feat(infra): add release script, secrets verification, and dump subcommands to setup CLI

This commit is contained in:
Tyler Gillispie 2026-08-23 10:41:03 -07:00
parent 8a6cd6f72e
commit 26739f4b63
3 changed files with 188 additions and 1 deletions

View File

@ -10,7 +10,12 @@
"fmt": "deno fmt", "fmt": "deno fmt",
"check": "deno check server/**/*.ts sdk/**/*.ts ui/**/*.ts infra/**/*.ts", "check": "deno check server/**/*.ts sdk/**/*.ts ui/**/*.ts infra/**/*.ts",
"test": "deno test -A", "test": "deno test -A",
"setup": "deno run -A infra/setup.ts" "setup": "deno run -A infra/setup.ts",
"secrets": "deno run -A infra/setup.ts secrets",
"dump:compose": "deno run -A infra/setup.ts dump_compose",
"dump:env": "deno run -A infra/setup.ts dump_env",
"build": "deno run -A infra/setup.ts build",
"release": "./infra/release.sh"
}, },
"lint": { "lint": {
"exclude": [ "exclude": [

56
infra/release.sh Executable file
View File

@ -0,0 +1,56 @@
#!/usr/bin/env bash
# ==============================================================================
# Auth-Yes Full Infrastructure Build & Release Pipeline
# ==============================================================================
set -e
# Change to repository root
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$REPO_ROOT"
echo "================================================================"
echo " Auth-Yes Build & Release Pipeline"
echo "================================================================"
# 1. Run Pre-flight Quality Gates
echo -e "\n[1/5] Running Quality Gates..."
deno fmt --check
deno task lint
deno task check
deno task test
# 2. Compile Protobufs & Workload APIs
echo -e "\n[2/5] Compiling Protobufs..."
deno run -A infra/setup.ts compile_proto
# 3. Generate Infrastructure Artifacts (Non-Interactive / Headless)
echo -e "\n[3/5] Generating Infrastructure Configuration Artifacts..."
deno run -A infra/setup.ts auth --auto \
--registry "${REG:-quay.atyg.org}" \
--ghcr-registry "${GHCR_REG:-ghcr.atyg.org}" \
--domain "${SYSTEM_DOMAIN:-auth.atyg.org}" \
--db-path "${DB_DATA_PATH:-/volume1/docker/auth-yes/data}" \
--spire-path "${SPIRE_DATA_PATH:-/volume1/docker/spire}"
# 4. Build & Push All Container Images to Registry
echo -e "\n[4/5] Building and Pushing Container Images..."
deno run -A infra/setup.ts build
# 5. Output Summary, Persistence Topology, and Compose Stacks
echo -e "\n[5/5] Release Summary & Stack Specifications..."
deno run -A infra/setup.ts secrets
echo -e "\n----------------------------------------------------------------"
echo " GENERATED DOCKER / PODMAN COMPOSE SPECIFICATIONS"
echo "----------------------------------------------------------------"
deno run -A infra/setup.ts dump_compose
echo -e "\n================================================================"
echo " DEPLOYMENT COMMANDS"
echo "================================================================"
echo "1. Deploy SPIRE Authority Stack:"
echo " podman-compose --project-name spire --env-file infra/.env -f infra/compose.spire.yml up -d"
echo ""
echo "2. Deploy Auth-Yes IAM Stack:"
echo " podman-compose --project-name auth-yes --env-file infra/.env -f infra/compose.yml up -d"
echo "================================================================"

View File

@ -667,6 +667,132 @@ if (import.meta.main) {
} }
Deno.exit(1); Deno.exit(1);
} }
})
.command("dump_compose", "Output all generated Compose YAML configurations")
.action(() => {
console.log(
colors.bold(
colors.blue(
"\n================================================================",
),
),
);
console.log(
colors.bold(
colors.green(" STACK 1: Auth-Yes Stack (infra/compose.yml)"),
),
);
console.log(
colors.bold(
colors.blue(
"================================================================\n",
),
),
);
console.log(generateDockerCompose());
console.log(
colors.bold(
colors.blue(
"================================================================",
),
),
);
console.log(
colors.bold(
colors.green(
" STACK 2: Standalone SPIRE Stack (infra/compose.spire.yml)",
),
),
);
console.log(
colors.bold(
colors.blue(
"================================================================\n",
),
),
);
console.log(generateSpireDockerCompose());
})
.command("dump_env", "Output current environment configuration (.env)")
.action(async () => {
const loadedEnv = await readEnv();
const currentConfig: AuthSetupConfig = {
...DEFAULT_AUTH_CONFIG,
...loadedEnv,
};
console.log(
colors.bold(
colors.blue(
"\n================================================================",
),
),
);
console.log(
colors.bold(
colors.green(" ENVIRONMENT CONFIGURATION (infra/.env)"),
),
);
console.log(
colors.bold(
colors.blue(
"================================================================\n",
),
),
);
console.log(generateEnv(currentConfig));
})
.command("secrets", "Inspect secrets status and persistence paths")
.action(async () => {
const loadedEnv = await readEnv();
const currentConfig: AuthSetupConfig = {
...DEFAULT_AUTH_CONFIG,
...loadedEnv,
};
console.log(
colors.bold(
colors.blue(
"\n=== Auth-Yes Secrets & Persistence Topology ===\n",
),
),
);
console.log(
`${
colors.cyan("Database Persistence Path:")
} ${currentConfig.dbDataPath}`,
);
console.log(
`${
colors.cyan("SPIRE Persistence Path:")
} ${currentConfig.spireDataPath}`,
);
console.log(
`${
colors.cyan("Local Artifact Files:")
} ${ENV_PATH}, ${COMPOSE_PATH}, ${SPIRE_COMPOSE_PATH}`,
);
console.log(
`${colors.cyan("PostgreSQL Password:")} ${
currentConfig.dbPassword
? colors.green(
"✓ Configured (len: " + currentConfig.dbPassword.length + ")",
)
: colors.red("✗ Missing")
}`,
);
console.log(
`${colors.cyan("Application Secret:")} ${
currentConfig.appSecret
? colors.green(
"✓ Configured (len: " + currentConfig.appSecret.length + ")",
)
: colors.red("✗ Missing")
}`,
);
console.log(
colors.gray(
"\nTip: To dump raw environment variables, run: deno run -A infra/setup.ts dump_env\n",
),
);
}); });
await cmd.parse(Deno.args); await cmd.parse(Deno.args);