Keep legacy load profiles upgradeable

This commit is contained in:
SimpleTest 2026-07-22 07:14:19 +03:00
parent c634c136c9
commit 3d320ce182
2 changed files with 72 additions and 10 deletions

View File

@ -2,8 +2,8 @@
set -eu set -eu
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
TEMPLATE="$ROOT/.env.load.example" TEMPLATE=${WNH_LOAD_ENV_TEMPLATE:-"$ROOT/.env.load.example"}
ENV_FILE="$ROOT/.env.load" ENV_FILE=${WNH_LOAD_ENV_FILE:-"$ROOT/.env.load"}
for command in openssl perl; do for command in openssl perl; do
if ! command -v "$command" >/dev/null 2>&1; then if ! command -v "$command" >/dev/null 2>&1; then
@ -12,9 +12,46 @@ for command in openssl perl; do
fi fi
done done
if [ ! -f "$TEMPLATE" ]; then
echo "Missing tracked template: $TEMPLATE" >&2
exit 1
fi
if [ -f "$ENV_FILE" ]; then if [ -f "$ENV_FILE" ]; then
chmod 600 "$ENV_FILE" chmod 600 "$ENV_FILE"
template_upgrade_keys='
DEPLOYMENT_TARGET
DEPLOYMENT_ENV
COMPOSE_PROJECT_NAME
APP_IMAGE
SOCKET_PROXY_IMAGE
POSTGIS_IMAGE
DATABASE_MODE
APP_TOPOLOGY
WEB_REPLICAS
WORKER_REPLICAS
COMBINED_POOL_SIZE
GITHUB_OAUTH_BASE_URL
GITHUB_OAUTH_AUTHORIZE_URL
GITHUB_OAUTH_TOKEN_URL
GITHUB_OAUTH_USER_URL
GITHUB_OAUTH_HTTP_CONNECT_TIMEOUT_MS
GITHUB_OAUTH_HTTP_RECEIVE_TIMEOUT_MS
GOOGLE_OAUTH_CLIENT_ID
GOOGLE_OAUTH_CLIENT_SECRET
GOOGLE_OAUTH_BASE_URL
GOOGLE_OAUTH_HTTP_CONNECT_TIMEOUT_MS
GOOGLE_OAUTH_HTTP_RECEIVE_TIMEOUT_MS
'
missing_template_keys=
for key in $template_upgrade_keys; do
if ! grep -q "^${key}=" "$ENV_FILE"; then
missing_template_keys="$missing_template_keys $key"
fi
done
needs_fixture_password=true needs_fixture_password=true
needs_oban_maintenance_concurrency=true needs_oban_maintenance_concurrency=true
needs_oban_push_concurrency=true needs_oban_push_concurrency=true
@ -90,7 +127,8 @@ if [ -f "$ENV_FILE" ]; then
grep -q '^BACKUP_INTERRUPTION_INTERVAL_SECONDS=' "$ENV_FILE" && grep -q '^BACKUP_INTERRUPTION_INTERVAL_SECONDS=' "$ENV_FILE" &&
needs_backup_interruption_interval=false needs_backup_interruption_interval=false
if [ "$needs_fixture_password" = false ] && if [ -z "$missing_template_keys" ] &&
[ "$needs_fixture_password" = false ] &&
[ "$needs_oban_maintenance_concurrency" = false ] && [ "$needs_oban_maintenance_concurrency" = false ] &&
[ "$needs_oban_push_concurrency" = false ] && [ "$needs_oban_push_concurrency" = false ] &&
[ "$needs_resilience_timeout" = false ] && [ "$needs_resilience_timeout" = false ] &&
@ -147,6 +185,14 @@ if [ -f "$ENV_FILE" ]; then
fi fi
{ {
if [ -n "$missing_template_keys" ]; then
printf '\n# Added from the tracked load-profile deployment defaults.\n'
for key in $missing_template_keys; do
grep "^${key}=" "$TEMPLATE" | head -n 1
done
fi
if [ "$needs_fixture_password" = true ]; then if [ "$needs_fixture_password" = true ]; then
printf '\n# Added by the authenticated-load profile upgrade.\n' printf '\n# Added by the authenticated-load profile upgrade.\n'
printf 'LOAD_AUTH_VUS=8\n' printf 'LOAD_AUTH_VUS=8\n'
@ -301,16 +347,11 @@ if [ -f "$ENV_FILE" ]; then
needs_backup_minio_root_password needs_backup_restic_password \ needs_backup_minio_root_password needs_backup_restic_password \
needs_backup_bucket_prefix needs_backup_timeout \ needs_backup_bucket_prefix needs_backup_timeout \
needs_backup_interruption_chunks needs_backup_interruption_chunk_bytes \ needs_backup_interruption_chunks needs_backup_interruption_chunk_bytes \
needs_backup_interruption_interval needs_backup_interruption_interval missing_template_keys template_upgrade_keys
echo "Added missing queue/load/resilience/observability/backup inputs to ignored .env.load." echo "Added missing deployment/queue/load/resilience/observability/backup inputs to ignored .env.load."
exit 0 exit 0
fi fi
if [ ! -f "$TEMPLATE" ]; then
echo "Missing tracked template: $TEMPLATE" >&2
exit 1
fi
umask 077 umask 077
postgres_password=$(openssl rand -hex 32) postgres_password=$(openssl rand -hex 32)
secret_key_base=$(openssl rand -hex 64) secret_key_base=$(openssl rand -hex 64)

