{"thread":{"id":"29125","subject":"git for change control of software deployment updates","startedAt":"2011-12-10T02:37:53Z","lastAt":"2011-12-11T05:09:47Z","messageCount":3,"participants":["Neal Kreitzinger","David Aguilar"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"180740","messageId":"jbugm2$afc$1@dough.gmane.org","threadId":"29125","inReplyTo":null,"subject":"git for change control of software deployment updates","fromName":"Neal Kreitzinger","fromEmail":"neal@rsss.com","sentAt":"2011-12-10T02:37:53Z","receivedAt":"2011-12-10T02:37:53Z","isPatch":false,"sender":{"key":"neal@rsss.com","avatar":null},"body":"I am considering using git with submodules to deploy most of our updates to \nour customer linux servers (not including third party rpm updates already \ntracked by linux distro rpm repository).  Has anyone else done this? \nComments?  (Sanity check.)  (I am new to submodules.)\n\nHere are some rationale and concerns I submit for review:\n\nReasons:\n- (Main Premise)  I maintain dozens of divergent custom versions \nconcurrently with each running on its own server (we do merge these versions \neventually and then immediately start diverging again).  (This is the main \nreason we chose git for scm.)  Hundreds of servers run the 'main generic' \nversion.  Git will allow these branches to deploy to their respective \ncustomers.\n- (Main Supporting Premise)  others on the git-newsgroup talk about using \ngit submodules to maintain web sites.  Not sure how robust they are.  In \ntheory, a website seems no different than any other application server.\n- git on the customer server would allow better tracking of what the \ncustomer is really running (ie, dirty tree).\n- Submodules will track everything outside of linux distro rpms that we \nupdate outside of linux rpms (third party binaries, html, etc.).\n- Submodules containing source will be separate and not deployed.\n- I already use git to deploy test versions of the core software from \ndev-server to qa-servers (using git-pull --ff-only, git-clone, etc. on the \nqa-server end).\n- I can do most of the work using git features/git-scripts with a minimum of \nhomegrown bash scripts/tars.\n- git with ssh will make it secure (most customer servers are in vpn \nanyway).\n- using separate worktree will separate git repos from deployed binaries.\n- git will figure out the 'patches' to transfer in order to effect a version \nchange.\n- versioning of config files (apache, etc.) to aid in troubleshooting.\n- trying to do this with rpm's makes no sense when I can do it with git.\n- trying to do this with homemade scripts/tars makes no sense when I can do \nthis with git.\n- gitweb will make semi-technical support personnel use possible on the \ncustomer server in the absence of gitk (gui portion of linux).\n- I can have a development superproject pointing to all submodules, and a \ndeployment superproject pointing to same submodules but not including source \ncode submodules.\n- if fetch/pull are better for this than push I can setup a deployment \nserver that customers have access to.  It seems fetch/pull are more \nconducive to monitoring success/failure, but push is more conducive to \ncentral control.\n- having some history of previous versions seems valuable for rapid \nremediation of regressions (git checkout <prev-version> -- mybinary).\n- remote tracking of customer server configurations.\n- git could track pre/post-conversion/initialization data file states.\n- track customer server configuration file customizations and merge them \nwith subsequent changes to base version.\n- such a git deployment setup would make emulating a prod server on a test \nserver a matter of course.\n\nConcerns:\n- is there something about git that would make this unsecure during the \n\"patch\" transfer (push, fetch, etc)?\n- can I limit disk use (repo history) using shallow-clone or some disk \nsaving tricks?  IOW, repo on customer server only needs sufficient common \nancestor to accept updates and not the whole history before the common \nancestor.  (The majority of deployed content will be binaries.)\n- customer servers will not have gui portion of linux loaded (minimal VM \nimages on an array in most cases).