ci: reach the instance through GITBAY_SSH !4

merged merged by cmc on 2026-09-10 03:12 UTC · krz/omaha-metro-blotter:use-gitbay-ssh into main

1 file changed, +8 −6

Layout: unified · split

.gitbay/ci.yml +8 −6
@@ -8,8 +8,9 @@
8# The build runs in a container on the instance's runner, which holds no 8# The build runs in a container on the instance's runner, which holds no
9# key of its own inside the container. Publishing goes over SSH as the 9# key of its own inside the container. Publishing goes over SSH as the
10# blotter-ci account (write on this repository): its private key arrives 10# blotter-ci account (write on this repository): its private key arrives
11# as the BOT_SSH_KEY build secret, is written into the workspace for the 11# as the BOT_SSH_KEY build secret and is written into the workspace for
12# build, and ~/.ssh/config points ssh and git at it for gitbay.org. 12# the build. GITBAY_SSH, set by the runner, is the instance as this build
13# reaches it; ~/.ssh/config points ssh and git at the key for that host.
13jobs: 14jobs:
14 daily-pull: 15 daily-pull:
15 schedule: "17 11,23 * * *" 16 schedule: "17 11,23 * * *"
@@ -18,14 +19,15 @@ jobs:
18 - | 19 - |
19 set -e 20 set -e
20 test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; } 21 test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; }
22 test -n "$GITBAY_SSH" || { echo "ERROR: GITBAY_SSH is not set; the runner is too old"; exit 1; }
21 umask 077 23 umask 077
22 printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key" 24 printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key"
23 mkdir -p ~/.ssh 25 mkdir -p ~/.ssh
24 printf 'Host gitbay.org\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$PWD/.bot_key" > ~/.ssh/config 26 printf 'Host %s\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "${GITBAY_SSH#*@}" "$PWD/.bot_key" > ~/.ssh/config
25 ssh git@gitbay.org whoami 27 ssh "$GITBAY_SSH" whoami
26 - | 28 - |
27 set -e 29 set -e
28 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@gitbay.org R=krz/omaha-metro-blotter 30 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=$GITBAY_SSH R=krz/omaha-metro-blotter
29 mkdir -p raw_data 31 mkdir -p raw_data
30 32
31 # Restore the published archive; a crashed publish leaves metro.db.new.gz. 33 # Restore the published archive; a crashed publish leaves metro.db.new.gz.
@@ -126,7 +128,7 @@ jobs:
126 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db 128 export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db
127 .venv/bin/pip install -q -r requirements.txt 129 .venv/bin/pip install -q -r requirements.txt
128 python build_site.py 130 python build_site.py
129 origin=ssh://git@gitbay.org/krz/omaha-metro-blotter.git 131 origin=ssh://$GITBAY_SSH/krz/omaha-metro-blotter.git
130 cd site && git init -q -b pages 132 cd site && git init -q -b pages
131 git -c user.name=ci -c user.email=ci@gitbay.org add -A 133 git -c user.name=ci -c user.email=ci@gitbay.org add -A
132 git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" 134 git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')"