refactor: move deploy logic to bin/deploy-compose, transfer and invoke instead of building script inline
This commit is contained in:
+8
-19
@@ -49,36 +49,25 @@ steps:
|
|||||||
- echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy
|
- echo "$DEPLOY_SSH_KEY" > /tmp/ssh/id_deploy
|
||||||
- chmod 600 /tmp/ssh/id_deploy
|
- chmod 600 /tmp/ssh/id_deploy
|
||||||
# Ensure the remote working directory exists, then transfer
|
# Ensure the remote working directory exists, then transfer
|
||||||
# compose.yaml, release.env, the decrypted secrets and a small deploy
|
# compose.yaml, release.env, the decrypted secrets and the generic
|
||||||
# script to the target host.
|
# bin/deploy-compose script to the target host.
|
||||||
- >-
|
- >-
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
||||||
"$SSH_USER@$SSH_HOST"
|
"$SSH_USER@$SSH_HOST"
|
||||||
"mkdir -p /tmp/poc-deploy"
|
"mkdir -p /tmp/poc-deploy"
|
||||||
- echo "#!/bin/sh" > /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- echo "set -e" >> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- echo "set -a" >> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- echo ". /tmp/poc-deploy/release.env" >> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- echo "set +a" >> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- >-
|
|
||||||
echo "docker compose --project-directory /tmp/poc-deploy -f
|
|
||||||
/tmp/poc-deploy/compose.yaml --env-file
|
|
||||||
/tmp/poc-deploy/secrets.decrypted.env pull" >> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- >-
|
|
||||||
echo "docker compose --project-directory /tmp/poc-deploy -f
|
|
||||||
/tmp/poc-deploy/compose.yaml --env-file
|
|
||||||
/tmp/poc-deploy/secrets.decrypted.env up -d --remove-orphans"
|
|
||||||
>> /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- cat /tmp/deploy-bundle/run-deploy.sh
|
|
||||||
- >-
|
- >-
|
||||||
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
||||||
compose.yaml release.env secrets.decrypted.env run-deploy.sh
|
compose.yaml release.env secrets.decrypted.env
|
||||||
|
"$SSH_USER@$SSH_HOST:/tmp/poc-deploy/"
|
||||||
|
- >-
|
||||||
|
scp -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
||||||
|
"$CI_WORKSPACE/bin/deploy-compose"
|
||||||
"$SSH_USER@$SSH_HOST:/tmp/poc-deploy/"
|
"$SSH_USER@$SSH_HOST:/tmp/poc-deploy/"
|
||||||
# Run the deployment on the target host, then remove the plaintext secrets.
|
# Run the deployment on the target host, then remove the plaintext secrets.
|
||||||
- >-
|
- >-
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
||||||
"$SSH_USER@$SSH_HOST"
|
"$SSH_USER@$SSH_HOST"
|
||||||
"sh /tmp/poc-deploy/run-deploy.sh"
|
"chmod +x /tmp/poc-deploy/deploy-compose && /tmp/poc-deploy/deploy-compose"
|
||||||
- >-
|
- >-
|
||||||
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
ssh -i /tmp/ssh/id_deploy -o StrictHostKeyChecking=accept-new
|
||||||
"$SSH_USER@$SSH_HOST"
|
"$SSH_USER@$SSH_HOST"
|
||||||
|
|||||||
Executable
+23
@@ -0,0 +1,23 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Runs a Compose deployment on the target host. Invoked remotely via SSH
|
||||||
|
# after compose.yaml, release.env and secrets.decrypted.env have been
|
||||||
|
# transferred to the same directory as this script.
|
||||||
|
set -e
|
||||||
|
|
||||||
|
cd "$(dirname "$0")"
|
||||||
|
|
||||||
|
set -a
|
||||||
|
. ./release.env
|
||||||
|
set +a
|
||||||
|
|
||||||
|
docker compose \
|
||||||
|
--project-directory . \
|
||||||
|
-f compose.yaml \
|
||||||
|
--env-file secrets.decrypted.env \
|
||||||
|
pull
|
||||||
|
|
||||||
|
docker compose \
|
||||||
|
--project-directory . \
|
||||||
|
-f compose.yaml \
|
||||||
|
--env-file secrets.decrypted.env \
|
||||||
|
up -d --remove-orphans
|
||||||
Reference in New Issue
Block a user