mirror of
				https://github.com/honestbee/drone-kubernetes.git
				synced 2025-11-04 09:18:05 +00:00 
			
		
		
		
	script: rewrite with functions
This commit is contained in:
		
							parent
							
								
									661f470526
								
							
						
					
					
						commit
						e715f7e0e8
					
				
					 1 changed files with 190 additions and 80 deletions
				
			
		
							
								
								
									
										270
									
								
								update.sh
									
										
									
									
									
								
							
							
						
						
									
										270
									
								
								update.sh
									
										
									
									
									
								
							| 
						 | 
					@ -1,99 +1,209 @@
 | 
				
			||||||
#!/bin/bash
 | 
					#!/bin/bash
 | 
				
			||||||
set -euo pipefail
 | 
					set -euo pipefail
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# check optional params
 | 
					# globals
 | 
				
			||||||
if [ ! -z ${PLUGIN_USER} ]; then
 | 
					USER=""
 | 
				
			||||||
 | 
					NAMESPACE=""
 | 
				
			||||||
 | 
					CLUSTER=""
 | 
				
			||||||
 | 
					DEPLOYMENTS=""
 | 
				
			||||||
 | 
					CONTAINERS=""
 | 
				
			||||||
 | 
					SERVER_URL=""
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# set globals
 | 
				
			||||||
 | 
					setUser(){
 | 
				
			||||||
  USER=${PLUGIN_USER:-default}
 | 
					  USER=${PLUGIN_USER:-default}
 | 
				
			||||||
fi
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
if [ ! -z ${PLUGIN_NAMESPACE} ]; then
 | 
					setNamespace(){
 | 
				
			||||||
  NAMESPACE=${PLUGIN_NAMESPACE:-default}
 | 
					  NAMESPACE=${PLUGIN_NAMESPACE:-default}
 | 
				
			||||||
fi
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# check required params
 | 
					setDeployments(){
 | 
				
			||||||
if [ ! -z ${PLUGIN_CLUSTER} ]; then
 | 
					  IFS=',' read -r -a DEPLOYMENTS <<< "${PLUGIN_DEPLOYMENT}"
 | 
				
			||||||
  # convert cluster name to ucase and assign
 | 
					}
 | 
				
			||||||
  CLUSTER=${PLUGIN_CLUSTER^^}
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # create dynamic cert var names
 | 
					setContainers(){
 | 
				
			||||||
  SERVER_URL_VAR=SERVER_URL_${CLUSTER}
 | 
					  IFS=',' read -r -a CONTAINERS <<< "${PLUGIN_CONTAINER}"
 | 
				
			||||||
  SERVER_CERT_VAR=SERVER_CERT_${CLUSTER}
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # expand the var contents
 | 
					setCluster(){
 | 
				
			||||||
  SERVER_URL=${!SERVER_URL_VAR}
 | 
					  if [ ! -z ${PLUGIN_CLUSTER} ]; then
 | 
				
			||||||
  SERVER_CERT=${!SERVER_CERT_VAR}
 | 
					    # convert cluster name to ucase and assign
 | 
				
			||||||
 | 
					    CLUSTER=${PLUGIN_CLUSTER^^}
 | 
				
			||||||
  if [[ -z "${SERVER_URL}" ]]; then
 | 
					  else
 | 
				
			||||||
    echo "[ERROR] drone secret: ${SERVER_URL_VAR} not added!"
 | 
					    echo "[ERROR] Required pipeline parameter: cluster not provided"
 | 
				
			||||||
    exit 1
 | 
					    exit 1
 | 
				
			||||||
  fi
 | 
					  fi
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  if [[ ! -z "${SERVER_CERT}" ]]; then
 | 
					setServerUrl(){
 | 
				
			||||||
    echo "[INFO] Using secure connection with tls-certificate."
 | 
					  # create dynamic cert var names
 | 
				
			||||||
    echo ${SERVER_CERT} | base64 -d > ca.crt
 | 
					  local SERVER_URL_VAR=SERVER_URL_${CLUSTER}
 | 
				
			||||||
    kubectl config set-cluster ${CLUSTER} --server=${SERVER_URL} --certificate-authority=ca.crt
 | 
					  SERVER_URL=${!SERVER_URL_VAR}
 | 
				
			||||||
 | 
					  if [[ -z "${SERVER_URL}" ]]; then
 | 
				
			||||||
 | 
					    echo "[ERROR] Required drone secret: ${SERVER_URL_VAR} not added!"
 | 
				
