# Deploy: the scripts over rsync. Runs on every push to main and on manual dispatch, # because scripts are not versioned and go live immediately. # # Requires secrets: DEPLOY_HOST, DEPLOY_USER, DEPLOY_PATH, DEPLOY_PASSWORD, # DEPLOY_KNOWN_HOSTS (the host key, from ssh-keyscan -t ed25519 HOST). # # Every step is one command, and the scripted steps are Perl rather than shell, so # nothing has to be trusted to a shell option and no shell ever parses an argument. # The Perl uses builtins only. The host key is pinned from the secret before the # first connection: pointing UserKnownHostsFile at /dev/null would disable # verification and turn every deploy into a blind trust on first use. name: Deploy on: push: branches: [main] workflow_dispatch: jobs: deploy: runs-on: alpine timeout-minutes: 10 steps: - uses: actions/checkout@v7 - name: Install Perl # The alpine base image carries no Perl. run: apk add --no-cache perl - name: Generate SHA256SUMS run: | perl -e ' my @files = sort glob q{*.pl}; @files or die qq{ERROR: no scripts found\n}; open(my $out, q{>}, q{SHA256SUMS}) or die qq{SHA256SUMS: $!\n}; for my $file (@files) { open(my $sums, q{-|}, q{sha256sum}, $file) or die qq{sha256sum: $!\n}; my $line = <$sums>; # close waits for the child and answers false when it failed. close($sums) or die qq{ERROR: sha256sum failed for $file\n}; defined $line or die qq{ERROR: sha256sum produced nothing for $file\n}; print $out $line; print $line; } close($out) or die qq{SHA256SUMS: $!\n}; ' - name: Pin the host key env: DEPLOY_KNOWN_HOSTS: ${{ secrets.DEPLOY_KNOWN_HOSTS }} run: | # The runner has no persistent known_hosts, so the key comes from a secret # and is written before the first connection. perl -e ' my $key = $ENV{DEPLOY_KNOWN_HOSTS} // q{}; $key =~ m{\S} or die qq{ERROR: DEPLOY_KNOWN_HOSTS is empty\n}; my $dir = ($ENV{HOME} // q{.}) . q{/.ssh}; mkdir($dir, 0700) unless -d $dir; open(my $out, q{>}, qq{$dir/known_hosts}) or die qq{known_hosts: $!}; print $out $key; $key =~ m{\n\z} or print $out qq{\n}; close($out); chmod(0600, qq{$dir/known_hosts}) or die qq{chmod: $!}; print qq{host key pinned in $dir/known_hosts\n}; ' - name: Deploy via rsync env: DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }} DEPLOY_USER: ${{ secrets.DEPLOY_USER }} DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }} DEPLOY_PASSWORD: ${{ secrets.DEPLOY_PASSWORD }} run: | # rsync is driven from Perl through system() with a list, so no shell ever # parses the password, the remote path or the ssh options. The published # set is staged into one directory and mirrored whole, because --delete # only prunes when rsync walks a directory: a file list transfer would # leave a script removed from the repository live on the host. perl -e ' my $host = $ENV{DEPLOY_HOST} // die qq{ERROR: DEPLOY_HOST is unset\n}; my $user = $ENV{DEPLOY_USER} // die qq{ERROR: DEPLOY_USER is unset\n}; my $path = $ENV{DEPLOY_PATH} // die qq{ERROR: DEPLOY_PATH is unset\n}; my $pass = $ENV{DEPLOY_PASSWORD} // die qq{ERROR: DEPLOY_PASSWORD is unset\n}; my @files = sort glob q{*.pl}; @files or die qq{ERROR: no scripts found\n}; my $stage = ($ENV{HOME} // q{.}) . q{/.deploy-stage.} . $$; mkdir($stage, 0700) or die qq{ERROR: cannot create the staging directory: $!\n}; for my $file (@files, q{SHA256SUMS}) { system(q{cp}, q{-p}, $file, $stage) == 0 or die qq{ERROR: cannot stage $file\n}; } # The staged files are public on the host, so the directory must stay # traversable by nginx: rsync -a would carry 0700 over and every URL # behind it would answer 403. chmod(0755, $stage) or die qq{ERROR: cannot chmod the staging directory: $!\n}; print qq{Deploying to $user\@$host:$path\n}; my @cmd = (q{sshpass}, q{-p}, $pass, q{rsync}, q{-avz}, q{--delete}, q{-e}, q{ssh -o StrictHostKeyChecking=yes}, qq{$stage/}, qq{$user\@$host:$path}); system(@cmd) == 0 or die qq{ERROR: rsync failed\n}; system(q{rm}, q{-rf}, $stage) == 0 or die qq{ERROR: cannot remove the staging directory\n}; print qq{Deploy complete.\n}; '