refactor: move deployment orchestration into bin/run-deployment script
ci/woodpecker/push/deploy Pipeline was successful
ci/woodpecker/deployment/deploy Pipeline was successful

This commit is contained in:
2026-09-18 22:12:15 +02:00
parent 241ec54042
commit 72af903e21
2 changed files with 72 additions and 47 deletions
+70
View File
@@ -0,0 +1,70 @@
#!/bin/sh
# Runs a full deployment: retrieves the deployment artifact by reference,
# decrypts its secrets, transfers everything to the target host, and
# invokes bin/deploy-compose there.
#
# Usage: run-deployment <artifact-ref> <ssh-host> <ssh-user> \
# <registry> <zot-username> <zot-password> <sops-age-key> <ssh-private-key>
#
# Must be run from the deployments.git workspace root (so bin/deploy-compose
# and hosts/ are reachable as relative paths).
set -e
ARTIFACT="$1"
SSH_HOST="$2"
SSH_USER="$3"
REGISTRY="$4"
ZOT_USERNAME="$5"
ZOT_PASSWORD="$6"
SOPS_AGE_KEY="$7"
DEPLOY_SSH_KEY="$8"
export SOPS_AGE_KEY
WORKSPACE="$(pwd)"
# Tooling: oras (artifact retrieval) and sops (secret decryption).
apk add --no-cache curl openssh-client
curl -sL "https://github.com/oras-project/oras/releases/download/v1.3.4/oras_1.3.4_linux_amd64.tar.gz" -o /tmp/oras.tar.gz
mkdir -p /tmp/oras-install && tar -xzf /tmp/oras.tar.gz -C /tmp/oras-install
install /tmp/oras-install/oras /usr/local/bin/oras
curl -sL "https://github.com/getsops/sops/releases/download/v3.13.3/sops-v3.13.3.linux.amd64" -o /usr/local/bin/sops
chmod +x /usr/local/bin/sops
# Retrieve the exact deployment artifact by digest/tag reference.
mkdir -p /tmp/deploy-bundle
cd /tmp/deploy-bundle
oras login "$REGISTRY" -u "$ZOT_USERNAME" -p "$ZOT_PASSWORD"
oras pull "$ARTIFACT"
test -f compose.yaml || (echo "ERROR - compose.yaml missing from artifact" && exit 1)
test -f secrets.prod.env || (echo "ERROR - secrets.prod.env missing from artifact" && exit 1)
test -f release.env || (echo "ERROR - release.env missing from artifact" && exit 1)
# Decrypt the service's secrets transiently, using the deployment age key.
sops --decrypt secrets.prod.env > secrets.decrypted.env
chmod 600 secrets.decrypted.env
# Set up the SSH key used to reach the target host.
mkdir -p -m 700 /tmp/ssh
echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy
chmod 600 /tmp/ssh/id_deploy
# Transfer compose.yaml, release.env, the decrypted secrets and the
# generic bin/deploy-compose script to the target host, run the
# deployment, then remove the plaintext secrets.
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
$SSH_USER@$SSH_HOST mkdir -p /tmp/poc-deploy
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
compose.yaml release.env secrets.decrypted.env \
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
$WORKSPACE/bin/deploy-compose \
$SSH_USER@$SSH_HOST:/tmp/poc-deploy/
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
$SSH_USER@$SSH_HOST chmod +x /tmp/poc-deploy/deploy-compose
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
$SSH_USER@$SSH_HOST /tmp/poc-deploy/deploy-compose "$REGISTRY" "$ZOT_USERNAME" "$ZOT_PASSWORD"
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new \
$SSH_USER@$SSH_HOST rm -f /tmp/poc-deploy/secrets.decrypted.env
echo "Deployment finished."