fix: deploy to real /opt/wallarm, then move to /opt/fw/{name}/wallarm
No symlinks, no path patching. Setup.sh runs in its native environment. After success, os.Rename moves everything to the instance directory.
This commit is contained in:
parent
9cf6a2a66b
commit
d405c98ff8
1 changed files with 67 additions and 64 deletions
|
|
@ -12,7 +12,7 @@ import (
|
||||||
|
|
||||||
const (
|
const (
|
||||||
BaseDir = "/opt/fw"
|
BaseDir = "/opt/fw"
|
||||||
Symlink = "/opt/wallarm"
|
DeployTo = "/opt/wallarm" // setup.sh hardcodes this, deploy here then move
|
||||||
)
|
)
|
||||||
|
|
||||||
func installerURL() string {
|
func installerURL() string {
|
||||||
|
|
@ -31,46 +31,15 @@ func InstallNode(node state.Node, apiToken, apiHost, labels string) error {
|
||||||
instanceDir := filepath.Join(BaseDir, node.Name, "wallarm")
|
instanceDir := filepath.Join(BaseDir, node.Name, "wallarm")
|
||||||
installerPath := filepath.Join(BaseDir, "wallarm-aio.sh")
|
installerPath := filepath.Join(BaseDir, "wallarm-aio.sh")
|
||||||
|
|
||||||
// 1. Per-instance NGINX: copy binary, write config, start
|
// 1. Prepare clean /opt/wallarm for this deployment
|
||||||
nginxDir := filepath.Join(instanceDir, "nginx")
|
os.RemoveAll(DeployTo)
|
||||||
copyNginx(instanceDir)
|
os.MkdirAll(DeployTo, 0755)
|
||||||
|
|
||||||
// Write nginx.conf for this instance
|
// 2. Per-instance NGINX into /opt/wallarm
|
||||||
port := "80"
|
copyNginx(DeployTo)
|
||||||
if idx := strings.LastIndex(node.Address, ":"); idx != -1 {
|
startNginx(DeployTo, node)
|
||||||
port = node.Address[idx+1:]
|
|
||||||
}
|
|
||||||
nginxConf := filepath.Join(nginxDir, "conf", "nginx.conf")
|
|
||||||
os.MkdirAll(filepath.Dir(nginxConf), 0755)
|
|
||||||
os.WriteFile(nginxConf, []byte(fmt.Sprintf(`
|
|
||||||
worker_processes auto;
|
|
||||||
pid %s/nginx.pid;
|
|
||||||
error_log %s/error.log;
|
|
||||||
events { worker_connections 10240; }
|
|
||||||
http {
|
|
||||||
access_log %s/access.log;
|
|
||||||
server {
|
|
||||||
listen %s;
|
|
||||||
server_name _;
|
|
||||||
allow 127.0.0.0/8;
|
|
||||||
deny all;
|
|
||||||
wallarm_mode off;
|
|
||||||
access_log off;
|
|
||||||
location /wallarm-status { wallarm_status on; }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
`, nginxDir, nginxDir, nginxDir, port)), 0644)
|
|
||||||
|
|
||||||
// Start NGINX for this instance
|
// 3. Download AIO once
|
||||||
nginxBin := filepath.Join(nginxDir, "sbin", "nginx")
|
|
||||||
startCmd := exec.Command(nginxBin, "-c", nginxConf, "-p", nginxDir)
|
|
||||||
startCmd.Dir = nginxDir
|
|
||||||
if out, err := startCmd.CombinedOutput(); err != nil {
|
|
||||||
fmt.Printf("[%s] NGINX start warning: %v\n%s\n", node.Name, err, string(out))
|
|
||||||
}
|
|
||||||
fmt.Printf("[%s] NGINX started on port %s\n", node.Name, port)
|
|
||||||
|
|
||||||
// 2. Download AIO once
|
|
||||||
if _, err := os.Stat(installerPath); os.IsNotExist(err) {
|
if _, err := os.Stat(installerPath); os.IsNotExist(err) {
|
||||||
fmt.Printf("[%s] Downloading installer...\n", node.Name)
|
fmt.Printf("[%s] Downloading installer...\n", node.Name)
|
||||||
cmd := exec.Command("curl", "-fsSL", "-o", installerPath, installerURL())
|
cmd := exec.Command("curl", "-fsSL", "-o", installerPath, installerURL())
|
||||||
|
|
@ -80,28 +49,22 @@ http {
|
||||||
os.Chmod(installerPath, 0755)
|
os.Chmod(installerPath, 0755)
|
||||||
}
|
}
|
