mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
Motivation: Release images should be built, checked, published, and consumed through the same Nostr-native OCI path operators will use, without relying on an unreviewed local release procedure. Approach: Add a checked-in container manifest, a Docker-to-OCI layout helper, automatic tag publication and pull verification, a safe exact-tag backfill workflow, and deployment CI that imports and runs the exact generated layout. Correctness: Release tags come only from reviewed OCI index annotations; ordinary publication preserves prior tags; historical backfills cannot move latest or prerelease channels; generated images and temporary resources use bounded, validated names and cleanup. Excluded scope: This change does not alter ngit-grasp runtime behavior, change package versions, create v3.0.2, publish a container, move a release tag, or run the heavyweight container build in the coding VM. Validation: git diff --check; shellcheck on all container scripts; actionlint on all affected workflows; ngit parsing of .ngit/containers.yaml; canonical source and v3.0.1 tag resolution. The PR pipeline performs the full OCI build, import, and deployment test. Assisted-by: Codex (GPT-5)
100 lines
2.7 KiB
Bash
Executable File
100 lines
2.7 KiB
Bash
Executable File
#!/bin/sh
|
|
set -eu
|
|
|
|
container_engine=${CONTAINER_ENGINE:-docker}
|
|
test_suffix=$$
|
|
container_name=ngit-grasp-deployment-test-${test_suffix}
|
|
volume_name=ngit-grasp-deployment-test-${test_suffix}
|
|
if [ -n "${NGIT_TEST_IMAGE:-}" ]; then
|
|
image_name=${NGIT_TEST_IMAGE}
|
|
build_test_image=false
|
|
remove_test_image=false
|
|
else
|
|
image_name=ngit-grasp:deployment-test-${test_suffix}
|
|
build_test_image=true
|
|
remove_test_image=true
|
|
fi
|
|
|
|
case "${container_name}" in
|
|
ngit-grasp-deployment-test-[0-9]*) ;;
|
|
*)
|
|
echo "refusing to use unexpected test resource name" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
|
|
if ! command -v "${container_engine}" >/dev/null 2>&1; then
|
|
echo "missing container engine: ${container_engine}" >&2
|
|
exit 2
|
|
fi
|
|
for required_command in curl jq; do
|
|
if ! command -v "${required_command}" >/dev/null 2>&1; then
|
|
echo "missing required command: ${required_command}" >&2
|
|
exit 2
|
|
fi
|
|
done
|
|
|
|
cleanup() {
|
|
"${container_engine}" rm --force "${container_name}" >/dev/null 2>&1 || true
|
|
"${container_engine}" volume rm "${volume_name}" >/dev/null 2>&1 || true
|
|
if [ "${remove_test_image}" = true ]; then
|
|
"${container_engine}" image rm "${image_name}" >/dev/null 2>&1 || true
|
|
fi
|
|
}
|
|
trap cleanup EXIT HUP INT TERM
|
|
|
|
start_container() {
|
|
"${container_engine}" run \
|
|
--detach \
|
|
--name "${container_name}" \
|
|
--publish 127.0.0.1::7334 \
|
|
--volume "${volume_name}:/data" \
|
|
--env NGIT_DOMAIN=localhost \
|
|
"${image_name}" >/dev/null
|
|
}
|
|
|
|
relay_url() {
|
|
published_port=$("${container_engine}" port "${container_name}" 7334/tcp)
|
|
published_port=${published_port##*:}
|
|
printf 'http://127.0.0.1:%s' "${published_port}"
|
|
}
|
|
|
|
relay_pubkey() {
|
|
curl \
|
|
--fail \
|
|
--silent \
|
|
--show-error \
|
|
--connect-timeout 5 \
|
|
--max-time 15 \
|
|
--retry 30 \
|
|
--retry-all-errors \
|
|
--retry-max-time 180 \
|
|
--header 'Accept: application/nostr+json' \
|
|
"$1" | jq -er '.pubkey'
|
|
}
|
|
|
|
if [ "${build_test_image}" = true ]; then
|
|
"${container_engine}" build --tag "${image_name}" .
|
|
fi
|
|
"${container_engine}" volume create "${volume_name}" >/dev/null
|
|
|
|
start_container
|
|
first_url=$(relay_url)
|
|
first_pubkey=$(relay_pubkey "${first_url}")
|
|
"${container_engine}" exec "${container_name}" \
|
|
test -s /data/.relay-owner.nsec
|
|
|
|
"${container_engine}" stop --time 300 "${container_name}" >/dev/null
|
|
"${container_engine}" rm "${container_name}" >/dev/null
|
|
|
|
start_container
|
|
second_url=$(relay_url)
|
|
second_pubkey=$(relay_pubkey "${second_url}")
|
|
|
|
if [ "${first_pubkey}" != "${second_pubkey}" ]; then
|
|
echo "relay identity changed after container replacement" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "container deployment verified; relay identity persisted"
|