#!/usr/bin/env xonsh hosts = [ "kankali.darkhelm.lan", "zhokq.darkhelm.lan", "urtzul.darkhelm.lan", "pi-desktop.darkhelm.lan", ] publisher_host = "kankali.darkhelm.lan" # Pull upstream tags on the registry host, publish mirror tags there, then verify pullability on every host. remote_code_template = """ mirror_pairs = [ ("ACT_UBUNTU", "ghcr.io/catthehacker/ubuntu:act-latest", "kankali.darkhelm.lan:3001/darkhelm.org/act-ubuntu:act-latest"), ("RENOVATE", "ghcr.io/renovatebot/renovate:41", "kankali.darkhelm.lan:3001/darkhelm.org/renovate:41"), ("PLAYWRIGHT", "mcr.microsoft.com/playwright:v1.56.1-jammy", "kankali.darkhelm.lan:3001/darkhelm.org/playwright-browsers:v1.56.1-jammy"), ] is_publisher = __IS_PUBLISHER__ def classify_failure(prefix, log_path): mismatch = !(grep -qi "http response to https client" @(log_path)) if mismatch.returncode == 0: print(f"{prefix}:https-mismatch") else: print(f"{prefix}:failed") tail = !(tail -n 20 @(log_path) 2> /dev/null) if tail.returncode == 0 and str(tail.out).strip(): print(f"{prefix}_LOG_START") print(str(tail.out).rstrip()) print(f"{prefix}_LOG_END") def image_present(image): result = !(docker image inspect @(image) > /dev/null 2>&1) return result.returncode == 0 ubuntu_pull_log = "/tmp/ubuntu22-pull.log" ubuntu_pull = !(docker pull ubuntu:22.04 > @(ubuntu_pull_log) 2>&1) if ubuntu_pull.returncode == 0: print("UBUNTU22_PULL:ok") else: classify_failure("UBUNTU22_PULL", ubuntu_pull_log) if image_present("ubuntu:22.04"): print("UBUNTU22_PRESENT") else: print("UBUNTU22_MISSING") for label, source_image, mirror_image in mirror_pairs: print(f"{label}_SOURCE={source_image}") print(f"{label}_MIRROR={mirror_image}") src_pull_log = f"/tmp/{label.lower()}-source-pull.log" mirror_push_log = f"/tmp/{label.lower()}-mirror-push.log" mirror_verify_log = f"/tmp/{label.lower()}-mirror-verify.log" if is_publisher: src_pull = !(docker pull @(source_image) > @(src_pull_log) 2>&1) if src_pull.returncode == 0: print(f"{label}_SOURCE_PULL:ok") else: classify_failure(f"{label}_SOURCE_PULL", src_pull_log) continue tag = !(docker tag @(source_image) @(mirror_image) > /dev/null 2>&1) if tag.returncode != 0: print(f"{label}_TAG:failed") continue push = !(docker push @(mirror_image) > @(mirror_push_log) 2>&1) if push.returncode == 0: print(f"{label}_MIRROR_PUSH:ok") else: classify_failure(f"{label}_MIRROR_PUSH", mirror_push_log) continue else: print(f"{label}_SOURCE_PULL:skipped") print(f"{label}_MIRROR_PUSH:skipped") # Validate mirror pullability with this host's Docker registry config. rm_image = !(docker image rm @(mirror_image) > /dev/null 2>&1) verify = !(docker pull @(mirror_image) > @(mirror_verify_log) 2>&1) if verify.returncode == 0: print(f"{label}_MIRROR_PULL:ok") else: classify_failure(f"{label}_MIRROR_PULL", mirror_verify_log) if image_present(mirror_image): print(f"{label}_MIRROR_PRESENT") else: print(f"{label}_MIRROR_MISSING") """ for host in hosts: print(f"\n=== {host} ===") remote_code = remote_code_template.replace("__IS_PUBLISHER__", "True" if host == publisher_host else "False") ssh @(host) @(remote_code)