Continuous Integration / config (pull_request) Successful in 10s
Continuous Integration / prepare (pull_request) Successful in 1m27s
Continuous Integration / build-production (pull_request) Skipped
Continuous Integration / build (pull_request) Successful in 2m6s
Continuous Integration / test (pull_request) Successful in 1m58s
Continuous Integration / deploy-production (pull_request) Skipped
Deploy / deploy (pull_request) Successful in 35s
Continuous Integration / deploy-test (pull_request) Successful in 34s
Gitea Actions plakt ${{ secrets.* }} als platte tekst in het run-script
vóórdat bash het uitvoert. Bevat het wachtwoord een shell-metateken
zoals '$', dan interpreteert bash dat alsnog, waardoor sshpass een
ander wachtwoord krijgt dan bedoeld ("Permission denied"). Via env:
en sshpass -e komt de waarde als kant-en-klare string binnen, zonder
die tweede interpretatieslag.
60 lines
2.6 KiB
YAML
60 lines
2.6 KiB
YAML
name: Deploy
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
artifact_name:
|
|
required: true
|
|
type: string
|
|
environment:
|
|
required: true
|
|
type: string
|
|
deploy_path:
|
|
required: true
|
|
type: string
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Download build artifact
|
|
uses: actions/download-artifact@v3
|
|
with:
|
|
name: ${{ inputs.artifact_name }}
|
|
path: ${{ inputs.artifact_name }}
|
|
|
|
# Uploadt de inhoud van dist/ via SCP (over SSH) naar de webroot van de
|
|
# test-omgeving (een Raspberry Pi achter een andere Raspberry Pi met
|
|
# nginx reverse proxy - zie operations/deployment/nginx/ voor de
|
|
# bijbehorende nginx-voorbeeldconfiguratie). Inloggegevens komen uit
|
|
# Gitea Actions Secrets (wachtwoord-login voor nu; zie
|
|
# deployment-instructions.md voor hoe je later naar een SSH-key omzet).
|
|
#
|
|
# Let op: dit gebeurt via een gewone shell-stap in plaats van de
|
|
# appleboy/scp-action Docker-container-action. Die laatste faalt op
|
|
# deze runner met "failed to attach to container: unable to upgrade
|
|
# to tcp, received 409" - een bekende beperking van Podman's
|
|
# Docker-compatibele API, die het attach/log-streaming-mechanisme
|
|
# voor containeracties niet volledig ondersteunt. Een scp-commando
|
|
# in een normale run-stap heeft die geneste container niet nodig.
|
|
- name: Upload dist to ${{ inputs.environment }} web server via SCP
|
|
env:
|
|
# Secrets via env: in plaats van rechtstreeks in het `run:`-script
|
|
# ge-interpoleerd: Gitea Actions plakt ${{ secrets.* }} als platte
|
|
# tekst in het script vóórdat bash het uitvoert. Staat er een
|
|
# shell-metateken in de waarde (zoals '$' of '`'), dan probeert
|
|
# bash dat alsnog te interpreteren, waardoor een ander wachtwoord
|
|
# bij sshpass terechtkomt dan verwacht ("Permission denied"). Via
|
|
# env: krijgt bash de waarde als kant-en-klare string doorgegeven,
|
|
# zonder die tweede interpretatieslag.
|
|
SSHPASS: ${{ secrets.PI_MAIN_PASSWORD }}
|
|
PI_MAIN_PORT: ${{ secrets.PI_MAIN_PORT }}
|
|
PI_MAIN_USERNAME: ${{ secrets.PI_MAIN_USERNAME }}
|
|
PI_MAIN_ADDRESS: ${{ secrets.PI_MAIN_ADDRESS }}
|
|
run: |
|
|
sudo apt-get update && sudo apt-get install -y sshpass
|
|
sshpass -e scp \
|
|
-P "$PI_MAIN_PORT" \
|
|
-o StrictHostKeyChecking=no \
|
|
-r ${{ inputs.artifact_name }}/* \
|
|
"$PI_MAIN_USERNAME@$PI_MAIN_ADDRESS:${{ inputs.deploy_path }}"
|