From be7e92b000bf8a0a5eb7c02e7c83ce2fcdcdfa8b Mon Sep 17 00:00:00 2001 From: lilsus Date: Thu, 16 Jul 2026 06:33:38 +0300 Subject: [PATCH] ci: SSH host key accept-new (drop SSH_KNOWN_HOSTS requirement) --- .gitea/workflows/deploy.yml | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 7a6986a..b80fdcf 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -12,7 +12,9 @@ # DEPLOY_HOST - server hostname/IP that Caddy runs on (e.g. lilsus.fun) # DEPLOY_USER - ssh user with write access to DEPLOY_PATH # DEPLOY_PATH - base web root, e.g. /srv/www (brand goes to /) -# SSH_KNOWN_HOSTS - output of `ssh-keyscan -H ` (pins the host key) +# The server's SSH host key is trusted on first connect (accept-new) and pinned +# after, so no SSH_KNOWN_HOSTS secret is needed. For strict pinning instead, add +# a SSH_KNOWN_HOSTS secret and change accept-new -> yes in the deploy step. # OPTIONAL Gitea variables (Settings → Actions → Variables): # TEMPLATE_REPO - clone URL of the template repo # (default: https://git.lilsus.fun/lilsus/igaming-template.git) @@ -99,15 +101,16 @@ jobs: cd "$TEMPLATE_DIR" if [ -f package-lock.json ]; then npm ci --no-audit --no-fund; else npm install --no-audit --no-fund; fi - # --- 5. Prepare SSH (key + known_hosts) for rsync deploy. --- + # --- 5. Prepare the SSH deploy key for rsync. Host key is trusted on + # first connect and pinned thereafter (StrictHostKeyChecking=accept-new + # in the deploy step), so no SSH_KNOWN_HOSTS secret is required. --- - name: Configure SSH run: | set -euo pipefail mkdir -p "$HOME/.ssh" && chmod 700 "$HOME/.ssh" printf '%s\n' "${{ secrets.DEPLOY_SSH_KEY }}" > "$HOME/.ssh/deploy_key" chmod 600 "$HOME/.ssh/deploy_key" - printf '%s\n' "${{ secrets.SSH_KNOWN_HOSTS }}" > "$HOME/.ssh/known_hosts" - chmod 644 "$HOME/.ssh/known_hosts" + touch "$HOME/.ssh/known_hosts" && chmod 644 "$HOME/.ssh/known_hosts" # --- 6. Build every brand and deploy it to .. --- - name: Build & deploy each brand @@ -119,7 +122,7 @@ jobs: [ -n "$DEPLOY_HOST" ] && [ -n "$DEPLOY_USER" ] && [ -n "$DEPLOY_PATH" ] \ || { echo "Missing DEPLOY_HOST/USER/PATH secrets"; exit 1; } - SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=yes" + SSH_OPTS="-i $HOME/.ssh/deploy_key -o UserKnownHostsFile=$HOME/.ssh/known_hosts -o StrictHostKeyChecking=accept-new" for BRAND_PATH in "$CONTENT_DIR"/repo/*/; do BRAND="$(basename "$BRAND_PATH")"