mirror of
https://github.com/balena-io/balena-cli.git
synced 2025-06-25 02:47:55 +00:00
Compare commits
2 Commits
renovate/a
...
balena-dep
Author | SHA1 | Date | |
---|---|---|---|
7338c4a841 | |||
baa5478132 |
@ -239,13 +239,11 @@ export const authorizePush = function (
|
|||||||
tokenAuthEndpoint: string,
|
tokenAuthEndpoint: string,
|
||||||
registry: string,
|
registry: string,
|
||||||
images: string[],
|
images: string[],
|
||||||
previousRepos: string[],
|
|
||||||
): Promise<string> {
|
): Promise<string> {
|
||||||
if (!Array.isArray(images)) {
|
if (!Array.isArray(images)) {
|
||||||
images = [images];
|
images = [images];
|
||||||
}
|
}
|
||||||
|
|
||||||
images.push(...previousRepos);
|
|
||||||
return sdk.request
|
return sdk.request
|
||||||
.send({
|
.send({
|
||||||
baseUrl: tokenAuthEndpoint,
|
baseUrl: tokenAuthEndpoint,
|
||||||
|
@ -1215,31 +1215,58 @@ export async function validateProjectDirectory(
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* While testing, pushing a release with a token of up to 125 repos (new + past) worked
|
||||||
|
* and resulted a token of 15967 characters. Generating a token with more repos, thus
|
||||||
|
* bigger token fails since the request would exceed the max allowed headers size of 16KB.
|
||||||
|
* We use a value slightly smaller than the max to account for unknown factors that
|
||||||
|
* might increase the request header size.
|
||||||
|
*/
|
||||||
|
const MAX_SAFE_IMAGE_REPOS_PER_TOKEN = 120;
|
||||||
|
|
||||||
async function getTokenForPreviousRepos(
|
async function getTokenForPreviousRepos(
|
||||||
logger: Logger,
|
logger: Logger,
|
||||||
appId: number,
|
appId: number,
|
||||||
apiEndpoint: string,
|
apiEndpoint: string,
|
||||||
taggedImages: TaggedImage[],
|
taggedImages: TaggedImage[],
|
||||||
): Promise<string> {
|
): Promise<Array<[taggedImage: TaggedImage, token: string]>> {
|
||||||
logger.logDebug('Authorizing push...');
|
logger.logDebug('Authorizing push...');
|
||||||
const { authorizePush, getPreviousRepos } = await import('./compose');
|
const { authorizePush, getPreviousRepos } = await import('./compose');
|
||||||
const sdk = getBalenaSdk();
|
const sdk = getBalenaSdk();
|
||||||
const previousRepos = await getPreviousRepos(sdk, logger, appId);
|
const previousRepos = await getPreviousRepos(sdk, logger, appId);
|
||||||
|
|
||||||
const token = await authorizePush(
|
const newImageChunks = _.chunk(
|
||||||
sdk,
|
taggedImages,
|
||||||
apiEndpoint,
|
Math.max(MAX_SAFE_IMAGE_REPOS_PER_TOKEN - previousRepos.length, 1),
|
||||||
taggedImages[0].registry,
|
|
||||||
_.map(taggedImages, 'repo'),
|
|
||||||
previousRepos,
|
|
||||||
);
|
);
|
||||||
return token;
|
|
||||||
|
const imagesAndTokens: Array<[taggedImage: TaggedImage, token: string]> = [];
|
||||||
|
for (const newImageChunk of newImageChunks) {
|
||||||
|
const token = await authorizePush(
|
||||||
|
sdk,
|
||||||
|
apiEndpoint,
|
||||||
|
newImageChunk[0].registry,
|
||||||
|
// We request access to the previous repos as well, so that while pushing we have access
|
||||||
|
// to cross mount old-matching layers, so that we can avoid re-uploading them every time.
