4fb3fe3fee
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
50 lines
2.3 KiB
Bash
50 lines
2.3 KiB
Bash
#!/usr/bin/env bash
|
|
# deploy-server.sh <tag> — deploy the pangolin control-plane binaries
|
|
# (pangolin-server / pangolin-agent / pangolin-migrate) to pangolin1, in the
|
|
# exact manual sequence used for F3/F4: stop → wal checkpoint → backup db →
|
|
# migrate (rollback db + restart old binary on failure) → swap binaries →
|
|
# start → healthcheck. Assumes compile-backend.sh has already produced
|
|
# server/out/{pangolin-server,pangolin-agent,pangolin-migrate}.
|
|
#
|
|
# Usage: scripts/ci/deploy-server.sh <tag> (e.g. server-v1.2.3)
|
|
# Requires env: DEPLOY_SSH_KEY (see lib-ssh.sh).
|
|
set -euo pipefail
|
|
|
|
# shellcheck source=scripts/ci/lib-ssh.sh
|
|
. scripts/ci/lib-ssh.sh
|
|
|
|
DB=/var/lib/pangolin/pangolin.db
|
|
BIN=/usr/local/bin
|
|
TAG="${1:?usage: deploy-server.sh <tag>}"
|
|
|
|
# setup_ssh registers the EXIT cleanup trap itself (before writing the key),
|
|
# so a mid-setup failure still cleans up — see lib-ssh.sh. It exports
|
|
# SSH_KEY_FILE / DEPLOY_PORT / SSH_KNOWN_HOSTS_FILE / DEPLOY_HOST used below
|
|
# to build SCP (mirroring the SSH/RSYNC_SSH command-string convention).
|
|
setup_ssh
|
|
SCP="scp -i ${SSH_KEY_FILE} -P ${DEPLOY_PORT} -o StrictHostKeyChecking=accept-new -o UserKnownHostsFile=${SSH_KNOWN_HOSTS_FILE}"
|
|
|
|
echo "==> deploy-server: tag=${TAG} host=${DEPLOY_HOST}"
|
|
echo "==> deploy-server: uploading binaries to ${DEPLOY_HOST}:/tmp/"
|
|
$SCP server/out/pangolin-server server/out/pangolin-agent server/out/pangolin-migrate "root@${DEPLOY_HOST}:/tmp/"
|
|
|
|
$SSH "root@${DEPLOY_HOST}" "bash -s" <<REMOTE
|
|
set -euo pipefail
|
|
systemctl stop pangolin-server
|
|
runuser -u pangolin -- sqlite3 "$DB" 'PRAGMA wal_checkpoint(TRUNCATE);'
|
|
cp -p "$DB" "$DB.bak-pre-$TAG"
|
|
if ! runuser -u pangolin -- env DB_DRIVER=sqlite DB_DSN=$DB /tmp/pangolin-migrate up; then
|
|
echo "!! migrate 失败,回滚"; cp -p "$DB.bak-pre-$TAG" "$DB"; systemctl start pangolin-server; exit 1
|
|
fi
|
|
cp -p "$BIN/pangolin-server" "$BIN/pangolin-server.bak-$TAG" || true
|
|
install -m755 /tmp/pangolin-server "$BIN/pangolin-server"
|
|
install -m755 /tmp/pangolin-agent "$BIN/pangolin-agent"
|
|
install -m755 /tmp/pangolin-migrate "$BIN/pangolin-migrate"
|
|
systemctl start pangolin-server
|
|
systemctl is-active pangolin-server
|
|
REMOTE
|
|
|
|
curl -fsS -m 10 --retry 5 --retry-connrefused "http://${DEPLOY_HOST}:8080/healthz" >/dev/null && echo "healthz OK"
|
|
|
|
echo "==> deploy-server: done"
|