propellor/src/Propellor/Property/SiteSpecific/GitAnnexBuilder.hs

144 lines
5.4 KiB
Haskell
Raw Normal View History

2014-04-01 20:58:11 +00:00
module Propellor.Property.SiteSpecific.GitAnnexBuilder where
import Propellor
import qualified Propellor.Property.Apt as Apt
import qualified Propellor.Property.User as User
2014-04-01 22:06:02 +00:00
import qualified Propellor.Property.Cron as Cron
2014-05-23 01:42:57 +00:00
import qualified Propellor.Property.Ssh as Ssh
2014-05-20 22:49:03 +00:00
import qualified Propellor.Property.File as File
2014-05-23 01:42:57 +00:00
import qualified Propellor.Property.Docker as Docker
2014-04-01 20:58:11 +00:00
import Propellor.Property.Cron (CronTimes)
builduser :: UserName
builduser = "builder"
2014-04-08 05:42:59 +00:00
homedir :: FilePath
homedir = "/home/builder"
gitbuilderdir :: FilePath
gitbuilderdir = homedir </> "gitbuilder"
2014-04-01 20:58:11 +00:00
builddir :: FilePath
2014-04-08 05:42:59 +00:00
builddir = gitbuilderdir </> "build"
2014-04-01 20:58:11 +00:00
2014-05-19 21:27:21 +00:00
type TimeOut = String -- eg, 5h
builder :: Architecture -> CronTimes -> TimeOut -> Bool -> Property
2014-05-20 22:28:13 +00:00
builder = builder' buildDeps
builder' :: Property -> Architecture -> CronTimes -> TimeOut -> Bool -> Property
builder' buildepsprop buildarch crontimes timeout rsyncupload = combineProperties "gitannexbuilder"
[ tree buildarch
, buildepsprop
2014-04-08 23:31:03 +00:00
, Apt.serviceInstalledRunning "cron"
2014-05-19 21:27:21 +00:00
, Cron.niceJob "gitannexbuilder" crontimes builduser gitbuilderdir $
"git pull ; timeout " ++ timeout ++ " ./autobuild"
2014-04-01 20:58:11 +00:00
-- The builduser account does not have a password set,
-- instead use the password privdata to hold the rsync server
-- password used to upload the built image.
, property "rsync password" $ do
2014-04-08 05:42:59 +00:00
let f = homedir </> "rsyncpassword"
if rsyncupload
then withPrivData (Password builduser) $ \p -> do
oldp <- liftIO $ catchDefaultIO "" $
readFileStrict f
if p /= oldp
then makeChange $ writeFile f p
else noChange
else do
ifM (liftIO $ doesFileExist f)
( noChange
, makeChange $ writeFile f "no password configured"
)
2014-04-01 20:58:11 +00:00
]
2014-05-19 21:27:21 +00:00
2014-05-20 22:28:13 +00:00
tree :: Architecture -> Property
tree buildarch = combineProperties "gitannexbuilder tree"
[ User.accountFor builduser
, Apt.installed ["git"]
2014-05-21 16:58:53 +00:00
-- gitbuilderdir directory already exists when docker volume is used,
-- but with wrong owner.