|
||||||
|
[
|
||||||
|
...newImageChunk.map((taggedImage) => taggedImage.repo),
|
||||||
|
...previousRepos,
|
||||||
|
],
|
||||||
|
);
|
||||||
|
imagesAndTokens.push(
|
||||||
|
...newImageChunk.map((taggedImage): (typeof imagesAndTokens)[number] => [
|
||||||
|
taggedImage,
|
||||||
|
token,
|
||||||
|
]),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return imagesAndTokens;
|
||||||
}
|
}
|
||||||
|
|
||||||
async function pushAndUpdateServiceImages(
|
async function pushAndUpdateServiceImages(
|
||||||
docker: Dockerode,
|
docker: Dockerode,
|
||||||
token: string,
|
imagesAndTokens: Array<[taggedImage: TaggedImage, token: string]>,
|
||||||
images: TaggedImage[],
|
|
||||||
afterEach: (
|
afterEach: (
|
||||||
serviceImage: import('@balena/compose/dist/release/models').ImageModel,
|
serviceImage: import('@balena/compose/dist/release/models').ImageModel,
|
||||||
props: object,
|
props: object,
|
||||||
@ -1249,16 +1276,19 @@ async function pushAndUpdateServiceImages(
|
|||||||
const { retry } = await import('./helpers');
|
const { retry } = await import('./helpers');
|
||||||
const { pushProgressRenderer } = await import('./compose');
|
const { pushProgressRenderer } = await import('./compose');
|
||||||
const tty = (await import('./tty'))(process.stdout);
|
const tty = (await import('./tty'))(process.stdout);
|
||||||
const opts = { authconfig: { registrytoken: token } };
|
|
||||||
const progress = new DockerProgress({ docker });
|
const progress = new DockerProgress({ docker });
|
||||||
const renderer = pushProgressRenderer(
|
const renderer = pushProgressRenderer(
|
||||||
tty,
|
tty,
|
||||||
getChalk().blue('[Push]') + ' ',
|
getChalk().blue('[Push]') + ' ',
|
||||||
);
|
);
|
||||||
const reporters = progress.aggregateProgress(images.length, renderer);
|
const reporters = progress.aggregateProgress(
|
||||||
|
imagesAndTokens.length,
|
||||||
|
renderer,
|
||||||
|
);
|
||||||
|
|
||||||
const pushImage = async (
|
const pushImage = async (
|
||||||
localImage: Dockerode.Image,
|
localImage: Dockerode.Image,
|
||||||
|
token: string,
|
||||||
index: number,
|
index: number,
|
||||||
): Promise<string> => {
|
): Promise<string> => {
|
||||||
try {
|
try {
|
||||||
@ -1267,7 +1297,10 @@ async function pushAndUpdateServiceImages(
|
|||||||
// "name": "registry2.balena-cloud.com/v2/aa27790dff571ec7d2b4fbcf3d4648d5:latest"
|
// "name": "registry2.balena-cloud.com/v2/aa27790dff571ec7d2b4fbcf3d4648d5:latest"
|
||||||
const imgName: string = (localImage as any).name || '';
|
const imgName: string = (localImage as any).name || '';
|
||||||
const imageDigest: string = await retry({
|
const imageDigest: string = await retry({
|
||||||
func: () => progress.push(imgName, reporters[index], opts),
|
func: () =>
|
||||||
|
progress.push(imgName, reporters[index], {
|
||||||
|
authconfig: { registrytoken: token },
|
||||||
|
}),
|
||||||
maxAttempts: 3, // try calling func 3 times (max)
|
maxAttempts: 3, // try calling func 3 times (max)
|
||||||
label: imgName, // label for retry log messages
|
label: imgName, // label for retry log messages
|
||||||
initialDelayMs: 2000, // wait 2 seconds before the 1st retry
|
initialDelayMs: 2000, // wait 2 seconds before the 1st retry
|
||||||
@ -1285,13 +1318,16 @@ async function pushAndUpdateServiceImages(
|
|||||||
};
|
};
|
||||||
|
|
||||||
const inspectAndPushImage = async (
|
const inspectAndPushImage = async (
|
||||||
{ serviceImage, localImage, props, logs }: TaggedImage,
|
[{ serviceImage, localImage, props, logs }, token]: [
|
||||||
|
TaggedImage,
|
||||||
|
token: string,
|
||||||
|
],
|
||||||
index: number,
|
index: number,
|
||||||
) => {
|
) => {
|
||||||
try {
|
try {
|
||||||
const [imgInfo, imgDigest] = await Promise.all([
|
const [imgInfo, imgDigest] = await Promise.all([
|
||||||
localImage.inspect(),
|
localImage.inspect(),
|
||||||
pushImage(localImage, index),
|
pushImage(localImage, token, index),
|
||||||
]);
|
]);
|
||||||
serviceImage.image_size = imgInfo.Size;
|
serviceImage.image_size = imgInfo.Size;
|
||||||
serviceImage.content_hash = imgDigest;
|
serviceImage.content_hash = imgDigest;
|
||||||
@ -1317,7 +1353,7 @@ async function pushAndUpdateServiceImages(
|
|||||||
|
|
||||||
tty.hideCursor();
|
tty.hideCursor();
|
||||||
try {
|
try {
|
||||||
await Promise.all(images.map(inspectAndPushImage));
|
await Promise.all(imagesAndTokens.map(inspectAndPushImage));
|
