Compare commits

..

27 Commits

Author SHA1 Message Date
Bo-Yi Wu 69b3a40978 update drone-docker plugin. (#107)
* update drone-docker plugin.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* add testing

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* add testing

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* add testing

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-11-09 23:32:01 -06:00
Damian Kaczmarek 4d443c40f2 fix: ssh process error not resulting in pipeline error (#105)
* fix: ssh process error not resulting in pipeline error

* Update main.go
2017-11-09 20:47:15 -06:00
Bo-Yi Wu 9dd4b8db8d add arm arm64 and amd64 build. (#106)
* add arm arm64 and amd64 build.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* add release folder to ignore list.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-11-09 20:12:30 -06:00
Damian Kaczmarek 45f43d7ffd fix: escaping special characters when passing env to ssh (#104) 2017-11-09 19:01:28 -06:00
Bo-Yi Wu 7220c94832 Add sync mode. (#101)
* Add sync mode.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* close channel in sync mode.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* close channel in sync mode.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-10-29 21:31:51 -05:00
Bo-Yi Wu 2d5668ff17 Update document for mount key path. (#100)
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-10-29 20:46:16 -05:00
Bo-Yi Wu 6f1ace35bf add build number for drone.
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-09-04 17:22:52 +08:00
Bo-Yi Wu 05ebe5b663 update docs
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-09-04 14:40:20 +08:00
Bo-Yi Wu e331f975ad update docs.
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-09-04 14:38:04 +08:00
Bo-Yi Wu f943ff7179 update dockerfile. (#99)
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-19 21:48:30 +08:00
Bo-Yi Wu 65e15c4aab update gopath (#98)
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-19 21:45:07 +08:00
Bo-Yi Wu 83273b5669 add cloc command
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-19 21:35:53 +08:00
Bo-Yi Wu a8392b5f22 fix typo
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-15 15:01:51 +08:00
Bo-Yi Wu e057a699a4 refactor: add group build for drone. (#97)
* refactor: add group build for drone.

* remove codecov_token

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* fix format

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* fix path

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-15 14:52:35 +08:00
Bo-Yi Wu 14fddbbba5 feat: add multiple stage build for docker. (#96)
* feat: add multiple stage build for docker.

* remove unused target

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-15 14:23:25 +08:00
Bo-Yi Wu 5fbd22f265 refactor(Makefile): allow overriding default go program (#95)
* refactor(Makefile): allow overriding default go program

* fix typo

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-15 14:05:11 +08:00
Bo-Yi Wu bf269615ce update docs (#94)
* update docs

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>

* [ci skip] add username secret.

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-13 23:06:31 +08:00
Bo-Yi Wu 538a5a6ce5 remove unsed space.
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-09 22:25:26 +08:00
DINESH S 78f4f15754 Update doc with custom secrets example (#93) fix #19 2017-08-09 22:24:08 +08:00
Bo-Yi Wu 40323f23e5 update testing
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-01 17:24:38 +08:00
Bo-Yi Wu ed83305de8 add debug mode. (#92)
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-01 16:54:34 +08:00
Bo-Yi Wu 4e625fa760 feat: add editor config. 2017-08-01 16:04:55 +08:00
Bo-Yi Wu c79b44dca2 update env key.
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-01 12:51:36 +08:00
Bo-Yi Wu c86c472904 fix: env to ToUpper
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-01 12:40:35 +08:00
Bo-Yi Wu ecfaecd46d feat(env): pass secret to remote server. (#91)
* feat(env): pass secret to remote server.

