All checks were successful
CI - Build and Push / Build and Push Docker Image (push) Successful in 50s
216 lines
7.7 KiB
Bash
216 lines
7.7 KiB
Bash
#!/bin/bash
|
|
|
|
# Continuous Deployment Script for Kubernetes
|
|
# This script deploys your application to a Kubernetes cluster
|
|
|
|
# =============================================================================
|
|
# Environment Variables (with default values)
|
|
# =============================================================================
|
|
|
|
# Kubernetes Configuration
|
|
KUBECONFIG_DATA="${KUBECONFIG_DATA:-}"
|
|
KUBERNETES_URL="${KUBERNETES_URL:-https://kubernetes.default.svc}"
|
|
KUBERNETES_NAMESPACE="${KUBERNETES_NAMESPACE:-default}"
|
|
KUBERNETES_INGRESS_HOST="${KUBERNETES_INGRESS_HOST:-auth-api.example.com}"
|
|
KUBERNETES_DEPLOYMENT_REPLICAS="${KUBERNETES_DEPLOYMENT_REPLICAS:-2}"
|
|
|
|
# Container Registry
|
|
CONTAINER_REGISTRY_URL="${CONTAINER_REGISTRY_URL:-127.0.0.1}"
|
|
CONTAINER_REGISTRY_USERNAME="${CONTAINER_REGISTRY_USERNAME:-username}"
|
|
CONTAINER_REGISTRY_NAMESPACE="${CONTAINER_REGISTRY_NAMESPACE:-username}"
|
|
CONTAINER_REGISTRY_PASSWORD="${CONTAINER_REGISTRY_PASSWORD:-password}"
|
|
CONTAINER_IMAGE_NAME="${CONTAINER_IMAGE_NAME:-authenticator}"
|
|
CONTAINER_IMAGE_TAG="${CONTAINER_IMAGE_TAG:-latest}"
|
|
|
|
# Application Configuration
|
|
DATABASE_DSN="${DATABASE_DSN:-postgres://postgres:password@localhost:5432/steam_union?sslmode=disable}"
|
|
JWT_SECRET="${JWT_SECRET:-your-secret-key-change-in-production}"
|
|
JWT_ISSUER="${JWT_ISSUER:-cialloo-authenticator}"
|
|
JWT_EXPIRES_IN="${JWT_EXPIRES_IN:-604800}"
|
|
STEAM_CALLBACK_URL="${STEAM_CALLBACK_URL:-https://www.cialloo.com/api/authenticator/steam/callback}"
|
|
STEAM_FRONTEND_CALLBACK_URL="${STEAM_FRONTEND_CALLBACK_URL:-https://www.cialloo.com/auth/callback}"
|
|
REDIS_HOST="${REDIS_HOST:-redis.production.svc.cluster.local:6379}"
|
|
REDIS_TYPE="${REDIS_TYPE:-node}"
|
|
REDIS_PASS="${REDIS_PASS:-}"
|
|
FORCE_RESTART="${FORCE_RESTART:-true}"
|
|
|
|
# =============================================================================
|
|
# Functions
|
|
# =============================================================================
|
|
|
|
# Print help message
|
|
print_help() {
|
|
echo "Usage: $0 [OPTIONS]"
|
|
echo ""
|
|
echo "Environment Variables:"
|
|
echo " KUBECONFIG_DATA Kubernetes config data (base64 encoded)"
|
|
echo " KUBERNETES_URL Kubernetes API URL (default: https://kubernetes.default.svc)"
|
|
echo " KUBERNETES_NAMESPACE Kubernetes namespace (default: default)"
|
|
echo " KUBERNETES_INGRESS_HOST Ingress host (default: auth-api.example.com)"
|
|
echo " KUBERNETES_DEPLOYMENT_REPLICAS Number of pod replicas (default: 2)"
|
|
echo " CONTAINER_REGISTRY_URL Container registry URL (default: 127.0.0.1)"
|
|
echo " CONTAINER_REGISTRY_USERNAME Registry username"
|
|
echo " CONTAINER_REGISTRY_PASSWORD Registry password"
|
|
echo " CONTAINER_IMAGE_NAME Image name (default: authenticator)"
|
|
echo " CONTAINER_IMAGE_TAG Image tag (default: latest)"
|
|
echo " DATABASE_DSN Database connection string"
|
|
echo " JWT_SECRET JWT secret key"
|
|
echo " JWT_ISSUER JWT issuer"
|
|
echo " JWT_EXPIRES_IN JWT expiration time in seconds"
|
|
echo " STEAM_CALLBACK_URL Steam OAuth callback URL"
|
|
echo " STEAM_FRONTEND_CALLBACK_URL Frontend callback URL after auth"
|
|
echo " REDIS_HOST Redis host and port"
|
|
echo " REDIS_TYPE Redis type (node/cluster)"
|
|
echo " REDIS_PASS Redis password"
|
|
echo " FORCE_RESTART Force rollout restart (default: true)"
|
|
echo ""
|
|
echo "Commands:"
|
|
echo " deploy Deploy application to Kubernetes"
|
|
echo " help Show this help message (default)"
|
|
}
|
|
|
|
# Setup kubectl configuration
|
|
setup_kubectl() {
|
|
echo "Setting up kubectl configuration..."
