Publish the reviewed allowlisted snapshot whose exact binary completed maintenance deployment, rollback, and reactivation exercises for Gamertan and Sandwich Hime. Private-Source-Commit: 4d7094c8b7c61991bfb67b11fc1558724c874eb2 Private-Source-Tree: 54a2f74804f7acddf3755d7d4da5b97f5fc28381 AI-Assistance: OpenAI Codex assisted implementation, testing, security review, and release verification. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
25 lines
1.3 KiB
Bash
Executable File
25 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
set -euo pipefail
|
|
root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
|
cd "$root"
|
|
./scripts/check-licenses.sh
|
|
go test -count=1 ./...
|
|
go test -race -count=1 ./...
|
|
go vet ./...
|
|
for script in scripts/*.sh; do bash -n "$script"; done
|
|
work=$(mktemp -d); trap 'rm -rf -- "$work"' EXIT
|
|
GOWORK=off CGO_ENABLED=0 go build -mod=readonly -trimpath -o "$work/tend-1" ./cmd/tend
|
|
GOWORK=off CGO_ENABLED=0 go build -mod=readonly -trimpath -o "$work/tend-2" ./cmd/tend
|
|
cmp "$work/tend-1" "$work/tend-2"
|
|
"$work/tend-1" check --config "$root/examples/blue-green/tend.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/singleton/tend.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/server/services/example-site.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/examples/server/services/docs-site.json" >/dev/null
|
|
"$work/tend-1" check --config "$root/release/tend.json" >/dev/null
|
|
grep -Fqx 'Defaults:tend-deploy env_keep += "SSH_ORIGINAL_COMMAND"' "$root/examples/server/tend-receive.sudoers"
|
|
grep -Fqx 'tend-deploy ALL=(root) NOPASSWD: /usr/local/bin/tend receive --policy /etc/tend/receive-policy.json' "$root/examples/server/tend-receive.sudoers"
|
|
[[ $(GOWORK=off go list -m all | wc -l) -eq 1 ]]
|
|
git diff --check
|
|
echo "Tend verification passed"
|