Files
twislaandClaude Opus 5.5 12c88c98d3
CI / build (pull_request) Successful in 1m20s
Site / build (pull_request) Successful in 11s
Site: published by CI after a push to main and after a release (#79)
The Site workflow's last step, and the release workflow after publishing,
ask the web server over SSH to rebuild the site. The key CI holds is tied
on the server to one forced command (restrict,command=...), so CI sends no
command and a leaked key can only refresh the site. The server, the user,
the key and the server's host key are Gitea secrets; with none of them set
the step does nothing.

scripts/site_refresh.sh is what both workflows run;
scripts/site_deploy_keygen.sh makes the key and prints where each half goes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-07 14:34:02 +02:00

67 lines
3.3 KiB
YAML

# The project site (docs/milestones/W1.md): built with Zola to see that it builds and that its pages
# are sound. After a push to main it is then published: the job asks the web server, over SSH, to
# pull main and rebuild (issue #79, scripts/site_refresh.sh). The key it holds can run that one
# command there and nothing else; the server, the user and the keys are secrets, not in this file.
#
# It runs when the site, or a document the site is built from, changes (a pull request, or a push to
# main); the firmware workflow (ci.yml) skips a change that touches only these files. A change that
# touches both runs both. src/main.cpp and lib/core/src/app_keys.h are here too: the site's command
# reference and its key tables are generated from them, and this job checks that they are still current.
name: Site
on:
push:
branches: [main]
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh']
pull_request:
paths: ['site/**', 'docs/**', 'README.md', 'CONTEXT.md', 'src/main.cpp', 'lib/core/src/app_keys.h', '.gitea/workflows/site.yml', 'scripts/site_refresh.sh']
jobs:
build:
runs-on: ubuntu
# A pull request from a fork would run someone else's code on our runner: not without us.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
container:
image: python:3.12-slim
steps:
- name: Tools
run: |
apt-get update -qq
apt-get install -y -qq --no-install-recommends git ca-certificates curl >/dev/null
# Zola, pinned by its checksum.
curl -fsSL -o /tmp/zola.tgz https://github.com/getzola/zola/releases/download/v0.22.0/zola-v0.22.0-x86_64-unknown-linux-gnu.tar.gz
echo "f1d491f8956b94384c27d75cb6b2bf60d3916d1ade9564bcbfe7c03f0258aebf /tmp/zola.tgz" | sha256sum -c -
tar xzf /tmp/zola.tgz -C /usr/local/bin zola
zola --version
- name: Check out
run: |
find . -mindepth 1 -maxdepth 1 -exec rm -rf {} +
git config --global --add safe.directory '*'
git init -q .
git remote add origin "${{ github.server_url }}/${{ github.repository }}.git"
git fetch -q origin '+refs/heads/*:refs/remotes/origin/*' '+refs/pull/*/head:refs/remotes/pull/*'
git checkout -q --detach "${{ github.sha }}"
- name: The generated developer pages are current
run: python3 site/tools/gen_dev_docs.py --check
- name: Build the site
run: |
cd site
zola check --skip-external-links
zola build --output-dir /tmp/site-out
- name: Check the pages
run: python3 site/tools/check_site.py /tmp/site-out
# Only what has been merged, and only once it has built and passed the checks above. A pull
# request never gets here, and the secrets are given to this step alone.
- name: Publish the site
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
env:
SITE_DEPLOY_KEY: ${{ secrets.SITE_DEPLOY_KEY }}
SITE_DEPLOY_HOST: ${{ secrets.SITE_DEPLOY_HOST }}
SITE_DEPLOY_USER: ${{ secrets.SITE_DEPLOY_USER }}
SITE_DEPLOY_KNOWN_HOSTS: ${{ secrets.SITE_DEPLOY_KNOWN_HOSTS }}
run: scripts/site_refresh.sh