* add testing

Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-08-01 12:01:37 +08:00
Bo-Yi Wu e6d4fa77d1 add notify
Signed-off-by: Bo-Yi Wu <appleboy.tw@gmail.com>
2017-06-24 22:58:13 +08:00
Bo-Yi Wu 9651a4eb6c feat: add check unused package. (#85) 2017-06-03 01:13:19 -05:00
11 changed files with 418 additions and 156 deletions
+56 -34
View File
@@ -1,6 +1,6 @@
workspace: workspace:
base: /srv/app base: /go/src
path: src/github.com/appleboy/drone-ssh path: github.com/appleboy/drone-ssh
clone: clone:
git: git:
@@ -9,67 +9,89 @@ clone:
tags: true tags: true
pipeline: pipeline:
lint:
image: appleboy/golang-testing
pull: true
group: golang
commands:
- make vet
- make lint
- make test-vendor
linux_amd64:
image: appleboy/golang-testing
pull: true
group: golang
commands:
- make linux_amd64
linux_arm64:
image: appleboy/golang-testing
pull: true
group: golang
commands:
- make linux_arm64
linux_arm:
image: appleboy/golang-testing
pull: true
group: golang
commands:
- make linux_arm
test: test:
image: appleboy/golang-testing image: appleboy/golang-testing
pull: true pull: true
environment: group: golang
TAGS: netgo
GOPATH: /srv/app
secrets: [ codecov_token ]
commands: commands:
- make ssh-server - make ssh-server
- make vet - make test
- make lint
# - make test
- coverage all
- make coverage - make coverage
- make build
# build binary for docker image
- make static_build
when:
event: [ push, tag, pull_request ]
publish_latest:
image: plugins/docker
repo: ${DRONE_REPO}
tags: [ 'latest' ]
secrets: [ docker_username, docker_password ]
when:
event: [ push ]
branch: [ master ]
local: false
release: release:
image: appleboy/golang-testing image: appleboy/golang-testing
pull: true pull: true
environment:
TAGS: netgo
GOPATH: /srv/app
commands: commands:
- make release - make release
when: when:
event: [ tag ] event: [ tag ]
branch: [ refs/tags/* ]
local: false local: false
publish_tag: codecov:
image: robertstettner/drone-codecov
secrets: [ codecov_token ]
files:
- .cover/coverage.txt
when:
event: [ push, pull_request ]
status: [ success ]
publish:
image: plugins/docker image: plugins/docker
pull: true
repo: ${DRONE_REPO} repo: ${DRONE_REPO}
tags: [ '${DRONE_TAG}' ] default_tags: true
secrets: [ docker_username, docker_password ] secrets: [ docker_username, docker_password ]
group: release group: release
when: when:
event: [ tag ] event: [ push, tag ]
branch: [ refs/tags/* ]
local: false local: false
release_tag: release_tag:
image: plugins/github-release image: plugins/github-release
pull: true
secrets: [ github_release_api_key ] secrets: [ github_release_api_key ]
group: release group: release
files: files:
- dist/release/* - dist/release/*
when: when:
event: [ tag ] event: [ tag ]
branch: [ refs/tags/* ]
local: false local: false
facebook:
image: appleboy/drone-facebook
secrets: [ fb_page_token, fb_verify_token ]
pull: true
to: 1234973386524610
when:
status: [ changed, failure ]
+42
View File
@@ -0,0 +1,42 @@
# unifying the coding style for different editors and IDEs => editorconfig.org
; indicate this is the root of the project
root = true
###########################################################
; common
###########################################################
[*]
charset = utf-8
end_of_line = LF
insert_final_newline = true
trim_trailing_whitespace = true
indent_style = space
indent_size = 2
