49 lines
1.8 KiB
Bash
Executable File
49 lines
1.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
|
|
set -euo pipefail
|
|
|
|
project_dir=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
|
|
namespace=plex
|
|
service_account=plex-deployer
|
|
secret=plex-deployer-token
|
|
|
|
if [[ "$(kubectl config current-context)" != kubernetes-admin@kubernetes ]]; then
|
|
echo 'Run this only with the kubernetes-admin@kubernetes homelab context.' >&2
|
|
exit 1
|
|
fi
|
|
kubectl apply --filename "${project_dir}/namespace.yaml" >&2
|
|
kubectl apply --filename "${project_dir}/ci-deployer.yaml" >&2
|
|
|
|
for attempt in {1..30}; do
|
|
if kubectl --namespace "${namespace}" get secret "${secret}" \
|
|
--output=jsonpath='{.data.token}' 2>/dev/null | grep -q .; then
|
|
break
|
|
fi
|
|
if [[ "${attempt}" == 30 ]]; then
|
|
echo 'Timed out waiting for the service-account token.' >&2
|
|
exit 1
|
|
fi
|
|
sleep 1
|
|
done
|
|
|
|
workdir=$(mktemp --directory)
|
|
trap 'rm -rf "${workdir}"' EXIT
|
|
server=$(kubectl config view --minify --output=jsonpath='{.clusters[0].cluster.server}')
|
|
kubectl --namespace "${namespace}" get secret "${secret}" \
|
|
--output=jsonpath='{.data.ca\.crt}' | base64 --decode > "${workdir}/ca.crt"
|
|
token=$(kubectl --namespace "${namespace}" get secret "${secret}" \
|
|
--output=jsonpath='{.data.token}' | base64 --decode)
|
|
|
|
export KUBECONFIG="${workdir}/config"
|
|
kubectl config set-cluster cluster --server="${server}" \
|
|
--certificate-authority="${workdir}/ca.crt" --embed-certs=true >/dev/null
|
|
kubectl config set-credentials "${service_account}" --token="${token}" >/dev/null
|
|
kubectl config set-context plex --cluster=cluster --user="${service_account}" \
|
|
--namespace="${namespace}" >/dev/null
|
|
kubectl config use-context plex >/dev/null
|
|
|
|
echo 'Store this single line as the Gitea Actions secret KUBE_CONFIG_BASE64.' >&2
|
|
echo 'Treat it as a password; do not commit it.' >&2
|
|
base64 --wrap=0 "${KUBECONFIG}"
|
|
printf '\n'
|