-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathTaskfile.yml
More file actions
283 lines (257 loc) · 11.3 KB
/
Copy pathTaskfile.yml
File metadata and controls
283 lines (257 loc) · 11.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
version: "3"
vars:
# Everything deployment-shaped lives under deploy/. Compose resolves the
# relative paths inside these files against the directory holding them, so
# -f is all that is needed — the volume paths stay readable from deploy/.
COMPOSE: "docker compose -f deploy/docker-compose.yml"
COMPOSE_DEV: "docker compose -f deploy/docker-compose.dev.yml"
# The three files the deployed stand actually runs on: tiers, telemetry, and
# the public entry point. Named here because the combination is what has been
# running for weeks while the documentation described a one-file command —
# anyone rebuilding from the docs got a smaller stack, silently, with no
# Grafana and no public TLS.
COMPOSE_DEV_FULL: "docker compose -f deploy/docker-compose.dev.yml -f deploy/docker-compose.observability.yml -f deploy/docker-compose.public.yml"
tasks:
certs:
desc: "Generate the development CA and the server/client/edge certificates in deploy/certs/"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- "./deploy/scripts/gen-dev-certs.sh"
up:
desc: "Start all services. For Enterprise: LICENSE_PUBLIC_KEYS=<kid>:<hex> LICENSE_KEY=... task up"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.yml"
cmds:
# The stack speaks mTLS; without certificates the service refuses to start.
- task: certs
- "{{.COMPOSE}} up --build --remove-orphans --detach"
up-minimal:
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.yml"
cmds:
- "sh -c 'EASYP_POSTGRES_PORT=${EASYP_POSTGRES_PORT:-5433} {{.COMPOSE}} up -d postgres'"
down:
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.yml"
cmds:
- "{{.COMPOSE}} down --volumes"
deploy-dev:
desc: "Sync deploy/ to the dev stand and roll the two tiers (HOST=user@host)"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- sh: 'test -n "{{.HOST}}"'
msg: "HOST is required: task deploy-dev HOST=user@host"
cmds:
- deploy/scripts/deploy-dev.sh "{{.HOST}}"
up-dev:
desc: "Start community and enterprise side by side (8080-8083 / 9080-9083)"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.dev.yml"
# Without a licence the enterprise container starts, reports community and
# serves happily — which makes the stack look fine while testing nothing
# the stack exists to test. Refuse instead.
- sh: "test -f deploy/.env.dev"
msg: "deploy/.env.dev not found. Copy deploy/.env.dev.example to deploy/.env.dev — it carries the development licence."
cmds:
# Both tiers sit behind traefik, which speaks mTLS to them.
- task: certs
- "{{.COMPOSE_DEV}} --env-file deploy/.env.dev up --remove-orphans --detach"
- |
echo
echo " community localhost:8080-8083 community.easyp.localhost easyp_community_db"
echo " enterprise localhost:9080-9083 enterprise.easyp.localhost easyp_enterprise_db"
echo
echo "Confirm the tiers actually differ before trusting the stack:"
echo " task tier-dev"
up-dev-full:
desc: "Start both tiers with telemetry and the public entry point — what the deployed stand runs"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.dev.yml"
- sh: "test -f deploy/.env.dev"
msg: "deploy/.env.dev not found. Copy deploy/.env.dev.example to deploy/.env.dev — it carries the development licence."
# The overlay requires these through `${VAR:?}`, so a missing one fails
# somewhere inside compose rather than here. Named up front instead.
- sh: "grep -q '^OBS_S3_ACCESS_KEY_ID=.' deploy/.env.dev"
msg: "deploy/.env.dev has no OBS_S3_* keys. The observability overlay stores metrics, logs, traces and profiles in object storage and will not start without them. They were TELEMETRY_S3_* before v0.13.0."
cmds:
- task: certs
- "{{.COMPOSE_DEV_FULL}} --env-file deploy/.env.dev up --remove-orphans --detach"
- |
echo
echo " community localhost:8080-8083 enterprise localhost:9080-9083"
echo " grafana localhost:3000"
echo
echo "Confirm the tiers actually differ before trusting the stack:"
echo " task tier-dev"
down-dev:
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/docker-compose.dev.yml"
cmds:
# The full set, so that `down` reaches everything `up-dev-full` started.
# With the one-file variant the six telemetry containers survive a down
# and are then adopted by the next up, which is how a stack ends up half
# from one revision and half from another.
- "{{.COMPOSE_DEV_FULL}} down --volumes"
logs-dev:
desc: "Follow both dev tiers"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- "{{.COMPOSE_DEV}} logs --follow service-community service-enterprise"
tier-dev:
desc: "Check that the dev stack's two tiers are actually different tiers"
dir: "{{.USER_WORKING_DIR}}"
cmds:
# The check itself lives in deploy/scripts/ because the deployment
# directory is copied to hosts that carry neither this file nor task.
- "./deploy/scripts/check-tiers.sh"
build-plugins:
desc: "Build all plugin binaries from registry/ Dockerfiles"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- "go run ./cmd/easyp-svc/ plugins build registry --parallel 12 --output plugins "
build-plugins-filter:
desc: "Build a subset of plugins, e.g. FILTER='protocolbuffers/*' task build-plugins-filter"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- "go run ./cmd/easyp-svc/ plugins build registry --output plugins --filter '{{.FILTER}}'"
push-plugins:
desc: "Pack and upload built plugin archives to S3 storage (rustfs in the dev stack)"
dir: "{{.USER_WORKING_DIR}}"
env:
# Credentials reach the AWS SDK default chain; the service reads its own
# from registry.s3 in config.yml.
AWS_ACCESS_KEY_ID: "rustfsadmin"
AWS_SECRET_ACCESS_KEY: "rustfsadmin"
cmds:
# The compose config points at rustfs:9000, which is unreachable from the
# host — pass the published endpoint explicitly.
- >-
go run ./cmd/easyp-svc/ plugins push
--endpoint http://localhost:9000
--bucket easyp-plugins
--region us-east-1
--force-path-style
--non-interactive
push-archives:
desc: >-
Upload a packed archive tree (from `plugins pack`) to any S3-compatible storage, e.g.