||||||
} finally {
|
} finally {
|
||||||
tty.showCursor();
|
tty.showCursor();
|
||||||
}
|
}
|
||||||
@ -1329,16 +1365,14 @@ async function pushServiceImages(
|
|||||||
pineClient: ReturnType<
|
pineClient: ReturnType<
|
||||||
typeof import('@balena/compose/dist/release').createClient
|
typeof import('@balena/compose/dist/release').createClient
|
||||||
>,
|
>,
|
||||||
taggedImages: TaggedImage[],
|
imagesAndTokens: Array<[taggedImage: TaggedImage, token: string]>,
|
||||||
token: string,
|
|
||||||
skipLogUpload: boolean,
|
skipLogUpload: boolean,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
const releaseMod = await import('@balena/compose/dist/release');
|
const releaseMod = await import('@balena/compose/dist/release');
|
||||||
logger.logInfo('Pushing images to registry...');
|
logger.logInfo('Pushing images to registry...');
|
||||||
await pushAndUpdateServiceImages(
|
await pushAndUpdateServiceImages(
|
||||||
docker,
|
docker,
|
||||||
token,
|
imagesAndTokens,
|
||||||
taggedImages,
|
|
||||||
async function (serviceImage) {
|
async function (serviceImage) {
|
||||||
logger.logDebug(
|
logger.logDebug(
|
||||||
`Saving image ${serviceImage.is_stored_at__image_location}`,
|
`Saving image ${serviceImage.is_stored_at__image_location}`,
|
||||||
@ -1405,7 +1439,7 @@ export async function deployProject(
|
|||||||
// awaitInterruptibleTask throws SIGINTError on CTRL-C,
|
// awaitInterruptibleTask throws SIGINTError on CTRL-C,
|
||||||
// causing the release status to be set to 'failed'
|
// causing the release status to be set to 'failed'
|
||||||
await awaitInterruptibleTask(async () => {
|
await awaitInterruptibleTask(async () => {
|
||||||
const token = await getTokenForPreviousRepos(
|
const imagesAndTokens = await getTokenForPreviousRepos(
|
||||||
logger,
|
logger,
|
||||||
appId,
|
appId,
|
||||||
apiEndpoint,
|
apiEndpoint,
|
||||||
@ -1415,8 +1449,7 @@ export async function deployProject(
|
|||||||
docker,
|
docker,
|
||||||
logger,
|
logger,
|
||||||
pineClient,
|
pineClient,
|
||||||
taggedImages,
|
imagesAndTokens,
|
||||||
token,
|
|
||||||
skipLogUpload,
|
skipLogUpload,
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
36
npm-shrinkwrap.json
generated
36
npm-shrinkwrap.json
generated
@ -9120,9 +9120,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/etcher-sdk/node_modules/node-abi": {
|
"node_modules/etcher-sdk/node_modules/node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
},
|
},
|
||||||
@ -17173,9 +17173,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/pkg/node_modules/node-abi": {
|
"node_modules/pkg/node_modules/node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
@ -22577,9 +22577,9 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/winusb-driver-generator/node_modules/node-abi": {
|
"node_modules/winusb-driver-generator/node_modules/node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"optional": true,
|
"optional": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
@ -31882,9 +31882,9 @@
|
|||||||
"integrity": "sha512-z0yWI+4FDrrweS8Zmt4Ej5HdJmky15+L2e6Wgn3+iK5fWzb6T3fhNFq2+MeTRb064c6Wr4N/wv0DzQTjNzHNGQ=="
|
"integrity": "sha512-z0yWI+4FDrrweS8Zmt4Ej5HdJmky15+L2e6Wgn3+iK5fWzb6T3fhNFq2+MeTRb064c6Wr4N/wv0DzQTjNzHNGQ=="
|
||||||
},
|
},
|
||||||
"node-abi": {
|
"node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"requires": {
|
"requires": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
}
|
}
|
||||||
@ -38024,9 +38024,9 @@
|
|||||||
"dev": true
|
"dev": true
|
||||||
},
|
},
|
||||||
"node-abi": {
|
"node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"dev": true,
|
"dev": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
@ -42338,9 +42338,9 @@
|
|||||||
"optional": true
|
"optional": true
|
||||||
},
|
},
|
||||||
"node-abi": {
|
"node-abi": {
|
||||||
"version": "3.51.0",
|
"version": "3.52.0",
|
||||||
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.51.0.tgz",
|
"resolved": "https://registry.npmjs.org/node-abi/-/node-abi-3.52.0.tgz",
|
||||||
"integrity": "sha512-SQkEP4hmNWjlniS5zdnfIXTk1x7Ome85RDzHlTbBtzE97Gfwz/Ipw4v/Ryk20DWIy3yCNVLVlGKApCnmvYoJbA==",
|
"integrity": "sha512-JJ98b02z16ILv7859irtXn4oUaFWADtvkzy2c0IAatNVX2Mc9Yoh8z6hZInn3QwvMEYhHuQloYi+TTQy67SIdQ==",
|
||||||
"optional": true,
|
"optional": true,
|
||||||
"requires": {
|
"requires": {
|
||||||
"semver": "^7.3.5"
|
"semver": "^7.3.5"
|
||||||
|
Reference in New Issue
Block a user