#!/usr/bin/env bash # Creates the key CI uses to ask the web server for a site refresh, once (issue #79, # docs/milestones/W1.md), and says where each half goes. The private key stays in # ~/.config/roro9stack/ until it is pasted into the Gitea secret; it is never committed and this # script doesn't print it. # # scripts/site_deploy_keygen.sh [/full/path/to/rororefresh.sh] [the runner's address] set -euo pipefail KEY="${RORO_SITE_DEPLOY_KEY:-$HOME/.config/roro9stack/site-deploy-key}" COMMAND="${1:-/full/path/to/rororefresh.sh}" FROM="${2:-}" if [ -e "$KEY" ]; then echo "A site deploy key already exists at $KEY; not overwriting it." >&2 else mkdir -p "$(dirname "$KEY")" ( umask 077; ssh-keygen -q -t ed25519 -N "" -C roro9stack-ci-site-refresh -f "$KEY" ) fi options="restrict,command=\"$COMMAND\"" [ -z "$FROM" ] || options="from=\"$FROM\",$options" cat < Actions > Secrets: SITE_DEPLOY_KEY the whole of $KEY (the private key, with its BEGIN and END lines) SITE_DEPLOY_HOST the server's address as the runner reaches it, or address:port SITE_DEPLOY_USER that user's name SITE_DEPLOY_KNOWN_HOSTS the server's host key, one line, from a machine you trust the network of: ssh-keyscan -t ed25519
(or: -p
) and compare it with the server's own: ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub (on the server) ssh-keyscan -t ed25519
| ssh-keygen -lf - (here) 3. Try it, from here, with the same four values in the environment: SITE_DEPLOY_KEY="\$(cat $KEY)" SITE_DEPLOY_HOST=... SITE_DEPLOY_USER=... \\ SITE_DEPLOY_KNOWN_HOSTS="\$(ssh-keyscan -t ed25519 ... 2>/dev/null)" scripts/site_refresh.sh (with from= set, this works from the runner's address only.) Then, to see that the key can do nothing else: ssh -i $KEY @
id must run the refresh, not \`id\`. Once the secret is in Gitea, the copy at $KEY can be deleted. TEXT