www/.forgejo/workflows/deploy.yaml
xengi 3173d0766c
Some checks failed
deploy blog / deploy (push) Has been cancelled
Update .forgejo/workflows/deploy.yaml
2026-08-25 20:57:44 +02:00

59 lines
1.9 KiB
YAML

name: deploy blog
# Create secrets with:
# KNOWN_HOST=$(ssh-keyscan -H www.berlin.ccc.de | grep ssh-ed25519 | base64 -w0)
# SSH_PRIVATE_KEY_PRODUCTION=$(agenix -d id_ed25519_www-production.age | base64 -w0)
# SSH_PRIVATE_KEY_STAGING=$(agenix -d id_ed25519_www-staging.age | base64 -w0)
on:
workflow_dispatch:
schedule:
- cron: '0 10 * * *' # daily at 10:00
push:
branches:
- staging
- production
jobs:
deploy:
runs-on: alpine-latest
steps:
- name: Install dependencies
run: apk --no-cache add hugo git openssh-client rsync
- name: Check versions
run: |
cat /etc/os-release
git version
hugo version
rsync --version
ssh -V
- name: Set envionment vars
run: echo "GIT_BRANCH=${{ forgejo.event_name == 'schedule' && 'production' || forgejo.ref_name }}" >> "$FORGEJO_ENV"
- name: Checkout repository
run: |
git clone -b $GIT_BRANCH --recursive https://git.berlin.ccc.de/cccb-website-team/www.git .
git status
- name: Render site
run: ./build.sh
- name: Setup SSH
run: |
mkdir -p ~/.ssh
printf "%s" "${{ secrets.KNOWN_HOSTS }}" | base64 -d > ~/.ssh/known_hosts
printf "%s" "${{ env.GIT_BRANCH == 'production' && secrets.SSH_PRIVATE_KEY_PRODUCTION || secrets.SSH_PRIVATE_KEY_STAGING }}" | base64 -d > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
ssh-keygen -f ~/.ssh/id_ed25519 -y > ~/.ssh/id_ed25519.pub
cat ~/.ssh/id_ed25519.pub
- name: Rsync rendered site
# TODO: add --delete
run: rsync -var -e 'ssh -i ~/.ssh/id_ed25519 -o StrictHostKeyChecking=yes' ./public/ deploy@www.berlin.ccc.de:${{ env.GIT_BRANCH == 'production' && '/srv/http/www/' || '/srv/http/www-staging/' }}
- name: Cleanup
if: ${{ always() }}
run: rm -rf ~/.ssh