###########################################################
; make
###########################################################
[Makefile]
indent_style = tab
[makefile]
indent_style = tab
###########################################################
; markdown
###########################################################
[*.md]
trim_trailing_whitespace = false
###########################################################
; golang
###########################################################
[*.go]
indent_style = tab
+1
View File
@@ -25,5 +25,6 @@ _testmain.go
.env .env
coverage.txt coverage.txt
release
drone-ssh drone-ssh
.cover .cover
+76 -39
View File
@@ -40,38 +40,6 @@ pipeline:
- echo world - echo world
``` ```
Example configuration for login with user private key:
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: foo.com
username: root
- password: 1234
+ key: ${DEPLOY_KEY}
port: 22
script:
- echo hello
- echo world
```
Example configuration for login with file path of user private key:
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: foo.com
username: root
- password: 1234
+ key_path: ./deploy/key.pem
port: 22
script:
- echo hello
- echo world
```
Example configuration for command timeout (unit: second), default value is 60 seconds: Example configuration for command timeout (unit: second), default value is 60 seconds:
```diff ```diff
@@ -82,7 +50,7 @@ pipeline:
username: root username: root
password: 1234 password: 1234
port: 22 port: 22
+ command_timeout: 10 + command_timeout: 120
script: script:
- echo hello - echo hello
- echo world - echo world
@@ -96,18 +64,18 @@ pipeline:
image: appleboy/drone-ssh image: appleboy/drone-ssh
host: foo.com host: foo.com
username: root username: root
password: 1234
port: 22 port: 22
key: ${DEPLOY_KEY}
script: script:
- echo hello - echo hello
- echo world - echo world
+ proxy_host: 10.130.33.145 + proxy_host: 10.130.33.145
+ proxy_user: ubuntu + proxy_user: ubuntu
+ proxy_port: 22 + proxy_port: 22
+ proxy_key: ${PROXY_KEY} + proxy_password: 1234
``` ```
Example configuration for success build: Example configuration for `master` branch:
```diff ```diff
pipeline: pipeline:
@@ -121,10 +89,10 @@ pipeline:
- echo hello - echo hello
- echo world - echo world
+ when: + when:
+ status: success + branch: master
``` ```
Example configuration for tag event: Example configuration for `tag` event:
```diff ```diff
pipeline: pipeline:
@@ -138,10 +106,76 @@ pipeline:
- echo hello - echo hello
- echo world - echo world
+ when: + when:
+ status: success
+ event: tag + event: tag
``` ```
Example configuration using password from secrets:
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: foo.com
username: root
- password: 1234
port: 22
+ secrets: [ ssh_password ]
script:
- echo hello
- echo world
```
Example configuration using ssh key from secrets:
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: foo.com
username: root
port: 22
+ secrets: [ ssh_key ]
script:
- echo hello
- echo world
```
Example configuration for exporting custom secrets:
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: foo.com
username: root
password: 1234
port: 22
+ secrets: [ aws_access_key_id ]
+ envs: [ aws_access_key_id ]
script:
- export AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID
```
# Secret Reference
ssh_username
: account for target host user
ssh_password