			||||||
 | 
					    exit 1
 | 
				
			||||||
 | 
					  fi
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    # vars based on auth_mode
 | 
					setGlobals(){
 | 
				
			||||||
    if [ ! -z ${PLUGIN_AUTH_MODE} ]; then
 | 
					  setUser
 | 
				
			||||||
      if [[ "${PLUGIN_AUTH_MODE}" == "token" ]]; then
 | 
					  setNamespace
 | 
				
			||||||
        echo "[INFO] Using Server token to authorize"
 | 
					  setDeployments
 | 
				
			||||||
        SERVER_TOKEN_VAR=SERVER_TOKEN_${CLUSTER}
 | 
					  setContainers
 | 
				
			||||||
        # expand
 | 
					  setCluster
 | 
				
			||||||
        SERVER_TOKEN=${!SERVER_TOKEN_VAR}
 | 
					  setServerUrl
 | 
				
			||||||
        if [[ ! -z "${SERVER_TOKEN}" ]]; then
 | 
					}
 | 
				
			||||||
          kubectl config set-credentials ${USER} --token=${SERVER_TOKEN}
 | 
					 | 
				
			||||||
        else
 | 
					 | 
				
			||||||
          echo "[ERROR] Required plugin param - server_token - not provided."
 | 
					 | 
				
			||||||
          exit 1
 | 
					 | 
				
			||||||
        fi
 | 
					 | 
				
			||||||
      elif [[ "${PLUGIN_AUTH_MODE}" == "client-cert" ]]; then
 | 
					 | 
				
			||||||
        echo "[INFO] Using Client cert and Key to authorize"
 | 
					 | 
				
			||||||
        CLIENT_CERT_VAR=CLIENT_CERT_${CLUSTER}
 | 
					 | 
				
			||||||
        CLIENT_KEY_VAR=CLIENT_KEY_${CLUSTER}
 | 
					 | 
				
			||||||
        # expand
 | 
					 | 
				
			||||||
        CLIENT_CERT=${!CLIENT_CERT_VAR}
 | 
					 | 
				
			||||||
        CLIENT_KEY=${!CLIENT_KEY_VAR}
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
        if [[ ! -z "${CLIENT_CERT}" ]] && [[ ! -z "${CLIENT_KEY}" ]]; then
 | 
					setSecureCluster(){
 | 
				
			||||||
          echo "[INFO] Setting client credentials with signed-certificate and key."
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
          echo ${CLIENT_CERT} | base64 -d > client.crt
 | 
					  local SERVER_URL=$1; shift
 | 
				
			||||||
          echo ${CLIENT_KEY} | base64 -d > client.key
 | 
					  local SERVER_CERT=$1
 | 
				
			||||||
          kubectl config set-credentials ${USER} --client-certificate=client.crt --client-key=client.key
 | 
					
 | 
				
			||||||
        else
 | 
					  echo "[INFO] Using secure connection with tls-certificate."
 | 
				
			||||||
          echo "[ERROR] Required plugin parameters:"
 | 
					  echo ${SERVER_CERT} | base64 -d > ca.crt
 | 
				
			||||||
          echo " - client_cert"
 | 
					  kubectl config set-cluster ${CLUSTER} --server=${SERVER_URL} --certificate-authority=ca.crt
 | 
				
			||||||
          echo " - client_key"
 | 
					}
 | 
				
			||||||
          echo "are not provided"
 | 
					
 | 
				
			||||||
          exit 1
 | 
					setInsecureCluster(){
 | 
				
			||||||
        fi
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
      else
 | 
					  local SERVER_URL=$1
 | 
				
			||||||
        echo "[ERROR] Required plugin param - auth_mode - not provided"
 | 
					
 | 
				
			||||||
        echo "[INFO] Should be either [ token | client-cert ]"
 | 
					  echo "[WARNING] Using insecure connection to cluster"
 | 
				
			||||||
        exit 1
 | 
					  kubectl config set-cluster ${CLUSTER} --server=${SERVER_URL} --insecure-skip-tls-verify=true
 | 
				
			||||||
      fi
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					setServerToken(){
 | 
				
			||||||
 | 
					  local USER=$1; shift
 | 
				
			||||||
 | 
					  local SERVER_TOKEN=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  echo "[INFO] Setting client credentials with token"
 | 
				
			||||||
 | 
					  kubectl config set-credentials ${USER} --token=${SERVER_TOKEN}
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					setClientCertAndKey(){
 | 
				
