Deploy workflow: commit-id image tags, guarded deploy.sh, opt-in prune
- Makefile builds from 'git archive HEAD' (stale-remote-HEAD impossible): tags registry.tanshu.com/mozimo:<short-commit> + :main; build-check target verifies both architectures without pushing - deploy.sh: refuses dirty tracked tree / HEAD != origin/main (--force to bypass), ff-only pull, passes the commit as image_tag to ansible, --prune flag for opt-in image cleanup - ansible: docker_image uses image_tag extra-var (falls back to tag), prune task keeps the 3 newest mozimo images, mozimo-repo only
This commit is contained in:
@@ -1,14 +1,51 @@
|
||||
#!/usr/bin/env bash
|
||||
# Mozimo deploy — build the exact commit at origin/main, tag it with its
|
||||
# commit id, and hand that tag to ansible. Guards make it impossible to
|
||||
# deploy anything other than what git knows about.
|
||||
#
|
||||
# ./deploy.sh deploy HEAD (must be pushed, tree must be clean)
|
||||
# ./deploy.sh --prune also drop old mozimo images on the server (keep 3)
|
||||
# ./deploy.sh --force skip the guards (know what you are doing)
|
||||
set -euo pipefail
|
||||
parent_path=$( cd "$(dirname "${BASH_SOURCE[0]}")" || exit ; pwd -P )
|
||||
cd "$parent_path" || exit
|
||||
git pull
|
||||
if [ 1 -eq "$#" ]
|
||||
then
|
||||
make build-production TAG="$1"
|
||||
else
|
||||
make build-production
|
||||
cd "$(dirname "${BASH_SOURCE[0]}")"
|
||||
|
||||
FORCE=false
|
||||
PRUNE=false
|
||||
for arg in "$@"; do
|
||||
case "$arg" in
|
||||
--force) FORCE=true ;;
|
||||
--prune) PRUNE=true ;;
|
||||
*)
|
||||
echo "Usage: $0 [--force] [--prune]"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
# guards: only tracked-file state matters (untracked files never enter a
|
||||
# `git archive HEAD` build); HEAD must equal origin/main
|
||||
if [ "$FORCE" != true ]; then
|
||||
if [ -n "$(git status --porcelain --untracked-files=no)" ]; then
|
||||
echo "✗ tracked files modified — commit or stash first (or --force)" >&2
|
||||
exit 1
|
||||
fi
|
||||
git fetch origin --quiet
|
||||
if [ "$(git rev-parse HEAD)" != "$(git rev-parse origin/main)" ]; then
|
||||
echo "✗ HEAD != origin/main — push or pull first (or --force)" >&2
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
cd "$parent_path/ansible" || exit
|
||||
ansible-playbook playbook.yml
|
||||
git pull --ff-only
|
||||
TAG=$(git rev-parse --short HEAD)
|
||||
echo "▶ deploying commit $TAG"
|
||||
make build-production TAG="$TAG"
|
||||
|
||||
PRUNE_FLAG=""
|
||||
if [ "$PRUNE" = true ]; then
|
||||
PRUNE_FLAG="-e mozimo_image_prune=true"
|
||||
fi
|
||||
|
||||
cd ansible
|
||||
# shellcheck disable=SC2086
|
||||
ansible-playbook playbook.yml -e "image_tag=$TAG" $PRUNE_FLAG
|
||||
|
||||
Reference in New Issue
Block a user