ia_dev/deploy/_lib/ssh.sh
Nicolas Cantu 907807f4d6 Generic project config, deploy scripts, gitea-issues, no reverse dependency
**Motivations:**
- Single config file per project (projects/<id>/conf.json)
- Project must not depend on ia_dev; only ia_dev solicits the project

**Root causes:**
- N/A (evolution)

**Correctifs:**
- N/A

**Evolutions:**
- lib/project_config.sh: resolve PROJECT_SLUG from IA_PROJECT, .ia_project, ai_project_id; PROJECT_CONFIG_PATH = projects/<id>/conf.json
- projects/lecoffreio.json moved to projects/lecoffreio/conf.json; projects/ia_dev/conf.json added
- deploy: branch-align, bump-version, change-to-all-branches, pousse, deploy-by-script-to use PROJECT_ROOT/IA_DEV_ROOT and project_config.sh; SCRIPT_REAL for symlink-safe paths
- deploy/_lib: shared colors, env-map, ssh, git-flow
- gitea-issues: mail list/mark-read/get-thread/send-reply, thread log, agent-loop, wiki scripts; lib.sh loads project config
- README: principle no dependency from host project; invoke ./ia_dev/deploy/bump-version.sh etc. from repo root

**Pages affectées:**
- README.md, projects/README.md, lib/, deploy/, gitea-issues/, projects/lecoffreio/, projects/ia_dev/
2026-03-12 22:35:15 +01:00

96 lines
2.1 KiB
Bash

#!/usr/bin/env bash
set -euo pipefail
require_ssh_key() {
local key_path="$1"
if [[ -z "$key_path" ]]; then
echo "SSH key path is required" >&2
return 1
fi
if [[ ! -f "$key_path" ]]; then
echo "SSH key not found: $key_path" >&2
return 1
fi
}
ssh_common_opts() {
local ssh_user="$1"
local ssh_host="$2"
# Keepalive to reduce flakiness through ProxyJump
# (observed: "Connection reset by peer" during scp/ssh).
#
# Notes:
# - Avoid SSH multiplexing here: ControlPath/ControlMaster can be flaky on Windows OpenSSH + MSYS paths.
# - Increased timeouts and keepalive settings to handle network instability
# - Compression disabled to reduce overhead and potential connection issues
echo \
-o BatchMode=yes \
-o StrictHostKeyChecking=accept-new \
-o ConnectTimeout=30 \
-o ServerAliveInterval=10 \
-o ServerAliveCountMax=6 \
-o TCPKeepAlive=yes \
-o Compression=no
}
ssh_run() {
local ssh_key="$1"
local ssh_user="$2"
local ssh_host="$3"
shift 3
require_ssh_key "$ssh_key"
local proxy_host="${DEPLOY_SSH_PROXY_HOST:-}"
local proxy_user="${DEPLOY_SSH_PROXY_USER:-$ssh_user}"
local proxy_args=()
if [[ -n "$proxy_host" ]]; then
proxy_args=(-J "$proxy_user@$proxy_host")
fi
# shellcheck disable=SC2207
local common_opts=($(ssh_common_opts "$ssh_user" "$ssh_host"))
ssh -i "$ssh_key" \
"${common_opts[@]}" \
"${proxy_args[@]}" \
"$ssh_user@$ssh_host" "$@"
}
scp_copy() {
local ssh_key="$1"
local src="$2"
local ssh_user="$3"
local ssh_host="$4"
local dst="$5"
local recursive="${6:-false}"
require_ssh_key "$ssh_key"
local proxy_host="${DEPLOY_SSH_PROXY_HOST:-}"
local proxy_user="${DEPLOY_SSH_PROXY_USER:-$ssh_user}"
local proxy_args=()
if [[ -n "$proxy_host" ]]; then
proxy_args=(-o "ProxyJump=$proxy_user@$proxy_host")
fi
# shellcheck disable=SC2207
local common_opts=($(ssh_common_opts "$ssh_user" "$ssh_host"))
local scp_opts=()
# Add -r for recursive copy if requested or if source is a directory
if [[ "$recursive" == "true" ]] || [[ -d "$src" ]]; then
scp_opts=(-r)
fi
scp -i "$ssh_key" \
"${scp_opts[@]}" \
"${common_opts[@]}" \
"${proxy_args[@]}" \
"$src" "$ssh_user@$ssh_host:$dst"
}