			||||||
 | 
					  local USER=$1; shift
 | 
				
			||||||
 | 
					  local CLIENT_CERT=$1; shift
 | 
				
			||||||
 | 
					  local CLIENT_KEY=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  echo "[INFO] Setting client credentials with signed-certificate and key."
 | 
				
			||||||
 | 
					  echo ${CLIENT_CERT} | base64 -d > client.crt
 | 
				
			||||||
 | 
					  echo ${CLIENT_KEY} | base64 -d > client.key
 | 
				
			||||||
 | 
					  kubectl config set-credentials ${USER} --client-certificate=client.crt --client-key=client.key
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					setContext(){
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local USER=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  kubectl config set-context ${CLUSTER} --cluster=${CLUSTER} --user=${USER}
 | 
				
			||||||
 | 
					  kubectl config use-context ${CLUSTER}
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					pollDeploymentRollout(){
 | 
				
			||||||
 | 
					  local NAMESPACE=$1; shift
 | 
				
			||||||
 | 
					  local DEPLOY=$1
 | 
				
			||||||
 | 
					  # wait on deployment rollout status
 | 
				
			||||||
 | 
					  kubectl -n ${NAMESPACE} rollout status --watch=false --revision=0 deployment/${DEPLOY}
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					startDeployment(){
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local NAMESPACE=$1; shift
 | 
				
			||||||
 | 
					  local DEPLOYMENTS=$1; shift
 | 
				
			||||||
 | 
					  local CONTAINERS=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  for DEPLOY in ${DEPLOYMENTS[@]}; do
 | 
				
			||||||
 | 
					    echo Deploying to ${CLUSTER}
 | 
				
			||||||
 | 
					    for CONTAINER in ${CONTAINERS[@]}; do
 | 
				
			||||||
 | 
					      kubectl -n ${NAMESPACE} set image deployment/${DEPLOY} \
 | 
				
			||||||
 | 
					        ${CONTAINER}="${PLUGIN_REPO}:${PLUGIN_TAG}" --record
 | 
				
			||||||
 | 
					    done
 | 
				
			||||||
 | 
					    #pollDeploymentRollout ${NAMESPACE} ${DEPLOY}
 | 
				
			||||||
 | 
					  done
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					clientAuthToken(){
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local USER=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  echo "[INFO] Using Server token to authorize"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  CLIENT_TOKEN_VAR=CLIENT_TOKEN_${CLUSTER}
 | 
				
			||||||
 | 
					  CLIENT_TOKEN=${!CLIENT_TOKEN_VAR}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  if [[ ! -z "${CLIENT_TOKEN}" ]]; then
 | 
				
			||||||
 | 
					    setClientToken ${USER} ${CLIENT_TOKEN}
 | 
				
			||||||
 | 
					  else
 | 
				
			||||||
 | 
					    echo "[ERROR] Required plugin secrets:"
 | 
				
			||||||
 | 
					    echo " - ${CLIENT_TOKEN_VAR}"
 | 
				
			||||||
 | 
					    echo "not provided."
 | 
				
			||||||
 | 
					    exit 1
 | 
				
			||||||
 | 
					  fi
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					clientAuthCert(){
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local USER=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  echo "[INFO] Using Client cert and Key to authorize"
 | 
				
			||||||
 | 
					  CLIENT_CERT_VAR=CLIENT_CERT_${CLUSTER}
 | 
				
			||||||
 | 
					  CLIENT_KEY_VAR=CLIENT_KEY_${CLUSTER}
 | 
				
			||||||
 | 
					  # expand
 | 
				
			||||||
 | 
					  CLIENT_CERT=${!CLIENT_CERT_VAR}
 | 
				
			||||||
 | 
					  CLIENT_KEY=${!CLIENT_KEY_VAR}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  if [[ ! -z "${CLIENT_CERT}" ]] && [[ ! -z "${CLIENT_KEY}" ]]; then
 | 
				
			||||||
 | 
					    setClientCertAndKey ${USER} ${CLIENT_CERT} ${CLIENT_KEY}
 | 
				
			||||||
 | 
					  else
 | 
				
			||||||
 | 
					    echo "[ERROR] Required plugin secrets:"
 | 
				
			||||||
 | 
					    echo " - ${CLIENT_CERT_VAR}"
 | 
				
			||||||
 | 
					    echo " - ${CLIENT_KEY_VAR}"
 | 
				
			||||||
 | 
					    echo "not provided"
 | 
				
			||||||
 | 
					    exit 1
 | 
				
			||||||
 | 
					  fi
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					clientAuth(){
 | 
				
