fix(lxc106): deploy script merges config.json and updates itself (#13)
Lint / Shell (shellcheck) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 5s
Lint / No secrets in webhook configs (push) Successful in 4s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 8s
Lint / Python deps (pip-audit) (push) Successful in 1m2s
Lint / Secret scan (gitleaks) (push) Successful in 10s
Lint / Shell (shellcheck) (pull_request) Successful in 12s
Lint / JS (eslint) (pull_request) Successful in 12s
Lint / No secrets in webhook configs (pull_request) Successful in 8s
Lint / Landing page is rendered (matrix (pull_request) Successful in 8s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 1m15s
Lint / Secret scan (gitleaks) (pull_request) Successful in 12s
Lint / Shell (shellcheck) (push) Successful in 31s
Lint / JS (eslint) (push) Successful in 5s
Lint / No secrets in webhook configs (push) Successful in 4s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 8s
Lint / Python deps (pip-audit) (push) Successful in 1m2s
Lint / Secret scan (gitleaks) (push) Successful in 10s
Lint / Shell (shellcheck) (pull_request) Successful in 12s
Lint / JS (eslint) (pull_request) Successful in 12s
Lint / No secrets in webhook configs (pull_request) Successful in 8s
Lint / Landing page is rendered (matrix (pull_request) Successful in 8s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 1m15s
Lint / Secret scan (gitleaks) (pull_request) Successful in 12s
LXC 106's matrix-deploy hook has not fired since May: Gitea posts to 10.10.10.6:9000, which webhook.service binds to 127.0.0.1. The same hooks (same secret) are served by webhook-lotus on :9001; the Gitea hook is being re-pointed there. Before it starts firing again: - cinny/config.json is merged into the live file instead of copied over it. The live file carries gifApiKey (injected by lotus_deploy.sh), empty in git, which a copy would blank. Repo keys win except where the repo value is empty and the live one isn't. Backup goes to /root/config-backups; the live file is left untouched on error. - The script installs its own updates (deploy/lxc106-cinny.sh → /usr/local/bin/matrix-deploy.sh, after bash -n). Until now repo edits to it never reached the server. - A hooks.json change restarts webhook-lotus 15 s after the script exits, since that listener is the one running this script. - README: port 9001, the file list, and the history. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
9baafd4928
commit
8d47df711d
+53
-5
@@ -3,7 +3,8 @@
|
||||
# Handles: cinny/config.json, cinny/nginx.conf, cinny/upstream-check.sh,
|
||||
# cinny/lotus-build.sh, cinny/lotus_deploy.sh,
|
||||
# deploy/hooks-lxc106.json, systemd/cinny-upstream-check.cron
|
||||
# Triggered by: Gitea webhook on push to main
|
||||
# Triggered by: Gitea webhook on push to main → http://10.10.10.6:9001/hooks/matrix-deploy
|
||||
# (webhook-lotus; the :9000 listener is bound to 127.0.0.1 and unreachable).
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="/opt/matrix-config"
|
||||
@@ -27,9 +28,39 @@ else
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^cinny/config.json'; then
|
||||
echo "Deploying cinny config.json..."
|
||||
cp "$REPO_DIR/cinny/config.json" /var/www/html/config.json
|
||||
echo "✓ config.json deployed"
|
||||
echo "Deploying cinny config.json (merged: keeps server-only values)..."
|
||||
# The live file carries values injected on the server that are empty in git
|
||||
# (gifApiKey, set by lotus_deploy.sh from GIPHY_API_KEY). A plain copy would
|
||||
# blank them, so repo keys win except where the repo value is empty and the
|
||||
# live one isn't. Backup outside the web root; on any error the live file
|
||||
# is left untouched.
|
||||
mkdir -p /root/config-backups
|
||||
cp -p /var/www/html/config.json "/root/config-backups/config.json.$(date +%Y%m%d%H%M%S)" 2>/dev/null || true
|
||||
if python3 - "$REPO_DIR/cinny/config.json" /var/www/html/config.json <<'PY'
|
||||
import json, os, sys, tempfile
|
||||
repo_path, live_path = sys.argv[1], sys.argv[2]
|
||||
repo = json.load(open(repo_path))
|
||||
live = json.load(open(live_path)) if os.path.exists(live_path) else {}
|
||||
merged = dict(repo)
|
||||
kept = []
|
||||
for key, value in live.items():
|
||||
if key in repo and repo[key] in ("", None) and value not in ("", None):
|
||||
merged[key] = value
|
||||
kept.append(key)
|
||||
fd, tmp = tempfile.mkstemp(dir=os.path.dirname(live_path))
|
||||
with os.fdopen(fd, "w") as f:
|
||||
json.dump(merged, f, indent=2)
|
||||
f.write("\n")
|
||||
json.load(open(tmp))
|
||||
os.chmod(tmp, 0o644)
|
||||
os.replace(tmp, live_path)
|
||||
print("kept server values for: " + (", ".join(kept) or "none"))
|
||||
PY
|
||||
then
|
||||
echo "✓ config.json deployed"
|
||||
else
|
||||
echo "✗ config.json merge FAILED — live file left unchanged"
|
||||
fi
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^cinny/nginx.conf'; then
|
||||
@@ -80,7 +111,11 @@ if echo "$CHANGED" | grep -q '^deploy/hooks-lxc106.json'; then
|
||||
echo "Deploying hooks-lxc106.json..."
|
||||
cp "$REPO_DIR/deploy/hooks-lxc106.json" /etc/webhook/hooks.json
|
||||
systemctl restart webhook
|
||||
echo "✓ hooks.json deployed, webhook restarted"
|
||||
# webhook-lotus (:9001) serves the same hooks and is the one running THIS
|
||||
# script (Gitea posts matrix-deploy there), so restarting it now would kill
|
||||
# this deploy mid-run: restart it shortly after we exit instead.
|
||||
systemd-run --on-active=15s --unit="webhook-lotus-reload-$(date +%s)" systemctl restart webhook-lotus
|
||||
echo "✓ hooks.json deployed, webhook restarted (webhook-lotus in 15s)"
|
||||
fi
|
||||
|
||||
if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
|
||||
@@ -90,4 +125,17 @@ if echo "$CHANGED" | grep -q '^systemd/cinny-upstream-check.cron'; then
|
||||
echo "✓ cron deployed"
|
||||
fi
|
||||
|
||||
# Keep the installed copy of this script in step with the repo (the webhook
|
||||
# runs /usr/local/bin/matrix-deploy.sh, not the repo file). Checked with bash -n
|
||||
# first; takes effect from the next deploy.
|
||||
if echo "$CHANGED" | grep -q '^deploy/lxc106-cinny.sh'; then
|
||||
if bash -n "$REPO_DIR/deploy/lxc106-cinny.sh"; then
|
||||
cp "$REPO_DIR/deploy/lxc106-cinny.sh" /usr/local/bin/matrix-deploy.sh
|
||||
chmod +x /usr/local/bin/matrix-deploy.sh
|
||||
echo "✓ matrix-deploy.sh updated"
|
||||
else
|
||||
echo "✗ bash -n FAILED on lxc106-cinny.sh — keeping the installed copy"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo "=== $(date) === LXC106 deploy complete ==="
|
||||
|
||||
Reference in New Issue
Block a user