Repository navigation
Expand file tree
/
Copy path03-run-docker-container.sh
More file actions
executable file
·67 lines (57 loc) · 2.49 KB
/
Copy path03-run-docker-container.sh
File metadata and controls
executable file
·67 lines (57 loc) · 2.49 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
#!/bin/bash
# Variables
source ./00-variables.sh
# Change the current directory to the script's directory
cd "$CURRENT_DIR" || exit
# Read one setting from the App Configuration store. --resolve-keyvault makes the CLI follow a Key Vault
# reference and return the secret behind it, so the same call works for a plain key-value and for a
# reference. Reading the settings from the store rather than from 00-variables.sh means this local run
# proves the store's contents, not just that the image starts.
# $1: the key
resolve_setting() {
local key=$1
local value
value=$(az appconfig kv list \
--name "$APP_CONFIG_NAME" \
--key "$key" \
--resolve-keyvault \
--query "[0].value" \
--output tsv \
--only-show-errors 2>/dev/null)
if [[ -z $value ]]; then
echo "Failed to resolve the [$key] key from the [$APP_CONFIG_NAME] App Configuration store." >&2
echo "Run 01-deploy-resources.sh first, and make sure you can read the key vault." >&2
exit 1
fi
echo "$value"
}
echo "Resolving the application settings from the [$APP_CONFIG_NAME] App Configuration store..."
# || exit 1 on every call: resolve_setting's `exit 1` only leaves the command substitution's
# subshell, so without this docker run would start with empty settings.
PG_HOST_VALUE=$(resolve_setting "PG_HOST") || exit 1
PG_PORT_VALUE=$(resolve_setting "PG_PORT") || exit 1
PG_DATABASE_VALUE=$(resolve_setting "PG_DATABASE") || exit 1
LOGIN_NAME_VALUE=$(resolve_setting "LOGIN_NAME") || exit 1
CONFIG_VERSION_VALUE=$(resolve_setting "$SENTINEL_KEY") || exit 1
PG_USER_VALUE=$(resolve_setting "PG_USER") || exit 1
PG_PASSWORD_VALUE=$(resolve_setting "PG_PASSWORD") || exit 1
SECRET_KEY_VALUE=$(resolve_setting "SECRET_KEY") || exit 1
# The credentials are resolved but never echoed.
echo "PG_HOST=$PG_HOST_VALUE PG_PORT=$PG_PORT_VALUE PG_DATABASE=$PG_DATABASE_VALUE LOGIN_NAME=$LOGIN_NAME_VALUE $SENTINEL_KEY=$CONFIG_VERSION_VALUE"
echo "PG_USER, PG_PASSWORD and SECRET_KEY resolved from Key Vault references"
# --network=host so endpoints like *.localhost.localstack.cloud resolve to the
# host's loopback (where LocalStack is listening), not the container's.
docker run -it \
--rm \
--network=host \
-e PORT="$PORT" \
-e PG_HOST="$PG_HOST_VALUE" \
-e PG_PORT="$PG_PORT_VALUE" \
-e PG_DATABASE="$PG_DATABASE_VALUE" \
-e PG_USER="$PG_USER_VALUE" \
-e PG_PASSWORD="$PG_PASSWORD_VALUE" \
-e LOGIN_NAME="$LOGIN_NAME_VALUE" \
-e SECRET_KEY="$SECRET_KEY_VALUE" \
-e CONFIG_VERSION="$CONFIG_VERSION_VALUE" \
--name "$IMAGE_NAME" \
"$IMAGE_NAME:$IMAGE_TAG"