fix: consolidate ssh/scp calls into one step, docker logout after deploy
This commit is contained in:
+16
-15
@@ -50,28 +50,29 @@ steps:
|
|||||||
- chmod 600 /tmp/ssh/id_deploy
|
- chmod 600 /tmp/ssh/id_deploy
|
||||||
# Ensure the remote working directory exists, then transfer
|
# Ensure the remote working directory exists, then transfer
|
||||||
# compose.yaml, release.env, the decrypted secrets and the generic
|
# compose.yaml, release.env, the decrypted secrets and the generic
|
||||||
# bin/deploy-compose script to the target host.
|
# bin/deploy-compose script to the target host, run the deployment,
|
||||||
|
# and remove the plaintext secrets. Kept as a single commands: item
|
||||||
|
# (one shell script) rather than several, since separate ssh/scp
|
||||||
|
# list items have intermittently triggered a Woodpecker command
|
||||||
|
# parsing bug (log-streaming artifact, not a real shell syntax
|
||||||
|
# error - confirmed by direct SSH inspection of target1's state
|
||||||
|
# after affected runs).
|
||||||
- |
|
- |
|
||||||
|
set -e
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
$SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy
|
$SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy
|
||||||
- |
|
|
||||||
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
compose.yaml release.env secrets.decrypted.env \
|
compose.yaml release.env secrets.decrypted.env \
|
||||||
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
|
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
|
||||||
- |
|
|
||||||
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
$CI_WORKSPACE/bin/deploy-compose \
|
$CI_WORKSPACE/bin/deploy-compose \
|
||||||
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
|
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
|
||||||
# Run the deployment on the target host, then remove the plaintext secrets.
|
|
||||||
- |
|
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
$SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose
|
$SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose
|
||||||
- |
|
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
$SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose registry.ci.poc.mehl.mx $ZOT_USERNAME $ZOT_PASSWORD
|
$SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose registry.ci.poc.mehl.mx $ZOT_USERNAME $ZOT_PASSWORD
|
||||||
- |
|
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
|
||||||
$SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env
|
$SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env
|
||||||
- echo "Deployment finished."
|
- echo "Deployment finished."
|
||||||
when:
|
when:
|
||||||
event: [deployment, manual]
|
event: [deployment, manual]
|
||||||
|
|||||||
@@ -29,3 +29,5 @@ docker compose \
|
|||||||
-f compose.yaml \
|
-f compose.yaml \
|
||||||
--env-file secrets.decrypted.env \
|
--env-file secrets.decrypted.env \
|
||||||
up -d --remove-orphans
|
up -d --remove-orphans
|
||||||
|
|
||||||
|
docker logout "$REGISTRY"
|
||||||
|
|||||||
Reference in New Issue
Block a user