, File.dirExists gitbuilderdir
, File.ownerGroup gitbuilderdir builduser builduser
, check (not <$> (doesDirectoryExist (gitbuilderdir </> ".git"))) $
userScriptProperty builduser
[ "git clone git://git.kitenet.net/gitannexbuilder " ++ gitbuilderdir
, "cd " ++ gitbuilderdir
, "git checkout " ++ buildarch
]
`describe` "gitbuilder setup"
2014-05-19 21:27:21 +00:00
, check (not <$> doesDirectoryExist builddir) $ userScriptProperty builduser
[ "git clone git://git-annex.branchable.com/ " ++ builddir
]
2014-05-20 22:28:13 +00:00
]
buildDeps :: Property
buildDeps = combineProperties "gitannexbuilder build deps"
2014-05-20 23:49:07 +00:00
[ Apt.buildDep ["git-annex"]
2014-05-20 22:28:13 +00:00
, buildDepsNoHaskellLibs
2014-05-19 21:27:21 +00:00
, "git-annex source build deps installed" ==> Apt.buildDepIn builddir
]
2014-05-20 22:28:13 +00:00
buildDepsNoHaskellLibs :: Property
buildDepsNoHaskellLibs = Apt.installed ["git", "rsync", "moreutils", "ca-certificates",
"debhelper", "ghc", "curl", "openssh-client", "git-remote-gcrypt",
2014-05-20 23:49:07 +00:00
"liblockfile-simple-perl", "cabal-install", "vim", "less",
"alex", "happy", "c2hs",
-- these haskell libs depend on C libs and don't use TH
"libghc-dbus-dev", "libghc-fdo-notify-dev", "libghc-network-protocol-xmpp-dev"
]
2014-05-20 22:28:13 +00:00
2014-05-19 21:27:21 +00:00
-- Installs current versions of git-annex's deps from cabal, but only
-- does so once.
cabalDeps :: Property
cabalDeps = flagFile go cabalupdated
where
go = userScriptProperty builduser ["cabal update && cabal install git-annex --only-dependencies || true"]
cabalupdated = homedir </> ".cabal" </> "packages" </> "hackage.haskell.org" </> "00-index.cache"
2014-05-23 01:42:57 +00:00
standardContainer :: (System -> Docker.Image) -> Architecture -> Int -> TimeOut -> Host
standardContainer dockerImage arch buildminute timeout = Docker.container (arch ++ "-git-annex-builder")
(dockerImage $ System (Debian Unstable) arch)
& Apt.stdSourcesList Unstable
& Apt.unattendedUpgrades
& builder arch (show buildminute ++ " * * * *") timeout True
-- armel builder has a companion container using amd64 that
-- runs the build first to get TH splices. They need
-- to have the same versions of all haskell libraries installed.
armelCompanionContainer :: (System -> Docker.Image) -> Host
armelCompanionContainer dockerImage = Docker.container "armel-git-annex-builder-companion"
(dockerImage $ System (Debian Unstable) "amd64")
& Apt.stdSourcesList Unstable
& Apt.unattendedUpgrades
-- This volume is shared with the armel builder.
& Docker.volume gitbuilderdir
-- Install current versions of build deps from cabal.
& tree "armel"
& buildDepsNoHaskellLibs
& cabalDeps
2014-05-23 14:46:25 +00:00
-- The armel builder can ssh to this companion.
2014-05-23 01:42:57 +00:00
& Docker.expose "22"
& Apt.serviceInstalledRunning "ssh"
& Ssh.authorizedKeys builduser
armelContainer :: (System -> Docker.Image) -> Cron.CronTimes -> TimeOut -> Host
armelContainer dockerImage crontimes timeout = Docker.container "armel-git-annex-builder"
(dockerImage $ System (Debian Unstable) "armel")
& Apt.stdSourcesList Unstable
& Apt.unattendedUpgrades
& Apt.installed ["openssh-client"]
& Docker.link "armel-git-annex-builder-companion" "companion"
& Docker.volumes_from "armel-git-annex-builder-companion"
-- TODO: automate installing haskell libs
-- (Currently have to run
-- git-annex/standalone/linux/install-haskell-packages
-- which is not fully automated.)
& builder' buildDepsNoHaskellLibs "armel" crontimes timeout True
& Ssh.keyImported SshRsa builduser
2014-05-23 14:46:25 +00:00
& trivial writecompanionaddress
where
writecompanionaddress = scriptProperty
[ "echo \"$COMPANION_PORT_22_TCP_ADDR\" > " ++ homedir </> "companion_address"
2014-05-23 16:30:25 +00:00
] `describe` "companion_address file"