From 241ec5404298cdf38627aeb0450e6a23aeefcd99 Mon Sep 17 00:00:00 2001 From: Max Mehl Date: Fri, 18 Sep 2026 22:10:19 +0200 Subject: [PATCH] fix: consolidate ssh/scp calls into one step, docker logout after deploy --- .woodpecker/deploy.yaml | 31 ++++++++++++++++--------------- bin/deploy-compose | 2 ++ 2 files changed, 18 insertions(+), 15 deletions(-) diff --git a/.woodpecker/deploy.yaml b/.woodpecker/deploy.yaml index 259d9a1..4aeddad 100644 --- a/.woodpecker/deploy.yaml +++ b/.woodpecker/deploy.yaml @@ -50,28 +50,29 @@ steps: - chmod 600 /tmp/ssh/id_deploy # Ensure the remote working directory exists, then transfer # compose.yaml, release.env, the decrypted secrets and the generic - # bin/deploy-compose script to the target host. + # bin/deploy-compose script to the target host, run the deployment, + # and remove the plaintext secrets. Kept as a single commands: item + # (one shell script) rather than several, since separate ssh/scp + # list items have intermittently triggered a Woodpecker command + # parsing bug (log-streaming artifact, not a real shell syntax + # error - confirmed by direct SSH inspection of target1's state + # after affected runs). - | + set -e ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - $SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy - - | + $SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - compose.yaml release.env secrets.decrypted.env \ - $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ - - | + compose.yaml release.env secrets.decrypted.env \ + $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - $CI_WORKSPACE/bin/deploy-compose \ - $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ - # Run the deployment on the target host, then remove the plaintext secrets. - - | + $CI_WORKSPACE/bin/deploy-compose \ + $SSH_USER@$SSH_HOST:/tmp/poc-deploy/ ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - $SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose - - | + $SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - $SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose registry.ci.poc.mehl.mx $ZOT_USERNAME $ZOT_PASSWORD - - | + $SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose registry.ci.poc.mehl.mx $ZOT_USERNAME $ZOT_PASSWORD ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \ - $SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env + $SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env - echo "Deployment finished." when: event: [deployment, manual] diff --git a/bin/deploy-compose b/bin/deploy-compose index 9df5482..2d5e5e5 100755 --- a/bin/deploy-compose +++ b/bin/deploy-compose @@ -29,3 +29,5 @@ docker compose \ -f compose.yaml \ --env-file secrets.decrypted.env \ up -d --remove-orphans + +docker logout "$REGISTRY"