ci: publish as blotter-ci from inside the runner's container !2
1 file changed, +16 −2
Layout: unified · split
.gitbay/ci.yml +16 −2
| @@ -4,6 +4,12 @@ | ||
| 4 | 4 | # so it refuses to publish an archive smaller than the one it started with. |
| 5 | 5 | # The archive lives as metro.db.gz on the gitbay release tagged "archive"; |
| 6 | 6 | # the site deploys to the pages branch. |
| 7 | # | |
| 8 | # The build runs in a container on the instance's runner, which holds no | |
| 9 | # key of its own inside the container. Publishing goes over SSH as the | |
| 10 | # blotter-ci account (write on this repository): its private key arrives | |
| 11 | # as the BOT_SSH_KEY build secret, is written into the workspace for the | |
| 12 | # build, and ~/.ssh/config points ssh and git at it for gitbay.org. | |
| 7 | 13 | jobs: |
| 8 | 14 | daily-pull: |
| 9 | 15 | schedule: "17 11,23 * * *" |
| @@ -11,7 +17,15 @@ jobs: | ||
| 11 | 17 | - python3 -m venv .venv && .venv/bin/pip install -q -r requirements-ingest.txt |
| 12 | 18 | - | |
| 13 | 19 | set -e |
| 14 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@127.0.0.1 R=krz/omaha-metro-blotter | |
| 20 | test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; } | |
| 21 | umask 077 | |
| 22 | printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key" | |
| 23 | mkdir -p ~/.ssh | |
| 24 | printf 'Host gitbay.org\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$PWD/.bot_key" > ~/.ssh/config | |
| 25 | ssh git@gitbay.org whoami | |
| 26 | - | | |
| 27 | set -e | |
| 28 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@gitbay.org R=krz/omaha-metro-blotter | |
| 15 | 29 | mkdir -p raw_data |
| 16 | 30 | |
| 17 | 31 | # Restore the published archive; a crashed publish leaves metro.db.new.gz. |
| @@ -112,7 +126,7 @@ jobs: | ||
| 112 | 126 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db |
| 113 | 127 | .venv/bin/pip install -q -r requirements.txt |
| 114 | 128 | python build_site.py |
| 115 | origin=$(git remote get-url origin) | |
| 129 | origin=ssh://git@gitbay.org/krz/omaha-metro-blotter.git | |
| 116 | 130 | cd site && git init -q -b pages |
| 117 | 131 | git -c user.name=ci -c user.email=ci@gitbay.org add -A |
| 118 | 132 | git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" |