diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml new file mode 100644 index 0000000..606c1b9 --- /dev/null +++ b/.gitea/workflows/deploy.yml @@ -0,0 +1,34 @@ +name: deploy +on: + push: + branches: [main] +jobs: + deploy: + runs-on: ubuntu-latest + container: + image: hugomods/hugo:exts + steps: + - uses: actions/checkout@v4 + with: + submodules: recursive + - name: Install rsync + ssh client + run: | + if command -v apk >/dev/null; then + apk add --no-cache rsync openssh-client + else + apt-get update && apt-get install -y rsync openssh-client + fi + - run: hugo --minify -d public + - name: Deploy via rsync + run: | + mkdir -p ~/.ssh + printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/deploy_key + chmod 600 ~/.ssh/deploy_key + # The server-side key is forced-command, restricted via rrsync to + # this site's own docroot only (see the static-site-deploy + # Ansible role) — it can push new files but can never read/list + # anything back off the server, and can't reach any other site's + # directory regardless of what path is requested here. + rsync -az --delete -e "ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=accept-new" public/ root@sunfloweracres.reground.org: + env: + DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}