d272405be0
Missed two spots: the git.haemka.in keyscan and the submodule fetch's GIT_SSH_COMMAND. If git.haemka.in's DNS answer includes an AAAA record (depends on which resolver the runner hits), these hit the same no IPv6 route issue intermittently, explaining the flaky failures.
62 lines
2.1 KiB
YAML
62 lines
2.1 KiB
YAML
name: Build and deploy
|
|
|
|
on:
|
|
push:
|
|
branches: [master]
|
|
workflow_dispatch: {}
|
|
|
|
jobs:
|
|
build-and-deploy:
|
|
runs-on: self-hosted
|
|
container: python:3.12-slim
|
|
steps:
|
|
- name: Install system dependencies
|
|
run: |
|
|
apt-get update
|
|
apt-get install -y --no-install-recommends git rsync openssh-client nodejs
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
submodules: false
|
|
|
|
- name: Set up SSH key
|
|
# Same key used both as the theme repo's deploy key (Gitea) and for
|
|
# the webserver login (below) — one secret, two authorized_keys entries.
|
|
env:
|
|
DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
|
DEPLOY_HOST: ${{ vars.DEPLOY_HOST }}
|
|
DEPLOY_PORT: ${{ vars.DEPLOY_PORT }}
|
|
run: |
|
|
mkdir -p ~/.ssh
|
|
printf '%s\n' "$DEPLOY_SSH_KEY" > ~/.ssh/deploy_key
|
|
chmod 600 ~/.ssh/deploy_key
|
|
ssh-keyscan -4 -H git.haemka.in >> ~/.ssh/known_hosts
|
|
ssh-keyscan -4 -H -p "${DEPLOY_PORT:-22}" "$DEPLOY_HOST" >> ~/.ssh/known_hosts
|
|
|
|
- name: Fetch theme submodule
|
|
run: |
|
|
# Override the submodule's tracked HTTPS URL for this checkout only,
|
|
# so it's fetched over SSH with the deploy key instead of needing a
|
|
# token with access to both repos.
|
|
git config submodule.themes/latex.url git@git.haemka.in:hmk/pelican-latex.git
|
|
GIT_SSH_COMMAND="ssh -4 -i ~/.ssh/deploy_key -o StrictHostKeyChecking=yes" \
|
|
git submodule update --init --recursive
|
|
|
|
- name: Install Python dependencies
|
|
run: pip install --no-cache-dir -r requirements.txt
|
|
|
|
- name: Build site
|
|
run: pelican -s publishconf.py
|
|
|
|
- name: Deploy via rsync
|
|
env:
|
|
DEPLOY_HOST: ${{ vars.DEPLOY_HOST }}
|
|
DEPLOY_PORT: ${{ vars.DEPLOY_PORT }}
|
|
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
|
|
DEPLOY_PATH: ${{ vars.DEPLOY_PATH }}
|
|
run: |
|
|
rsync -avz --delete \
|
|
-e "ssh -4 -i ~/.ssh/deploy_key -p ${DEPLOY_PORT:-22} -o StrictHostKeyChecking=yes" \
|
|
output/ "${DEPLOY_USER}@${DEPLOY_HOST}:${DEPLOY_PATH}"
|