: password for target host user
ssh_key
: plain text of user private key
proxy_ssh_username
: account for user of proxy server
proxy_ssh_password
: password for user of proxy server
proxy_ssh_key
: plain text of user private key for proxy server
# Parameter Reference # Parameter Reference
host host
@@ -162,6 +196,9 @@ key
key_path key_path
: key path of user private key : key path of user private key
envs
: custom secrets which are made available in the script section
script script
: execute commands on a remote server : execute commands on a remote server
+10 -4
View File
@@ -1,10 +1,16 @@
FROM alpine:3.4 FROM alpine:3.4
RUN apk update && \ RUN apk update && \
apk add \ apk add -U --no-cache \
ca-certificates \ ca-certificates \
openssh-client && \ openssh-client && \
rm -rf /var/cache/apk/* rm -rf /var/cache/apk/*
ADD drone-ssh /bin/ LABEL org.label-schema.version=latest
LABEL org.label-schema.vcs-url="https://github.com/appleboy/drone-ssh.git"
LABEL org.label-schema.name="drone-ssh"
LABEL org.label-schema.vendor="Bo-Yi Wu"
LABEL org.label-schema.schema-version="1.0"
ADD release/linux/amd64/drone-ssh /bin/
ENTRYPOINT ["/bin/drone-ssh"] ENTRYPOINT ["/bin/drone-ssh"]
+45 -22
View File
@@ -2,6 +2,7 @@
DIST := dist DIST := dist
EXECUTABLE := drone-ssh EXECUTABLE := drone-ssh
GO ?= go
# for dockerhub # for dockerhub
DEPLOY_ACCOUNT := appleboy DEPLOY_ACCOUNT := appleboy
@@ -9,11 +10,12 @@ DEPLOY_IMAGE := $(EXECUTABLE)
GOFMT ?= gofmt "-s" GOFMT ?= gofmt "-s"
TARGETS ?= linux darwin windows TARGETS ?= linux darwin windows
PACKAGES ?= $(shell go list ./... | grep -v /vendor/) PACKAGES ?= $(shell $(GO) list ./... | grep -v /vendor/)
GOFILES := $(shell find . -name "*.go" -type f -not -path "./vendor/*") GOFILES := $(shell find . -name "*.go" -type f -not -path "./vendor/*")
SOURCES ?= $(shell find . -name "*.go" -type f) SOURCES ?= $(shell find . -name "*.go" -type f)
TAGS ?= TAGS ?=
LDFLAGS ?= -X 'main.Version=$(VERSION)' LDFLAGS ?= -X 'main.Version=$(VERSION)' -X 'main.build=$(NUMBER)'
TMPDIR := $(shell mktemp -d 2>/dev/null || mktemp -d -t 'tempdir')
ifneq ($(shell uname), Darwin) ifneq ($(shell uname), Darwin)
EXTLDFLAGS = -extldflags "-static" $(null) EXTLDFLAGS = -extldflags "-static" $(null)
@@ -23,6 +25,10 @@ endif
ifneq ($(DRONE_TAG),) ifneq ($(DRONE_TAG),)
VERSION ?= $(DRONE_TAG) VERSION ?= $(DRONE_TAG)
endif
ifneq ($(DRONE_BUILD_NUMBER),)
NUMBER ?= $(DRONE_BUILD_NUMBER)
else else
VERSION ?= $(shell git describe --tags --always || git rev-parse --short HEAD) VERSION ?= $(shell git describe --tags --always || git rev-parse --short HEAD)
endif endif
@@ -31,7 +37,6 @@ all: build
.PHONY: fmt-check .PHONY: fmt-check
fmt-check: fmt-check:
# get all go files and run go fmt on them
@diff=$$($(GOFMT) -d $(GOFILES)); \ @diff=$$($(GOFMT) -d $(GOFILES)); \
if [ -n "$$diff" ]; then \ if [ -n "$$diff" ]; then \
echo "Please run 'make fmt' and commit the result:"; \ echo "Please run 'make fmt' and commit the result:"; \
@@ -39,43 +44,56 @@ fmt-check:
exit 1; \ exit 1; \
fi; fi;
.PHONY: test-vendor
test-vendor:
@hash govendor > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
$(GO) get -u github.com/kardianos/govendor; \
fi
govendor list +unused | tee "$(TMPDIR)/wc-gitea-unused"
[ $$(cat "$(TMPDIR)/wc-gitea-unused" | wc -l) -eq 0 ] || echo "Warning: /!\\ Some vendor are not used /!\\"
govendor list +outside | tee "$(TMPDIR)/wc-gitea-outside"
