Switch deploy to CI-build + scoped rsync instead of shared-runner bind-mount
deploy / deploy (push) Successful in 5s
deploy / deploy (push) Successful in 5s
Fleet-wide change: CI now builds the site in an isolated container and pushes output via rsync to a forced-command SSH key restricted (via rrsync) to this site's own docroot only, instead of relying on the shared Actions runner's blanket /var/www/** bind-mount capability. See the static-site-deploy Ansible role in reground-infrastructure. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -7,10 +7,28 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
image: hugomods/hugo:exts
|
image: hugomods/hugo:exts
|
||||||
volumes:
|
|
||||||
- /var/www/michaelferrara.org:/var/www/michaelferrara.org
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
submodules: recursive
|
submodules: recursive
|
||||||
- run: hugo --minify -d /var/www/michaelferrara.org
|
- name: Install rsync + ssh client
|
||||||
|
run: |
|
||||||
|
if command -v apk >/dev/null; then
|
||||||
|
apk add --no-cache rsync openssh-client
|
||||||
|
else
|
||||||
|
apt-get update && apt-get install -y rsync openssh-client
|
||||||
|
fi
|
||||||
|
- run: hugo --minify -d public
|
||||||
|
- name: Deploy via rsync
|
||||||
|
run: |
|
||||||
|
mkdir -p ~/.ssh
|
||||||
|
printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/deploy_key
|
||||||
|
chmod 600 ~/.ssh/deploy_key
|
||||||
|
# The server-side key is forced-command, restricted via rrsync to
|
||||||
|
# this site's own docroot only (see the static-site-deploy
|
||||||
|
# Ansible role) — it can push new files but can never read/list
|
||||||
|
# anything back off the server, and can't reach any other site's
|
||||||
|
# directory regardless of what path is requested here.
|
||||||
|
rsync -az --delete -e "ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=accept-new" public/ root@michaelferrara.org:
|
||||||
|
env:
|
||||||
|
DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||||
|
|||||||
Reference in New Issue
Block a user