Something went wrong. Try again.
Backend environment for match hosting for lance.blue
Something went wrong. Try again.
Shell
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849#!/usr/bin/env bash# Build the match image (scripts/build.sh) and push it to ECR.## ./scripts/push.sh# REGISTRY=… IMAGE_TAG=dev ./scripts/push.sh## The default registry is infra's `tofu output -raw ecr_push_registry`, all of# which is fixed.set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"# shellcheck source=../versions.env. "$ROOT/versions.env"
: "${AWS_PROFILE:?set AWS_PROFILE; default credentials are almost never the right account}"
REGISTRY="${REGISTRY:-179302349187.dkr.ecr.us-east-1.amazonaws.com/lance-blue}"
# Only clean, committed builds get pushed: the registry will be immutable,# and a -dirty tag is not reproducible from any commit.case "$IMAGE_TAG" in *-dirty | *-unknown) echo "ERROR: refusing to push '$IMAGE_TAG'; commit first" >&2 exit 1 ;;esac
# The build sources versions.env too; exporting pins it to this tag even if# the tree changes under us.export BUILD_REF IMAGE_TAG"$ROOT/scripts/build.sh"
LOCAL="${IMAGE_NAME}:${IMAGE_TAG}"
# One tag per build, and it is what a task definition pins. Nothing here pushes# `latest`: a moving tag cannot say which build is running, and the registry# refuses to overwrite one anyway now that the repositories are IMMUTABLE.# build.sh does not tag `latest` locally either: this machine runs several# agent sessions at once, and a build in one of them silently repointed# `latest` under whoever else was resolving it.REMOTE="${REGISTRY}/$(basename "$IMAGE_NAME"):${IMAGE_TAG}"aws ecr get-login-password --region us-east-1 \ | docker login --username AWS --password-stdin "${REGISTRY%%/*}"echo "pushing $LOCAL -> $REMOTE"docker tag "$LOCAL" "$REMOTE"docker push "$REMOTE"
echo "pushed $REMOTE"