ci/woodpecker/pr/ci Pipeline was successful
Implements the rev-security-01 verdict on #1320 (comment 23282): Should Fix (first, per tasking): mosaic-deploy's branch-protected-repos section shipped a working recipe for both failure modes the estate removes identity that is not the actor's (a legacy shared credential path, ~/.config/mosaic/credentials/gitea.env, which no longer exists in the credential system) and a quality gate routed around (raw curl + force_merge:true, no queue guard, no head pin). Replaced with wrapper-only merge guidance: protection blocks are signals to fix, not to bypass. Placeholder-ized estate RFC1918 topology and hostnames (six carriers, one more than the verdict's five — the original scan missed guides/): - skills/mosaic-portainer: Portainer URL, Docker host - skills/mosaic-gitea: SSH resolution target - skills/mosaic-deploy: Docker node, stack-name map (now generic example shape; estate mappings belong in skills-local overrides, which link with precedence) - tools/coolify/README: base URL - guides/INFRASTRUCTURE: cloudflare example moved from 10.0.0.5 to the RFC 5737 documentation range (192.0.2.5), the unambiguous example form Left as-is per the verdict's split: estate DNS endpoints (e.g. git.mosaicstack.dev, ci.mosaicstack.dev) pass as examples. Rescan of the whole shipped framework tree for RFC1918, estate hosts, and stack-name patterns: zero remaining hits. The gate defect itself is filed separately as #1321 (cross-referenced on #1320, comment 23285).
2.3 KiB
2.3 KiB
name, description
| name | description |
|---|---|
| mosaic-portainer | Manage Portainer stacks on the Mosaic infrastructure. Use when asked to list, start, stop, redeploy, or check logs of Docker Swarm stacks via Portainer. Wraps scripts in ~/.config/mosaic/tools/portainer/. Requires load_credentials portainer first. |
mosaic-portainer
Manage Portainer stacks via pre-built Mosaic scripts.
Setup
Always load credentials before running scripts:
source ~/.config/mosaic/tools/_lib/credentials.sh
load_credentials portainer
# Exports: PORTAINER_URL, PORTAINER_API_KEY
Scripts
All scripts live in ~/.config/mosaic/tools/portainer/.
| Script | Purpose | Key flags |
|---|---|---|
stack-list.sh |
List all stacks | — |
stack-status.sh |
Status of a stack | -n <name> |
stack-redeploy.sh |
Redeploy (file or git-based) | -n <name> [-p] (pull images) |
stack-start.sh |
Start a stopped stack | -n <name> |
stack-stop.sh |
Stop a running stack | -n <name> |
stack-logs.sh |
Tail stack logs | -n <name> [-l lines] |
endpoint-list.sh |
List Portainer endpoints | — |
Common Workflows
Redeploy a stack with fresh images:
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials portainer
~/.config/mosaic/tools/portainer/stack-redeploy.sh -n mosaic-stack -p
Check all stack statuses:
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials portainer
~/.config/mosaic/tools/portainer/stack-list.sh
Tail logs for a service:
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials portainer
~/.config/mosaic/tools/portainer/stack-logs.sh -n mosaic-stack -l 100
Notes
- Portainer URL:
https://portainer.example.internal:9443 - Primary Docker host:
node-01, managed via Portainer agent - Docker Swarm image updates:
stack-redeploy.sh -pdoes NOT guarantee new image pull if digest is pinned; SSH to node anddocker pullfirst if needed - Credentials:
load_credentials portainer(framework credentials store)