From 886bbc6a0b8861de8449973b16c681a30fff9ae7 Mon Sep 17 00:00:00 2001 From: Max Mehl Date: Fri, 18 Sep 2026 21:47:58 +0200 Subject: [PATCH] fix: use a remote script file instead of inline quoted ssh command --- .woodpecker/deploy.yaml | 34 +++++++++++++++++++++------------- 1 file changed, 21 insertions(+), 13 deletions(-) diff --git a/.woodpecker/deploy.yaml b/.woodpecker/deploy.yaml index 68cf0df..5e70c74 100644 --- a/.woodpecker/deploy.yaml +++ b/.woodpecker/deploy.yaml @@ -49,29 +49,37 @@ steps: - echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy - chmod 600 /tmp/ssh/id_deploy # Ensure the remote working directory exists, then transfer - # compose.yaml, release.env and the decrypted secrets to the target host. + # compose.yaml, release.env, the decrypted secrets and a small deploy + # script to the target host. - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new "$SSH_USER@$SSH_HOST" "mkdir -p /tmp/poc-deploy" + - | + cat > /tmp/deploy-bundle/run-deploy.sh <<'SCRIPT' + #!/bin/sh + set -e + set -a + . /tmp/poc-deploy/release.env + set +a + docker compose --project-directory /tmp/poc-deploy \ + -f /tmp/poc-deploy/compose.yaml \ + --env-file /tmp/poc-deploy/secrets.decrypted.env \ + pull + docker compose --project-directory /tmp/poc-deploy \ + -f /tmp/poc-deploy/compose.yaml \ + --env-file /tmp/poc-deploy/secrets.decrypted.env \ + up -d --remove-orphans + SCRIPT - >- scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new - compose.yaml release.env secrets.decrypted.env + compose.yaml release.env secrets.decrypted.env run-deploy.sh "$SSH_USER@$SSH_HOST:/tmp/poc-deploy/" # Run the deployment on the target host, then remove the plaintext secrets. - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new - "$SSH_USER@$SSH_HOST" ' - set -a; . /tmp/poc-deploy/release.env; set +a; - docker compose --project-directory /tmp/poc-deploy - -f /tmp/poc-deploy/compose.yaml - --env-file /tmp/poc-deploy/secrets.decrypted.env - pull && - docker compose --project-directory /tmp/poc-deploy - -f /tmp/poc-deploy/compose.yaml - --env-file /tmp/poc-deploy/secrets.decrypted.env - up -d --remove-orphans - ' + "$SSH_USER@$SSH_HOST" + "sh /tmp/poc-deploy/run-deploy.sh" - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new "$SSH_USER@$SSH_HOST"