			||||||
 | 
					  local AUTH_MODE=$1; shift
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local USER=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  if [ ! -z ${AUTH_MODE} ]; then
 | 
				
			||||||
 | 
					    if [[ "${AUTH_MODE}" == "token" ]]; then
 | 
				
			||||||
 | 
					      clientAuthToken ${CLUSTER} ${USER}
 | 
				
			||||||
 | 
					    elif [[ "${AUTH_MODE}" == "client-cert" ]]; then
 | 
				
			||||||
 | 
					      clientAuthCert ${CLUSTER} ${USER}
 | 
				
			||||||
 | 
					    else
 | 
				
			||||||
 | 
					      echo "[ERROR] Required plugin param - auth_mode - Should be either:"
 | 
				
			||||||
 | 
					      echo "[ token | client-cert ]"
 | 
				
			||||||
 | 
					      exit 1
 | 
				
			||||||
    fi
 | 
					    fi
 | 
				
			||||||
  else
 | 
					  else
 | 
				
			||||||
    echo "[WARNING] Required plugin parameter: ${SERVER_CERT_VAR} not added!"
 | 
					    echo "[ERROR] Required plugin param - auth_mode - not provided"
 | 
				
			||||||
    echo "[WARNING] Using insecure connection to cluster"
 | 
					    exit 1
 | 
				
			||||||
    kubectl config set-cluster ${CLUSTER} --server=${SERVER_URL} --insecure-skip-tls-verify=true
 | 
					 | 
				
			||||||
  fi
 | 
					  fi
 | 
				
			||||||
else
 | 
					}
 | 
				
			||||||
  echo "[ERROR] Required pipeline parameter: cluster not provided"
 | 
					 | 
				
			||||||
  exit 1
 | 
					 | 
				
			||||||
fi
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
kubectl config set-context ${CLUSTER} --cluster=${CLUSTER} --user=${USER}
 | 
					clusterAuth(){
 | 
				
			||||||
kubectl config use-context ${CLUSTER}
 | 
					  local SERVER_URL=$1; shift
 | 
				
			||||||
 | 
					  local CLUSTER=$1; shift
 | 
				
			||||||
 | 
					  local USER=$1
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# kubectl version
 | 
					  SERVER_CERT_VAR=SERVER_CERT_${CLUSTER}
 | 
				
			||||||
IFS=',' read -r -a DEPLOYMENTS <<< "${PLUGIN_DEPLOYMENT}"
 | 
					  SERVER_CERT=${!SERVER_CERT_VAR}
 | 
				
			||||||
IFS=',' read -r -a CONTAINERS <<< "${PLUGIN_CONTAINER}"
 | 
					
 | 
				
			||||||
for DEPLOY in ${DEPLOYMENTS[@]}; do
 | 
					  if [[ ! -z "${SERVER_CERT}" ]]; then
 | 
				
			||||||
  echo Deploying to ${CLUSTER}
 | 
					    setSecureCluster ${CLUSTER} ${SERVER_URL} ${SERVER_CERT}
 | 
				
			||||||
  for CONTAINER in ${CONTAINERS[@]}; do
 | 
					    AUTH_MODE=${PLUGIN_AUTH_MODE}
 | 
				
			||||||
    kubectl -n ${NAMESPACE} set image deployment/${DEPLOY} \
 | 
					    clientAuth ${AUTH_MODE} ${CLUSTER} ${USER}
 | 
				
			||||||
      ${CONTAINER}="${PLUGIN_REPO}:${PLUGIN_TAG}" --record
 | 
					  else
 | 
				
			||||||
  done
 | 
					    echo "[WARNING] Required plugin parameter: ${SERVER_CERT_VAR} not added!"
 | 
				
			||||||
  # wait on deployment rollout status
 | 
					    setInsecureCluster ${CLUSTER} ${SERVER_URL}
 | 
				
			||||||
  # kubectl -n ${NAMESPACE} rollout status deployment/${DEPLOY}
 | 
					  fi
 | 
				
			||||||
done
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					setGlobals
 | 
				
			||||||
 | 
					clusterAuth ${SERVER_URL} ${CLUSTER} ${USER}
 | 
				
			||||||
 | 
					setContext ${CLUSTER} ${USER}
 | 
				
			||||||
 | 
					startDeployment ${CLUSTER} ${NAMESPACE} ${DEPLOYMENTS} ${CONTAINERS}
 | 
				
			||||||
| 
						 | 
					
 | 
				
			||||||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue