name: Deploy on: workflow_call: inputs: artifact_name: required: true type: string environment: required: true type: string deploy_path: required: true type: string jobs: deploy: runs-on: ubuntu-latest steps: - name: Download build artifact uses: actions/download-artifact@v3 with: name: ${{ inputs.artifact_name }} path: ${{ inputs.artifact_name }} # Uploadt de inhoud van dist/ via SCP (over SSH) naar de webroot van de # test-omgeving (een Raspberry Pi achter een andere Raspberry Pi met # nginx reverse proxy - zie operations/deployment/nginx/ voor de # bijbehorende nginx-voorbeeldconfiguratie). Inloggegevens komen uit # Gitea Actions Secrets (wachtwoord-login voor nu; zie # deployment-instructions.md voor hoe je later naar een SSH-key omzet). # # Let op: dit gebeurt via een gewone shell-stap in plaats van de # appleboy/scp-action Docker-container-action. Die laatste faalt op # deze runner met "failed to attach to container: unable to upgrade # to tcp, received 409" - een bekende beperking van Podman's # Docker-compatibele API, die het attach/log-streaming-mechanisme # voor containeracties niet volledig ondersteunt. Een scp-commando # in een normale run-stap heeft die geneste container niet nodig. - name: Upload dist to ${{ inputs.environment }} web server via SCP env: # Secrets via env: in plaats van rechtstreeks in het `run:`-script # ge-interpoleerd: Gitea Actions plakt ${{ secrets.* }} als platte # tekst in het script vóórdat bash het uitvoert. Staat er een # shell-metateken in de waarde (zoals '$' of '`'), dan probeert # bash dat alsnog te interpreteren, waardoor een ander wachtwoord # bij sshpass terechtkomt dan verwacht ("Permission denied"). Via # env: krijgt bash de waarde als kant-en-klare string doorgegeven, # zonder die tweede interpretatieslag. SSHPASS: ${{ secrets.PI_MAIN_PASSWORD }} PI_MAIN_PORT: ${{ secrets.PI_MAIN_PORT }} PI_MAIN_USERNAME: ${{ secrets.PI_MAIN_USERNAME }} PI_MAIN_ADDRESS: ${{ secrets.PI_MAIN_ADDRESS }} run: | sudo apt-get update && sudo apt-get install -y sshpass sshpass -e scp \ -P "$PI_MAIN_PORT" \ -o StrictHostKeyChecking=no \ -r ${{ inputs.artifact_name }}/* \ "$PI_MAIN_USERNAME@$PI_MAIN_ADDRESS:${{ inputs.deploy_path }}"