||||||
|
|
||||||
// 3. Extract AIO to instance
|
// 4. Extract AIO to /opt/wallarm
|
||||||
fmt.Printf("[%s] Extracting...\n", node.Name)
|
fmt.Printf("[%s] Extracting...\n", node.Name)
|
||||||
cmd := exec.Command("bash", installerPath, "--noexec", "--keep", "--target", instanceDir, "--noprogress", "--accept")
|
cmd := exec.Command("bash", installerPath, "--noexec", "--keep", "--target", DeployTo, "--noprogress", "--accept")
|
||||||
if out, err := cmd.CombinedOutput(); err != nil {
|
if out, err := cmd.CombinedOutput(); err != nil {
|
||||||
return fmt.Errorf("extract: %w\n%s", err, string(out))
|
return fmt.Errorf("extract: %w\n%s", err, string(out))
|
||||||
}
|
}
|
||||||
|
|
||||||
// 4. Patch setup.sh to use instance path (bypasses /opt/wallarm hardcoding)
|
// 5. Run setup.sh natively
|
||||||
setupPath := filepath.Join(instanceDir, "setup.sh")
|
|
||||||
exec.Command("sed", "-i",
|
|
||||||
fmt.Sprintf("s|/opt/wallarm|%s|g", instanceDir),
|
|
||||||
setupPath).Run()
|
|
||||||
|
|
||||||
// 5. Run setup.sh
|
|
||||||
fmt.Printf("[%s] Running setup...\n", node.Name)
|
fmt.Printf("[%s] Running setup...\n", node.Name)
|
||||||
cmd = exec.Command("bash", filepath.Join(instanceDir, "setup.sh"),
|
cmd = exec.Command("bash", filepath.Join(DeployTo, "setup.sh"),
|
||||||
"--batch", "--token", apiToken, "--cloud", cloudFromHost(apiHost),
|
"--batch", "--token", apiToken, "--cloud", cloudFromHost(apiHost),
|
||||||
"--custom-ngx-build",
|
"--custom-ngx-build",
|
||||||
)
|
)
|
||||||
cmd.Dir = instanceDir
|
cmd.Dir = DeployTo
|
||||||
|
|
||||||
logFile, _ := os.Create(filepath.Join(instanceDir, "install.log"))
|
logFile, _ := os.Create(filepath.Join(DeployTo, "install.log"))
|
||||||
if logFile != nil {
|
if logFile != nil {
|
||||||
cmd.Stdout = logFile
|
cmd.Stdout = logFile
|
||||||
cmd.Stderr = logFile
|
cmd.Stderr = logFile
|
||||||
|
|
@ -111,7 +74,7 @@ http {
|
||||||
logFile.Close()
|
logFile.Close()
|
||||||
}
|
}
|
||||||
if runErr != nil {
|
if runErr != nil {
|
||||||
if data, _ := os.ReadFile(filepath.Join(instanceDir, "install.log")); len(data) > 0 {
|
if data, _ := os.ReadFile(filepath.Join(DeployTo, "install.log")); len(data) > 0 {
|
||||||
lines := strings.Split(string(data), "\n")
|
lines := strings.Split(string(data), "\n")
|
||||||
s := len(lines) - 5
|
s := len(lines) - 5
|
||||||
if s < 0 {
|
if s < 0 {
|
||||||
|
|
@ -122,16 +85,22 @@ http {
|
||||||
return fmt.Errorf("setup failed: %v", runErr)
|
return fmt.Errorf("setup failed: %v", runErr)
|
||||||
}
|
}
|
||||||
|
|
||||||
fmt.Printf("[%s] Done.\n", node.Name)
|
// 6. Move /opt/wallarm → /opt/fw/{name}/wallarm
|
||||||
|
os.MkdirAll(BaseDir+"/"+node.Name, 0755)
|
||||||
|
os.RemoveAll(instanceDir)
|
||||||
|
if err := os.Rename(DeployTo, instanceDir); err != nil {
|
||||||
|
return fmt.Errorf("move to instance dir: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Printf("[%s] Done. Installed to %s\n", node.Name, instanceDir)
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func copyNginx(instanceDir string) {
|
func copyNginx(dir string) {
|
||||||
dst := filepath.Join(instanceDir, "nginx", "sbin", "nginx")
|
dst := filepath.Join(dir, "nginx", "sbin", "nginx")
|
||||||
if _, err := os.Stat(dst); err == nil {
|
if _, err := os.Stat(dst); err == nil {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
fmt.Println("Installing NGINX per instance...")