[ $$(cat "$(TMPDIR)/wc-gitea-outside" | wc -l) -eq 0 ] || exit 1
govendor status || exit 1
fmt: fmt:
$(GOFMT) -w $(GOFILES) $(GOFMT) -w $(GOFILES)
vet: vet:
go vet $(PACKAGES) $(GO) vet $(PACKAGES)
errcheck: errcheck:
@hash errcheck > /dev/null 2>&1; if [ $$? -ne 0 ]; then \ @hash errcheck > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
go get -u github.com/kisielk/errcheck; \ $(GO) get -u github.com/kisielk/errcheck; \
fi fi
errcheck $(PACKAGES) errcheck $(PACKAGES)
lint: lint:
@hash golint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \ @hash golint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
go get -u github.com/golang/lint/golint; \ $(GO) get -u github.com/golang/lint/golint; \
fi fi
for PKG in $(PACKAGES); do golint -set_exit_status $$PKG || exit 1; done; for PKG in $(PACKAGES); do golint -set_exit_status $$PKG || exit 1; done;
unconvert: unconvert:
@hash unconvert > /dev/null 2>&1; if [ $$? -ne 0 ]; then \ @hash unconvert > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
go get -u github.com/mdempsky/unconvert; \ $(GO) get -u github.com/mdempsky/unconvert; \
fi fi
for PKG in $(PACKAGES); do unconvert -v $$PKG || exit 1; done; for PKG in $(PACKAGES); do unconvert -v $$PKG || exit 1; done;
test: fmt-check test: fmt-check
for PKG in $(PACKAGES); do go test -v -cover -coverprofile $$GOPATH/src/$$PKG/coverage.txt $$PKG || exit 1; done; for PKG in $(PACKAGES); do $(GO) test -v -cover -coverprofile $$GOPATH/src/$$PKG/coverage.txt $$PKG || exit 1; done;
html: html:
go tool cover -html=coverage.txt $(GO) tool cover -html=coverage.txt
install: $(SOURCES) install: $(SOURCES)
go install -v -tags '$(TAGS)' -ldflags '$(EXTLDFLAGS)-s -w $(LDFLAGS)' $(GO) install -v -tags '$(TAGS)' -ldflags "$(EXTLDFLAGS)-s -w $(LDFLAGS)"
build: $(EXECUTABLE) build: $(EXECUTABLE)
$(EXECUTABLE): $(SOURCES) $(EXECUTABLE): $(SOURCES)
go build -v -tags '$(TAGS)' -ldflags '$(EXTLDFLAGS)-s -w $(LDFLAGS)' -o $@ $(GO) build -v -tags '$(TAGS)' -ldflags "$(EXTLDFLAGS)-s -w $(LDFLAGS)" -o $@
release: release-dirs release-build release-copy release-check release: release-dirs release-build release-copy release-check
@@ -84,7 +102,7 @@ release-dirs:
release-build: release-build:
@hash gox > /dev/null 2>&1; if [ $$? -ne 0 ]; then \ @hash gox > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
go get -u github.com/mitchellh/gox; \ $(GO) get -u github.com/mitchellh/gox; \
fi fi
gox -os="$(TARGETS)" -arch="amd64 386" -tags="$(TAGS)" -ldflags="-s -w $(LDFLAGS)" -output="$(DIST)/binaries/$(EXECUTABLE)-$(VERSION)-{{.OS}}-{{.Arch}}" gox -os="$(TARGETS)" -arch="amd64 386" -tags="$(TAGS)" -ldflags="-s -w $(LDFLAGS)" -output="$(DIST)/binaries/$(EXECUTABLE)-$(VERSION)-{{.OS}}-{{.Arch}}"
@@ -94,15 +112,18 @@ release-copy:
release-check: release-check:
cd $(DIST)/release; $(foreach file,$(wildcard $(DIST)/release/$(EXECUTABLE)-*),sha256sum $(notdir $(file)) > $(notdir $(file)).sha256;) cd $(DIST)/release; $(foreach file,$(wildcard $(DIST)/release/$(EXECUTABLE)-*),sha256sum $(notdir $(file)) > $(notdir $(file)).sha256;)
# for docker. linux_amd64:
static_build: CGO_ENABLED=0 GOOS=linux GOARCH=amd64 $(GO) build -a -tags '$(TAGS)' -ldflags "$(EXTLDFLAGS)-s -w $(LDFLAGS)" -o release/linux/amd64/$(EXECUTABLE)
CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -a -tags '$(TAGS)' -ldflags '$(EXTLDFLAGS)-s -w $(LDFLAGS)' -o $(DEPLOY_IMAGE)