\n- automation of the execution of data format conversion/initialization \nprograms (receive hook that checks for and executes and waits for completion \nof such programs) as such commits apply on the repo on the customer server \nor as an aggregate after all commits apply.  (I think of the new execute \noption in rebase, but that is different from receiving during a push.)\n- upgrading git versions (breaking deployment system).\n- size limits in git to versioning large data files (works for most \ncustomers, but not the huge ones).\n- gitweb is getting smarter and is no longer 'view only' like the old days. \nCan it be made 'view only'?\n- github (paid version) is too dumbed down to play well with this usage. \n(I've only read about github but may be asked to use it to some extent.)\n- one little git command could wreak havoc on a live customer server.  Then \nagain, so can one little linux command.  Is there a way to 'sudo' the git \ncommands?\n- I rely on porcelain and do not recreate my own porcelain from plumbing. \n(I am a porcelain level user.)\n- detection of failures allowing for reset to previous version of software \nand data.\n- limits to mass deployment (max approx 500 servers in one night). \nConcurrent pushes?  Concurrent fetches from same remote?\n- is there something else about git that might make this untenable over \ntime?\n\nThanks in advance.\n\nv/r,\nneal\n"},{"id":"180817","messageId":"CAJDDKr7+GeJTR986DSqKpQRWsXGFVzjBqg6WgRyG-EtycrQs7A@mail.gmail.com","threadId":"29125","inReplyTo":"jbugm2$afc$1@dough.gmane.org","subject":"Re: git for change control of software deployment updates","fromName":"David Aguilar","fromEmail":"davvid@gmail.com","sentAt":"2011-12-11T03:19:00Z","receivedAt":"2011-12-11T03:19:00Z","isPatch":false,"sender":{"key":"davvid@gmail.com","avatar":"https://avatars.githubusercontent.com/u/13196?v=4"},"body":"On Fri, Dec 9, 2011 at 6:37 PM, Neal Kreitzinger <neal@rsss.com> wrote:\n> I am considering using git with submodules to deploy most of our updates to\n> our customer linux servers (not including third party rpm updates already\n> tracked by linux distro rpm repository).  Has anyone else done this?\n> Comments?  (Sanity check.)  (I am new to submodules.)\n\nI wrote a script that converts a git source repository into a redhat\nsrc.rpm.  We use it at my $dayjob.  How about doing something like\nthat?  After you have a src.rpm you can create rpms that you can\ndistribute using yum.  You are already using rpm which is why I\nmention it.  Converting a directory of rpm files into a hostable\nrepository is as simple as `createrepo /path/to/rpms/`.\n\nThe git project has a 'make rpm' target in its Makefile that you could\nuse as an example.\n-- \n            David\n"},{"id":"180818","messageId":"jc1dur$80q$1@dough.gmane.org","threadId":"29125","inReplyTo":"CAJDDKr7+GeJTR986DSqKpQRWsXGFVzjBqg6WgRyG-EtycrQs7A@mail.gmail.com","subject":"Re: git for change control of software deployment updates","fromName":"Neal Kreitzinger","fromEmail":"nkreitzinger@gmail.com","sentAt":"2011-12-11T05:09:47Z","receivedAt":"2011-12-11T05:09:47Z","isPatch":false,"sender":{"key":"nkreitzinger@gmail.com","avatar":null},"body":"On 12/10/2011 9:19 PM, David Aguilar wrote:\n> On Fri, Dec 9, 2011 at 6:37 PM, Neal Kreitzinger<neal@rsss.com>  wrote:\n>> I am considering using git with submodules to deploy most of our updates to\n>> our customer linux servers (not including third party rpm updates already\n>> tracked by linux distro rpm repository).  Has anyone else done this?\n>> Comments?  (Sanity check.)  (I am new to submodules.)\n>\n> I wrote a script that converts a git source repository into a redhat\n> src.rpm.  We use it at my $dayjob.  How about doing something like\n> that?  After you have a src.rpm you can create rpms that you can\n> distribute using yum.  You are already using rpm which is why I\n> mention it.  Converting a directory of rpm files into a hostable\n> repository is as simple as `createrepo /path/to/rpms/`.\n>\n> The git project has a 'make rpm' target in its Makefile that you could\n> use as an example.\nWe use rhel so, yes, we use the redhat repo to get rhel patches.  Is \nthat what you mean by \"You are already using rpm\"?  (We do not write our \nown rpm's at this time.)\n\nv/r,\nneal\n"}]}