A node that pulls an image authenticates as nobody unless the task carries credentials, and the registry counts anonymous pulls per address, so the whole estate shares one budget. Deployments and image updates now pass --with-registry-auth, and --rotate-key writes the current credentials into every service of a stack after the account token has been rotated, without touching the images. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
64 lines
1.6 KiB
Bash
Executable File
64 lines
1.6 KiB
Bash
Executable File
#!/bin/bash -e
|
|
|
|
while test $# -gt 0; do
|
|
case "$1" in
|
|
(-h|--help) cat <<EOF
|
|
$0 [OPTIONS] FILES…
|
|
|
|
OPTIONS
|
|
|
|
-h, --help show this help
|
|
|
|
FILES…
|
|
|
|
List of stack names or yaml files to deploy. There must be yaml
|
|
files with the same name. The extension .yaml may be given or not.
|
|
|
|
DESCRIPTION
|
|
|
|
Deploys stack from yaml files. The stack name is identical to the
|
|
file name, but wihout path and without .yaml extendsion.
|
|
|
|
The deployment carries the registry credentials of this machine to
|
|
the nodes, so run docker login here before deploying images from a
|
|
registry that asks for one or counts anonymous pulls.
|
|
|
|
EXAMPLS
|
|
|
|
The following calls ado the same and deploy a local yaml file:
|
|
|
|
$0 yaml-file-name
|
|
$0 yaml-file-name.yaml
|
|
$0 ./yaml-file-name.yaml
|
|
|
|
Deploy three files from three sources:
|
|
|
|
$0 /path/to/file1/first.yaml /path/to/file2/second.yaml third
|
|
|
|
EOF
|
|
exit;;
|
|
(*) break;;
|
|
esac
|
|
if test $# -lt 1; then
|
|
echo "error: missing argument, try $0 --help" 1>&2
|
|
exit 1
|
|
fi
|
|
shift
|
|
done
|
|
|
|
for f in $*; do
|
|
f=${f%.yaml}
|
|
if ! test -e ${f}.yaml; then
|
|
echo "ERROR: no file ${f}.yaml" 1>&2
|
|
exit 1
|
|
fi
|
|
echo "... deploying ${f##*/}"
|
|
for d in $(sed -n 's,^ *source: \(/.*\),\1,p' ${f}.yaml); do
|
|
test -e $d || mkdir -p $d
|
|
done
|
|
# --with-registry-auth hands the credentials of this machine to the swarm
|
|
# managers, which pass them on with every task: without them each node
|
|
# pulls anonymously and runs into the pull limit of the registry
|
|
docker stack deploy --with-registry-auth --compose-file ${f}.yaml ${f##*/}
|
|
done
|