44 lines
1.6 KiB
Bash
Executable File
44 lines
1.6 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
cd "$(dirname "$0")/.."
|
|
|
|
test -f .env.example
|
|
test -f deploy/secrets/thothii.secrets.example
|
|
grep -q '^docker compose up --build -d$' docs/installazione-docker-4-contesti.md
|
|
if grep -q 'cp deploy/env.example deploy/.env\|THT_[A-Z0-9_]*_SECRET_FILE=' docs/installazione-docker-4-contesti.md; then
|
|
echo "installation guide still presents the legacy per-file secret setup" >&2
|
|
exit 1
|
|
fi
|
|
|
|
tmp=$(mktemp -d)
|
|
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
|
|
|
mkdir -p "$tmp/deploy/secrets" "$tmp/deploy/workspaces"
|
|
cp compose.yaml "$tmp/compose.yaml"
|
|
cp .env.example "$tmp/.env"
|
|
cp deploy/secrets/thothii.secrets.example "$tmp/deploy/secrets/thothii.secrets"
|
|
printf '%s\n' 'THT_MODEL_API_KEY=example-secret' >>"$tmp/deploy/secrets/thothii.secrets"
|
|
chmod 0600 "$tmp/deploy/secrets/thothii.secrets"
|
|
|
|
services=$(docker compose --project-directory "$tmp" config --services)
|
|
[ "$services" = "core
|
|
frontend" ] || {
|
|
echo "default Compose services must be core and frontend (got: $services)" >&2
|
|
exit 1
|
|
}
|
|
|
|
rendered=$(docker compose --project-directory "$tmp" config)
|
|
printf '%s\n' "$rendered" | grep -q 'target: thothii.secrets'
|
|
if printf '%s\n' "$rendered" | grep -Eq 'dwh_api_key|vector_reader_api_key|vector_writer_api_key|model_api_key|thoth_ca'; then
|
|
echo "default Compose must not declare legacy per-secret mounts" >&2
|
|
exit 1
|
|
fi
|
|
if printf '%s\n' "$rendered" | grep -Eq 'THT_[A-Z0-9_]+_SECRET_FILE:'; then
|
|
echo "default Compose must not require legacy secret-file variables" >&2
|
|
exit 1
|
|
fi
|
|
printf '%s\n' "$rendered" | grep -q 'THT_SECRETS_FILE: /run/secrets/thothii.secrets'
|
|
|
|
echo "default Compose contract passed."
|