S3_ENDPOINT=https://storage.example.com AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=... task push-archives
dir: "{{.USER_WORKING_DIR}}"
vars:
ARCHIVES: '{{.ARCHIVES | default "../plugin-archives"}}'
S3_BUCKET: '{{.S3_BUCKET | default "easyp-plugins"}}'
# Storage tends to cap one connection well below the uplink, so the
# default here is high enough to saturate an ordinary link.
PARALLEL: '{{.PARALLEL | default "24"}}'
preconditions:
- sh: 'test -n "$S3_ENDPOINT"'
msg: "S3_ENDPOINT is required, e.g. S3_ENDPOINT=https://storage.example.com task push-archives"
- sh: 'test -d "{{.ARCHIVES}}"'
msg: "{{.ARCHIVES}} not found; pack first or pass ARCHIVES=<dir>"
cmds:
# Credentials are left to the AWS SDK default chain: they belong in the
# environment or a secret manager, never in this file.
- >-
go run ./cmd/easyp-svc/ plugins push {{.ARCHIVES}} --packed
--endpoint "$S3_ENDPOINT"
--bucket {{.S3_BUCKET}}
--force-path-style
--parallel {{.PARALLEL}}
register-plugins:
desc: "Register all built plugins via gRPC CreatePlugin API"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/certs/ca.crt"
cmds:
# The gRPC port is not published: the only way in is through traefik,
# which terminates the edge certificate and re-establishes mTLS inward.
# CreatePlugin is a mutating method: it needs a token whose digest is
# listed in auth.write_tokens. The default matches the throwaway token
# shipped in config.yml; set EASYP_TOKEN to override it.
- >-
go run ./cmd/easyp-svc/ plugins register
--addr easyp.api.localhost:${EASYP_TRAEFIK_TLS_PORT:-4443}
--tls-ca deploy/certs/ca.crt
--token ${EASYP_TOKEN:-local-dev-token}
--cfg deploy/config/config.yml
--non-interactive
run:
desc: "Full cycle: build plugins → restart services → register → follow logs"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- task: build-plugins
- task: down
- task: up
- "echo 'Waiting for service to be ready...' && until curl -sf http://localhost:8082/ >/dev/null 2>&1; do sleep 2; done && echo 'Service is ready!'"
- task: push-plugins
- task: register-plugins
setup:
desc: "Build plugins, start services, register plugins (no logs)"
dir: "{{.USER_WORKING_DIR}}"
cmds:
- task: build-plugins
- task: down
- task: up
- "echo 'Waiting for service to be ready...' && until curl -sf http://localhost:8082/ >/dev/null 2>&1; do sleep 2; done && echo 'Service is ready!'"
- task: push-plugins
- task: register-plugins
run-local:
desc: "Start local service and automatically migrate plugins"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/config/config.local.yml"
cmds:
- |
(
echo "Waiting for local service to be ready..."
until curl -sf http://localhost:8082/ >/dev/null 2>&1; do
sleep 1
done
echo "Service is ready! Running plugin migration..."
# config.local.yml leaves server.tls empty, so this leg is plaintext,
# and it ships the matching throwaway write token.
go run ./cmd/easyp-svc/ plugins register --addr localhost:8080 --cfg deploy/config/config.local.yml \
--non-interactive --insecure --token local-dev-token
) &
go run ./cmd/easyp-svc/ service start --cfg deploy/config/config.local.yml --log_level debug
run-local-test:
desc: "Start local service with mock plugins for testing migration CLI"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f deploy/config/config.local.yml"
cmds:
- "mkdir -p plugins/grpc/go/v1.5.1 && touch plugins/grpc/go/v1.5.1/plugin"
- "mkdir -p plugins/grpc-ecosystem/gateway/v2.27.3 && touch plugins/grpc-ecosystem/gateway/v2.27.3/plugin"
- "mkdir -p plugins/protocolbuffers/go/v1.36.10 && touch plugins/protocolbuffers/go/v1.36.10/plugin"
- defer: "rm -rf plugins/grpc plugins/grpc-ecosystem plugins/protocolbuffers"
- task: run-local
test-mcp:
dir: "{{.USER_WORKING_DIR}}"
cmds:
- "go test ./internal/api -count=1"
smoke-mcp:
dir: "{{.USER_WORKING_DIR}}"
deps:
- "up"
cmds:
- "go run ./cmd/mcp-smoke --endpoint http://localhost:8083/mcp"
generate:
desc: "Run easyp generate against locally running service (localhost:8080)"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f easyp.yaml"
cmds:
- "easyp --cfg easyp.yaml generate"
generate-local:
desc: "Run easyp generate against local service (localhost:8080)"
dir: "{{.USER_WORKING_DIR}}"
preconditions:
- "test -f easyp.local.yaml"
cmds:
- "easyp --cfg easyp.local.yaml generate"