Public Access
Site: published by CI after a push to main and after a release (#79)
The Site workflow's last step, and the release workflow after publishing, ask the web server over SSH to rebuild the site. The key CI holds is tied on the server to one forced command (restrict,command=...), so CI sends no command and a leaked key can only refresh the site. The server, the user, the key and the server's host key are Gitea secrets; with none of them set the step does nothing. scripts/site_refresh.sh is what both workflows run; scripts/site_deploy_keygen.sh makes the key and prints where each half goes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
+13
-1
@@ -4,7 +4,8 @@
|
||||
# A pull request: the same tests and coverage, then the firmware (from the build cache).
|
||||
# A branch's pushes run nothing by themselves: its pull request runs, once.
|
||||
# A tag v*: the tests, then the firmware built once, clean, signed and published as a
|
||||
# Gitea release.
|
||||
# Gitea release. The site is then rebuilt: its home page and Downloads name
|
||||
# the latest release when they are built (issue #79).
|
||||
# Run by hand: the release of a tag that exists already (the ones from before CI).
|
||||
#
|
||||
# The job runs in a plain Python image, as scripts/ci.sh does on a developer's machine, with the
|
||||
@@ -153,3 +154,14 @@ jobs:
|
||||
GITEA_REPO: ${{ github.repository }}
|
||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
run: scripts/release_publish.py dist
|
||||
|
||||
# The site names the latest release on its home page and lists them all on Downloads, both
|
||||
# read when it is built: so it is rebuilt now (issue #79, as the Site workflow does).
|
||||
- name: Refresh the site
|
||||
if: steps.release.outputs.tag != ''
|
||||
env:
|
||||
SITE_DEPLOY_KEY: ${{ secrets.SITE_DEPLOY_KEY }}
|
||||
SITE_DEPLOY_HOST: ${{ secrets.SITE_DEPLOY_HOST }}
|
||||
SITE_DEPLOY_USER: ${{ secrets.SITE_DEPLOY_USER }}
|
||||
SITE_DEPLOY_KNOWN_HOSTS: ${{ secrets.SITE_DEPLOY_KNOWN_HOSTS }}
|
||||
run: scripts/site_refresh.sh
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# The project site (docs/milestones/W1.md): built with Zola to see that it builds and that its pages
|
||||
# are sound. Publishing is the maintainer's: the web server pulls main and runs `zola build`.
|
||||
# are sound. After a push to main it is then published: the job asks the web server, over SSH, to
|
||||
# pull main and rebuild (issue #79, scripts/site_refresh.sh). The key it holds can run that one
|
||||
# command there and nothing else; the server, the user and the keys are secrets, not in this file.
|
||||
#
|
||||
# It runs when the site, or a document the site is built from, changes (a pull request, or a push to
|
||||
# main); the firmware workflow (ci.yml) skips a change that touches only these files. A change that
|
||||
@@ -9,9 +11,9 @@ name: Site
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml']
|
||||
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh']
|
||||
pull_request:
|
||||
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml']
|
||||
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh']
|
||||
|
||||
jobs:
|
||||
build:
|
||||
@@ -51,3 +53,14 @@ jobs:
|
||||
|
||||
- name: Check the pages
|
||||
run: python3 site/tools/check_site.py /tmp/site-out
|
||||
|
||||
# Only what has been merged, and only once it has built and passed the checks above. A pull
|
||||
# request never gets here, and the secrets are given to this step alone.
|
||||
- name: Publish the site
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
env:
|
||||
SITE_DEPLOY_KEY: ${{ secrets.SITE_DEPLOY_KEY }}
|
||||
SITE_DEPLOY_HOST: ${{ secrets.SITE_DEPLOY_HOST }}
|
||||
SITE_DEPLOY_USER: ${{ secrets.SITE_DEPLOY_USER }}
|
||||
SITE_DEPLOY_KNOWN_HOSTS: ${{ secrets.SITE_DEPLOY_KNOWN_HOSTS }}
|
||||
run: scripts/site_refresh.sh
|
||||
|
||||
Reference in New Issue
Block a user