fix(deploy): sanitized agent config — use Docker to read openclaw.json
CI - Build & Test / Backend (.NET) (push) Successful in 33s
CI - Build & Test / Frontend (Vue/TS) (push) Successful in 17s
CI - Build & Test / Security Check (push) Successful in 3s
CI - Build & Test / Deploy Nexus (push) Successful in 27s

The Gitea runner doesn't have direct filesystem access to
/home/projekte_bao/openclaw/, so the previous python3 inline extraction
would fail silently and no agents-sanitized.json would be generated.

Now the deploy script uses a Docker container with bind mounts to read
openclaw.json (readonly) and write agents-sanitized.json to the host.

This completes the P4 migration: Nexus no longer needs read access to
openclaw.json for any code path or deployment step.
This commit is contained in:
2026-07-12 15:08:49 +02:00
parent dbda764190
commit 8ad8c956eb
+34
View File
@@ -105,6 +105,40 @@ git archive --format=tar HEAD | docker run --rm -i \
chown -R "$dest_owner" /dest chown -R "$dest_owner" /dest
' '
# ── Sanitized agents config for Nexus (no secrets) ──
echo "Generating sanitized agents config for Nexus (no secrets from openclaw.json)"
AGENTS_SANITIZED_PATH="/home/projekte_bao/openclaw/data/openclaw/agents-sanitized.json"
OPENCLAW_CONFIG="/home/projekte_bao/openclaw/data/openclaw/openclaw.json"
OPENCLAW_CONFIG_DIR="/home/projekte_bao/openclaw/data/openclaw"
# Use Docker to read openclaw.json (runner doesn't have direct host fs access)
if docker run --rm \
-v "$OPENCLAW_CONFIG:/input/openclaw.json:ro" \
-v "$OPENCLAW_CONFIG_DIR:/output" \
python:3.12-alpine \
python3 -c "
import json, sys, os
config_path = '/input/openclaw.json'
output_path = '/output/agents-sanitized.json'
if not os.path.isfile(config_path):
print(f'WARNING: openclaw.json not found at {config_path} — agents-sanitized.json NOT generated', file=sys.stderr)
sys.exit(1)
with open(config_path) as f:
data = json.load(f)
agents = data.get('agents')
if agents is None:
print('ERROR: \"agents\" key not found in openclaw.json', file=sys.stderr)
sys.exit(1)
with open(output_path, 'w') as f:
json.dump({'agents': agents}, f, indent=2)
f.write('\n')
print(f'Sanitized agents config written ({len(agents.get(\"list\", []))} agents)')
" 2>&1; then
echo "Sanitized agents config written to $AGENTS_SANITIZED_PATH"
else
echo "WARNING: Failed to generate agents-sanitized.json — Nexus will use fallback agent IDs" >&2
fi
echo "Building and starting Docker compose stack" echo "Building and starting Docker compose stack"
docker run --rm \ docker run --rm \
-v "$DEPLOY_PATH:/workspace/nexus" \ -v "$DEPLOY_PATH:/workspace/nexus" \