who_need_help/scripts/prepare-play-review.sh

101 lines
2.9 KiB
Bash
Executable File

#!/bin/sh
set -eu
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
EXPECTED_ROOT=/srv/who_need_help-production
EXPECTED_PROJECT=who_need_help_production
EXPECTED_ORIGIN=https://whoneedhelp.com
if [ "$#" -ne 5 ] || [ "$3" != "--confirm" ] || [ "$4" != "whoneedhelp.com" ]; then
echo "Usage: $0 REVIEWER_EMAIL COUNTERPART_EMAIL --confirm whoneedhelp.com ENV_FILE" >&2
echo "Both existing accounts must be active, confirmed, password-enabled, and non-staff." >&2
exit 1
fi
REVIEWER_EMAIL=$1
COUNTERPART_EMAIL=$2
ENV_FILE=$5
if [ "$(realpath --canonicalize-existing "$ROOT")" != "$EXPECTED_ROOT" ]; then
echo "Play review fixtures must run from $EXPECTED_ROOT." >&2
exit 1
fi
if [ ! -f "$ENV_FILE" ]; then
echo "Environment file does not exist: $ENV_FILE" >&2
exit 1
fi
read_env() {
key=$1
awk -F= -v key="$key" '
$1 == key {
value = substr($0, index($0, "=") + 1)
sub(/\r$/, "", value)
if ((value ~ /^".*"$/) || (value ~ /^\047.*\047$/)) {
value = substr(value, 2, length(value) - 2)
}
count++
}
END {
if (count == 1) print value
else exit 1
}
' "$ENV_FILE"
}
if [ "$(read_env DEPLOYMENT_ENV)" != production ]; then
echo "Play review fixtures may only target DEPLOYMENT_ENV=production." >&2
exit 1
fi
project=$(read_env COMPOSE_PROJECT_NAME)
if [ "$project" != "$EXPECTED_PROJECT" ]; then
echo "Unexpected production Compose project: $project" >&2
exit 1
fi
if [ "$(read_env WNH_BASE_URL)" != "$EXPECTED_ORIGIN" ]; then
echo "Production origin must be $EXPECTED_ORIGIN." >&2
exit 1
fi
container=$("$ROOT/scripts/compose.sh" "$ENV_FILE" ps -q app | head -n 1)
if [ -z "$container" ]; then
container=$("$ROOT/scripts/compose.sh" "$ENV_FILE" ps -q web | head -n 1)
fi
if [ -z "$container" ]; then
echo "No running production app or web container was found for project $project." >&2
exit 1
fi
expected_image=$(read_env APP_IMAGE)
observed_image=$(docker inspect --format '{{.Config.Image}}' "$container")
container_state=$(docker inspect --format '{{.State.Status}}' "$container")
container_health=$(docker inspect --format '{{if .State.Health}}{{.State.Health.Status}}{{else}}none{{end}}' "$container")
if [ "$observed_image" != "$expected_image" ]; then
echo "Running container image does not match APP_IMAGE." >&2
exit 1
fi
if [ "$container_state" != running ] || [ "$container_health" != healthy ]; then
echo "Production application container is not running and healthy." >&2
exit 1
fi
encode() {
printf %s "$1" | base64 | tr -d '\n'
}
reviewer=$(encode "$REVIEWER_EMAIL")
counterpart=$(encode "$COUNTERPART_EMAIL")
expression="case WhoNeedHelp.Release.prepare_play_review(Base.decode64!(\"$reviewer\"), Base.decode64!(\"$counterpart\")) do {:ok, result} -> IO.inspect(result); {:error, reason} -> raise \"Play review preparation failed: #{inspect(reason)}\" end"
docker exec "$container" /app/bin/who_need_help rpc "$expression"