aboutsummaryrefslogtreecommitdiff
path: root/scripts/ci/deploy.sh
blob: 9be575811e0e5e6641c4d2e52de2175e4f9832c7 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
#!/usr/bin/env nix-shell
#!nix-shell -i bash ../../shell.nix
# shellcheck shell=bash
set -Eeuo pipefail
cd "$(dirname "${BASH_SOURCE[0]}")"
cd ../../
PROJECT_ROOT="${PWD}"

finish-phase() {
  local -r exit_code="${?}"

  cd "${PROJECT_ROOT}"

  if [[ "${exit_code}" = 0 ]]; then
    echo "Finished successfully."
  else
    echo "TRAPPED ERROR!"
  fi
  echo "Running final steps..."

  echo "Sending logs via email..."
  ./scripts/ci/mail.sh "${exit_code}"
  echo "Done."

  echo "Storing file changes to '.tfstate' files..."
  pushd ../vps-state/
  git add .
  git commit -m "CI: fallback add all after deploy.sh failure for CI run $VPS_COMMIT_SHA" ||:
  git push origin master
  popd
  echo "Done."

  echo "Locking git-crypt repositories back..."
  git crypt lock
  pushd ../vps-state/
  git crypt lock
  popd
  echo "Done."

  echo "Finished cleanup."
}
trap finish-phase EXIT

create-known-hosts-file() {
  echo "${TLD},$(terraform output public_floating_ip) ssh-rsa $(awk '{print $2}' < ./secrets/ssh/vps-box-server.pub)" > ./generated/generated-known-hosts.txt
}

echo "Interpolating files with envsubst..."
envsubst < ./ssh.env.conf >> ~/.ssh/config
envsubst < ./hosts.env                         > ./generated/hosts
envsubst < ./docker-compose.env.yaml           > ./generated/docker-compose.yaml
envsubst < ./provision.env.yaml                > ./generated/provision.yaml
envsubst < ./scripts/box/user-data.env.sh      > ./generated/user-data.sh
envsubst < ./scripts/box/create-backup.env.sh  > ./generated/create-backup.sh
envsubst < ./scripts/box/restore-backup.env.sh > ./generated/restore-backup.sh
echo "Done."

echo "Running the Ansible shutdown.yaml playbook..."
create-known-hosts-file
ansible-playbook -v shutdown.yaml > ./logs/ansible-shutdown.txt
echo "Done."

echo "Initializing Terraform..."
terraform --version
terraform init
echo "Done."

if [[ "${DESTROY_VPS:-}" != "" ]]; then
  echo "Destroying existing infrastructure..."
  terraform destroy -input=false -auto-approve > ./logs/terraform-destroy.txt 2>&1
else
  echo 'Refreshing view on existing infrastructure...'
  terraform refresh > ./logs/terraform-refresh.txt 2>&1
fi
echo "Done."

echo "Running 'terraform plan' and storing the planfile..."
mkdir -p "../vps-state/secrets/plan-files/"
PLAN_FILE_NAME="$(date -Iseconds)-${VPS_COMMIT_SHA}.tfplan"
PLAN_FILE_PATH="../vps-state/secrets/plan-files/${PLAN_FILE_NAME}"
terraform plan -input=false -out="${PLAN_FILE_PATH}" > ./logs/terraform-plan.txt 2>&1
pushd ../vps-state/
git add "secrets/plan-files/${PLAN_FILE_NAME}"
git commit -m "CI: add .tfplan plan file for CI run ${VPS_COMMIT_SHA}"
git push origin master
popd
echo "Done."

echo "Running 'terraform apply'..."
terraform apply -input=false -auto-approve "${PLAN_FILE_PATH}" > ./logs/terraform-apply.txt 2>&1
echo "Done."

echo "Storing .tfstate file..."
pushd ../vps-state/
git add secrets/terraform.tfstate secrets/terraform.tfstate.backup
git commit -m "CI: update Terraform .tfstate files for CI run ${VPS_COMMIT_SHA}" --allow-empty
git push origin master
popd
echo "Done."

echo "Running the Ansible provision.yaml playbook..."
create-known-hosts-file
cp ./generated/provision.yaml ./provision.yaml
ansible-playbook -v provision.yaml > ./logs/ansible-provision.txt
echo "Done."