diff --git a/python/deploy.py b/python/deploy.py index 1e7f2b1..3eb3243 100644 --- a/python/deploy.py +++ b/python/deploy.py @@ -139,13 +139,18 @@ http {{ print(f"[{name}] Registering node...") r = run(f"bash -c 'source {DEPLOY_TO}/env.list 2>/dev/null; {DEPLOY_TO}/register-node job:register -token {token} -host {api_host}'", timeout=120) - if r.returncode != 0 and "node instance registered" not in r.stdout: - print(f"Registration output:\n{r.stdout}\n{r.stderr}") - # Not fatal — check if UUID assigned - if not os.path.exists(f"{DEPLOY_TO}/etc/wallarm/node.yaml"): - raise RuntimeError(f"Registration failed: {r.stderr or r.stdout}") + # Check for success indicators + registered = "node instance registered" in r.stdout or "init done" in r.stdout + access_denied = "access denied" in r.stdout + r.stderr + invalid_token = "invalid token" in (r.stdout + r.stderr).lower() - # Move to instance + if access_denied or invalid_token: + raise RuntimeError("Token rejected by Wallarm. Check token permissions and cloud region.") + if not registered: + raise RuntimeError(f"Registration failed:\n{r.stdout[-500:]}\n{r.stderr[-500:]}") + + # Kill deploy nginx + move to instance + run(f"pkill -9 -f '{DEPLOY_TO}/nginx' 2>/dev/null; true", timeout=5) print(f"[{name}] Installing...") shutil.rmtree(instance, ignore_errors=True) os.makedirs(os.path.dirname(instance), exist_ok=True) @@ -383,6 +388,7 @@ def main(): elif c.lower() == "q": break def deploy_all(): + print("Deploying all from fw.conf...") cfg = load_config() for name, nc in cfg.get("nodes", {}).items(): if is_deployed(name):