# The project site (docs/milestones/W1.md): built with Zola to see that it builds and that its pages # are sound. After a push to main it is then published: the job asks the web server, over SSH, to # pull main and rebuild (issue #79, scripts/site_refresh.sh). The key it holds can run that one # command there and nothing else; the server, the user and the keys are secrets, not in this file. # # It runs when the site, or a document the site is built from, changes (a pull request, or a push to # main); the firmware workflow (ci.yml) skips a change that touches only these files. A change that # touches both runs both. src/main.cpp and lib/core/src/app_keys.h are here too: the site's command # reference and its key tables are generated from them, and this job checks that they are still current. name: Site on: push: branches: [main] paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh'] pull_request: paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh'] jobs: build: runs-on: ubuntu # A pull request from a fork would run someone else's code on our runner: not without us. if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository container: image: python:3.12-slim steps: - name: Tools run: | apt-get update -qq apt-get install -y -qq --no-install-recommends git ca-certificates curl >/dev/null # Zola, pinned by its checksum. curl -fsSL -o /tmp/zola.tgz https://github.com/getzola/zola/releases/download/v0.22.0/zola-v0.22.0-x86_64-unknown-linux-gnu.tar.gz echo "f1d491f8956b94384c27d75cb6b2bf60d3916d1ade9564bcbfe7c03f0258aebf /tmp/zola.tgz" | sha256sum -c - tar xzf /tmp/zola.tgz -C /usr/local/bin zola zola --version - name: Check out run: | find . -mindepth 1 -maxdepth 1 -exec rm -rf {} + git config --global --add safe.directory '*' git init -q . git remote add origin "${{ github.server_url }}/${{ github.repository }}.git" git fetch -q origin '+refs/heads/*:refs/remotes/origin/*' '+refs/pull/*/head:refs/remotes/pull/*' git checkout -q --detach "${{ github.sha }}" - name: The generated developer pages are current run: python3 site/tools/gen_dev_docs.py --check - name: Build the site run: | cd site zola check --skip-external-links zola build --output-dir /tmp/site-out - name: Check the pages run: python3 site/tools/check_site.py /tmp/site-out # Only what has been merged, and only once it has built and passed the checks above. A pull # request never gets here, and the secrets are given to this step alone. - name: Publish the site if: github.event_name == 'push' && github.ref == 'refs/heads/main' env: SITE_DEPLOY_KEY: ${{ secrets.SITE_DEPLOY_KEY }} SITE_DEPLOY_HOST: ${{ secrets.SITE_DEPLOY_HOST }} SITE_DEPLOY_USER: ${{ secrets.SITE_DEPLOY_USER }} SITE_DEPLOY_KNOWN_HOSTS: ${{ secrets.SITE_DEPLOY_KNOWN_HOSTS }} run: scripts/site_refresh.sh