d2/ci/release/builders/aws/ensure.sh

295 lines
10 KiB
Bash
Raw Normal View History

2022-11-13 03:10:45 +00:00
#!/bin/sh
set -eu
cd -- "$(dirname "$0")/../../.."
. ./ci/sub/lib.sh
help() {
cat <<EOF
2022-11-14 19:56:40 +00:00
usage: $0 [--dry-run] [--skip-create]
2022-11-13 03:10:45 +00:00
2022-11-13 04:39:14 +00:00
$0 creates and ensures the d2 builders in AWS.
2022-11-13 03:10:45 +00:00
EOF
}
main() {
2022-11-16 18:48:39 +00:00
while flag_parse "$@"; do
2022-11-13 03:10:45 +00:00
case "$FLAG" in
h|help)
help
return 0
;;
2022-11-14 06:59:09 +00:00
dry-run)
2022-11-14 05:58:55 +00:00
flag_noarg && shift "$FLAGSHIFT"
2022-11-14 06:59:09 +00:00
DRY_RUN=1
2022-11-13 03:10:45 +00:00
;;
2022-11-14 19:56:40 +00:00
skip-create)
flag_noarg && shift "$FLAGSHIFT"
SKIP_CREATE=1
;;
2022-11-13 03:10:45 +00:00
*)
flag_errusage "unrecognized flag $FLAGRAW"
;;
esac
done
2022-11-16 18:48:39 +00:00
shift "$FLAGSHIFT"
2022-11-13 03:10:45 +00:00
if [ $# -gt 0 ]; then
flag_errusage "no arguments are accepted"
fi
2022-11-14 19:56:40 +00:00
if [ -z "${SKIP_CREATE-}" ]; then
2022-11-16 14:14:07 +00:00
create_remote_hosts
2022-11-14 19:56:40 +00:00
fi
2022-11-16 14:14:07 +00:00
init_remote_hosts
2022-11-13 03:10:45 +00:00
}
2022-11-16 14:14:07 +00:00
create_remote_hosts() {
2022-11-13 03:10:45 +00:00
KEY_NAME=$(aws ec2 describe-key-pairs | jq -r .KeyPairs[0].KeyName)
VPC_ID=$(aws ec2 describe-vpcs | jq -r .Vpcs[0].VpcId)
header security-group
SG_ID=$(aws ec2 describe-security-groups --group-names ssh 2>/dev/null \
| jq -r .SecurityGroups[0].GroupId)
if [ -z "$SG_ID" ]; then
SG_ID=$(sh_c aws ec2 create-security-group \
--group-name ssh \
--description ssh \
--vpc-id "$VPC_ID" | jq -r .GroupId)
fi
header security-group-ingress
SG_RULES_COUNT=$(aws ec2 describe-security-groups --group-names ssh \
| jq -r '.SecurityGroups[0].IpPermissions | length')
if [ "$SG_RULES_COUNT" -eq 0 ]; then
sh_c aws ec2 authorize-security-group-ingress \
--group-id "$SG_ID" \
--protocol tcp \
--port 22 \
--cidr 0.0.0.0/0 >/dev/null
fi
header linux-amd64
state=$(aws ec2 describe-instances --filters \
'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-linux-amd64' \
| jq -r '.Reservations[].Instances[].State.Name')
if [ -z "$state" ]; then
2022-11-13 03:10:45 +00:00
sh_c aws ec2 run-instances \
--image-id=ami-071e6cafc48327ca2 \
2022-11-13 03:10:45 +00:00
--count=1 \
2022-11-13 04:39:14 +00:00
--instance-type=t2.small \
2022-11-13 03:10:45 +00:00
--security-groups=ssh \
"--key-name=$KEY_NAME" \
2022-11-14 14:57:01 +00:00
--tag-specifications '"ResourceType=instance,Tags=[{Key=Name,Value=d2-builder-linux-amd64}]"' \
'"ResourceType=volume,Tags=[{Key=Name,Value=d2-builder-linux-amd64}]"' >/dev/null
2022-11-13 03:10:45 +00:00
fi
2022-11-13 03:36:56 +00:00
while true; do
dnsname=$(sh_c aws ec2 describe-instances \
