Files
plex-playlist/scripts/gitea-actions/repair_runner_mirror.xsh
copilotcoder 3db1b0676f
Some checks failed
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Source Checks (push) Has been cancelled
CICD / Dependency Audits (Informational) (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Release Images (push) Has been cancelled
CICD / Build Tester Images (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Promote Staging Images To Release (push) Has been cancelled
CICD / Build and Push CICD Images (push) Has been cancelled
chore(ci): centralize runtime and image version constants
2026-07-22 17:38:34 -04:00

122 lines
4.1 KiB
Plaintext
Executable File

#!/usr/bin/env xonsh
from pathlib import Path
def load_ci_versions():
env_path = Path(__file__).resolve().parents[2] / "versions" / "ci.env"
values = {}
for raw_line in env_path.read_text().splitlines():
line = raw_line.strip()
if not line or line.startswith("#") or "=" not in line:
continue
key, value = line.split("=", 1)
values[key.strip()] = value.strip()
return values
ci_versions = load_ci_versions()
playwright_tag = ci_versions["PLAYWRIGHT_IMAGE_TAG"]
hosts = [
"kankali.darkhelm.lan",
"zhokq.darkhelm.lan",
"urtzul.darkhelm.lan",
"pi-desktop.darkhelm.lan",
]
publisher_host = "kankali.darkhelm.lan"
# Pull upstream tags on the registry host, publish mirror tags there, then verify pullability on every host.
remote_code_template = """
mirror_pairs = [
("ACT_UBUNTU", "ghcr.io/catthehacker/ubuntu:act-latest", "kankali.darkhelm.lan:3001/darkhelm.org/act-ubuntu:act-latest"),
("RENOVATE", "ghcr.io/renovatebot/renovate:41", "kankali.darkhelm.lan:3001/darkhelm.org/renovate:41"),
("PLAYWRIGHT", "mcr.microsoft.com/playwright:" + __PLAYWRIGHT_TAG__, "kankali.darkhelm.lan:3001/darkhelm.org/playwright-browsers:" + __PLAYWRIGHT_TAG__),
]
is_publisher = __IS_PUBLISHER__
def classify_failure(prefix, log_path):
mismatch = !(grep -qi "http response to https client" @(log_path))
if mismatch.returncode == 0:
print(f"{prefix}:https-mismatch")
else:
print(f"{prefix}:failed")
tail = !(tail -n 20 @(log_path) 2> /dev/null)
if tail.returncode == 0 and str(tail.out).strip():
print(f"{prefix}_LOG_START")
print(str(tail.out).rstrip())
print(f"{prefix}_LOG_END")
def image_present(image):
result = !(docker image inspect @(image) > /dev/null 2>&1)
return result.returncode == 0
ubuntu_pull_log = "/tmp/ubuntu22-pull.log"
ubuntu_pull = !(docker pull ubuntu:22.04 > @(ubuntu_pull_log) 2>&1)
if ubuntu_pull.returncode == 0:
print("UBUNTU22_PULL:ok")
else:
classify_failure("UBUNTU22_PULL", ubuntu_pull_log)
if image_present("ubuntu:22.04"):
print("UBUNTU22_PRESENT")
else:
print("UBUNTU22_MISSING")
for label, source_image, mirror_image in mirror_pairs:
print(f"{label}_SOURCE={source_image}")
print(f"{label}_MIRROR={mirror_image}")
src_pull_log = f"/tmp/{label.lower()}-source-pull.log"
mirror_push_log = f"/tmp/{label.lower()}-mirror-push.log"
mirror_verify_log = f"/tmp/{label.lower()}-mirror-verify.log"
if is_publisher:
src_pull = !(docker pull @(source_image) > @(src_pull_log) 2>&1)
if src_pull.returncode == 0:
print(f"{label}_SOURCE_PULL:ok")
else:
classify_failure(f"{label}_SOURCE_PULL", src_pull_log)
continue
tag = !(docker tag @(source_image) @(mirror_image) > /dev/null 2>&1)
if tag.returncode != 0:
print(f"{label}_TAG:failed")
continue
push = !(docker push @(mirror_image) > @(mirror_push_log) 2>&1)
if push.returncode == 0:
print(f"{label}_MIRROR_PUSH:ok")
else:
classify_failure(f"{label}_MIRROR_PUSH", mirror_push_log)
continue
else:
print(f"{label}_SOURCE_PULL:skipped")
print(f"{label}_MIRROR_PUSH:skipped")
# Validate mirror pullability with this host's Docker registry config.
rm_image = !(docker image rm @(mirror_image) > /dev/null 2>&1)
verify = !(docker pull @(mirror_image) > @(mirror_verify_log) 2>&1)
if verify.returncode == 0:
print(f"{label}_MIRROR_PULL:ok")
else:
classify_failure(f"{label}_MIRROR_PULL", mirror_verify_log)
if image_present(mirror_image):
print(f"{label}_MIRROR_PRESENT")
else:
print(f"{label}_MIRROR_MISSING")
"""
for host in hosts:
print(f"\n=== {host} ===")
quoted_playwright_tag = repr(playwright_tag)
remote_code = (
remote_code_template
.replace("__IS_PUBLISHER__", "True" if host == publisher_host else "False")
.replace("__PLAYWRIGHT_TAG__", quoted_playwright_tag)
)
ssh @(host) @(remote_code)