|
All checks were successful
PR build (required check) / changes (pull_request) Successful in 9s
shell-lint / shellcheck (pull_request) Successful in 8s
secrets-guard / encrypted (pull_request) Successful in 9s
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Successful in 16s
PR build (required check) / build-backend (pull_request) Successful in 53s
PR build (required check) / gate (pull_request) Successful in 3s
The RETURN trap added in the previous commit leaked out of the function and killed every deploy on a SOPS-configured host. A RETURN trap set inside a SOURCED function is not function-scoped: it persists in the caller's shell after the function returns, and a RETURN trap also fires when a `.`/source completes. deploy.sh sources /etc/thermograph.env six lines after calling render_thermograph_secrets, which re-fired the trap at top level where `tmp` -- function-local -- is unset. Under deploy.sh's `set -u` that is fatal, and silent: that line already sends stderr to /dev/null, so the deploy rendered secrets and then died with no diagnostic before pulling or rolling anything. Replaced with explicit `rm -f "$tmp"` on each exit path, plus a comment recording why the tidier-looking trap is wrong here so it doesn't come back. The original defect the trap was meant to fix stays fixed: the decrypt-failure path removes the plaintext temp file before returning 1. The write section now captures its status in `rc` and cleans up once, rather than ending on `rm` -- as the last command it was masking a failed in-place `cat` write to status 0, so a half-written /etc/thermograph.env would have deployed as if it succeeded. Verified in a container against the real call pattern (strict-mode caller, source lib, call, then source the rendered env): success path returns 0 and the caller survives the subsequent source; decrypt-failure path aborts the caller with no /etc/thermograph.env written; both leave zero temp files. |
||
|---|---|---|
| .. | ||
| db | ||
| forgejo | ||
| migrations | ||
| openmeteo | ||
| secrets | ||
| stack | ||
| swarm | ||
| twa | ||
| Caddyfile | ||
| deploy-dev.sh | ||
| deploy.sh | ||
| migrate-db.py | ||
| POSTGRES-MIGRATION.md | ||
| provision-agent-access.sh | ||
| provision-dev-lan.sh | ||
| provision-mail.sh | ||
| provision-secrets.sh | ||
| render-secrets.sh | ||
| thermograph-dev.service | ||
| thermograph.env.example | ||
| thermograph.service | ||