--filters 'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-linux-amd64' \
2022-11-13 03:36:56 +00:00
| jq -r '.Reservations[].Instances[].PublicDnsName')
if [ -n "$dnsname" ]; then
log "TSTRUCT_LINUX_AMD64_BUILDER=admin@$dnsname"
export TSTRUCT_LINUX_AMD64_BUILDER=admin@$dnsname
2022-11-13 03:36:56 +00:00
break
fi
sleep 5
done
2022-11-13 03:10:45 +00:00
header linux-arm64
state=$(aws ec2 describe-instances --filters \
'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-linux-arm64' \
| jq -r '.Reservations[].Instances[].State.Name')
if [ -z "$state" ]; then
2022-11-13 03:10:45 +00:00
sh_c aws ec2 run-instances \
--image-id=ami-0e67506f183e5ab60 \
2022-11-13 03:10:45 +00:00
--count=1 \
2022-11-13 04:39:14 +00:00
--instance-type=t4g.small \
2022-11-13 03:10:45 +00:00
--security-groups=ssh \
"--key-name=$KEY_NAME" \
2022-11-14 14:57:01 +00:00
--tag-specifications '"ResourceType=instance,Tags=[{Key=Name,Value=d2-builder-linux-arm64}]"' \
'"ResourceType=volume,Tags=[{Key=Name,Value=d2-builder-linux-arm64}]"' >/dev/null
2022-11-13 03:10:45 +00:00
fi
2022-11-13 03:36:56 +00:00
while true; do
dnsname=$(sh_c aws ec2 describe-instances \
--filters 'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-linux-arm64' \
2022-11-13 03:36:56 +00:00
| jq -r '.Reservations[].Instances[].PublicDnsName')
if [ -n "$dnsname" ]; then
log "TSTRUCT_LINUX_ARM64_BUILDER=admin@$dnsname"
export TSTRUCT_LINUX_ARM64_BUILDER=admin@$dnsname
2022-11-13 03:36:56 +00:00
break
fi
sleep 5
done
2022-11-14 14:57:01 +00:00
header "macos-amd64-host"
MACOS_AMD64_HOST_ID=$(aws ec2 describe-hosts --filter 'Name=state,Values=pending,available' 'Name=tag:Name,Values=d2-builder-macos-amd64' | jq -r '.Hosts[].HostId')
if [ -z "$MACOS_AMD64_HOST_ID" ]; then
MACOS_AMD64_HOST_ID=$(sh_c aws ec2 allocate-hosts --instance-type mac1.metal --quantity 1 --availability-zone us-west-2a \
--tag-specifications '"ResourceType=dedicated-host,Tags=[{Key=Name,Value=d2-builder-macos-amd64}]"' \
| jq -r .HostIds[0])
2022-11-14 14:57:01 +00:00
fi
header "macos-arm64-host"
MACOS_ARM64_HOST_ID=$(aws ec2 describe-hosts --filter 'Name=state,Values=pending,available' 'Name=tag:Name,Values=d2-builder-macos-arm64' | jq -r '.Hosts[].HostId')
if [ -z "$MACOS_ARM64_HOST_ID" ]; then
MACOS_ARM64_HOST_ID=$(sh_c aws ec2 allocate-hosts --instance-type mac2.metal --quantity 1 --availability-zone us-west-2a \
--tag-specifications '"ResourceType=dedicated-host,Tags=[{Key=Name,Value=d2-builder-macos-amd64}]"' \
| jq -r .HostIds[0])
2022-11-14 14:57:01 +00:00
fi
header macos-amd64
state=$(aws ec2 describe-instances --filters \
'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-macos-amd64' \
| jq -r '.Reservations[].Instances[].State.Name')
if [ -z "$state" ]; then
2022-11-14 14:57:01 +00:00
sh_c aws ec2 run-instances \
--image-id=ami-0dd2ded7568750663 \
--count=1 \
--instance-type=mac1.metal \
