ci: reach the instance through GITBAY_SSH !4
1 file changed, +8 −6
Layout: unified · split
.gitbay/ci.yml +8 −6
| @@ -8,8 +8,9 @@ | ||
| 8 | 8 | # The build runs in a container on the instance's runner, which holds no |
| 9 | 9 | # key of its own inside the container. Publishing goes over SSH as the |
| 10 | 10 | # blotter-ci account (write on this repository): its private key arrives |
| 11 | # as the BOT_SSH_KEY build secret, is written into the workspace for the | |
| 12 | # build, and ~/.ssh/config points ssh and git at it for gitbay.org. | |
| 11 | # as the BOT_SSH_KEY build secret and is written into the workspace for | |
| 12 | # the build. GITBAY_SSH, set by the runner, is the instance as this build | |
| 13 | # reaches it; ~/.ssh/config points ssh and git at the key for that host. | |
| 13 | 14 | jobs: |
| 14 | 15 | daily-pull: |
| 15 | 16 | schedule: "17 11,23 * * *" |
| @@ -18,14 +19,15 @@ jobs: | ||
| 18 | 19 | - | |
| 19 | 20 | set -e |
| 20 | 21 | test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; } |
| 22 | test -n "$GITBAY_SSH" || { echo "ERROR: GITBAY_SSH is not set; the runner is too old"; exit 1; } | |
| 21 | 23 | umask 077 |
| 22 | 24 | printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key" |
| 23 | 25 | mkdir -p ~/.ssh |
| 24 | printf 'Host gitbay.org\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$PWD/.bot_key" > ~/.ssh/config | |
| 25 | ssh git@gitbay.org whoami | |
| 26 | printf 'Host %s\n IdentityFile %s\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "${GITBAY_SSH#*@}" "$PWD/.bot_key" > ~/.ssh/config | |
| 27 | ssh "$GITBAY_SSH" whoami | |
| 26 | 28 | - | |
| 27 | 29 | set -e |
| 28 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=git@gitbay.org R=krz/omaha-metro-blotter | |
| 30 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db HOST=$GITBAY_SSH R=krz/omaha-metro-blotter | |
| 29 | 31 | mkdir -p raw_data |
| 30 | 32 | |
| 31 | 33 | # Restore the published archive; a crashed publish leaves metro.db.new.gz. |
| @@ -126,7 +128,7 @@ jobs: | ||
| 126 | 128 | export PATH="$PWD/.venv/bin:$PATH" DB=raw_data/metro.db |
| 127 | 129 | .venv/bin/pip install -q -r requirements.txt |
| 128 | 130 | python build_site.py |
| 129 | origin=ssh://git@gitbay.org/krz/omaha-metro-blotter.git | |
| 131 | origin=ssh://$GITBAY_SSH/krz/omaha-metro-blotter.git | |
| 130 | 132 | cd site && git init -q -b pages |
| 131 | 133 | git -c user.name=ci -c user.email=ci@gitbay.org add -A |
| 132 | 134 | git -c user.name=ci -c user.email=ci@gitbay.org commit -q -m "site $(date -u '+%Y-%m-%d %H:%M')" |