fix(cdn): restore Alliance pull-zone hostname (#166)
All checks were successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline was successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was successful
ci/crow/cron/process-updates/12 Pipeline was successful
ci/crow/cron/process-updates/6 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline was successful
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/2 Pipeline was successful
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/8 Pipeline was successful
ci/crow/cron/process-updates/9 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
All checks were successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline was successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was successful
ci/crow/cron/process-updates/12 Pipeline was successful
ci/crow/cron/process-updates/6 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline was successful
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/2 Pipeline was successful
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/8 Pipeline was successful
ci/crow/cron/process-updates/9 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
## Motivation Applying #165 recreated the Alliance SwissPass pull zone without its custom hostname because the hostname association was not represented in OpenTofu. The recreated zone also received a new numeric ID, making the weekly purge configuration stale. ## Changes - Manage `cran.allianceswisspass.devxy.io` as a pull-zone hostname with TLS and forced HTTPS. - Resolve the Alliance pull-zone ID from its hostname before purging instead of persisting a replaceable numeric ID. - Install `jq` in the purge step for the Bunny API lookup. ## Verification - Targeted `prek` hooks pass. - `tofu validate` passes. - `crow lint .crow/` passes. - `just edge-test` passes all 14 routing steps. - `bash -n scripts/purge_cdn_zone.sh` passes. ## Deployment Run `tofu apply` to restore the Alliance hostname on the recreated pull zone. Reviewed-on: #166
This commit is contained in:
parent
a1c1f5e78f
commit
9bded261ee
3 changed files with 45 additions and 6 deletions
|
|
@ -175,9 +175,9 @@ steps:
|
||||||
from_secret: BUNNYNET_API_KEY
|
from_secret: BUNNYNET_API_KEY
|
||||||
# cran.rpkgs.com and cran.allianceswisspass.devxy.io are on separate
|
# cran.rpkgs.com and cran.allianceswisspass.devxy.io are on separate
|
||||||
# Bunny pull zones, so both must be purged after the shared origin changes.
|
# Bunny pull zones, so both must be purged after the shared origin changes.
|
||||||
BUNNY_PULLZONES: '3857050 3265648'
|
BUNNY_PULLZONES: '3857050 cran.allianceswisspass.devxy.io'
|
||||||
commands:
|
commands:
|
||||||
- apk add --no-cache -q bash curl
|
- apk add --no-cache -q bash curl jq
|
||||||
# Crow carries the checkout from the re-index step into this step.
|
# Crow carries the checkout from the re-index step into this step.
|
||||||
- bash scripts/purge_cdn_zone.sh "$BUNNYNET_API_KEY" $BUNNY_PULLZONES
|
- bash scripts/purge_cdn_zone.sh "$BUNNYNET_API_KEY" $BUNNY_PULLZONES
|
||||||
# Runs on every row rather than on one designated slot: a cron fires only
|
# Runs on every row rather than on one designated slot: a cron fires only
|
||||||
|
|
|
||||||
7
cdn.tf
7
cdn.tf
|
|
@ -199,6 +199,13 @@ resource "bunnynet_pullzone" "cran_allianceswisspass" {
|
||||||
block_root_path = true
|
block_root_path = true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
resource "bunnynet_pullzone_hostname" "cran_allianceswisspass" {
|
||||||
|
pullzone = bunnynet_pullzone.cran_allianceswisspass.id
|
||||||
|
name = "cran.allianceswisspass.devxy.io"
|
||||||
|
force_ssl = true
|
||||||
|
tls_enabled = true
|
||||||
|
}
|
||||||
|
|
||||||
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
|
# resource "bunnynet_storage_zone" "devxy-r-binaries" {
|
||||||
# name = "devxy-r-binaries-storage"
|
# name = "devxy-r-binaries-storage"
|
||||||
# region = "DE"
|
# region = "DE"
|
||||||
|
|
|
||||||
|
|
@ -19,22 +19,54 @@
|
||||||
# why this is not used by the daily update path.
|
# why this is not used by the daily update path.
|
||||||
#
|
#
|
||||||
# The public hostnames currently use separate pull zones, so callers must pass
|
# The public hostnames currently use separate pull zones, so callers must pass
|
||||||
# every zone that serves the repository.
|
# every zone that serves the repository. A zone can be identified by its
|
||||||
|
# numeric ID or by one of its hostnames; hostname lookup avoids persisting IDs
|
||||||
|
# that change when a zone is recreated.
|
||||||
#
|
#
|
||||||
# Usage:
|
# Usage:
|
||||||
# purge_cdn_zone.sh <BUNNYNET_API_KEY> <pull_zone_id> [<pull_zone_id>...]
|
# purge_cdn_zone.sh <BUNNYNET_API_KEY> <pull_zone> [<pull_zone>...]
|
||||||
#
|
#
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
if (($# < 2)); then
|
if (($# < 2)); then
|
||||||
echo "usage: $0 <api_key> <pull_zone_id> [<pull_zone_id>...]" >&2
|
echo "usage: $0 <api_key> <pull_zone> [<pull_zone>...]" >&2
|
||||||
exit 2
|
exit 2
|
||||||
fi
|
fi
|
||||||
|
|
||||||
api_key="$1"
|
api_key="$1"
|
||||||
shift
|
shift
|
||||||
|
|
||||||
for zone_id in "$@"; do
|
resolve_zone_id() {
|
||||||
|
local zone="$1"
|
||||||
|
local response_file
|
||||||
|
local zone_id
|
||||||
|
|
||||||
|
if [[ "${zone}" =~ ^[0-9]+$ ]]; then
|
||||||
|
echo "${zone}"
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
response_file=$(mktemp)
|
||||||
|
curl -sS -o "${response_file}" \
|
||||||
|
-H "AccessKey: ${api_key}" \
|
||||||
|
"https://api.bunny.net/pullzone"
|
||||||
|
zone_id=$(
|
||||||
|
jq -r --arg hostname "${zone}" \
|
||||||
|
'(.Items // .)[] | select(any(.Hostnames[]?; .Value == $hostname)) | .Id' \
|
||||||
|
"${response_file}"
|
||||||
|
)
|
||||||
|
rm -f "${response_file}"
|
||||||
|
|
||||||
|
if [[ -z "${zone_id}" ]]; then
|
||||||
|
echo "Could not find BunnyCDN pull zone for hostname ${zone}" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "${zone_id}"
|
||||||
|
}
|
||||||
|
|
||||||
|
for zone in "$@"; do
|
||||||
|
zone_id=$(resolve_zone_id "${zone}")
|
||||||
echo "Purging BunnyCDN pull zone ${zone_id}"
|
echo "Purging BunnyCDN pull zone ${zone_id}"
|
||||||
|
|
||||||
response_file="/tmp/purge_zone_response_${zone_id}.txt"
|
response_file="/tmp/purge_zone_response_${zone_id}.txt"
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue