2017-09-26 12:52:39 +02:00
|
|
|
#!/bin/bash
|
|
|
|
|
|
|
|
|
|
limit=''
|
2020-04-15 11:57:36 +02:00
|
|
|
force=''
|
2026-09-30 15:30:47 +02:00
|
|
|
rotate=''
|
2017-09-26 12:52:39 +02:00
|
|
|
while test $# -gt 0; do
|
|
|
|
|
case "$1" in
|
|
|
|
|
(-h|--help) cat <<EOF
|
2017-09-26 13:15:14 +02:00
|
|
|
$0 [OPTIONS] FILES…
|
2017-09-26 12:52:39 +02:00
|
|
|
|
|
|
|
|
OPTIONS
|
|
|
|
|
|
|
|
|
|
-h, --help show this help
|
|
|
|
|
-s, --limit service limit update to given service
|
2020-04-15 11:57:36 +02:00
|
|
|
-f, --force force update
|
2026-09-30 15:30:47 +02:00
|
|
|
-r, --rotate-key hand the current registry credentials to the
|
|
|
|
|
services and leave their images as they are
|
2017-09-26 12:52:39 +02:00
|
|
|
|
2017-09-26 13:15:14 +02:00
|
|
|
FILES…
|
2017-09-26 12:52:39 +02:00
|
|
|
|
2017-09-26 13:15:14 +02:00
|
|
|
List of stack names or yaml files to deploy. There must be yaml
|
|
|
|
|
files with the same name. The extension .yaml may be given or not.
|
2017-09-26 12:52:39 +02:00
|
|
|
|
|
|
|
|
DESCRIPTION
|
|
|
|
|
|
2017-09-26 13:15:14 +02:00
|
|
|
Updates the docker images of all services in the given stacks.
|
2017-09-26 12:52:39 +02:00
|
|
|
|
2026-09-30 15:30:47 +02:00
|
|
|
A service carries the registry credentials of the moment it was
|
|
|
|
|
deployed, and a node uses them when it pulls an image. After the
|
|
|
|
|
token of the registry account has been rotated, --rotate-key writes
|
|
|
|
|
the credentials of this machine into every service of the stacks,
|
|
|
|
|
without touching the image any service runs.
|
|
|
|
|
|
2017-09-26 12:52:39 +02:00
|
|
|
EOF
|
|
|
|
|
exit;;
|
|
|
|
|
(-l|--limit) shift; limit=$1;;
|
2020-04-15 11:57:36 +02:00
|
|
|
(-f|--force) force='--force';;
|
2026-09-30 15:30:47 +02:00
|
|
|
(-r|--rotate-key) rotate='yes';;
|
2017-09-26 12:52:39 +02:00
|
|
|
(*) break;;
|
|
|
|
|
esac
|
|
|
|
|
if test $# -lt 1; then
|
|
|
|
|
echo "error: missing argument, try $0 --help" 1>&2
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
shift
|
|
|
|
|
done
|
|
|
|
|
|
|
|
|
|
for f in $*; do
|
|
|
|
|
name=${f%.yaml}
|
|
|
|
|
file=${name}.yaml
|
2018-08-24 15:54:59 +02:00
|
|
|
name=${name##*/}
|
2017-09-26 12:52:39 +02:00
|
|
|
echo "upgrading ${name}"
|
|
|
|
|
IFS="
|
|
|
|
|
"
|
2018-12-06 14:27:42 +01:00
|
|
|
for param in $(sed -n '/^ *\([^:]\+\): *$/{s,,'"${name}"'_\1,;h};/^ *image: */{s///;G;s/\n/ /p}' $file); do
|
2017-09-26 12:52:39 +02:00
|
|
|
IFS=" "
|
|
|
|
|
if [ -z "$limit" ] || [[ "${param}" =~ " ${name}_${limit}" ]]; then
|
2026-09-30 15:30:47 +02:00
|
|
|
# --with-registry-auth hands the credentials of this machine to the
|
|
|
|
|
# nodes that pull the image, as docker-deploy does
|
|
|
|
|
if test -n "$rotate"; then
|
|
|
|
|
# the service name is the second word of the pair, the image
|
|
|
|
|
# the first: only the credentials are written, the image of the
|
|
|
|
|
# service stays the one it runs
|
|
|
|
|
service=${param#* }
|
|
|
|
|
echo "....rotate key of $service"
|
|
|
|
|
docker service update --with-registry-auth $force $service
|
|
|
|
|
else
|
|
|
|
|
echo "....update $param: docker service update --image $param"
|
|
|
|
|
docker service update --with-registry-auth $force --image $param
|
|
|
|
|
fi
|
2017-09-26 12:52:39 +02:00
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
done
|
|
|
|
|
|