From ac735bb27ada98f9c1023f6e4e92a9c643c66028 Mon Sep 17 00:00:00 2001 From: Max Mehl Date: Fri, 18 Sep 2026 21:53:37 +0200 Subject: [PATCH] refactor: move deploy logic to bin/deploy-compose, transfer and invoke instead of building script inline --- .woodpecker/deploy.yaml | 27 ++++++++------------------- bin/deploy-compose | 23 +++++++++++++++++++++++ 2 files changed, 31 insertions(+), 19 deletions(-) create mode 100755 bin/deploy-compose diff --git a/.woodpecker/deploy.yaml b/.woodpecker/deploy.yaml index 733d158..3ebdd3b 100644 --- a/.woodpecker/deploy.yaml +++ b/.woodpecker/deploy.yaml @@ -49,36 +49,25 @@ steps: - echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy - chmod 600 /tmp/ssh/id_deploy # Ensure the remote working directory exists, then transfer - # compose.yaml, release.env, the decrypted secrets and a small deploy - # script to the target host. + # compose.yaml, release.env, the decrypted secrets and the generic + # bin/deploy-compose script to the target host. - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new "$SSH_USER@$SSH_HOST" "mkdir -p /tmp/poc-deploy" - - echo "#!/bin/sh" > /tmp/deploy-bundle/run-deploy.sh - - echo "set -e" >> /tmp/deploy-bundle/run-deploy.sh - - echo "set -a" >> /tmp/deploy-bundle/run-deploy.sh - - echo ". /tmp/poc-deploy/release.env" >> /tmp/deploy-bundle/run-deploy.sh - - echo "set +a" >> /tmp/deploy-bundle/run-deploy.sh - - >- - echo "docker compose --project-directory /tmp/poc-deploy -f - /tmp/poc-deploy/compose.yaml --env-file - /tmp/poc-deploy/secrets.decrypted.env pull" >> /tmp/deploy-bundle/run-deploy.sh - - >- - echo "docker compose --project-directory /tmp/poc-deploy -f - /tmp/poc-deploy/compose.yaml --env-file - /tmp/poc-deploy/secrets.decrypted.env up -d --remove-orphans" - >> /tmp/deploy-bundle/run-deploy.sh - - cat /tmp/deploy-bundle/run-deploy.sh - >- scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new - compose.yaml release.env secrets.decrypted.env run-deploy.sh + compose.yaml release.env secrets.decrypted.env + "$SSH_USER@$SSH_HOST:/tmp/poc-deploy/" + - >- + scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new + "$CI_WORKSPACE/bin/deploy-compose" "$SSH_USER@$SSH_HOST:/tmp/poc-deploy/" # Run the deployment on the target host, then remove the plaintext secrets. - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new "$SSH_USER@$SSH_HOST" - "sh /tmp/poc-deploy/run-deploy.sh" + "chmod +x /tmp/poc-deploy/deploy-compose && /tmp/poc-deploy/deploy-compose" - >- ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new "$SSH_USER@$SSH_HOST" diff --git a/bin/deploy-compose b/bin/deploy-compose new file mode 100755 index 0000000..30bea95 --- /dev/null +++ b/bin/deploy-compose @@ -0,0 +1,23 @@ +#!/bin/sh +# Runs a Compose deployment on the target host. Invoked remotely via SSH +# after compose.yaml, release.env and secrets.decrypted.env have been +# transferred to the same directory as this script. +set -e + +cd "$(dirname "$0")" + +set -a +. ./release.env +set +a + +docker compose \ + --project-directory . \ + -f compose.yaml \ + --env-file secrets.decrypted.env \ + pull + +docker compose \ + --project-directory . \ + -f compose.yaml \ + --env-file secrets.decrypted.env \ + up -d --remove-orphans