ci: publish as blotter-ci from inside the runner's container !2

merged merged by cmc on 2026-09-10 02:44 UTC · krz/omaha-metro-blotter:ci-in-container into main

1 file changed, +16 −2

Layout: unified · split

.gitbay/ci.yml +16 −2
@@ -4,6 +4,12 @@
4# so it refuses to publish an archive smaller than the one it started with. 4# so it refuses to publish an archive smaller than the one it started with.
5# The archive lives as metro.db.gz on the gitbay release tagged "archive"; 5# The archive lives as metro.db.gz on the gitbay release tagged "archive";
6# the site deploys to the pages branch. 6# the site deploys to the pages branch.
7#
8# The build runs in a container on the instance's runner, which holds no
9# key of its own inside the container. Publishing goes over SSH as the
10# blotter-ci account (write on this repository): its private key arrives
11# as the BOT_SSH_KEY build secret, is written into the workspace for the
12# build, and ~/.ssh/config points ssh and git at it for gitbay.org.
7jobs: 13jobs:
8 daily-pull: 14 daily-pull:
9 schedule: "17 11,23 * * *" 15 schedule: "17 11,23 * * *"
@@ -11,7 +17,15 @@ jobs:
11 - python3 -m venv .venv && .venv/bin/pip install -q -r requirements-ingest.txt 17 - python3 -m venv .venv && .venv/bin/pip install -q -r requirements-ingest.txt
12 - | 18 - |
13 set -e 19 set -e
14 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@127.0.0.1 R=krz/omaha-metro-blotter 20 test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; }
21 umask 077
22 printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key"
23 mkdir -p ~/.ssh
24 printf 'Host gitbay.org\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$PWD/.bot_key" > ~/.ssh/config
25 ssh git@gitbay.org whoami
26 - |
27 set -e
28 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@gitbay.org R=krz/omaha-metro-blotter
15 mkdir -p raw_data 29 mkdir -p raw_data
16 30
17 # Restore the published archive; a crashed publish leaves metro.db.new.gz. 31 # Restore the published archive; a crashed publish leaves metro.db.new.gz.
@@ -112,7 +126,7 @@ jobs:
112 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db 126 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db
113 .venv/bin/pip install -q -r requirements.txt 127 .venv/bin/pip install -q -r requirements.txt
114 python build_site.py 128 python build_site.py
115 origin=$(git remote get-url origin) 129 origin=ssh://git@gitbay.org/krz/omaha-metro-blotter.git
116 cd site && git init -q -b pages 130 cd site && git init -q -b pages
117 git -c user.name=ci -c user.email=ci@gitbay.org add -A 131 git -c user.name=ci -c user.email=ci@gitbay.org add -A
118 git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" 132 git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')"