# Deploying cointainers from Gitlab-ci

**URL:** <https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643>\
**Category:** Rancher 1.x\
**Created:** [August 5, 2016, 10:06am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643 "2016-08-05T10:06:05Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 5, 2016, 10:06am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/1 "2016-08-05T10:06:05Z")

</div>

Hi there,

I am experimenting about a full Continous integration/Continous deployment workflow just using Gitlab (with pipelines and docker registry) and Rancher. Actually Gitlab is really cool platform providing everything very well integrated.

I am in the last phase: using rancher-compose to deploy the container in my Rancher infrastructure. I am using a Gitlab-Runner to execute the CI/CD pipelines and now I need to have the rancher-compose-cli inside the container where is been everything executed. Any suggestion to have the cli inside the runner? Should I use an ubuntu base image, then download an install the debian package?

I have seen there is a docker version of [docker-compose](https://hub.docker.com/r/edevil/docker-rancher-compose/). Because inside the runner I have docker, I could use it to lunch the deployment, but I am passing a lot of private information (keys) through a third-person container.

Thanks for suggestions.,

---

<div class="post-metadata">

**Author:** ![sra](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sra/32/1514_2.png) [@sra](https://forums.suse.com/u/sra)\
**Post date:** [August 5, 2016, 1:16pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/2 "2016-08-05T13:16:24Z")

</div>

Hi! We are doing a similar thing to test out gitlab ci. I kind of hacked a working system together for this. I created a custom gitlab runner image from gitlab-runner that has `docker`, `docker-compose` and `rancher-compose` installed and they are running and registered with gitlab.

Our current pipeline is defined in 3 stages in `.gitlab-ci.yml`. The `publish` stage pushes the built images into the private repo, tagged propertly. The `deploy` stage is set to manual so if you push the button in Gitlab it runs the deployment phase for that version. The `gozerthedeployer.sh` script is just a wrapper around `make` that issues announcement of start and end and result to slack using `curl` posting to a webhook. In a previous version, the gozer script also just installed the compose tools that it needed in the runner if they were missing, which can avoid the need for a custom runner image.

```
image: docker:git

stages:
  - build
  - publish
  - deploy

.shared: &template
  tags:
    - docker
  only:
    - BRANCH

build_job:
  <<: *template
  stage: build
  script:
    - make TAG=$CI_BUILD_REF_NAME VER=$CI_PIPELINE_ID build

publish_job:
  <<: *template
  stage: publish
  script:
    - make TAG=$CI_BUILD_REF_NAME VER=$CI_PIPELINE_ID tag push

deploy_job:
  <<: *template
  stage: deploy
  script:
    - cd envs && ./gozerthedeployer.sh REDACTED
  when: manual
  environment: REDACTED

```

Maybe some of that will help 😉

---

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 11, 2016, 11:32am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/3 "2016-08-11T11:32:52Z")

</div>

@sra please, could you provide me any point with information about how to create these customs runners? or, do you know if we could use some docker image as base including rancher-compose?

In any case, very useful information with you pipeline, thank you very much.

---

<div class="post-metadata">

**Author:** ![etlweather](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/etlweather/32/419_2.png) [@etlweather](https://forums.suse.com/u/etlweather)\
**Post date:** [August 12, 2016, 4:57pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/4 "2016-08-12T16:57:03Z")

</div>

Are you trying to start new services in Rancher or upgrade existing ones?

If you are upgrading, which is what I do, then I can help you.

---

<div class="post-metadata">

**Author:** ![sra](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sra/32/1514_2.png) [@sra](https://forums.suse.com/u/sra)\
**Post date:** [August 12, 2016, 7:07pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/5 "2016-08-12T19:07:22Z")