|
|
||||||
os.MkdirAll(filepath.Dir(dst), 0755)
|
os.MkdirAll(filepath.Dir(dst), 0755)
|
||||||
if path, err := exec.LookPath("nginx"); err == nil {
|
if path, err := exec.LookPath("nginx"); err == nil {
|
||||||
exec.Command("cp", path, dst).Run()
|
exec.Command("cp", path, dst).Run()
|
||||||
|
|
@ -160,9 +129,43 @@ func cloudFromHost(host string) string {
|
||||||
|
|
||||||
func CreateNodesDir() error { return os.MkdirAll(BaseDir, 0755) }
|
func CreateNodesDir() error { return os.MkdirAll(BaseDir, 0755) }
|
||||||
func GenerateSystemdTemplate() error { return nil }
|
func GenerateSystemdTemplate() error { return nil }
|
||||||
func RemoveNode(name string) error {
|
func RemoveNode(name string) error { return nil }
|
||||||
exec.Command("systemctl", "stop", "wallarm-node@"+name).Run()
|
|
||||||
exec.Command("systemctl", "disable", "wallarm-node@"+name).Run()
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
func Status(name string) (string, error) { return "", nil }
|
func Status(name string) (string, error) { return "", nil }
|
||||||
|
|
||||||
|
func startNginx(dir string, node state.Node) {
|
||||||
|
nginxDir := filepath.Join(dir, "nginx")
|
||||||
|
port := "80"
|
||||||
|
if idx := strings.LastIndex(node.Address, ":"); idx != -1 {
|
||||||
|
port = node.Address[idx+1:]
|
||||||
|
}
|
||||||
|
confDir := filepath.Join(nginxDir, "conf")
|
||||||
|
os.MkdirAll(confDir, 0755)
|
||||||
|
confPath := filepath.Join(confDir, "nginx.conf")
|
||||||
|
os.WriteFile(confPath, []byte(fmt.Sprintf(`
|
||||||
|
worker_processes auto;
|
||||||
|
pid %s/nginx.pid;
|
||||||
|
error_log %s/error.log;
|
||||||
|
events { worker_connections 10240; }
|
||||||
|
http {
|
||||||
|
access_log %s/access.log;
|
||||||
|
server {
|
||||||
|
listen %s;
|
||||||
|
server_name _;
|
||||||
|
allow 127.0.0.0/8;
|
||||||
|
deny all;
|
||||||
|
wallarm_mode off;
|
||||||
|
access_log off;
|
||||||
|
location /wallarm-status { wallarm_status on; }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
`, nginxDir, nginxDir, nginxDir, port)), 0644)
|
||||||
|
|
||||||
|
bin := filepath.Join(nginxDir, "sbin", "nginx")
|
||||||
|
cmd := exec.Command(bin, "-c", confPath, "-p", nginxDir)
|
||||||
|
cmd.Dir = nginxDir
|
||||||
|
if out, err := cmd.CombinedOutput(); err != nil {
|
||||||
|
fmt.Printf("[%s] NGINX start: %v\n%s\n", node.Name, err, string(out))
|
||||||
|
} else {
|
||||||
|
fmt.Printf("[%s] NGINX started on port %s\n", node.Name, port)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue