Publication atomique du catalogue par lien symbolique, droits du volume, repli sur le catalogue de l'image
build / Garde-fou (pull_request) Successful in 11s
build / Images Harbor (catalog-sync, Dockerfile.catalog-sync) (pull_request) Skipped
build / Images Harbor (web, Dockerfile) (pull_request) Skipped
build / Images Harbor (catalog-sync, Dockerfile.catalog-sync) (push) Successful in 9m49s
build / Garde-fou (push) Successful in 10s
build / Images Harbor (web, Dockerfile) (push) Successful in 11m25s

This commit is contained in:
hcornet committed 2026-09-10 13:39:42 +02:00
1 parent c51a6379bd
commit 5f76b08ae6
9 files changed
+126 -38

No files matched your search

+14
View File
@@ -0,0 +1,14 @@
#!/bin/sh
# Le volume partage appartient a root a sa creation. On l'ajuste en root, puis
# on abandonne les privileges avant de lancer la boucle de synchronisation.
set -eu
: "${CATALOG_DEST:=/catalogue}"
if [ "$(id -u)" = "0" ]; then
mkdir -p "$CATALOG_DEST"
chown enclume:enclume "$CATALOG_DEST"
exec su-exec enclume:enclume /usr/local/bin/catalog-sync "$@"
fi
exec /usr/local/bin/catalog-sync "$@"
+48 -20
View File
@@ -1,42 +1,70 @@
#!/bin/sh
# Clone ou met a jour le depot du catalogue, publie son contenu dans le volume
# partage, puis notifie l'application. Boucle jusqu'a l'arret du conteneur.
#
# La publication passe par un lien symbolique : on ne peut pas renommer le
# point de montage lui-meme, mais on peut faire basculer un lien a l'interieur,
# et cette bascule est atomique. L'application lit CATALOG_DEST/actuel.
set -eu
if [ -z "${CATALOG_REPO}" ]; then
echo "catalog-sync : CATALOG_REPO non defini, rien a synchroniser." >&2
exit 0
: "${CATALOG_DEST:=/catalogue}"
: "${CATALOG_BRANCH:=main}"
: "${CATALOG_SUBDIR:=catalog}"
: "${SYNC_INTERVAL:=300}"
: "${REVISIONS_CONSERVEES:=3}"
if [ -z "${CATALOG_REPO:-}" ]; then
echo "catalog-sync : CATALOG_REPO non defini. L'application utilisera le catalogue de son image."
# On reste en vie sans rien faire : le conteneur ne doit pas boucler en redemarrage.
while true; do sleep 3600; done
fi
TRAVAIL=/tmp/depot
sync_une_fois() {
if [ -d "$TRAVAIL/.git" ]; then
git -C "$TRAVAIL" fetch --quiet --depth 1 origin "$CATALOG_BRANCH"
git -C "$TRAVAIL" reset --quiet --hard "origin/$CATALOG_BRANCH"
git -C "$TRAVAIL" fetch --quiet --depth 1 origin "$CATALOG_BRANCH" || return 1
git -C "$TRAVAIL" reset --quiet --hard "origin/$CATALOG_BRANCH" || return 1
else
git clone --quiet --depth 1 --branch "$CATALOG_BRANCH" "$CATALOG_REPO" "$TRAVAIL"
rm -rf "$TRAVAIL"
git clone --quiet --depth 1 --branch "$CATALOG_BRANCH" "$CATALOG_REPO" "$TRAVAIL" || return 1
fi
SOURCE="$TRAVAIL/$CATALOG_SUBDIR"
[ -d "$SOURCE" ] || { echo "catalog-sync : $CATALOG_SUBDIR absent du depot." >&2; return 1; }
if [ ! -d "$SOURCE" ]; then
echo "catalog-sync : le repertoire $CATALOG_SUBDIR est absent du depot." >&2
return 1
fi
# Publication atomique : on ecrit a cote, puis on bascule.
NEUF="${CATALOG_DEST}.neuf"
rm -rf "$NEUF"
mkdir -p "$NEUF"
cp -a "$SOURCE"/. "$NEUF"/
rm -rf "${CATALOG_DEST}.ancien"
[ -d "$CATALOG_DEST" ] && mv "$CATALOG_DEST" "${CATALOG_DEST}.ancien"
mv "$NEUF" "$CATALOG_DEST"
rm -rf "${CATALOG_DEST}.ancien"
REVISION=$(git -C "$TRAVAIL" rev-parse --short HEAD) || return 1
CIBLE="$CATALOG_DEST/rev-$REVISION"
REVISION=$(git -C "$TRAVAIL" rev-parse --short HEAD)
echo "catalog-sync : catalogue a jour ($REVISION)"
curl -fsS -X POST "$RELOAD_URL" >/dev/null 2>&1 || echo "catalog-sync : rechargement non confirme"
if [ -L "$CATALOG_DEST/actuel" ] && [ "$(readlink "$CATALOG_DEST/actuel")" = "$CIBLE" ]; then
return 0 # deja publie, rien a faire
fi
rm -rf "$CIBLE.partiel" "$CIBLE"
mkdir -p "$CIBLE.partiel"
cp -a "$SOURCE"/. "$CIBLE.partiel"/ || return 1
mv "$CIBLE.partiel" "$CIBLE" || return 1
# Bascule atomique du lien, puis menage des anciennes revisions.
ln -sfn "$CIBLE" "$CATALOG_DEST/actuel.neuf"
mv -f "$CATALOG_DEST/actuel.neuf" "$CATALOG_DEST/actuel" || return 1
ls -1dt "$CATALOG_DEST"/rev-* 2>/dev/null | tail -n +$((REVISIONS_CONSERVEES + 1)) | while read -r vieux; do
rm -rf "$vieux"
done
echo "catalog-sync : catalogue publie ($REVISION)"
if [ -n "${RELOAD_URL:-}" ]; then
curl -fsS -X POST "$RELOAD_URL" >/dev/null 2>&1 || echo "catalog-sync : rechargement non confirme"
fi
}
while true; do
sync_une_fois || echo "catalog-sync : echec de la synchronisation, nouvelle tentative dans ${SYNC_INTERVAL}s" >&2
if ! sync_une_fois; then
echo "catalog-sync : echec de la synchronisation, nouvelle tentative dans ${SYNC_INTERVAL}s" >&2
fi
sleep "$SYNC_INTERVAL"
done