linux_arm64:
CGO_ENABLED=0 GOOS=linux GOARCH=arm64 $(GO) build -a -tags '$(TAGS)' -ldflags "$(EXTLDFLAGS)-s -w $(LDFLAGS)" -o release/linux/arm64/$(EXECUTABLE)
linux_arm:
CGO_ENABLED=0 GOOS=linux GOARCH=arm GOARM=7 $(GO) build -a -tags '$(TAGS)' -ldflags "$(EXTLDFLAGS)-s -w $(LDFLAGS)" -o release/arm/amd64/$(EXECUTABLE)
docker_image: docker_image:
docker build -t $(DEPLOY_ACCOUNT)/$(DEPLOY_IMAGE) . docker build -t $(DEPLOY_ACCOUNT)/$(DEPLOY_IMAGE) .
docker: static_build docker_image
docker_deploy: docker_deploy:
ifeq ($(tag),) ifeq ($(tag),)
@echo "Usage: make $@ tag=<tag>" @echo "Usage: make $@ tag=<tag>"
@@ -113,13 +134,10 @@ endif
docker push $(DEPLOY_ACCOUNT)/$(DEPLOY_IMAGE):$(tag) docker push $(DEPLOY_ACCOUNT)/$(DEPLOY_IMAGE):$(tag)
coverage: coverage:
sed -i '/main.go/d' .cover/coverage.txt sed -i '/main.go/d' coverage.txt
curl -s https://codecov.io/bash > .codecov && \
chmod +x .codecov && \
./.codecov -f .cover/coverage.txt
clean: clean:
go clean -x -i ./... $(GO) clean -x -i ./...
rm -rf coverage.txt $(EXECUTABLE) $(DIST) vendor rm -rf coverage.txt $(EXECUTABLE) $(DIST) vendor
ssh-server: ssh-server:
@@ -134,5 +152,10 @@ ssh-server:
rm -rf /etc/ssh/ssh_host_rsa_key /etc/ssh/ssh_host_dsa_key rm -rf /etc/ssh/ssh_host_rsa_key /etc/ssh/ssh_host_dsa_key
./tests/entrypoint.sh /usr/sbin/sshd -D & ./tests/entrypoint.sh /usr/sbin/sshd -D &
# Show source statistics.
cloc:
@cloc -exclude-dir=vendor,node_modules .
.PHONY: cloc
version: version:
@echo $(VERSION) @echo $(VERSION)
+23
View File
@@ -50,3 +50,26 @@ docker run --rm \
-w $(pwd) \ -w $(pwd) \
appleboy/drone-ssh appleboy/drone-ssh
``` ```
## Mount key from file path
Please make sure that enable the `trusted` mode in project setting.
![trusted mode](./screenshot/trust.png)
Mount private key in `volumes` setting of `.drone.yml` config
```diff
pipeline:
ssh:
image: appleboy/drone-ssh
host: xxxxx.com
username: deploy
+ volumes:
+ - /root/drone_rsa:/root/ssh/drone_rsa
key_path: /root/ssh/drone_rsa
script:
- echo "test ssh"
```
See the detail of [issue comment](https://github.com/appleboy/drone-ssh/issues/51#issuecomment-336732928).
+37 -2
View File
@@ -1,6 +1,7 @@
package main package main
import ( import (
"fmt"
"os" "os"
"github.com/appleboy/easyssh-proxy" "github.com/appleboy/easyssh-proxy"
@@ -9,10 +10,17 @@ import (
"github.com/urfave/cli" "github.com/urfave/cli"
) )
// build number set at compile-time
var build = "0"
// Version set at compile-time // Version set at compile-time
var Version = "v1.1.0-dev" var Version string
func main() { func main() {
if Version == "" {
Version = fmt.Sprintf("1.3.1+%s", build)
}
app := cli.NewApp() app := cli.NewApp()
app.Name = "Drone SSH" app.Name = "Drone SSH"
app.Usage = "Executing remote ssh commands" app.Usage = "Executing remote ssh commands"
@@ -58,6 +66,11 @@ func main() {
EnvVar: "PLUGIN_PORT,SSH_PORT", EnvVar: "PLUGIN_PORT,SSH_PORT",
Value: 22, Value: 22,
}, },
cli.BoolFlag{
Name: "sync",
Usage: "sync mode",
EnvVar: "PLUGIN_SYNC",
},
cli.DurationFlag{ cli.DurationFlag{
Name: "timeout,t", Name: "timeout,t",
Usage: "connection timeout", Usage: "connection timeout",
@@ -115,6 +128,21 @@ func main() {
Usage: "proxy connection timeout", Usage: "proxy connection timeout",
EnvVar: "PLUGIN_PROXY_TIMEOUT,PROXY_SSH_TIMEOUT", EnvVar: "PLUGIN_PROXY_TIMEOUT,PROXY_SSH_TIMEOUT",
