Commit bbe1b2737d

bbe1b2737dd281220532934893610d68e9a5b642

parent: 0c04c17297

Verified · cmc ci/accessibility: success ci/sync-man-pages: success

cmc <hello@cleberg.net> · 2026-09-11 01:04 UTC

ci: sync-man-pages publishes as hutch-ci from the container runner

The step writes the BOT_SSH_KEY secret into the workspace and points
every ssh and git call at it with -F. The instance is GITBAY_SSH, not
127.0.0.1, which inside the container is the container itself.

Closes #1

Layout: unified · split

.gitbay/ci.yml +17 −3
@@ -2,6 +2,14 @@
22# lands as an MR for review, never straight on main. The script refuses to
33# write a suspiciously short list, so an upstream markup change can't
44# silently gut the catalog.
5#
6# The build runs in a container on the instance's runner, which holds no
7# key of its own inside the container. The push and the merge request go
8# over SSH as the hutch-ci account (write on this repository): its private
9# key arrives as the BOT_SSH_KEY build secret and is written into the
10# workspace beside an ssh config every ssh and git call is pointed at
11# with -F. GITBAY_SSH, set by the runner, is the instance as this build
12# reaches it.
513jobs:
614 # Reads every view file for icon-only controls without accessibility
715 # labels — no build, no simulator. The xcodebuild test plan is not
@@ -19,9 +27,15 @@ jobs:
1927 echo "catalog unchanged"
2028 exit 0
2129 fi
30 test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; }
31 test -n "$GITBAY_SSH" || { echo "ERROR: GITBAY_SSH is not set; the runner is too old"; exit 1; }
32 umask 077
33 printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key"
34 printf 'IdentityFile %s\nIdentitiesOnly yes\nStrictHostKeyChecking accept-new\nUserKnownHostsFile %s\n' "$PWD/.bot_key" "$PWD/.known_hosts" > "$PWD/.ssh_config"
35 export GIT_SSH_COMMAND="ssh -F $PWD/.ssh_config"
2236 git -c user.name=ci -c user.email=ci@gitbay.org checkout -q -B automated/man-page-catalog
2337 git -c user.name=ci -c user.email=ci@gitbay.org commit -qam "Sync bundled man page catalog with man.sr.ht"
24 git push -qf origin automated/man-page-catalog
25 if ! ssh git@127.0.0.1 mr list krz/hutch --json | grep -q "automated/man-page-catalog"; then
26 ssh git@127.0.0.1 "mr create krz/hutch --source automated/man-page-catalog --target main --title 'Sync bundled man page catalog' --body 'Automated update from scripts/sync_man_pages.py. Review the diff to Hutch/Resources/man-pages.json before merging.'"
38 git push -qf "ssh://$GITBAY_SSH/krz/hutch.git" automated/man-page-catalog
39 if ! ssh -F "$PWD/.ssh_config" "$GITBAY_SSH" mr list krz/hutch --json | grep -q "automated/man-page-catalog"; then
40 ssh -F "$PWD/.ssh_config" "$GITBAY_SSH" "mr create krz/hutch --source automated/man-page-catalog --target main --title 'Sync bundled man page catalog' --body 'Automated update from scripts/sync_man_pages.py. Review the diff to Hutch/Resources/man-pages.json before merging.'"
2741 fi