#!/usr/bin/env bash set -euo pipefail export LC_ALL=C script_dir=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd) bundle_root=$(cd "$script_dir/../.." && pwd) env_file= allow_local_images=false usage() { cat <<'EOF' Usage: deploy/docker/deploy.sh [env-file] [--allow-local-images] Use --allow-local-images only with a SHA256-verified production bundle whose application images were loaded from its images/ archive. EOF } while (($#)); do case $1 in --allow-local-images) allow_local_images=true shift ;; -h | --help) usage exit 0 ;; -*) echo "unknown option: $1" >&2 usage >&2 exit 2 ;; *) if [[ -n $env_file ]]; then echo "only one env file may be specified" >&2 usage >&2 exit 2 fi env_file=$1 shift ;; esac done env_file=${env_file:-$bundle_root/.env} if ! env_file=$(realpath -e -- "$env_file"); then echo "environment file does not exist: $env_file" >&2 exit 1 fi if [[ -f $bundle_root/SHA256SUMS ]]; then (cd "$bundle_root" && sha256sum -c SHA256SUMS) elif [[ $allow_local_images == true ]]; then echo "--allow-local-images requires a SHA256-verified production bundle" >&2 exit 1 fi preflight_args=() if [[ $allow_local_images == true ]]; then preflight_args+=(--allow-local-images) fi "$script_dir/preflight.sh" "${preflight_args[@]}" "$env_file" compose=(docker compose --env-file "$env_file" -f "$script_dir/docker-compose.prod.yml") "${compose[@]}" config --quiet "${compose[@]}" --profile ops run --rm migrate "${compose[@]}" up -d --wait echo "production deployment is ready"