}, },
cli.StringSliceFlag{
Name: "secrets",
Usage: "plugin secret",
EnvVar: "PLUGIN_SECRETS",
},
cli.StringSliceFlag{
Name: "envs",
Usage: "Pass envs",
EnvVar: "PLUGIN_ENVS",
},
cli.BoolFlag{
Name: "debug",
Usage: "debug mode",
EnvVar: "PLUGIN_DEBUG",
},
} }
// Override a template // Override a template
@@ -150,7 +178,10 @@ REPOSITORY:
Github: https://github.com/appleboy/drone-ssh Github: https://github.com/appleboy/drone-ssh
` `
app.Run(os.Args) if err := app.Run(os.Args); err != nil {
fmt.Println("drone-ssh error: ", err)
os.Exit(1)
}
} }
func run(c *cli.Context) error { func run(c *cli.Context) error {
@@ -169,6 +200,10 @@ func run(c *cli.Context) error {
Timeout: c.Duration("timeout"), Timeout: c.Duration("timeout"),
CommandTimeout: c.Int("command.timeout"), CommandTimeout: c.Int("command.timeout"),
Script: c.StringSlice("script"), Script: c.StringSlice("script"),
Secrets: c.StringSlice("secrets"),
Envs: c.StringSlice("envs"),
Debug: c.Bool("debug"),
Sync: c.Bool("sync"),
Proxy: easyssh.DefaultConfig{ Proxy: easyssh.DefaultConfig{
Key: c.String("proxy.ssh-key"), Key: c.String("proxy.ssh-key"),
KeyPath: c.String("proxy.key-path"), KeyPath: c.String("proxy.key-path"),
+84 -55
View File
@@ -2,6 +2,7 @@ package main
import ( import (
"fmt" "fmt"
"os"
"strconv" "strconv"
"strings" "strings"
"sync" "sync"
@@ -29,7 +30,11 @@ type (
Timeout time.Duration Timeout time.Duration
CommandTimeout int CommandTimeout int
Script []string Script []string
Secrets []string
Envs []string
Proxy easyssh.DefaultConfig Proxy easyssh.DefaultConfig
Debug bool
Sync bool
} }
// Plugin structure // Plugin structure
@@ -38,6 +43,80 @@ type (
} }
) )
func (p Plugin) exec(host string, wg *sync.WaitGroup, errChannel chan error) {
// Create MakeConfig instance with remote username, server address and path to private key.
ssh := &easyssh.MakeConfig{
Server: host,
User: p.Config.UserName,
Password: p.Config.Password,
Port: strconv.Itoa(p.Config.Port),
Key: p.Config.Key,
KeyPath: p.Config.KeyPath,
Timeout: p.Config.Timeout,
Proxy: easyssh.DefaultConfig{
Server: p.Config.Proxy.Server,
User: p.Config.Proxy.User,
Password: p.Config.Proxy.Password,
Port: p.Config.Proxy.Port,
Key: p.Config.Proxy.Key,
KeyPath: p.Config.Proxy.KeyPath,
Timeout: p.Config.Proxy.Timeout,
},
}
p.log(host, "======CMD======")
p.log(host, strings.Join(p.Config.Script, "\n"))
p.log(host, "======END======")
env := []string{}
for _, key := range p.Config.Envs {
key = strings.ToUpper(key)
val := os.Getenv(key)
val = strings.Replace(val, " ", "", -1)
env = append(env, key+"='"+val+"'")
}
p.Config.Script = append(env, p.Config.Script...)
if p.Config.Debug {
p.log(host, "======ENV======")
p.log(host, strings.Join(env, "\n"))
p.log(host, "======END======")
}
stdoutChan, stderrChan, doneChan, errChan, err := ssh.Stream(strings.Join(p.Config.Script, "\n"), p.Config.CommandTimeout)
if err != nil {
errChannel <- err
} else {
// read from the output channel until the done signal is passed
isTimeout := true
loop:
for {
select {
case isTimeout = <-doneChan:
break loop
case outline := <-stdoutChan:
p.log(host, "out:", outline)
case errline := <-stderrChan:
p.log(host, "err:", errline)
case err = <-errChan:
}
}
// get exit code or command error.
if err != nil {
errChannel <- err
}
// command time out
if !isTimeout {
errChannel <- fmt.Errorf(commandTimeOut)
}
}
wg.Done()
