ci: deploy via ssh + tar (runner image has no rsync)
Build & Deploy Brands / build-and-deploy (push) Successful in 17s

This commit is contained in:
2026-07-16 07:18:57 +03:00
parent c2d1278318
commit 9208285591
+19 -12
View File
@@ -1,6 +1,6 @@
# ============================================================================= # =============================================================================
# deploy.yml — build every brand in this content repo with Hugo and deploy each # deploy.yml — build every brand in this content repo with Hugo and deploy each
# to <brand>.lilsus.fun via rsync over SSH. Runs on every push to main (i.e. # to <brand>.lilsus.fun via SSH (ssh + tar). Runs on every push to main (i.e.
# after each n8n pipeline run that commits repo/<brand>/...). # after each n8n pipeline run that commits repo/<brand>/...).
# #
# INSTALL: copy this file to .gitea/workflows/deploy.yml in the CONTENT repo # INSTALL: copy this file to .gitea/workflows/deploy.yml in the CONTENT repo
@@ -22,8 +22,9 @@
# SITE_TLD - base domain for per-brand hosts (default lilsus.fun) # SITE_TLD - base domain for per-brand hosts (default lilsus.fun)
# #
# RUNNER REQUIREMENTS: a registered Gitea act_runner whose image has bash, git, # RUNNER REQUIREMENTS: a registered Gitea act_runner whose image has bash, git,
# curl, tar, rsync, openssh-client and Node.js >= 20 (for Tailwind/PostCSS). # curl, tar, openssh-client and Node.js >= 20 (for Tailwind/PostCSS). rsync is
# The default `gitea/runner`/`catthehacker/ubuntu` images include these. # NOT required (deploy uses ssh + tar). The default runner-images/ubuntu images
# include these.
# ============================================================================= # =============================================================================
name: Build & Deploy Brands name: Build & Deploy Brands
run-name: deploy ${{ gitea.sha }} run-name: deploy ${{ gitea.sha }}
@@ -116,9 +117,10 @@ jobs:
npm install --no-audit --no-fund --ignore-scripts npm install --no-audit --no-fund --ignore-scripts
fi fi
# --- 5. Prepare the SSH deploy key for rsync. Host key is trusted on # --- 5. Prepare the SSH deploy key (deploy is plain ssh + tar, no rsync).
# first connect and pinned thereafter (StrictHostKeyChecking=accept-new # Host key is trusted on first connect and pinned thereafter
# in the deploy step), so no SSH_KNOWN_HOSTS secret is required. --- # (StrictHostKeyChecking=accept-new in the deploy step), so no
# SSH_KNOWN_HOSTS secret is required. ---
- name: Configure SSH - name: Configure SSH
run: | run: |
set -euo pipefail set -euo pipefail
@@ -158,12 +160,17 @@ jobs:
echo "::endgroup::" echo "::endgroup::"
echo "::group::Deploy ${BRAND}" echo "::group::Deploy ${BRAND}"
# Ensure the target dir exists, then mirror public/ into it. # Deploy over plain SSH only (no rsync — not present in the runner image).
ssh $SSH_OPTS "${DEPLOY_USER}@${DEPLOY_HOST}" "mkdir -p '${DEPLOY_PATH}/${BRAND}'" # Stream public/ as a tarball into a fresh temp dir on the server, then
rsync -az --delete \ # atomically swap it into place. Mirrors --delete semantics (stale files
-e "ssh $SSH_OPTS" \ # vanish because the live dir is fully replaced). Needs only ssh + tar.
"$BUILD_DIR/public/" \ REMOTE_TMP="${DEPLOY_PATH}/.deploy-${BRAND}-$(date +%s)"
"${DEPLOY_USER}@${DEPLOY_HOST}:${DEPLOY_PATH}/${BRAND}/" tar -czf - -C "$BUILD_DIR/public" . | ssh $SSH_OPTS "${DEPLOY_USER}@${DEPLOY_HOST}" "\
set -e; \
mkdir -p '${REMOTE_TMP}' '${DEPLOY_PATH}'; \
tar -xzf - -C '${REMOTE_TMP}'; \
rm -rf '${DEPLOY_PATH}/${BRAND}'; \
mv '${REMOTE_TMP}' '${DEPLOY_PATH}/${BRAND}'"
echo "Deployed ${BRAND} to ${DEPLOY_USER}@${DEPLOY_HOST}:${DEPLOY_PATH}/${BRAND}/" echo "Deployed ${BRAND} to ${DEPLOY_USER}@${DEPLOY_HOST}:${DEPLOY_PATH}/${BRAND}/"
echo "::endgroup::" echo "::endgroup::"
done done