|
|
|
|
if [ -z "${KUBECONFIG_DATA}" ]; then
|
|
echo "✗ KUBECONFIG_DATA is not set"
|
|
return 1
|
|
fi
|
|
|
|
mkdir -p ~/.kube
|
|
echo "${KUBECONFIG_DATA}" | base64 -d > ~/.kube/config
|
|
chmod 600 ~/.kube/config
|
|
|
|
echo "✓ kubectl configured"
|
|
return 0
|
|
}
|
|
|
|
# Create namespace if it doesn't exist
|
|
create_namespace() {
|
|
echo "Checking namespace: ${KUBERNETES_NAMESPACE}"
|
|
|
|
kubectl get namespace "${KUBERNETES_NAMESPACE}" &> /dev/null
|
|
|
|
if [ $? -ne 0 ]; then
|
|
echo "Creating namespace: ${KUBERNETES_NAMESPACE}"
|
|
kubectl create namespace "${KUBERNETES_NAMESPACE}"
|
|
else
|
|
echo "✓ Namespace exists: ${KUBERNETES_NAMESPACE}"
|
|
fi
|
|
}
|
|
|
|
# Create image pull secret
|
|
create_image_pull_secret() {
|
|
echo "Creating image pull secret..."
|
|
|
|
kubectl create secret docker-registry regcred \
|
|
--docker-server="${CONTAINER_REGISTRY_URL}" \
|
|
--docker-username="${CONTAINER_REGISTRY_USERNAME}" \
|
|
--docker-password="${CONTAINER_REGISTRY_PASSWORD}" \
|
|
--namespace="${KUBERNETES_NAMESPACE}" \
|
|
--dry-run=client -o yaml | kubectl apply -f -
|
|
|
|
echo "✓ Image pull secret created/updated"
|
|
}
|
|
|
|
# Create or update application secrets
|
|
create_app_secrets() {
|
|
echo "Creating application secrets..."
|
|
|
|
kubectl create secret generic authenticator-secrets \
|
|
--from-literal=database-dsn="${DATABASE_DSN}" \
|
|
--from-literal=jwt-secret="${JWT_SECRET}" \
|
|
--from-literal=redis-pass="${REDIS_PASS}" \
|
|
--namespace="${KUBERNETES_NAMESPACE}" \
|
|
--dry-run=client -o yaml | kubectl apply -f -
|
|
|
|
echo "✓ Application secrets created/updated"
|
|
}
|
|
|
|
# Deploy to Kubernetes
|
|
deploy_to_kubernetes() {
|
|
FULL_IMAGE_NAME="${CONTAINER_REGISTRY_URL}/${CONTAINER_REGISTRY_NAMESPACE}/${CONTAINER_IMAGE_NAME}:${CONTAINER_IMAGE_TAG}"
|
|
|
|
echo "=========================================="
|
|
echo "Deploying to Kubernetes"
|
|
echo "=========================================="
|
|
echo "Namespace: ${KUBERNETES_NAMESPACE}"
|
|
echo "Image: ${FULL_IMAGE_NAME}"
|
|
echo "Host: ${KUBERNETES_INGRESS_HOST}"
|
|
echo "Database DSN: ${DATABASE_DSN}"
|
|
echo ""
|
|
|
|
# Setup kubectl
|
|
setup_kubectl || return 1
|
|
|
|
# Create namespace
|
|
create_namespace || return 1
|
|
|
|
# Create image pull secret
|
|
create_image_pull_secret || return 1
|
|
|
|
# Create application secrets
|
|
create_app_secrets || return 1
|
|
|
|
# Apply Kubernetes manifests with variable substitution
|
|
echo "Applying Kubernetes manifests..."
|
|
|
|
export FULL_IMAGE_NAME
|
|
export KUBERNETES_NAMESPACE
|
|
export KUBERNETES_INGRESS_HOST
|
|
export KUBERNETES_DEPLOYMENT_REPLICAS
|
|
export CONTAINER_IMAGE_NAME
|
|
export CONTAINER_REGISTRY_URL
|
|
export CONTAINER_REGISTRY_NAMESPACE
|
|
export CONTAINER_IMAGE_TAG
|
|
export DATABASE_DSN
|
|
export JWT_ISSUER
|
|
export JWT_EXPIRES_IN
|
|
export STEAM_CALLBACK_URL
|
|
export STEAM_FRONTEND_CALLBACK_URL
|
|
export REDIS_HOST
|
|
export REDIS_TYPE
|
|
|
|
for file in script/k8s/*.yaml; do
|
|
echo "Applying: $(basename $file)"
|
|
envsubst < "$file" | kubectl apply -f -
|
|
done
|
|
|
|
echo ""
|
|
echo "✓ Deployment complete"
|
|
echo ""
|
|
echo "Waiting for rollout..."
|
|
|
|
# Force restart if enabled
|
|
if [ "${FORCE_RESTART}" = "true" ]; then
|
|
echo "Forcing rollout restart..."
|
|
kubectl rollout restart deployment/${CONTAINER_IMAGE_NAME} -n ${KUBERNETES_NAMESPACE}
|
|
fi
|
|
|
|
kubectl rollout status deployment/${CONTAINER_IMAGE_NAME} -n ${KUBERNETES_NAMESPACE} --timeout=300s
|
|
|
|
if [ $? -eq 0 ]; then
|
|
echo ""
|
|
echo "✓ Application is ready"
|
|
echo "URL: http://${KUBERNETES_INGRESS_HOST}"
|
|
return 0
|
|
else
|
|
echo ""
|
|
echo "✗ Rollout failed or timed out"
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
# =============================================================================
|
|
# Main Script
|
|
# =============================================================================
|
|
|
|
case "${1:-help}" in
|
|
deploy)
|
|
deploy_to_kubernetes
|
|
;;
|
|
help|*)
|
|
print_help
|
|
;;
|
|
esac |