Something went wrong. Try again.
Docker files for the TLE Community deployment
Something went wrong. Try again.
1.5 kB · 33 lines
Shell
at main
12345678910111213141516171819202122232425262728293031323334#!/bin/sh
## Runs inside the deploy-trigger webhook container after the request's HMAC# signature has already been verified by webhook itself (see hooks.json).## This script never touches docker or sudo. It only records the request - a# host-side systemd unit (../../systemd/deploy-trigger.{path,service}) watches# /deploy-requests and performs the actual deploy as root. Keeping privileged# execution entirely out of this container means a compromised webhook can at# worst write a request file, never pull images or restart containers itself.#
set -eu
REQUEST_ID=$(head -c8 /dev/urandom | od -An -tx1 | tr -d ' \n')TS="$(date -u '+%Y-%m-%dT%H:%M:%SZ')"
ACTOR=$(echo "$HOOK_PAYLOAD" | jq -r '.actor // "unknown"')REF=$(echo "$HOOK_PAYLOAD" | jq -r '.ref // "unknown"')COMMIT=$(echo "$HOOK_PAYLOAD" | jq -r '.commit // "unknown"')CI_RUN_URL=$(echo "$HOOK_PAYLOAD" | jq -r '.ci_run_url // "unknown"')SOURCE_IP="${HOOK_SOURCE_IP:-unknown}"
mkdir -p /deploy-requests
cat > "/deploy-requests/${REQUEST_ID}.json" <<EOF{"request_id":"${REQUEST_ID}","ts":"${TS}","source_ip":"${SOURCE_IP}","triggered_by":"ci","actor":"${ACTOR}","ref":"${REF}","commit":"${COMMIT}","ci_run_url":"${CI_RUN_URL}"}EOF
echo "{\"ts\":\"${TS}\",\"request_id\":\"${REQUEST_ID}\",\"source_ip\":\"${SOURCE_IP}\",\"triggered_by\":\"ci\",\"actor\":\"${ACTOR}\",\"ref\":\"${REF}\",\"commit\":\"${COMMIT}\",\"ci_run_url\":\"${CI_RUN_URL}\",\"status\":\"queued\"}" >> /deploy-log/deploy-audit.log
echo "queued deploy request ${REQUEST_ID}"