ci: SSH host key accept-new (drop SSH_KNOWN_HOSTS requirement)
Build & Deploy Brands / build-and-deploy (push) Has been cancelled

This commit is contained in:
2026-07-16 06:33:37 +03:00
parent 490819f884
commit 60c2f0ac60
+8 -5
View File
@@ -12,7 +12,9 @@
# DEPLOY_HOST - server hostname/IP that Caddy runs on (e.g. lilsus.fun)
# DEPLOY_USER - ssh user with write access to DEPLOY_PATH
# DEPLOY_PATH - base web root, e.g. /srv/www (brand goes to <path>/<brand>)
# SSH_KNOWN_HOSTS - output of `ssh-keyscan -H <DEPLOY_HOST>` (pins the host key)
# The server's SSH host key is trusted on first connect (accept-new) and pinned
# after, so no SSH_KNOWN_HOSTS secret is needed. For strict pinning instead, add
# a SSH_KNOWN_HOSTS secret and change accept-new -> yes in the deploy step.
# OPTIONAL Gitea variables (Settings → Actions → Variables):
# TEMPLATE_REPO - clone URL of the template repo
# (default: https://git.lilsus.fun/lilsus/igaming-template.git)
@@ -99,15 +101,16 @@ jobs:
cd "$TEMPLATE_DIR"
if [ -f package-lock.json ]; then npm ci --no-audit --no-fund; else npm install --no-audit --no-fund; fi
# --- 5. Prepare SSH (key + known_hosts) for rsync deploy. ---
# --- 5. Prepare the SSH deploy key for rsync. Host key is trusted on
# first connect and pinned thereafter (StrictHostKeyChecking=accept-new
# in the deploy step), so no SSH_KNOWN_HOSTS secret is required. ---
- name: Configure SSH
run: |
set -euo pipefail
mkdir -p "$HOME/.ssh" && chmod 700 "$HOME/.ssh"
printf '%s\n' "${{ secrets.DEPLOY_SSH_KEY }}" > "$HOME/.ssh/deploy_key"
chmod 600 "$HOME/.ssh/deploy_key"
printf '%s\n' "${{ secrets.SSH_KNOWN_HOSTS }}" > "$HOME/.ssh/known_hosts"
chmod 644 "$HOME/.ssh/known_hosts"
touch "$HOME/.ssh/known_hosts" && chmod 644 "$HOME/.ssh/known_hosts"
# --- 6. Build every brand and deploy it to <brand>.<SITE_TLD>. ---
- name: Build & deploy each brand
@@ -119,7 +122,7 @@ jobs:
[ -n "$DEPLOY_HOST" ] && [ -n "$DEPLOY_USER" ] && [ -n "$DEPLOY_PATH" ] \
|| { echo "Missing DEPLOY_HOST/USER/PATH secrets"; exit 1; }
SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=yes"
SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=accept-new"
for BRAND_PATH in "$CONTENT_DIR"/repo/*/; do
BRAND="$(basename "$BRAND_PATH")"