feat(updater): script para instalação do updater
para clientes que não usam o tuio (como o Colorado)
This commit is contained in:
Executable
+76
@@ -0,0 +1,76 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Manual fallback for tenants where the tuio installer's "run updater" step can't be
|
||||||
|
# used. Creates/recreates app-dono-updater: a poll loop (docker:cli, no third-party
|
||||||
|
# updater) that pulls app-dono-cliente's :latest image every 5 minutes and recreates the
|
||||||
|
# container when the image changes. Mirrors tuio's RunUpdaterDockerContainer /
|
||||||
|
# appClienteRunArgs (internal/tui/docker.go) -- keep the two in sync if either changes.
|
||||||
|
#
|
||||||
|
# Run this ON the tenant host, with app-dono-cliente already running. All of its run
|
||||||
|
# args (port, uid:gid, mounts, network, seccomp) are read live from the running
|
||||||
|
# container -- both now and every time the updater recreates it -- so nothing needs
|
||||||
|
# hand-editing per tenant and nothing baked-in goes stale if the container is ever
|
||||||
|
# changed by hand later (e.g. a manually remapped host port survives an auto-update).
|
||||||
|
set -e
|
||||||
|
|
||||||
|
APP_IMAGE="hub.davinti.com.br:443/app-dono/app-cliente:latest"
|
||||||
|
APP_NAME="app-dono-cliente"
|
||||||
|
UPDATER_NAME="app-dono-updater"
|
||||||
|
UPDATER_IMAGE="docker:cli"
|
||||||
|
POLL_INTERVAL="${POLL_INTERVAL:-300}"
|
||||||
|
DOCKER_CONFIG_HOST="${DOCKER_CONFIG_HOST:-$HOME/.docker/config.json}"
|
||||||
|
|
||||||
|
if ! docker inspect "$APP_NAME" >/dev/null 2>&1; then
|
||||||
|
echo "error: $APP_NAME is not running here -- start it first" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ ! -f "$DOCKER_CONFIG_HOST" ]; then
|
||||||
|
echo "error: $DOCKER_CONFIG_HOST not found -- run 'docker login' for the registry first" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker rm -f "$UPDATER_NAME" >/dev/null 2>&1 || true
|
||||||
|
docker pull "$UPDATER_IMAGE" >/dev/null
|
||||||
|
|
||||||
|
# The container is inspected again inside the poll loop on every recreate (not just
|
||||||
|
# here), so this whole block runs live in the updater container, not just once now.
|
||||||
|
POLL_SCRIPT=$(cat <<SCRIPT
|
||||||
|
set -e
|
||||||
|
IMAGE='$APP_IMAGE'
|
||||||
|
NAME='$APP_NAME'
|
||||||
|
while true; do
|
||||||
|
docker pull "\$IMAGE" >/dev/null 2>&1 || true
|
||||||
|
CURRENT=\$(docker inspect --format '{{.Image}}' "\$NAME" 2>/dev/null || true)
|
||||||
|
LATEST=\$(docker inspect --format '{{.Id}}' "\$IMAGE" 2>/dev/null || true)
|
||||||
|
if [ -n "\$LATEST" ] && [ "\$CURRENT" != "\$LATEST" ]; then
|
||||||
|
PORT=\$(docker inspect --format '{{(index (index .NetworkSettings.Ports "8080/tcp") 0).HostPort}}' "\$NAME")
|
||||||
|
UIDGID=\$(docker inspect --format '{{.Config.User}}' "\$NAME")
|
||||||
|
NET=\$(docker inspect --format '{{range \$k, \$v := .NetworkSettings.Networks}}{{\$k}}{{end}}' "\$NAME")
|
||||||
|
CONFMNT=\$(docker inspect --format '{{range .Mounts}}{{if eq .Destination "/app/config.toml"}}{{.Source}}{{end}}{{end}}' "\$NAME")
|
||||||
|
CERTMNT=\$(docker inspect --format '{{range .Mounts}}{{if eq .Destination "/app/certs"}}{{.Source}}{{end}}{{end}}' "\$NAME")
|
||||||
|
SECFLAG=""
|
||||||
|
case \$(docker inspect --format '{{json .HostConfig.SecurityOpt}}' "\$NAME") in
|
||||||
|
*seccomp=unconfined*) SECFLAG="--security-opt seccomp=unconfined" ;;
|
||||||
|
esac
|
||||||
|
docker stop "\$NAME" >/dev/null 2>&1 || true
|
||||||
|
docker rm "\$NAME" >/dev/null 2>&1 || true
|
||||||
|
docker run -d -u "\$UIDGID" -p "\$PORT:8080" --name "\$NAME" --network "\$NET" --restart unless-stopped -v "\$CONFMNT:/app/config.toml" -v "\$CERTMNT:/app/certs" \$SECFLAG "\$IMAGE"
|
||||||
|
fi
|
||||||
|
sleep $POLL_INTERVAL
|
||||||
|
done
|
||||||
|
SCRIPT
|
||||||
|
)
|
||||||
|
|
||||||
|
docker run -d \
|
||||||
|
--name "$UPDATER_NAME" \
|
||||||
|
--restart unless-stopped \
|
||||||
|
-v /var/run/docker.sock:/var/run/docker.sock \
|
||||||
|
-v "$DOCKER_CONFIG_HOST:/config.json" \
|
||||||
|
-e DOCKER_CONFIG=/ \
|
||||||
|
--log-opt max-size=5m \
|
||||||
|
--log-opt max-file=1 \
|
||||||
|
--entrypoint sh \
|
||||||
|
"$UPDATER_IMAGE" \
|
||||||
|
-c "$POLL_SCRIPT"
|
||||||
|
|
||||||
|
echo "app-dono-updater created for $APP_NAME."
|
||||||
Reference in New Issue
Block a user