- index index.html;
-%else
+ %end if
+ /usr/local/share/piwigo;
index index.php;
location ~ ^(?.+?\.php)(?/.*)?$ {
fastcgi_pass php-fpm;
@@ -25,6 +24,5 @@ location %%location {
fastcgi_param SCRIPT_FILENAME $request_filename;
include fastcgi_params;
}
-%end if
}
%end for
diff --git a/seed/pleroma/dictionaries/30_pleroma.xml b/seed/pleroma/dictionaries/30_pleroma.xml
index b457600c..6a6cc7ed 100644
--- a/seed/pleroma/dictionaries/30_pleroma.xml
+++ b/seed/pleroma/dictionaries/30_pleroma.xml
@@ -7,7 +7,7 @@
/tmpfiles.d/0peertube.conf
/etc/peertube/production.yaml
/etc/pam.d/login
- /etc/nginx/conf.d/peertube.conf
+ /etc/nginx/sites-enabled/peertube.conf
diff --git a/seed/postgresql/DEBUG.md b/seed/postgresql/DEBUG.md
new file mode 100644
index 00000000..c835ba01
--- /dev/null
+++ b/seed/postgresql/DEBUG.md
@@ -0,0 +1 @@
+pg_dumpall --clean > /srv/database.sql
diff --git a/seed/reverse-proxy-client/tests/revprox.py b/seed/reverse-proxy-client/tests/revprox.py
index bb9ab177..abc9c094 100644
--- a/seed/reverse-proxy-client/tests/revprox.py
+++ b/seed/reverse-proxy-client/tests/revprox.py
@@ -33,7 +33,7 @@ class Authentication:
ret = req.get(url)
code = ret.status_code
content = ret.content
- assert code == 200
+ assert code == 200, f"cannot access to lemonldap; {content}"
assert b'Authentication portal' in content, f'cannot find LemonLdap title: {content}'
def auth_lemonldap(self,