Skip to content
This repository was archived by the owner on Sep 11, 2024. It is now read-only.

Commit bdc6870

Browse files
vzalyginmikeGEINE
andauthored
Feature/deploy (#57)
* add yc registry login fix deploy flow fix deploy build commit stuf deploy with cert and db problems try to fix dns * fix traefik * fix deploy * Update load-token --------- Co-authored-by: Mikhail Geine <[email protected]>
1 parent ccd357f commit bdc6870

23 files changed

+871
-413
lines changed

.dockerignore

+1
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@
1212

1313
# Ignore all default key files.
1414
/config/master.key
15+
/config/authorized_key.json
1516
/config/credentials/*.key
1617

1718
# Ignore all logfiles and tempfiles.

.env.example

+1
Original file line numberDiff line numberDiff line change
@@ -6,3 +6,4 @@ DATABASE_URL=postgresql://postgres@postgres:5432
66
REDIS_URL=redis://redis:6379/1
77
VK_AUTH_REDIRECT_URL=http://localhost/auth/vkontakte/callback
88
VK_APP_ID=51989509
9+
RAILS_MASTER_KEY=

.gitignore

+1
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@
3434

3535
# Ignore master key for decrypting credentials and more.
3636
/config/master.key
37+
/config/authorized_key.json
3738

3839
/app/assets/builds/*
3940
!/app/assets/builds/.keep

.kamal/hooks/docker-setup.sample

+13
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
#!/usr/bin/env ruby
2+
3+
# A sample docker-setup hook
4+
#
5+
# Sets up a Docker network on defined hosts which can then be used by the application’s containers
6+
7+
hosts = ENV["KAMAL_HOSTS"].split(",")
8+
9+
hosts.each do |ip|
10+
destination = "root@#{ip}"
11+
puts "Creating a Docker network \"kamal\" on #{destination}"
12+
`ssh #{destination} docker network create kamal`
13+
end

.kamal/hooks/post-deploy.sample

+14
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
#!/bin/sh
2+
3+
# A sample post-deploy hook
4+
#
5+
# These environment variables are available:
6+
# KAMAL_RECORDED_AT
7+
# KAMAL_PERFORMER
8+
# KAMAL_VERSION
9+
# KAMAL_HOSTS
10+
# KAMAL_ROLE (if set)
11+
# KAMAL_DESTINATION (if set)
12+
# KAMAL_RUNTIME
13+
14+
echo "$KAMAL_PERFORMER deployed $KAMAL_VERSION to $KAMAL_DESTINATION in $KAMAL_RUNTIME seconds"
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Rebooted Traefik on $KAMAL_HOSTS"

.kamal/hooks/pre-build.sample

+51
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
#!/bin/sh
2+
3+
# A sample pre-build hook
4+
#
5+
# Checks:
6+
# 1. We have a clean checkout
7+
# 2. A remote is configured
8+
# 3. The branch has been pushed to the remote
9+
# 4. The version we are deploying matches the remote
10+
#
11+
# These environment variables are available:
12+
# KAMAL_RECORDED_AT
13+
# KAMAL_PERFORMER
14+
# KAMAL_VERSION
15+
# KAMAL_HOSTS
16+
# KAMAL_ROLE (if set)
17+
# KAMAL_DESTINATION (if set)
18+
19+
if [ -n "$(git status --porcelain)" ]; then
20+
echo "Git checkout is not clean, aborting..." >&2
21+
git status --porcelain >&2
22+
exit 1
23+
fi
24+
25+
first_remote=$(git remote)
26+
27+
if [ -z "$first_remote" ]; then
28+
echo "No git remote set, aborting..." >&2
29+
exit 1
30+
fi
31+
32+
current_branch=$(git branch --show-current)
33+
34+
if [ -z "$current_branch" ]; then
35+
echo "Not on a git branch, aborting..." >&2
36+
exit 1
37+
fi
38+
39+
remote_head=$(git ls-remote $first_remote --tags $current_branch | cut -f1)
40+
41+
if [ -z "$remote_head" ]; then
42+
echo "Branch not pushed to remote, aborting..." >&2
43+
exit 1
44+
fi
45+
46+
if [ "$KAMAL_VERSION" != "$remote_head" ]; then
47+
echo "Version ($KAMAL_VERSION) does not match remote HEAD ($remote_head), aborting..." >&2
48+
exit 1
49+
fi
50+
51+
exit 0