View File

@ -91,6 +91,27 @@ grep -Fx '/.runner' .dockerignore >/dev/null
grep -Fx '/act_runner' .dockerignore >/dev/null grep -Fx '/act_runner' .dockerignore >/dev/null
grep -Fx '/act_runner-data/' .dockerignore >/dev/null grep -Fx '/act_runner-data/' .dockerignore >/dev/null
echo "Checking the existing load environment upgrade path"
legacy_load_env="$scan_dir/legacy-load.env"
printf '%s\n' \
'LOAD_PROJECT=who_need_help_load' \
'LOAD_WEB_REPLICAS=3' \
'SECRET_KEY_BASE=preserve-existing-secret' >"$legacy_load_env"
chmod 600 "$legacy_load_env"
WNH_LOAD_ENV_FILE="$legacy_load_env" \
./scripts/ensure-local-load-env.sh >/dev/null
test "$(stat -c '%a' "$legacy_load_env")" = 600
grep -Fx 'APP_IMAGE=who-need-help:load' "$legacy_load_env" >/dev/null
grep -Fx 'POSTGIS_IMAGE=who-need-help:postgis-load' "$legacy_load_env" >/dev/null
grep -Fx 'SOCKET_PROXY_IMAGE=who-need-help:socket-proxy-load' "$legacy_load_env" >/dev/null
grep -Fx 'APP_TOPOLOGY=split' "$legacy_load_env" >/dev/null
grep -Fx 'LOAD_WEB_REPLICAS=3' "$legacy_load_env" >/dev/null
test "$(grep -Fc 'SECRET_KEY_BASE=preserve-existing-secret' "$legacy_load_env")" = 1
legacy_load_hash=$(sha256sum "$legacy_load_env" | awk '{print $1}')
WNH_LOAD_ENV_FILE="$legacy_load_env" \
./scripts/ensure-local-load-env.sh >/dev/null
test "$(sha256sum "$legacy_load_env" | awk '{print $1}')" = "$legacy_load_hash"
echo "Checking independent test and production environment initialization" echo "Checking independent test and production environment initialization"
test_env="$scan_dir/test.env" test_env="$scan_dir/test.env"
if ./scripts/init-test-env.sh test.help.test \ if ./scripts/init-test-env.sh test.help.test \