</div>

Hi - here is most of the Dockerfile that I build our runners with.

```auto
FROM gitlab/gitlab-runner:latest

RUN curl -s https://packagecloud.io/install/repositories/github/git-lfs/script.deb.sh | sudo bash

RUN apt-get update && \
    apt-get -y install \
            make \
            rsync \
            curl \
            nano \
            sshpass \
            git-lfs \
            awscli \
            zip \
        --no-install-recommends && \
    rm -r /var/lib/apt/lists/* # 150901

RUN git lfs install

# add missing SSL certificate https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1261855
RUN curl -o /usr/local/share/ca-certificates/como.crt \
      https://gist.githubusercontent.com/schmunk42/5abeaf7ca468dc259325/raw/2a8e19139d29aeea2871206576e264ef2d45a46d/comodorsadomainvalidationsecureserverca.crt \
 && update-ca-certificates

RUN curl -L https://get.docker.com/builds/Linux/x86_64/docker-1.10.3 > /usr/local/bin/docker-1.10.3 && \
    chmod +x /usr/local/bin/docker-1.10.3 && \
    ln -s /usr/local/bin/docker-1.10.3 /usr/local/bin/docker

#RUN curl -L https://get.docker.com/builds/Linux/x86_64/docker-1.11.0.tgz > /tmp/docker-1.11.0.tgz && \
# cd /tmp && tar -xzf ./docker-1.11.0.tgz && \
# rm /tmp/docker-1.11.0.tgz && \
# mv /tmp/docker/docker /usr/local/bin/docker && \
# chmod +x /usr/local/bin/docker

RUN curl -L https://github.com/docker/compose/releases/download/1.7.0/docker-compose-`uname -s`-`uname -m` > /usr/local/bin/docker-compose && \
    chmod +x /usr/local/bin/docker-compose

ENV TERM=linux

RUN wget https://github.com/Yelp/dumb-init/releases/download/v1.0.0/dumb-init_1.0.0_amd64.deb
RUN dpkg -i dumb-init_*.deb
ENTRYPOINT ["/usr/bin/dumb-init", "/entrypoint"]
CMD ["run", "--user=root", "--working-directory=/usr/local/gitlab-runner"]

COPY auth.json /root/.docker/config.json
RUN chmod 700 /root/.docker
RUN chmod 600 /root/.docker/config.json

```

The `auth.json` file is what is saved when you `docker login` to a private repository.  
I run it with:

```auto
docker run -d --restart always -v /var/run/docker.sock:/var/run/docker.sock \
            -v /usr/local/gitlab-runner/config:/etc/gitlab-runner \
            -v /usr/local/gitlab-runner/builds:/usr/local/gitlab-runner/builds \
            --name gitlab-runner PRIVATEREPO/gitlab-runner

```

You have to one-time register it with gitlab like a normal runner

```auto
docker exec -it gitlab-runner gitlab-runner register

```

Not sure if that was what you were asking about, but there it is. I think I got most of that docker file from a docker-in-docker setup somewhere.

---

<div class="post-metadata">

**Author:** ![Jose\_Gato\_Luis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jose_gato_luis/32/6587_2.png) [@Jose\_Gato\_Luis](https://forums.suse.com/u/Jose_Gato_Luis)\
**Post date:** [August 16, 2016, 10:56am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/6 "2016-08-16T10:56:22Z")

</div>

> [@sra](#):
>
> FROM gitlab/gitlab-runner:latest

Yeaah thank you, that is exactly what I need it 🙂

---

<div class="post-metadata">

**Author:** ![cdr](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@cdr](https://forums.suse.com/u/cdr)\
**Post date:** [September 15, 2016, 10:44am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/7 "2016-09-15T10:44:26Z")

</div>

I’ve written a tool to make upgrading Rancher services from gitlab-ci.yml files a lot easier (if you don’t keep your rancher-compose.yml files in the repo)

If you add a RANCHER\_URL, RANCHER\_ACCESS\_KEY and RANCHER\_SECRET\_KEY secret variables to your project, you just need to add a new stage to your .gitlab-ci.yml file to have it upgrade the service in Rancher:

```
deploy:rancher:
  stage: deploy
  image: cdrx/rancher-gitlab-deploy
  script: upgrade

```

No further configuration is necessary if the group and project name in GitLab match the stack and service name in Rancher. If your stack or service name is different, you can pass `--stack abc` and/or `--service xyz` to the `script: upgrade` line.

