#!/usr/bin/bash # # Runs as root via systemd (deploy-trigger.path -> deploy-trigger.service). # This is the only place a remotely-triggered deploy actually gains root: it # is invoked by systemd, never by a container, and reads its work from # ./data/deploy-requests/*.json - files the deploy-trigger webhook container # can write but not execute. # # Drains the request queue one file at a time, runs deploy.sh for each, and # appends a start/finish line to the shared audit log. # set -euo pipefail cd "$(dirname "$0")/.." REQ_DIR=./data/deploy-requests AUDIT_LOG=./log/deploy/deploy-audit.log for req in "$REQ_DIR"/*.json; do [ -e "$req" ] || continue REQUEST_ID=$(jq -r '.request_id' "$req") ACTOR=$(jq -r '.actor' "$req") REF=$(jq -r '.ref' "$req") COMMIT=$(jq -r '.commit' "$req") CI_RUN_URL=$(jq -r '.ci_run_url' "$req") SOURCE_IP=$(jq -r '.source_ip' "$req") STAMP=$(date -u '+%Y%m%d-%H%M%S') LOG_FILE="deploy-${STAMP}.log" START_TS="$(date -u '+%Y-%m-%dT%H:%M:%SZ')" START_EPOCH=$(date +%s) echo "{\"ts\":\"${START_TS}\",\"request_id\":\"${REQUEST_ID}\",\"source_ip\":\"${SOURCE_IP}\",\"triggered_by\":\"ci\",\"actor\":\"${ACTOR}\",\"ref\":\"${REF}\",\"commit\":\"${COMMIT}\",\"ci_run_url\":\"${CI_RUN_URL}\",\"status\":\"started\",\"log_file\":\"${LOG_FILE}\"}" >> "$AUDIT_LOG" set +e ./deploy.sh > "./log/deploy/${LOG_FILE}" 2>&1 EXIT_CODE=$? set -e END_EPOCH=$(date +%s) END_TS="$(date -u '+%Y-%m-%dT%H:%M:%SZ')" DURATION=$((END_EPOCH - START_EPOCH)) STATUS="succeeded" [ "$EXIT_CODE" -ne 0 ] && STATUS="failed" echo "{\"ts\":\"${END_TS}\",\"request_id\":\"${REQUEST_ID}\",\"status\":\"${STATUS}\",\"exit_code\":${EXIT_CODE},\"duration_s\":${DURATION},\"log_file\":\"${LOG_FILE}\"}" >> "$AUDIT_LOG" rm -f "$req" done