#!/bin/sh # # Runs inside the deploy-trigger webhook container after the request's HMAC # signature has already been verified by webhook itself (see hooks.json). # # This script never touches docker or sudo. It only records the request - a # host-side systemd unit (../../systemd/deploy-trigger.{path,service}) watches # /deploy-requests and performs the actual deploy as root. Keeping privileged # execution entirely out of this container means a compromised webhook can at # worst write a request file, never pull images or restart containers itself. # set -eu REQUEST_ID=$(head -c8 /dev/urandom | od -An -tx1 | tr -d ' \n') TS="$(date -u '+%Y-%m-%dT%H:%M:%SZ')" ACTOR=$(echo "$HOOK_PAYLOAD" | jq -r '.actor // "unknown"') REF=$(echo "$HOOK_PAYLOAD" | jq -r '.ref // "unknown"') COMMIT=$(echo "$HOOK_PAYLOAD" | jq -r '.commit // "unknown"') CI_RUN_URL=$(echo "$HOOK_PAYLOAD" | jq -r '.ci_run_url // "unknown"') SOURCE_IP="${HOOK_SOURCE_IP:-unknown}" mkdir -p /deploy-requests cat > "/deploy-requests/${REQUEST_ID}.json" <> /deploy-log/deploy-audit.log echo "queued deploy request ${REQUEST_ID}"