Repository navigation
deploy: one-command deploy, tracked stack, no secrets in git - #2
Merged
Merged
Conversation
Replaces the manual three-step: git pull, docker build by hand, click redeploy in Portainer. Fails loudly rather than half-deploying -- ff-only merge so a diverged checkout stops instead of merging, and set -e throughout. Install to /usr/local/sbin/faucet-deploy root-owned 755; see deploy/README.md for why it must not be sudo'd from its repo path.
The live stack lived only in Portainer's data dir and carried the Jackett key, Transmission password, Discord webhook and session secret inline -- unreadable without root and unsafe to paste anywhere. Everything in config.py's WIZARD_KEYS is dropped: faucet.env is loaded *over* process env, so those compose values were dead weight that only looked authoritative. What remains is the structural set the wizard deliberately excludes, plus SESSION_SECRET via env_file.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Turns the manual three-step deploy —
git pull,docker buildby hand, clickredeploy in Portainer — into one command, and gets the stack definition out of
Portainer's data dir and into git.
Changes
deploy/deploy.sh— fast-forward the checkout, rebuildfaucet:local,compose up -d --force-recreate faucet, verify the container is running.Exits non-zero on failure so a broken deploy reports as broken.
deploy/stack.yml— the compose definition, with no secrets.deploy/faucet.secrets.env.example— template forSESSION_SECRET.deploy/README.md— install steps and the config layering.Why the stack file shrank so much
config.py::_load_persisted()reads/config/faucet.envand writes its keysinto
os.environat import, so it overrides whatever the container wasstarted with. Every
WIZARD_KEYSentry in the old inlineenvironment:blockwas therefore dead weight that looked authoritative —
JACKETT_URL,CLIENT_*,NOTIFY_*,UI_*,APP_TITLE, the path keys. Dropped. Whatremains is the structural set the wizard deliberately excludes, plus
SESSION_SECRETviaenv_file.The practical consequence, documented in the README: rotating a credential at
its source and updating compose is not enough while
faucet.envstilldefines it.
Two things that are load-bearing, not style
--force-recreate: the image tag never changes, so without it compose seesno reason to replace the container and the deploy silently no-ops.
deploy.shto/usr/local/sbin/faucet-deploy, root-owned. Thecheckout belongs to the ops account, so a
NOPASSWDsudoers rule pointingat the repo path would let that account rewrite the script and get root.
Note on Portainer: it still displays the stack, but its "Update the stack"
button now redeploys from its own stale copy. Use the script. Portainer can't
run this deploy itself — it mounts only the Docker socket and its data dir, so
neither a
build:context at/opt/faucetnor a host-pathenv_file:wouldresolve from inside it.