Files
scripts/.gitea/workflows/deploy.yml
T
petrbalvin 788cf0571f
Deploy / deploy (push) Successful in 17s
Test / test (push) Successful in 53s
feat: initial release of the scripts collection
Assisted-by: GLM 5.3 Flash
2026-09-10 04:00:00 +00:00

105 lines
4.7 KiB
YAML

# Deploy: the scripts over rsync. Runs on every push to main and on manual dispatch,
# because scripts are not versioned and go live immediately.
#
# Requires secrets: DEPLOY_HOST, DEPLOY_USER, DEPLOY_PATH, DEPLOY_PASSWORD,
# DEPLOY_KNOWN_HOSTS (the host key, from ssh-keyscan -t ed25519 HOST).
#
# Every step is one command, and the scripted steps are Perl rather than shell, so
# nothing has to be trusted to a shell option and no shell ever parses an argument.
# The Perl uses builtins only. The host key is pinned from the secret before the
# first connection: pointing UserKnownHostsFile at /dev/null would disable
# verification and turn every deploy into a blind trust on first use.
name: Deploy
on:
push:
branches: [main]
workflow_dispatch:
jobs:
deploy:
runs-on: alpine
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- name: Install Perl
# The alpine base image carries no Perl.
run: apk add --no-cache perl
- name: Generate SHA256SUMS
run: |
perl -e '
my @files = sort glob q{*.pl};
@files or die qq{ERROR: no scripts found\n};
open(my $out, q{>}, q{SHA256SUMS}) or die qq{SHA256SUMS: $!\n};
for my $file (@files) {
open(my $sums, q{-|}, q{sha256sum}, $file) or die qq{sha256sum: $!\n};
my $line = <$sums>;
# close waits for the child and answers false when it failed.
close($sums) or die qq{ERROR: sha256sum failed for $file\n};
defined $line or die qq{ERROR: sha256sum produced nothing for $file\n};
print $out $line;
print $line;
}
close($out) or die qq{SHA256SUMS: $!\n};
'
- name: Pin the host key
env:
DEPLOY_KNOWN_HOSTS: ${{ secrets.DEPLOY_KNOWN_HOSTS }}
run: |
# The runner has no persistent known_hosts, so the key comes from a secret
# and is written before the first connection.
perl -e '
my $key = $ENV{DEPLOY_KNOWN_HOSTS} // q{};
$key =~ m{\S} or die qq{ERROR: DEPLOY_KNOWN_HOSTS is empty\n};
my $dir = ($ENV{HOME} // q{.}) . q{/.ssh};
mkdir($dir, 0700) unless -d $dir;
open(my $out, q{>}, qq{$dir/known_hosts}) or die qq{known_hosts: $!};
print $out $key;
$key =~ m{\n\z} or print $out qq{\n};
close($out);
chmod(0600, qq{$dir/known_hosts}) or die qq{chmod: $!};
print qq{host key pinned in $dir/known_hosts\n};
'
- name: Deploy via rsync
env:
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
DEPLOY_PASSWORD: ${{ secrets.DEPLOY_PASSWORD }}
run: |
# rsync is driven from Perl through system() with a list, so no shell ever
# parses the password, the remote path or the ssh options. The published
# set is staged into one directory and mirrored whole, because --delete
# only prunes when rsync walks a directory: a file list transfer would
# leave a script removed from the repository live on the host.
perl -e '
my $host = $ENV{DEPLOY_HOST} // die qq{ERROR: DEPLOY_HOST is unset\n};
my $user = $ENV{DEPLOY_USER} // die qq{ERROR: DEPLOY_USER is unset\n};
my $path = $ENV{DEPLOY_PATH} // die qq{ERROR: DEPLOY_PATH is unset\n};
my $pass = $ENV{DEPLOY_PASSWORD} // die qq{ERROR: DEPLOY_PASSWORD is unset\n};
my @files = sort glob q{*.pl};
@files or die qq{ERROR: no scripts found\n};
my $stage = ($ENV{HOME} // q{.}) . q{/.deploy-stage.} . $$;
mkdir($stage, 0700) or die qq{ERROR: cannot create the staging directory: $!\n};
for my $file (@files, q{SHA256SUMS}) {
system(q{cp}, q{-p}, $file, $stage) == 0
or die qq{ERROR: cannot stage $file\n};
}
# The staged files are public on the host, so the directory must stay
# traversable by nginx: rsync -a would carry 0700 over and every URL
# behind it would answer 403.
chmod(0755, $stage) or die qq{ERROR: cannot chmod the staging directory: $!\n};
print qq{Deploying to $user\@$host:$path\n};
my @cmd = (q{sshpass}, q{-p}, $pass, q{rsync}, q{-avz}, q{--delete},
q{-e}, q{ssh -o StrictHostKeyChecking=yes}, qq{$stage/},
qq{$user\@$host:$path});
system(@cmd) == 0 or die qq{ERROR: rsync failed\n};
system(q{rm}, q{-rf}, $stage) == 0
or die qq{ERROR: cannot remove the staging directory\n};
print qq{Deploy complete.\n};
'