ci: reach the instance through GITBAY_SSH !4
1 file changed, +8 −6
Layout: unified · split
.gitbay/ci.yml +8 −6
| @@ -8,8 +8,9 @@ | |||
| 8 | # The build runs in a container on the instance's runner, which holds no | 8 | # The build runs in a container on the instance's runner, which holds no |
| 9 | # key of its own inside the container. Publishing goes over SSH as the | 9 | # key of its own inside the container. Publishing goes over SSH as the |
| 10 | # blotter-ci account (write on this repository): its private key arrives | 10 | # blotter-ci account (write on this repository): its private key arrives |
| 11 | # as the BOT_SSH_KEY build secret, is written into the workspace for the | 11 | # as the BOT_SSH_KEY build secret and is written into the workspace for |
| 12 | # build, and ~/.ssh/config points ssh and git at it for gitbay.org. | 12 | # the build. GITBAY_SSH, set by the runner, is the instance as this build |
| 13 | # reaches it; ~/.ssh/config points ssh and git at the key for that host. | ||
| 13 | jobs: | 14 | jobs: |
| 14 | daily-pull: | 15 | daily-pull: |
| 15 | schedule: "17 11,23 * * *" | 16 | schedule: "17 11,23 * * *" |
| @@ -18,14 +19,15 @@ jobs: | |||
| 18 | - | | 19 | - | |
| 19 | set -e | 20 | set -e |
| 20 | test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; } | 21 | test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; } |
| 22 | test -n "$GITBAY_SSH" || { echo "ERROR: GITBAY_SSH is not set; the runner is too old"; exit 1; } | ||
| 21 | umask 077 | 23 | umask 077 |
| 22 | printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key" | 24 | printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key" |
| 23 | mkdir -p ~/.ssh | 25 | mkdir -p ~/.ssh |
| 24 | printf 'Host gitbay.org\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$PWD/.bot_key" > ~/.ssh/config | 26 | printf 'Host %s\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "${GITBAY_SSH#*@}" "$PWD/.bot_key" > ~/.ssh/config |
| 25 | ssh git@gitbay.org whoami | 27 | ssh "$GITBAY_SSH" whoami |
| 26 | - | | 28 | - | |
| 27 | set -e | 29 | set -e |
| 28 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@gitbay.org R=krz/omaha-metro-blotter | 30 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=$GITBAY_SSH R=krz/omaha-metro-blotter |
| 29 | mkdir -p raw_data | 31 | mkdir -p raw_data |
| 30 | 32 | ||
| 31 | # Restore the published archive; a crashed publish leaves metro.db.new.gz. | 33 | # Restore the published archive; a crashed publish leaves metro.db.new.gz. |
| @@ -126,7 +128,7 @@ jobs: | |||
| 126 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db | 128 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db |
| 127 | .venv/bin/pip install -q -r requirements.txt | 129 | .venv/bin/pip install -q -r requirements.txt |
| 128 | python build_site.py | 130 | python build_site.py |
| 129 | origin=ssh://git@gitbay.org/krz/omaha-metro-blotter.git | 131 | origin=ssh://$GITBAY_SSH/krz/omaha-metro-blotter.git |
| 130 | cd site && git init -q -b pages | 132 | cd site && git init -q -b pages |
| 131 | git -c user.name=ci -c user.email=ci@gitbay.org add -A | 133 | git -c user.name=ci -c user.email=ci@gitbay.org add -A |
| 132 | git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" | 134 | git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" |