Files
reground-site/.gitea/workflows/deploy.yml
T
will 2f4c7eaeb6
deploy / deploy (push) Successful in 6s
Switch deploy to CI-build + scoped rsync instead of shared-runner bind-mount
Piloting a fleet-wide change: CI now builds the site in an isolated
container and pushes output via rsync to a forced-command SSH key
restricted (via rrsync) to this site's own docroot only, instead of
relying on the shared Actions runner's blanket /var/www/** bind-mount
capability. See the static-site-deploy Ansible role.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-29 12:19:24 -04:00

35 lines
1.2 KiB
YAML

name: deploy
on:
push:
branches: [master]
jobs:
deploy:
runs-on: ubuntu-latest
container:
image: hugomods/hugo:exts
steps:
- uses: actions/checkout@v4
with:
submodules: recursive
- name: Install rsync + ssh client
run: |
if command -v apk >/dev/null; then
apk add --no-cache rsync openssh-client
else
apt-get update && apt-get install -y rsync openssh-client
fi
- run: hugo --minify -d public
- name: Deploy via rsync
run: |
mkdir -p ~/.ssh
printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
# The server-side key is forced-command, restricted via rrsync to
# this site's own docroot only (see the static-site-deploy
# Ansible role) — it can push new files but can never read/list
# anything back off the server, and can't reach any other site's
# directory regardless of what path is requested here.
rsync -az --delete -e "ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=accept-new" public/ root@reground.org:
env:
DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}