--security-groups=ssh \
"--key-name=$KEY_NAME" \
--placement "Tenancy=host,HostId=$MACOS_AMD64_HOST_ID" \
2022-11-14 14:57:01 +00:00
--tag-specifications '"ResourceType=instance,Tags=[{Key=Name,Value=d2-builder-macos-amd64}]"' \
'"ResourceType=volume,Tags=[{Key=Name,Value=d2-builder-macos-amd64}]"' >/dev/null
fi
while true; do
dnsname=$(sh_c aws ec2 describe-instances \
--filters 'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-macos-amd64' \
2022-11-14 14:57:01 +00:00
| jq -r '.Reservations[].Instances[].PublicDnsName')
if [ -n "$dnsname" ]; then
log "TSTRUCT_MACOS_AMD64_BUILDER=ec2-user@$dnsname"
export TSTRUCT_MACOS_AMD64_BUILDER=ec2-user@$dnsname
break
fi
sleep 5
done
header macos-arm64
state=$(aws ec2 describe-instances --filters \
'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-macos-arm64' \
| jq -r '.Reservations[].Instances[].State.Name')
if [ -z "$state" ]; then
2022-11-14 14:57:01 +00:00
sh_c aws ec2 run-instances \
--image-id=ami-0af0516ff2c43dbbe \
--count=1 \
--instance-type=mac2.metal \
--security-groups=ssh \
"--key-name=$KEY_NAME" \
--placement "Tenancy=host,HostId=$MACOS_ARM64_HOST_ID" \
2022-11-14 14:57:01 +00:00
--tag-specifications '"ResourceType=instance,Tags=[{Key=Name,Value=d2-builder-macos-arm64}]"' \
'"ResourceType=volume,Tags=[{Key=Name,Value=d2-builder-macos-arm64}]"' >/dev/null
fi
while true; do
dnsname=$(sh_c aws ec2 describe-instances \
--filters 'Name=instance-state-name,Values=pending,running,stopping,stopped' 'Name=tag:Name,Values=d2-builder-macos-arm64' \
2022-11-14 14:57:01 +00:00
| jq -r '.Reservations[].Instances[].PublicDnsName')
if [ -n "$dnsname" ]; then
log "TSTRUCT_MACOS_ARM64_BUILDER=ec2-user@$dnsname"
export TSTRUCT_MACOS_ARM64_BUILDER=ec2-user@$dnsname
break
fi
sleep 5
done
2022-11-13 03:10:45 +00:00
}
2022-11-16 14:14:07 +00:00
init_remote_hosts() {
2022-11-13 04:39:14 +00:00
header linux-amd64
2022-11-16 14:14:07 +00:00
REMOTE_HOST=$TSTRUCT_LINUX_AMD64_BUILDER init_remote_linux
2022-11-13 04:39:14 +00:00
header linux-arm64
2022-11-16 14:14:07 +00:00
REMOTE_HOST=$TSTRUCT_LINUX_ARM64_BUILDER init_remote_linux
2022-11-14 14:57:01 +00:00
header macos-amd64
2022-11-16 14:14:07 +00:00
REMOTE_HOST=$TSTRUCT_MACOS_AMD64_BUILDER init_remote_macos
2022-11-14 14:57:01 +00:00
header macos-arm64
2022-11-16 14:14:07 +00:00
REMOTE_HOST=$TSTRUCT_MACOS_ARM64_BUILDER init_remote_macos
2022-11-14 14:57:01 +00:00
2022-11-16 18:48:39 +00:00
FGCOLOR=2 header summary
2022-11-13 05:07:11 +00:00
log "export TSTRUCT_LINUX_AMD64_BUILDER=$TSTRUCT_LINUX_AMD64_BUILDER"
log "export TSTRUCT_LINUX_ARM64_BUILDER=$TSTRUCT_LINUX_ARM64_BUILDER"
2022-11-14 14:57:01 +00:00
log "export TSTRUCT_MACOS_AMD64_BUILDER=$TSTRUCT_MACOS_AMD64_BUILDER"
log "export TSTRUCT_MACOS_ARM64_BUILDER=$TSTRUCT_MACOS_ARM64_BUILDER"
2022-11-13 04:39:14 +00:00
}
2022-11-16 14:14:07 +00:00
init_remote_linux() {
