who_need_help/scripts/production-rollback.sh

71 lines
1.9 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
action=${1:-plan}
remote_manifest=${2:-}
ssh_target=${3:-whoneedhelp}
remote_root=${WNH_PRODUCTION_REMOTE_ROOT:-/srv/who_need_help-production}
expected_domain=${WNH_PRODUCTION_DOMAIN:-whoneedhelp.com}
case "$action" in
plan | apply) ;;
*)
echo "Usage: $0 [plan|apply] REMOTE_ROLLBACK_MANIFEST [SSH_TARGET]" >&2
exit 2
;;
esac
if [[ -z "$remote_manifest" ]]; then
echo "Provide the absolute rollback-manifest.txt path printed by a successful release." >&2
exit 2
fi
case "$remote_manifest" in
"$remote_root"/output/releases/*/rollback-manifest.txt) ;;
*)
echo "Rollback manifest must be below $remote_root/output/releases/." >&2
exit 2
;;
esac
command -v ssh >/dev/null 2>&1 || {
echo "Required command is unavailable: ssh" >&2
exit 2
}
quote() {
printf '%q' "$1"
}
remote_command() {
local remote_action=$1
printf 'bash -s -- %s %s %s %s' \
"$(quote "$remote_action")" \
"$(quote "$remote_root")" \
"$(quote "$expected_domain")" \
"$(quote "$remote_manifest")"
}
ssh -o BatchMode=yes "$ssh_target" \
"$(remote_command plan)" \
<"$ROOT/scripts/production-rollback-remote.sh"
if [[ "$action" == plan ]]; then
echo "Production application rollback plan passed; no remote state was changed."
exit 0
fi
if [[ -z "${WNH_PRODUCTION_ROLLBACK_CONFIRM:-}" ]]; then
echo "Rollback execution requires the exact confirmation token printed by plan:" >&2
echo "WNH_PRODUCTION_ROLLBACK_CONFIRM=... $0 apply $remote_manifest $ssh_target" >&2
exit 2
fi
confirmation=$(quote "$WNH_PRODUCTION_ROLLBACK_CONFIRM")
ssh -o BatchMode=yes "$ssh_target" \
"WNH_PRODUCTION_ROLLBACK_CONFIRM=$confirmation $(remote_command apply)" \
<"$ROOT/scripts/production-rollback-remote.sh"
echo "Production application rollback and public health verification completed."