ENV ?= dev export ENVIRONMENT = $(ENV) # DB_PASSWORD/DB_ROOT_PASSWORD are stripped from what Compose loads — they # only flow through secrets/ now, and Compose warns "variable not set" on # any $-shaped value in --env-file even when nothing consumes it. Rewritten # fresh on every `make` invocation, so it can't drift from .env.$(ENV). # chmod 600 (not the 644 elsewhere in deploy/ — those get read by containers # under a different UID; this one is only ever read by the `docker compose` # CLI on the host, as $(ENV) invokes it, so there's no reason it needs to be # world-readable) — and every target below removes it on the way out (see # each recipe's `; rc=$$?; rm -f ...; exit $$rc`) rather than leaving a # plaintext copy of every API key and both DB passwords sitting in the repo # root after every `make` invocation. Make has no built-in "on exit" # hook across arbitrary targets, so this is repeated per-target rather than # centralized; `$$rc`/`exit $$rc` preserves the underlying command's exit # code through the cleanup so a real failure (e.g. deploy.sh erroring) still # fails the `make` invocation. COMPOSE_ENV_FILE := .env.$(ENV).compose $(shell grep -Ev '^(DB_PASSWORD|DB_ROOT_PASSWORD)=' .env.$(ENV) > $(COMPOSE_ENV_FILE) 2>/dev/null; chmod 600 $(COMPOSE_ENV_FILE) 2>/dev/null) COMPOSE = docker compose -p bookstore-$(ENV) -f docker-compose.yml -f docker-compose.$(ENV).yml --env-file $(COMPOSE_ENV_FILE) .PHONY: up down ps logs shell wp deploy backup up: $(COMPOSE) up -d --build; rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc down: $(COMPOSE) down; rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc ps: $(COMPOSE) ps; rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc logs: $(COMPOSE) logs -f; rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc # add -u root yourself for one-off root debugging (installing a package, etc.) shell: $(COMPOSE) exec -u www-data wordpress bash; rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc # make wp ENV=staging ARGS="plugin list" wp: $(COMPOSE) exec -u www-data wordpress wp $(ARGS); rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc deploy: ./deploy/deploy.sh $(ENV); rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc backup: ./deploy/backup.sh $(ENV); rc=$$?; rm -f $(COMPOSE_ENV_FILE); exit $$rc