
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
cf-blue-green
Advanced tools
Note: if your application's manifest is "complete", use Autopilot instead. More info below, in the Autopilot README, and in this Issue.
Allows zero-downtime deployments of applications within Cloud Foundry, with no additional setup needed.
cf
CLI v6.12.4+.npm install -g cf-blue-green
.
cf-blue-green <appname>
(instead of cf-push
) from your application directory to deploy.This creates a copy of your already-running application, and safely switches traffic over to it. It's recommended that you try this script on a non-production application environment first, just to ensure that everything is switched over properly.
The script is distributed via NPM, but doesn't actually require Node.js beyond that. If you don't want to install Node, simply:
chmod a+x cf-blue-green
.Travis supports continuous deployment, which will automatically deploy your application after its tests pass on a specified branch. To use cf-blue-green
with Travis, you need to use a script provider instead of the default Cloud Foundry provider. Your Cloud Foundry settings are read from environment variables.
Set up continuous deployment with the following settings in your .travis.yml
file:
sudo: true
env:
global:
- CF_APP=[app name]
- CF_API=[API endpoint]
- CF_USERNAME=[user]
- CF_ORGANIZATION=[organization]
- CF_SPACE=[space]
- secure: [CF_PASSWORD=[encrypted with Travis](http://docs.travis-ci.com/user/environment-variables/#Encrypted-Variables)]
before_deploy: npm install -g cf-blue-green
deploy:
provider: script
script: cf-blue-green-travis
on:
branch: [git branch you want to deploy]
cf-blue-green
creates a temporary manifest from your live application, meaning that it ignores the manifest.yml
in your directory, if you have one. To deploy any changes to your manifest, use cf push
directly.
The script fails on apps with multiple domains, because the domains in the manifest are in the form of a list:
domain:
- 18f.gov
- digitalgov.gov
To work around this, use the env var B_DOMAIN
for the domain you'd like the B instance to use.
More information about blue-green deployment, all of which this script drew from.
FAQs
zero-downtime deployment for Cloud Foundry applications
The npm package cf-blue-green receives a total of 2 weekly downloads. As such, cf-blue-green popularity was classified as not popular.
We found that cf-blue-green demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.