105 lines
4.7 KiB
YAML
105 lines
4.7 KiB
YAML
# Deploy: the scripts over rsync. Runs on every push to main and on manual dispatch,
|
|
# because scripts are not versioned and go live immediately.
|
|
#
|
|
# Requires secrets: DEPLOY_HOST, DEPLOY_USER, DEPLOY_PATH, DEPLOY_PASSWORD,
|
|
# DEPLOY_KNOWN_HOSTS (the host key, from ssh-keyscan -t ed25519 HOST).
|
|
#
|
|
# Every step is one command, and the scripted steps are Perl rather than shell, so
|
|
# nothing has to be trusted to a shell option and no shell ever parses an argument.
|
|
# The Perl uses builtins only. The host key is pinned from the secret before the
|
|
# first connection: pointing UserKnownHostsFile at /dev/null would disable
|
|
# verification and turn every deploy into a blind trust on first use.
|
|
name: Deploy
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: alpine
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Install Perl
|
|
# The alpine base image carries no Perl.
|
|
run: apk add --no-cache perl
|
|
|
|
- name: Generate SHA256SUMS
|
|
run: |
|
|
perl -e '
|
|
my @files = sort glob q{*.pl};
|
|
@files or die qq{ERROR: no scripts found\n};
|
|
open(my $out, q{>}, q{SHA256SUMS}) or die qq{SHA256SUMS: $!\n};
|
|
for my $file (@files) {
|
|
open(my $sums, q{-|}, q{sha256sum}, $file) or die qq{sha256sum: $!\n};
|
|
my $line = <$sums>;
|
|
# close waits for the child and answers false when it failed.
|
|
close($sums) or die qq{ERROR: sha256sum failed for $file\n};
|
|
defined $line or die qq{ERROR: sha256sum produced nothing for $file\n};
|
|
print $out $line;
|
|
print $line;
|
|
}
|
|
close($out) or die qq{SHA256SUMS: $!\n};
|
|
'
|
|
|
|
- name: Pin the host key
|
|
env:
|
|
DEPLOY_KNOWN_HOSTS: ${{ secrets.DEPLOY_KNOWN_HOSTS }}
|
|
run: |
|
|
# The runner has no persistent known_hosts, so the key comes from a secret
|
|
# and is written before the first connection.
|
|
perl -e '
|
|
my $key = $ENV{DEPLOY_KNOWN_HOSTS} // q{};
|
|
$key =~ m{\S} or die qq{ERROR: DEPLOY_KNOWN_HOSTS is empty\n};
|
|
my $dir = ($ENV{HOME} // q{.}) . q{/.ssh};
|
|
mkdir($dir, 0700) unless -d $dir;
|
|
open(my $out, q{>}, qq{$dir/known_hosts}) or die qq{known_hosts: $!};
|
|
print $out $key;
|
|
$key =~ m{\n\z} or print $out qq{\n};
|
|
close($out);
|
|
chmod(0600, qq{$dir/known_hosts}) or die qq{chmod: $!};
|
|
print qq{host key pinned in $dir/known_hosts\n};
|
|
'
|
|
|
|
- name: Deploy via rsync
|
|
env:
|
|
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
|
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
|
DEPLOY_PATH: ${{ secrets.DEPLOY_PATH }}
|
|
DEPLOY_PASSWORD: ${{ secrets.DEPLOY_PASSWORD }}
|
|
run: |
|
|
# rsync is driven from Perl through system() with a list, so no shell ever
|
|
# parses the password, the remote path or the ssh options. The published
|
|
# set is staged into one directory and mirrored whole, because --delete
|
|
# only prunes when rsync walks a directory: a file list transfer would
|
|
# leave a script removed from the repository live on the host.
|
|
perl -e '
|
|
my $host = $ENV{DEPLOY_HOST} // die qq{ERROR: DEPLOY_HOST is unset\n};
|
|
my $user = $ENV{DEPLOY_USER} // die qq{ERROR: DEPLOY_USER is unset\n};
|
|
my $path = $ENV{DEPLOY_PATH} // die qq{ERROR: DEPLOY_PATH is unset\n};
|
|
my $pass = $ENV{DEPLOY_PASSWORD} // die qq{ERROR: DEPLOY_PASSWORD is unset\n};
|
|
my @files = sort glob q{*.pl};
|
|
@files or die qq{ERROR: no scripts found\n};
|
|
my $stage = ($ENV{HOME} // q{.}) . q{/.deploy-stage.} . $$;
|
|
mkdir($stage, 0700) or die qq{ERROR: cannot create the staging directory: $!\n};
|
|
for my $file (@files, q{SHA256SUMS}) {
|
|
system(q{cp}, q{-p}, $file, $stage) == 0
|
|
or die qq{ERROR: cannot stage $file\n};
|
|
}
|
|
# The staged files are public on the host, so the directory must stay
|
|
# traversable by nginx: rsync -a would carry 0700 over and every URL
|
|
# behind it would answer 403.
|
|
chmod(0755, $stage) or die qq{ERROR: cannot chmod the staging directory: $!\n};
|
|
print qq{Deploying to $user\@$host:$path\n};
|
|
my @cmd = (q{sshpass}, q{-p}, $pass, q{rsync}, q{-avz}, q{--delete},
|
|
q{-e}, q{ssh -o StrictHostKeyChecking=yes}, qq{$stage/},
|
|
qq{$user\@$host:$path});
|
|
system(@cmd) == 0 or die qq{ERROR: rsync failed\n};
|
|
system(q{rm}, q{-rf}, $stage) == 0
|
|
or die qq{ERROR: cannot remove the staging directory\n};
|
|
print qq{Deploy complete.\n};
|
|
'
|