ops: keep production SSH sessions alive
This commit is contained in:
@@ -322,7 +322,7 @@ jobs:
|
||||
printf '%s\n' "$PRODUCTION_KNOWN_HOSTS" | tr -d '\r' > "$known_hosts_path"
|
||||
chmod 600 "$key_path" "$known_hosts_path"
|
||||
ssh-keygen -y -f "$key_path" >/dev/null
|
||||
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
|
||||
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
|
||||
remote="$DEPLOY_USER@$DEPLOY_HOST"
|
||||
require_current_release_heads() {
|
||||
[[ "$ALLOW_ROLLBACK" == true ]] && return
|
||||
|
||||
@@ -302,7 +302,7 @@ jobs:
|
||||
printf '%s\n' "$PRODUCTION_KNOWN_HOSTS" | tr -d '\r' > "$known_hosts_path"
|
||||
chmod 600 "$key_path" "$known_hosts_path"
|
||||
ssh-keygen -y -f "$key_path" >/dev/null
|
||||
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
|
||||
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
|
||||
remote="$DEPLOY_USER@$DEPLOY_HOST"
|
||||
require_current_release_heads() {
|
||||
current_staging="$(curl --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-all-errors \
|
||||
|
||||
@@ -967,6 +967,7 @@ test("Gitea production deploy consumes only gate-attested digests under manual c
|
||||
assert.match(workflow, /bash '\$incoming\/deploy\/run-production-deploy\.sh'/);
|
||||
assert.match(workflow, /docker ps -aq[^\n]*com\.docker\.compose\.service=web/);
|
||||
assert.match(workflow, /state-present-without-container/);
|
||||
assert.match(workflow, /ServerAliveInterval=15.*ServerAliveCountMax=4/);
|
||||
assert.doesNotMatch(workflow, /then cat \"\\\$state\\\"/);
|
||||
assert.doesNotMatch(workflow, /docker compose[^\n]*build|db:migrate/);
|
||||
});
|
||||
@@ -1045,6 +1046,7 @@ test("Gitea production schema migration is exact-SHA gated and isolated from ETL
|
||||
assert.match(workflow, /run-production-migration\.sh/);
|
||||
assert.match(workflow, /docker ps -aq[^\n]*com\.docker\.compose\.service=web/);
|
||||
assert.match(workflow, /state-present-without-container/);
|
||||
assert.match(workflow, /ServerAliveInterval=15.*ServerAliveCountMax=4/);
|
||||
assert.doesNotMatch(workflow, /then cat "\\\$state\\"/);
|
||||
assert.doesNotMatch(workflow, /migrate-supabase-production|run-production-deploy|verification_mode|PRODUCTION_URL|CADDY/);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user