Docs are on GitHub here [https://github.com/cdrx/rancher-gitlab-deploy](https://github.com/cdrx/rancher-gitlab-deploy)

---

<div class="post-metadata">

**Author:** ![Chris1](https://avatars.discourse-cdn.com/v4/letter/c/ac91a4/32.png) [@Chris1](https://forums.suse.com/u/Chris1)\
**Post date:** [October 10, 2016, 5:13pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/8 "2016-10-10T17:13:32Z")

</div>

We’ve built a small solution that does not make assumptions about project or service names, but uses a configurable service URL instead: [https://github.com/Uber5/gitlab2rancher-deploy](https://github.com/Uber5/gitlab2rancher-deploy)

Maybe useful for some? It’s just a NodeJS package, so quite lightweight.

---

<div class="post-metadata">

**Author:** ![Nick\_Thomas](https://avatars.discourse-cdn.com/v4/letter/n/c0e974/32.png) [@Nick\_Thomas](https://forums.suse.com/u/Nick_Thomas)\
**Post date:** [December 1, 2016, 3:06pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/9 "2016-12-01T15:06:57Z")

</div>

We also built a solution, check it out at:

[https://docs.google.com/presentation/d/1FdB6myROKGYwkBoddskk7GQKblQBxPrTfBy3hA5RfiA/edit?usp=sharing](https://docs.google.com/presentation/d/1FdB6myROKGYwkBoddskk7GQKblQBxPrTfBy3hA5RfiA/edit?usp=sharing)

---

<div class="post-metadata">

**Author:** ![quadriq](https://avatars.discourse-cdn.com/v4/letter/q/ecccb3/32.png) [@quadriq](https://forums.suse.com/u/quadriq)\
**Post date:** [June 8, 2017, 4:58pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/10 "2017-06-08T16:58:42Z")

</div>

here how we do it:

> **[quadriq/rancher-deploy](https://github.com/quadriq/rancher-deploy)**
>
> Contribute to rancher-deploy development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![chucky2305](https://avatars.discourse-cdn.com/v4/letter/c/35a633/32.png) [@chucky2305](https://forums.suse.com/u/chucky2305)\
**Post date:** [August 4, 2017, 6:42am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/11 "2017-08-04T06:42:54Z")

</div>

Is there any way i can ask you some questions about the gitlab runner in detail? @sra

---

<div class="post-metadata">

**Author:** ![sra](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sra/32/1514_2.png) [@sra](https://forums.suse.com/u/sra)\
**Post date:** [August 4, 2017, 10:19am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/12 "2017-08-04T10:19:33Z")

</div>

I sent a private message

---

<div class="post-metadata">

**Author:** ![chucky2305](https://avatars.discourse-cdn.com/v4/letter/c/35a633/32.png) [@chucky2305](https://forums.suse.com/u/chucky2305)\
**Post date:** [August 4, 2017, 12:49pm UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/13 "2017-08-04T12:49:58Z")

</div>

After some help from @sra and others i finally came to this solution:

```
deploy_qa:
  before_script:
    - export RANCHER_SECRET_KEY=$(echo $RANCHER_SECRET_KEY_DEV)
    - export RANCHER_ACCESS_KEY=$(echo $RANCHER_ACCESS_KEY_DEV)
  stage: deploy_qa_environment
  image: badouralix/rancher-cli
  script:
    - "rancher env ls"
    - "rancher stacks create mytestbranchname -f rancher/docker-compose.yml -r rancher/rancher-compose.yml"
  except:
    - master
  when: manual

```

Its not perfect, but it is a good way to start from

---

<div class="post-metadata">

**Author:** ![irisp](https://avatars.discourse-cdn.com/v4/letter/i/b38774/32.png) [@irisp](https://forums.suse.com/u/irisp)\
**Post date:** [November 20, 2017, 8:10am UTC](https://forums.suse.com/t/deploying-cointainers-from-gitlab-ci/3643/14 "2017-11-20T08:10:36Z")

</div>

Love to suggest JSON tool which saved my lot of time to debug JSON data.

> **[Best JSON Formatter and JSON Validator: Online JSON Formatter](https://jsonformatter.org)**
>
> Online JSON Formatter and JSON Validator will format JSON data, and helps to validate, convert JSON to XML, JSON to CSV. Save and Share JSON
