This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
name: Test and deploy
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
|
||||
steps:
|
||||
- name: Check out the site
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 22
|
||||
|
||||
- name: Install dependencies
|
||||
run: npm ci
|
||||
|
||||
- name: Test the site
|
||||
run: npm test
|
||||
|
||||
- name: Install deployment tools
|
||||
run: |
|
||||
apt-get update
|
||||
apt-get install --yes --no-install-recommends openssh-client rsync
|
||||
|
||||
- name: Configure deployment SSH key
|
||||
env:
|
||||
DEPLOY_SSH_KEY: ${{ secrets.DEPLOY_SSH_KEY }}
|
||||
DEPLOY_KNOWN_HOSTS: ${{ secrets.DEPLOY_KNOWN_HOSTS }}
|
||||
run: |
|
||||
install -d -m 0700 "$HOME/.ssh"
|
||||
printf '%s\n' "$DEPLOY_SSH_KEY" > "$HOME/.ssh/deploy_key"
|
||||
printf '%s\n' "$DEPLOY_KNOWN_HOSTS" > "$HOME/.ssh/known_hosts"
|
||||
chmod 0600 "$HOME/.ssh/deploy_key" "$HOME/.ssh/known_hosts"
|
||||
|
||||
- name: Upload the website
|
||||
env:
|
||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
||||
run: |
|
||||
rsync \
|
||||
--archive \
|
||||
--compress \
|
||||
--delete \
|
||||
--delay-updates \
|
||||
--human-readable \
|
||||
--itemize-changes \
|
||||
--rsh "ssh -i $HOME/.ssh/deploy_key -o IdentitiesOnly=yes" \
|
||||
web/ \
|
||||
"firewallissues-deploy@${DEPLOY_HOST}:/var/www/html/firewallissues/web/"
|
||||
@@ -23,3 +23,30 @@ Some data was collected early on when the HTMLTable -> Markdown code was kind of
|
||||
The `external_refs.json` file allows for links to be added to other websites that have information or discussion about certain issues.
|
||||
|
||||
I have vague ideas of something similar for CVEs.
|
||||
|
||||
## Automatic deployment
|
||||
|
||||
Gitea Actions tests and publishes the website after every push to `main`. The
|
||||
workflow in [`.gitea/workflows/deploy.yml`](.gitea/workflows/deploy.yml) syncs
|
||||
the contents of `web/` to
|
||||
`firewallissues-deploy@<DEPLOY_HOST>:/var/www/html/firewallissues/web/`.
|
||||
It can also be run manually from the Actions page.
|
||||
|
||||
Before the first deployment:
|
||||
|
||||
1. Enable Actions for the Gitea repository and make sure an `ubuntu-latest`
|
||||
runner is available.
|
||||
2. Create a dedicated `firewallissues-deploy` account and SSH key pair. Install
|
||||
the public key for that account and give it ownership of
|
||||
`/var/www/html/firewallissues/web/`.
|
||||
3. Add these repository Actions secrets in Gitea:
|
||||
|
||||
- `DEPLOY_HOST`: the web server hostname or IP address as reached by the
|
||||
Actions runner.
|
||||
- `DEPLOY_SSH_KEY`: the complete private key, including its BEGIN and END
|
||||
lines.
|
||||
- `DEPLOY_KNOWN_HOSTS`: the web server's trusted SSH host-key line. Generate
|
||||
it from a trusted network with `ssh-keyscan -H <DEPLOY_HOST>`, then verify
|
||||
its fingerprint before saving it.
|
||||
|
||||
The deploy account only needs write access to the site's `web` directory.
|
||||
|
||||
Reference in New Issue
Block a user