.kamal/hooks/pre-connect.sample

+47
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
#!/usr/bin/env ruby
2+
3+
# A sample pre-connect check
4+
#
5+
# Warms DNS before connecting to hosts in parallel
6+
#
7+
# These environment variables are available:
8+
# KAMAL_RECORDED_AT
9+
# KAMAL_PERFORMER
10+
# KAMAL_VERSION
11+
# KAMAL_HOSTS
12+
# KAMAL_ROLE (if set)
13+
# KAMAL_DESTINATION (if set)
14+
# KAMAL_RUNTIME
15+
16+
hosts = ENV["KAMAL_HOSTS"].split(",")
17+
results = nil
18+
max = 3
19+
20+
elapsed = Benchmark.realtime do
21+
results = hosts.map do |host|
22+
Thread.new do
23+
tries = 1
24+
25+
begin
26+
Socket.getaddrinfo(host, 0, Socket::AF_UNSPEC, Socket::SOCK_STREAM, nil, Socket::AI_CANONNAME)
27+
rescue SocketError
28+
if tries < max
29+
puts "Retrying DNS warmup: #{host}"
30+
tries += 1
31+
sleep rand
32+
retry
33+
else
34+
puts "DNS warmup failed: #{host}"
35+
host
36+
end
37+
end
38+
39+
tries
40+
end
41+
end.map(&:value)
42+
end
43+
44+
retries = results.sum - hosts.size
45+
nopes = results.count { |r| r == max }
46+
47+
puts "Prewarmed %d DNS lookups in %.2f sec: %d retries, %d failures" % [ hosts.size, elapsed, retries, nopes ]

.kamal/hooks/pre-deploy.sample

+109
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
1+
#!/usr/bin/env ruby
2+
3+
# A sample pre-deploy hook
4+
#
5+
# Checks the Github status of the build, waiting for a pending build to complete for up to 720 seconds.
6+
#
7+
# Fails unless the combined status is "success"
8+
#
9+
# These environment variables are available:
10+
# KAMAL_RECORDED_AT
11+
# KAMAL_PERFORMER
12+
# KAMAL_VERSION
13+
# KAMAL_HOSTS
14+
# KAMAL_COMMAND
15+
# KAMAL_SUBCOMMAND
16+
# KAMAL_ROLE (if set)
17+
# KAMAL_DESTINATION (if set)
18+
19+
# Only check the build status for production deployments
20+
if ENV["KAMAL_COMMAND"] == "rollback" || ENV["KAMAL_DESTINATION"] != "production"
21+
exit 0
22+
end
23+
24+
require "bundler/inline"
25+
26+
# true = install gems so this is fast on repeat invocations
27+
gemfile(true, quiet: true) do
28+
source "https://rubygems.org"
29+
30+
gem "octokit"
31+
gem "faraday-retry"
32+
end
33+
34+
MAX_ATTEMPTS = 72
35+
ATTEMPTS_GAP = 10
36+
37+
def exit_with_error(message)
38+
$stderr.puts message
39+
exit 1
40+
end
41+
42+
class GithubStatusChecks
43+
attr_reader :remote_url, :git_sha, :github_client, :combined_status
44+
45+
def initialize
46+
@remote_url = `git config --get remote.origin.url`.strip.delete_prefix("https://github.com/")
47+
@git_sha = `git rev-parse HEAD`.strip
48+
@github_client = Octokit::Client.new(access_token: ENV["GITHUB_TOKEN"])
49+
refresh!
50+
end
51+
52+
def refresh!
53+
@combined_status = github_client.combined_status(remote_url, git_sha)
54+
end
55+
56+
def state
57+
combined_status[:state]
58+
end
59+
60+
def first_status_url
61+
first_status = combined_status[:statuses].find { |status| status[:state] == state }
62+
first_status && first_status[:target_url]
63+
end
64+
65+
def complete_count
66+
combined_status[:statuses].count { |status| status[:state] != "pending"}
67+
end
68+
69+
def total_count
70+
combined_status[:statuses].count
71+
end
72+
73+
def current_status
74+
if total_count > 0
75+
"Completed #{complete_count}/#{total_count} checks, see #{first_status_url} ..."
76+
else
77+
"Build not started..."
78+
end
79+
end
80+
end
81+
82+
83+
$stdout.sync = true
84+
85+
puts "Checking build status..."
86+
attempts = 0
87+
checks = GithubStatusChecks.new
88+
89+
begin
90+
loop do
91+
case checks.state
92+
when "success"
93+
puts "Checks passed, see #{checks.first_status_url}"
94+
exit 0
95+
when "failure"
96+
exit_with_error "Checks failed, see #{checks.first_status_url}"
97+
when "pending"
98+
attempts += 1
99+
end
100+
101+
exit_with_error "Checks are still pending, gave up after #{MAX_ATTEMPTS * ATTEMPTS_GAP} seconds" if attempts == MAX_ATTEMPTS
102+
103+
puts checks.current_status
104+
sleep(ATTEMPTS_GAP)
105+
checks.refresh!
106+
end
107+
rescue Octokit::NotFound
108+
exit_with_error "Build status could not be found"
109+
end
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
#!/bin/sh
2+
3+
echo "Rebooting Traefik on $KAMAL_HOSTS..."