}
func (p Plugin) log(host string, message ...interface{}) { func (p Plugin) log(host string, message ...interface{}) {
if count := len(p.Config.Host); count == 1 { if count := len(p.Config.Host); count == 1 {
fmt.Printf("%s", fmt.Sprintln(message...)) fmt.Printf("%s", fmt.Sprintln(message...))
@@ -65,60 +144,11 @@ func (p Plugin) Exec() error {
errChannel := make(chan error, 1) errChannel := make(chan error, 1)
finished := make(chan bool, 1) finished := make(chan bool, 1)
for _, host := range p.Config.Host { for _, host := range p.Config.Host {
go func(host string) { if p.Config.Sync {
// Create MakeConfig instance with remote username, server address and path to private key. p.exec(host, &wg, errChannel)
ssh := &easyssh.MakeConfig{ } else {
Server: host, go p.exec(host, &wg, errChannel)
User: p.Config.UserName, }
Password: p.Config.Password,
Port: strconv.Itoa(p.Config.Port),
Key: p.Config.Key,
KeyPath: p.Config.KeyPath,
Timeout: p.Config.Timeout,
Proxy: easyssh.DefaultConfig{
Server: p.Config.Proxy.Server,
User: p.Config.Proxy.User,
Password: p.Config.Proxy.Password,
Port: p.Config.Proxy.Port,
Key: p.Config.Proxy.Key,
KeyPath: p.Config.Proxy.KeyPath,
Timeout: p.Config.Proxy.Timeout,
},
}
p.log(host, "commands: ", strings.Join(p.Config.Script, "\n"))
stdoutChan, stderrChan, doneChan, errChan, err := ssh.Stream(strings.Join(p.Config.Script, "\n"), p.Config.CommandTimeout)
if err != nil {
errChannel <- err
} else {
// read from the output channel until the done signal is passed
isTimeout := true
loop:
for {
select {
case isTimeout = <-doneChan:
break loop
case outline := <-stdoutChan:
p.log(host, "out:", outline)
case errline := <-stderrChan:
p.log(host, "err:", errline)
case err = <-errChan:
}
}
// get exit code or command error.
if err != nil {
errChannel <- err
}
// command time out
if !isTimeout {
errChannel <- fmt.Errorf(commandTimeOut)
}
}
wg.Done()
}(host)
} }
go func() { go func() {
@@ -130,7 +160,6 @@ func (p Plugin) Exec() error {
case <-finished: case <-finished:
case err := <-errChannel: case err := <-errChannel:
if err != nil { if err != nil {
fmt.Println("drone-ssh error: ", err)
return err return err
} }
} }
+44
View File
@@ -1,6 +1,7 @@
package main package main
import ( import (
"os"
"testing" "testing"
"github.com/appleboy/easyssh-proxy" "github.com/appleboy/easyssh-proxy"
@@ -229,3 +230,46 @@ func TestSSHCommandExitCodeError(t *testing.T) {
err := plugin.Exec() err := plugin.Exec()
assert.NotNil(t, err) assert.NotNil(t, err)
} }
func TestSetENV(t *testing.T) {
os.Setenv("FOO", "1)")
plugin := Plugin{
Config: Config{
Host: []string{"localhost"},
UserName: "drone-scp",
Port: 22,
KeyPath: "./tests/.ssh/id_rsa",
Secrets: []string{"FOO"},
Envs: []string{"foo"},
Debug: true,
Script: []string{"whoami; echo $FOO"},
CommandTimeout: 1,
Proxy: easyssh.DefaultConfig{
Server: "localhost",
User: "drone-scp",
Port: "22",
KeyPath: "./tests/.ssh/id_rsa",
},
},
}
err := plugin.Exec()
assert.Nil(t, err)
}
func TestSyncMode(t *testing.T) {
plugin := Plugin{
Config: Config{
Host: []string{"localhost", "127.0.0.1"},
UserName: "drone-scp",
Port: 22,
KeyPath: "./tests/.ssh/id_rsa",
Script: []string{"whoami", "for i in {1..3}; do echo ${i}; sleep 1; done", "echo 'done'"},
CommandTimeout: 60,
Sync: true,
},
}
err := plugin.Exec()
assert.Nil(t, err)
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB