1 Commits

Author SHA1 Message Date
root 856f899448 Merge pull request 'fix(ci): auto-discover reachable Portainer URL from job container' (#5) from fix/runner-portainer-network into main
CI/CD Pipeline / Build & Deploy (push) Waiting to run
2026-07-10 13:22:01 +02:00
+87 -38
View File
@@ -62,53 +62,102 @@ jobs:
# PORTAINER_ENDPOINT_ID Numeric endpoint ID (usually 1)
# PORTAINER_STACK_ID Numeric stack ID to delete before recreating
# ----------------------------------------------------------------------
- name: Redeploy stack on Portainer via SSH
- name: Redeploy stack on Portainer
if: github.event_name == 'workflow_dispatch' && inputs.deploy == true
env:
NAS_SSH_KEY: ${{ secrets.NAS_SSH_KEY }}
NAS_HOST: ${{ secrets.NAS_HOST }}
NAS_USER: ${{ secrets.NAS_USER }}
STACK_NAME: davidaragon-portfolio
COMPOSE_FILE: docker-compose.prod.yml
PORTAINER_TOKEN: ${{ secrets.PORTAINER_TOKEN }}
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID }}
PORTAINER_STACK_ID: ${{ secrets.PORTAINER_STACK_ID }}
run: |
# The act_runner job container can't reach 'portainer' because it
# doesn't share the runner's network namespace in v0.6.1. We work
# around this by SSHing into the NAS (where Portainer is) and
# using the docker CLI directly to do `docker stack deploy`.
set -euo pipefail
mkdir -p ~/.ssh
echo "$NAS_SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
echo "--- Step 0: auto-discover a reachable Portainer URL ---"
# The runner creates an ephemeral docker network per job, so the
# canonical PORTAINER_URL (e.g. http://192.168.1.30:9000) often isn't
# reachable from inside the job container. Strategy: probe every IP
# we can find (container's own IPs + default gateways) against
# :9000/api/status and use the first one that responds 200.
PORTAINER_URL=""
CANDIDATES=()
echo "--- Pre-flight: ensure NAS is reachable ---"
# NAS_HOST can be either "host" or "host:port"
NAS_SSH_PORT=$(echo "$NAS_HOST" | grep -q ':' && echo "${NAS_HOST##*:}" || echo "22")
NAS_SSH_HOST="${NAS_HOST%%:*}"
echo "Using NAS_SSH_HOST=$NAS_SSH_HOST NAS_SSH_PORT=$NAS_SSH_PORT"
ssh -o StrictHostKeyChecking=no -o ConnectTimeout=5 -p "$NAS_SSH_PORT" \
"$NAS_USER@$NAS_SSH_HOST" \
'export PATH=/share/CACHEDEV1_DATA/.qpkg/container-station/usr/bin:$PATH; hostname && docker version --format "{{.Server.Version}}"' \
| head
# 1) Container's own IPv4 addresses
for ip in $(hostname -I 2>/dev/null | tr ' ' '\n' | grep -E '^[0-9]+\.'); do
CANDIDATES+=("http://${ip}:9000")
done
echo "--- Reading docker-compose.prod.yml from the repo ---"
if [ ! -f "$COMPOSE_FILE" ]; then
echo "ERROR: $COMPOSE_FILE not found in repo root" >&2
# 2) Default gateways of every default route
while IFS= read -r gw; do
[ -n "$gw" ] && CANDIDATES+=("http://${gw}:9000")
done < <(ip -4 route show default 2>/dev/null | awk '{print $3}' | sort -u)
# 3) Fallback: secret value (in case everything else fails)
CANDIDATES+=("${{ secrets.PORTAINER_URL }}")
echo "Candidates: ${CANDIDATES[@]}"
for url in "${CANDIDATES[@]}"; do
code=$(curl -sS -o /dev/null -w '%{http_code}' --max-time 3 "${url}/api/status" 2>/dev/null || echo "000")
echo " probe ${url}/api/status -> ${code}"
if [ "$code" = "200" ]; then
PORTAINER_URL="$url"
echo " -> using ${PORTAINER_URL}"
break
fi
done
if [ -z "$PORTAINER_URL" ]; then
echo "ERROR: no candidate URL reached Portainer. Tried: ${CANDIDATES[@]}" >&2
exit 1
fi
echo "--- Redeploying stack '$STACK_NAME' on the NAS ---"
# The NAS has Portainer and docker compose (v2) available. We stream
# the compose file over SSH and let docker compose recreate the
# project. We pin the project name to 'davidaragon-portfolio' so the
# volumes and networks of the existing stack are reused.
cat "$COMPOSE_FILE" | ssh -o StrictHostKeyChecking=no -p "$NAS_SSH_PORT" \
"$NAS_USER@$NAS_SSH_HOST" \
"export PATH=/share/CACHEDEV1_DATA/.qpkg/container-station/usr/bin:\$PATH; cd /tmp && docker compose -p '$STACK_NAME' -f - up -d"
echo "--- Step 1: pre-flight (delete existing stack if present) ---"
DELETE_HTTP_CODE=$(curl -sS -o /tmp/portainer-delete.json -w '%{http_code}' \
-X DELETE \
-H "X-API-Key: ${PORT...EN}" \
"${PORTAINER_URL}/api/stacks/${PORTAINER_STACK_ID}?endpointId=${PORTAINER_ENDPOINT_ID}")
echo "DELETE HTTP ${DELETE_HTTP_CODE}"
if [ "${DELETE_HTTP_CODE}" != "204" ] && [ "${DELETE_HTTP_CODE}" != "404" ]; then
echo "ERROR: Portainer rejected DELETE on stack ${PORTAINER_STACK_ID}:" >&2
cat /tmp/portainer-delete.json >&2
exit 1
fi
echo "--- Stack '$STACK_NAME' redeployed. Smoke-test: ---"
sleep 5
curl -sS -o /dev/null -w 'http://localhost:3001/ -> HTTP=%{http_code}\n' \
--max-time 5 http://localhost:3001/ || true
echo "--- Step 2: read docker-compose.prod.yml ---"
if [ ! -f docker-compose.prod.yml ]; then
echo "ERROR: docker-compose.prod.yml is missing from the repo root" >&2
exit 1
fi
# Inline the compose file. Portainer expects `composeFileContent` as raw text.
COMPOSE_BODY=$(jq -Rs --arg compose "$(cat docker-compose.prod.yml)" \
'{composeFileContent: $compose, env: []}' < /dev/null)
echo "--- Done ---"
echo "--- Step 3: create fresh stack from docker-compose.prod.yml ---"
CREATE_HTTP_CODE=$(curl -sS -o /tmp/portainer-create.json -w '%{http_code}' \
-X POST \
-H "X-API-Key: ${PORTAINER_TOKEN}" \
-H "Content-Type: application/json" \
--data "${COMPOSE_BODY}" \
"${PORTAINER_URL}/api/stacks?endpointId=${PORTAINER_ENDPOINT_ID}&type=2&method=string&name=davidaragon-portfolio")
echo "CREATE HTTP ${CREATE_HTTP_CODE}"
if [ "${CREATE_HTTP_CODE}" != 201 ]; then
echo "ERROR: Portainer rejected stack creation:" >&2
cat /tmp/portainer-create.json >&2
exit 1
fi
echo "--- Step 4: smoke-test the freshly deployed stack ---"
# Give the container a brief window to start before checking.
sleep 8
# The Portainer host:9000 is reachable from the job container
# (we just proved that with the auto-discovery step above). The
# portfolio container itself is published on host port 3001, so
# smoke-test through the same host. We don't fail the job if the
# proxy upstream isn't reachable from the runner's network.
HEALTH=$(curl -sS -o /dev/null -w '%{http_code}' \
--max-time 5 \
"${PORTAINER_URL%:[0-9]*}:3001/" 2>/dev/null || true)
echo "Health check on ${PORTAINER_URL%:[0-9]*}:3001/ returned: ${HEALTH:-<timeout/unreachable>}"
# We log but don't fail the job if 3001 isn't reachable — the upstream
# proxy (Nginx Proxy Manager → davidaragon.impresion3d.pro) is a better
# place to wire a hard-fail check in a future iteration.
echo "--- Stack recreated successfully. ---"