feat(woodpecker): add PA_MCP_CLIENT_ID secret provisioning for ai stack
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Temporary script to update .woodpecker.yml with PA_MCP_CLIENT_ID provisioning.
|
||||
Run once, then delete this file.
|
||||
"""
|
||||
import re
|
||||
import sys
|
||||
|
||||
def main():
|
||||
# Read the current .woodpecker.yml
|
||||
with open('.woodpecker.yml', 'r') as f:
|
||||
content = f.read()
|
||||
|
||||
# 1. Add PA_MCP_CLIENT_ID to the provision-secrets environment section
|
||||
# Find VAULTWARDEN_DATABASE_URL and add PA_MCP_CLIENT_ID after it
|
||||
if 'PA_MCP_CLIENT_ID:' not in content:
|
||||
env_pattern = r'(VAULTWARDEN_DATABASE_URL:\s+from_secret: vaultwarden_database_url)'
|
||||
env_replacement = r'\1\n PA_MCP_CLIENT_ID:\n from_secret: pa_mcp_client_id'
|
||||
content = re.sub(env_pattern, env_replacement, content)
|
||||
print("✓ Added PA_MCP_CLIENT_ID to provision-secrets environment")
|
||||
else:
|
||||
print("⊘ PA_MCP_CLIENT_ID already in environment section")
|
||||
|
||||
# 2. Replace the ai) case in provision-secrets commands
|
||||
# Find "ai) echo ..." and replace with actual provisioning
|
||||
if 'No Docker secrets for ai' in content:
|
||||
ai_case_pattern = r'(\s+)(ai\))\s+echo\s+"[^"]*No Docker secrets for ai[^"]*";;'
|
||||
ai_replacement = r'\1\2\n\1 ssh -o StrictHostKeyChecking=no root@${SWARM_MANAGER_IP} "source /tmp/cs.sh\n\1 create_or_update_secret \'pa_mcp_client_id\' \'${PA_MCP_CLIENT_ID}\'";;'
|
||||
content = re.sub(ai_case_pattern, ai_replacement, content)
|
||||
print("✓ Updated ai) case to provision pa_mcp_client_id secret")
|
||||
else:
|
||||
print("⊘ ai) case already updated")
|
||||
|
||||
# 3. Add mcpo/config.json sync in the deploy step
|
||||
# Find the deploy scripts sync and add mcpo sync after it
|
||||
if 'mcpo/config.json' not in content:
|
||||
# Find the "Always sync deploy/ scripts first" section
|
||||
deploy_pattern = r'(# Always sync deploy/ scripts first\s+rsync[^\n]+\n\s+deploy/[^\n]+\n)'
|
||||
mcpo_sync = (
|
||||
r'\1\n'
|
||||
r' # Sync mcpo/config.json to host\n'
|
||||
r' if [ -f "mcpo/config.json" ]; then\n'
|
||||
r' rsync -av -e "ssh -o StrictHostKeyChecking=no -i ~/.ssh/id_rsa" \\\n'
|
||||
r' mcpo/config.json root@${SWARM_MANAGER_IP}:/volume1/docker/mcpo/config.json\n'
|
||||
r' fi\n'
|
||||
)
|
||||
content = re.sub(deploy_pattern, mcpo_sync, content, flags=re.DOTALL)
|
||||
print("✓ Added mcpo/config.json sync to deploy step")
|
||||
else:
|
||||
print("⊘ mcpo/config.json sync already present")
|
||||
|
||||
# Write the updated content
|
||||
with open('.woodpecker.yml', 'w') as f:
|
||||
f.write(content)
|
||||
|
||||
print("\n✓ .woodpecker.yml updated successfully")
|
||||
return 0
|
||||
|
||||
if __name__ == '__main__':
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user