2022-12-06 12:03:47 +00:00
wait_remote_host
sh_c ssh "$REMOTE_HOST" sh -s -- <<EOF
set -eux
export DEBIAN_FRONTEND=noninteractive
sudo -E apt-get update -y
sudo -E apt-get dist-upgrade -y
sudo -E apt-get install -y build-essential rsync
# Docker from https://docs.docker.com/engine/install/debian/
sudo -E apt-get -y install \
ca-certificates \
curl \
gnupg \
lsb-release
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/debian/gpg | sudo gpg --batch --yes --dearmor -o /etc/apt/keyrings/docker.gpg
echo \
"deb [arch=\$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/debian \
\$(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo -E apt-get update -y
sudo -E apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin
sudo groupadd docker || true
sudo usermod -aG docker \$USER
2022-12-06 12:56:23 +00:00
mkdir -p \$HOME/.local/bin
mkdir -p \$HOME/.local/share/man
EOF
2022-12-06 12:03:47 +00:00
init_remote_env
2022-11-16 14:14:07 +00:00
sh_c ssh "$REMOTE_HOST" 'sudo reboot' || true
2022-11-13 04:39:14 +00:00
}
2022-11-16 14:14:07 +00:00
init_remote_macos() {
2022-12-06 12:03:47 +00:00
wait_remote_host
sh_c ssh "$REMOTE_HOST" '"/bin/bash -c \"\$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\""'
if sh_c ssh "$REMOTE_HOST" uname -m | grep -qF arm64; then
shellenv=$(sh_c ssh "$REMOTE_HOST" /opt/homebrew/bin/brew shellenv)
else
shellenv=$(sh_c ssh "$REMOTE_HOST" /usr/local/bin/brew shellenv)
fi
if ! echo "$shellenv" | sh_c ssh "$REMOTE_HOST" "IFS= read -r regex\; \"grep -qF \\\"\\\$regex\\\" ~/.zshrc\""; then
echo "$shellenv" | sh_c ssh "$REMOTE_HOST" "\"(echo && cat) >> ~/.zshrc\""
fi
2022-12-06 12:03:47 +00:00
if ! sh_c ssh "$REMOTE_HOST" "'grep -qF \\\$HOME/.local ~/.zshrc'"; then
sh_c ssh "$REMOTE_HOST" "\"(echo && cat) >> ~/.zshrc\"" <<EOF
PATH=\$HOME/.local/bin:\$PATH
MANPATH=\$HOME/.local/share/man:\$MANPATH
EOF
fi
2022-12-06 12:03:47 +00:00
init_remote_env
sh_c ssh "$REMOTE_HOST" brew update
sh_c ssh "$REMOTE_HOST" brew upgrade
sh_c ssh "$REMOTE_HOST" brew install go rsync
}
init_remote_env() {
sh_c ssh "$REMOTE_HOST" '"rm -f ~/.ssh/environment"'
2022-12-06 12:03:47 +00:00
sh_c ssh "$REMOTE_HOST" '"echo PATH=\$(echo \"echo \\\$PATH\" | \"\$SHELL\" -ils) >\$HOME/.ssh/environment"'
sh_c ssh "$REMOTE_HOST" '"echo MANPATH=\$(echo \"echo \\\$MANPATH\" | \"\$SHELL\" -ils) >>\$HOME/.ssh/environment"'
sh_c ssh "$REMOTE_HOST" "sudo sed -i.bak '\"s/#PermitUserEnvironment no/PermitUserEnvironment yes/\"' /etc/ssh/sshd_config"
2022-12-06 12:03:47 +00:00
if sh_c ssh "$REMOTE_HOST" uname | grep -qF Darwin; then
sh_c ssh "$REMOTE_HOST" "sudo launchctl stop com.openssh.sshd"
else
sh_c ssh "$REMOTE_HOST" "sudo systemctl restart sshd"
fi
}
wait_remote_host() {
while true; do
if sh_c ssh "$REMOTE_HOST" true; then
break
fi
sleep 5
done
2022-11-14 14:57:01 +00:00
}
2022-11-13 03:10:45 +00:00
main "$@"