deploy: unify local and server compose stack
This commit is contained in:
@@ -1,43 +1,26 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
test -f .env.example
|
||||
test -f deploy/secrets/thothii.secrets.example
|
||||
grep -q '^docker compose up --build -d$' docs/installazione-docker-4-contesti.md
|
||||
if grep -q 'cp deploy/env.example deploy/.env\|THT_[A-Z0-9_]*_SECRET_FILE=' docs/installazione-docker-4-contesti.md; then
|
||||
echo "installation guide still presents the legacy per-file secret setup" >&2
|
||||
test -f deploy/env/local.env.example
|
||||
test -f deploy/env/server.env.example
|
||||
|
||||
rendered=$(mktemp)
|
||||
trap 'rm -f "$rendered"' EXIT HUP INT TERM
|
||||
|
||||
docker compose --env-file deploy/env/local.env.example \
|
||||
-f compose.yaml -f deploy/compose.local.yaml config >"$rendered"
|
||||
|
||||
grep -q '^ core:' "$rendered"
|
||||
grep -q '^ frontend:' "$rendered"
|
||||
grep -q 'host_ip: 127.0.0.1' "$rendered"
|
||||
grep -q 'AUTH_MODE: none' "$rendered"
|
||||
grep -q 'THT_WORKSPACE_INSTALLATION_ID: local' "$rendered"
|
||||
if grep -Eqi 'omics_portal|chirone|localllm_default|/home/chirone' "$rendered"; then
|
||||
echo "default Compose contains application-specific coupling" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
tmp=$(mktemp -d)
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
|
||||
mkdir -p "$tmp/deploy/secrets" "$tmp/deploy/workspaces"
|
||||
cp compose.yaml "$tmp/compose.yaml"
|
||||
cp .env.example "$tmp/.env"
|
||||
cp deploy/secrets/thothii.secrets.example "$tmp/deploy/secrets/thothii.secrets"
|
||||
printf '%s\n' 'THT_MODEL_API_KEY=example-secret' >>"$tmp/deploy/secrets/thothii.secrets"
|
||||
chmod 0600 "$tmp/deploy/secrets/thothii.secrets"
|
||||
|
||||
services=$(docker compose --project-directory "$tmp" config --services)
|
||||
[ "$services" = "core
|
||||
frontend" ] || {
|
||||
echo "default Compose services must be core and frontend (got: $services)" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
rendered=$(docker compose --project-directory "$tmp" config)
|
||||
printf '%s\n' "$rendered" | grep -q 'target: thothii.secrets'
|
||||
if printf '%s\n' "$rendered" | grep -Eq 'dwh_api_key|vector_reader_api_key|vector_writer_api_key|model_api_key|thoth_ca'; then
|
||||
echo "default Compose must not declare legacy per-secret mounts" >&2
|
||||
exit 1
|
||||
fi
|
||||
if printf '%s\n' "$rendered" | grep -Eq 'THT_[A-Z0-9_]+_SECRET_FILE:'; then
|
||||
echo "default Compose must not require legacy secret-file variables" >&2
|
||||
exit 1
|
||||
fi
|
||||
printf '%s\n' "$rendered" | grep -q 'THT_SECRETS_FILE: /run/secrets/thothii.secrets'
|
||||
|
||||
echo "default Compose contract passed."
|
||||
|
||||
Executable
+84
@@ -0,0 +1,84 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
tmp=$(mktemp -d)
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
|
||||
render_profile() {
|
||||
local profile=$1
|
||||
local env_file=$2
|
||||
local compose_file=$3
|
||||
local rendered="$tmp/$profile.json"
|
||||
|
||||
docker compose --env-file "$env_file" -f compose.yaml -f "$compose_file" \
|
||||
config --format json >"$rendered"
|
||||
|
||||
node - "$rendered" "$profile" <<'NODE'
|
||||
const fs = require("fs");
|
||||
|
||||
const [configPath, profile] = process.argv.slice(2);
|
||||
const config = JSON.parse(fs.readFileSync(configPath, "utf8"));
|
||||
const services = Object.keys(config.services).sort();
|
||||
if (services.join(",") !== "core,frontend") throw new Error("mandatory stack must be core,frontend");
|
||||
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
|
||||
throw new Error("forbidden application coupling");
|
||||
}
|
||||
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
|
||||
|
||||
const ports = Object.fromEntries(
|
||||
Object.entries(config.services).map(([name, service]) => [name, service.ports || []]),
|
||||
);
|
||||
if (profile === "local") {
|
||||
if (!ports.frontend.some((port) => port.host_ip === "127.0.0.1")) {
|
||||
throw new Error("local frontend must publish a loopback port");
|
||||
}
|
||||
if (ports.core.length !== 0 && !ports.core.every((port) => port.host_ip === "127.0.0.1")) {
|
||||
throw new Error("local core may publish only loopback ports");
|
||||
}
|
||||
} else {
|
||||
if (ports.core.length !== 0) throw new Error("server core must not publish a host port");
|
||||
if (ports.frontend.length === 0) throw new Error("server frontend must publish a host port");
|
||||
}
|
||||
NODE
|
||||
}
|
||||
|
||||
assert_remote_required() {
|
||||
local env_file=$1
|
||||
local compose_file=$2
|
||||
local without_remote="$tmp/without-remote.env"
|
||||
grep -v '^THT_WORKSPACE_GIT_REMOTE=' "$env_file" >"$without_remote"
|
||||
|
||||
if env -u THT_WORKSPACE_GIT_REMOTE docker compose --env-file "$without_remote" -f compose.yaml -f "$compose_file" \
|
||||
config --format json >"$tmp/missing-remote.out" 2>"$tmp/missing-remote.err"; then
|
||||
echo "Compose must require THT_WORKSPACE_GIT_REMOTE" >&2
|
||||
exit 1
|
||||
fi
|
||||
grep -q 'THT_WORKSPACE_GIT_REMOTE' "$tmp/missing-remote.err"
|
||||
}
|
||||
|
||||
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
|
||||
PI_AUTH_FILE=/dev/null \
|
||||
docker compose -f compose.yaml config --format json >"$tmp/base.json"
|
||||
node - "$tmp/base.json" <<'NODE'
|
||||
const fs = require("fs");
|
||||
|
||||
const config = JSON.parse(fs.readFileSync(process.argv[2], "utf8"));
|
||||
const services = Object.keys(config.services).sort();
|
||||
if (services.join(",") !== "core,frontend") throw new Error("mandatory stack must be core,frontend");
|
||||
if (/omics_portal|chirone|localllm_default|\/home\/chirone/i.test(JSON.stringify(config))) {
|
||||
throw new Error("forbidden application coupling");
|
||||
}
|
||||
if (!config.networks || !config.networks.thothii) throw new Error("base stack must define the thothii network");
|
||||
for (const volume of ["settings", "pi-state", "workspace-registry", "sessions"]) {
|
||||
if (!config.volumes || !config.volumes[volume]) throw new Error(`missing required volume: ${volume}`);
|
||||
}
|
||||
NODE
|
||||
|
||||
render_profile local deploy/env/local.env.example deploy/compose.local.yaml
|
||||
render_profile server deploy/env/server.env.example deploy/compose.server.yaml
|
||||
assert_remote_required deploy/env/local.env.example deploy/compose.local.yaml
|
||||
assert_remote_required deploy/env/server.env.example deploy/compose.server.yaml
|
||||
|
||||
echo "unified Compose contract passed."
|
||||
Reference in New Issue
Block a user