diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index d24a677..3b8b770 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -7,10 +7,28 @@ jobs: runs-on: ubuntu-latest container: image: hugomods/hugo:exts - volumes: - - /var/www/twosquirrelspress.com:/var/www/twosquirrelspress.com steps: - uses: actions/checkout@v4 with: submodules: recursive - - run: hugo --minify -d /var/www/twosquirrelspress.com \ No newline at end of file + - name: Install rsync + ssh client + run: | + if command -v apk >/dev/null; then + apk add --no-cache rsync openssh-client + else + apt-get update && apt-get install -y rsync openssh-client + fi + - run: hugo --minify -d public + - name: Deploy via rsync + run: | + mkdir -p ~/.ssh + printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/deploy_key + chmod 600 ~/.ssh/deploy_key + # The server-side key is forced-command, restricted via rrsync to + # this site's own docroot only (see the static-site-deploy + # Ansible role) — it can push new files but can never read/list + # anything back off the server, and can't reach any other site's + # directory regardless of what path is requested here. + rsync -az --delete -e "ssh -i ~/.ssh/deploy_key -o StrictHostKeyChecking=accept-new" public/ root@twosquirrelspress.com: + env: + DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}