Dockerfile

+18-12
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
# Make sure RUBY_VERSION matches the Ruby version in .ruby-version and Gemfile
44
ARG RUBY_VERSION=3.2.4
5-
FROM registry.docker.com/library/ruby:$RUBY_VERSION-alpine as base
5+
FROM registry.docker.com/library/ruby:$RUBY_VERSION-alpine AS base
66

77
# Rails app lives here
88
WORKDIR /rails
@@ -24,15 +24,17 @@ RUN yarn install --frozen-lockfile --modules-folder $NODE_PATH
2424
# Throw-away build stage to reduce size of final image
2525
FROM base AS build
2626

27-
RUN apk add --no-cache --virtual .build-deps build-base git postgresql-dev vips-dev tzdata pkgconfig
28-
RUN apk add --no-cache curl vips-dev postgresql-client tzdata
29-
RUN rm -rf /var/lib/apt/lists /var/cache/apt/archives
27+
WORKDIR /rails
28+
29+
RUN apk add --no-cache --virtual .build-deps build-base git postgresql-dev vips-dev tzdata pkgconfig && \
30+
apk add --no-cache curl vips-dev postgresql-client tzdata && \
31+
rm -rf /var/lib/apt/lists /var/cache/apt/archives
3032

3133
# Install application gems
3234
COPY Gemfile Gemfile.lock ./
33-
RUN bundle install
34-
RUN rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git
35-
RUN bundle exec bootsnap precompile --gemfile
35+
RUN bundle install && \
36+
rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git && \
37+
bundle exec bootsnap precompile --gemfile
3638

3739
# Copy application code
3840
COPY . .
@@ -41,32 +43,36 @@ COPY . .
4143
RUN bundle exec bootsnap precompile app/ lib/
4244

4345
# Precompiling assets for production without requiring secret RAILS_MASTER_KEY
44-
RUN ./bin/rails assets:precompile
46+
COPY --from=node /node_modules /node_modules
47+
RUN apk add --virtual .build-deps yarn
48+
RUN SECRET_KEY_BASE_DUMMY=1 ./bin/rails assets:precompile
4549

4650
# Final stage for app image
4751
FROM base
4852

53+
WORKDIR /rails
54+
4955
# Copy built artifacts: gems, application
5056
COPY --from=build /usr/local/bundle /usr/local/bundle
5157
COPY --from=build /rails /rails
5258

5359
# Install packages needed for deployment
54-
RUN apk add --no-cache --virtual .build-deps curl build-base postgresql-dev vips-dev tzdata yarn
55-
RUN rm -rf /var/lib/apt/lists /var/cache/apt/archives
60+
RUN apk add --no-cache --virtual .build-deps curl build-base postgresql-dev vips-dev tzdata yarn && \
61+
rm -rf /var/lib/apt/lists /var/cache/apt/archives
5662

5763
# Copy node build artifacts
5864
COPY --from=node /node_modules /node_modules
5965
RUN yarn global add nodemon sass postcss-cli --prefix /usr/local
6066

6167
# Run and own only the runtime files as a non-root user for security
62-
RUN adduser -D rails --shell /bin/bash
68+
RUN adduser -D rails --shell /bin/ash
6369
RUN mkdir -p /usr/local/bundle/ruby/3.2.0/cache
6470
RUN chown -R rails:rails db log storage tmp /usr/local/bundle/ruby/3.2.0/cache
6571
RUN chmod -R 777 /usr/local/bundle/ruby/3.2.0/cache
6672
USER rails:rails
6773

6874
# Entrypoint prepares the database.
69-
ENTRYPOINT ["/rails/bin/docker-entrypoint"]
75+
ENTRYPOINT ["./bin/docker-entrypoint"]
7076

7177
# Start the server by default, this can be overwritten at runtime
7278
EXPOSE 3000

0 commit comments

Comments
 (0)