ci: SSH host key accept-new (drop SSH_KNOWN_HOSTS requirement)
Build & Deploy Brands / build-and-deploy (push) Has been cancelled
Build & Deploy Brands / build-and-deploy (push) Has been cancelled
This commit is contained in:
@@ -12,7 +12,9 @@
|
||||
# DEPLOY_HOST - server hostname/IP that Caddy runs on (e.g. lilsus.fun)
|
||||
# DEPLOY_USER - ssh user with write access to DEPLOY_PATH
|
||||
# DEPLOY_PATH - base web root, e.g. /srv/www (brand goes to <path>/<brand>)
|
||||
# SSH_KNOWN_HOSTS - output of `ssh-keyscan -H <DEPLOY_HOST>` (pins the host key)
|
||||
# The server's SSH host key is trusted on first connect (accept-new) and pinned
|
||||
# after, so no SSH_KNOWN_HOSTS secret is needed. For strict pinning instead, add
|
||||
# a SSH_KNOWN_HOSTS secret and change accept-new -> yes in the deploy step.
|
||||
# OPTIONAL Gitea variables (Settings → Actions → Variables):
|
||||
# TEMPLATE_REPO - clone URL of the template repo
|
||||
# (default: https://git.lilsus.fun/lilsus/igaming-template.git)
|
||||
@@ -99,15 +101,16 @@ jobs:
|
||||
cd "$TEMPLATE_DIR"
|
||||
if [ -f package-lock.json ]; then npm ci --no-audit --no-fund; else npm install --no-audit --no-fund; fi
|
||||
|
||||
# --- 5. Prepare SSH (key + known_hosts) for rsync deploy. ---
|
||||
# --- 5. Prepare the SSH deploy key for rsync. Host key is trusted on
|
||||
# first connect and pinned thereafter (StrictHostKeyChecking=accept-new
|
||||
# in the deploy step), so no SSH_KNOWN_HOSTS secret is required. ---
|
||||
- name: Configure SSH
|
||||
run: |
|
||||
set -euo pipefail
|
||||
mkdir -p "$HOME/.ssh" && chmod 700 "$HOME/.ssh"
|
||||
printf '%s\n' "${{ secrets.DEPLOY_SSH_KEY }}" > "$HOME/.ssh/deploy_key"
|
||||
chmod 600 "$HOME/.ssh/deploy_key"
|
||||
printf '%s\n' "${{ secrets.SSH_KNOWN_HOSTS }}" > "$HOME/.ssh/known_hosts"
|
||||
chmod 644 "$HOME/.ssh/known_hosts"
|
||||
touch "$HOME/.ssh/known_hosts" && chmod 644 "$HOME/.ssh/known_hosts"
|
||||
|
||||
# --- 6. Build every brand and deploy it to <brand>.<SITE_TLD>. ---
|
||||
- name: Build & deploy each brand
|
||||
@@ -119,7 +122,7 @@ jobs:
|
||||
[ -n "$DEPLOY_HOST" ] && [ -n "$DEPLOY_USER" ] && [ -n "$DEPLOY_PATH" ] \
|
||||
|| { echo "Missing DEPLOY_HOST/USER/PATH secrets"; exit 1; }
|
||||
|
||||
SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=yes"
|
||||
SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=accept-new"
|
||||
|
||||
for BRAND_PATH in "$CONTENT_DIR"/repo/*/; do
|
||||
BRAND="$(basename "$BRAND_PATH")"
|
||||
|
||||
Reference in New Issue
Block a user