use vars.DEPLOY_HOST instead of secrets since hostname is not sensitive
This commit is contained in:
@@ -15,4 +15,4 @@ jobs:
|
|||||||
mkdir -p ~/.ssh
|
mkdir -p ~/.ssh
|
||||||
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
||||||
chmod 600 ~/.ssh/deploy_key
|
chmod 600 ~/.ssh/deploy_key
|
||||||
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ secrets.DEPLOY_HOST }} deploy-nginx
|
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ vars.DEPLOY_HOST }} deploy-nginx
|
||||||
|
|||||||
@@ -15,4 +15,4 @@ jobs:
|
|||||||
mkdir -p ~/.ssh
|
mkdir -p ~/.ssh
|
||||||
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
||||||
chmod 600 ~/.ssh/deploy_key
|
chmod 600 ~/.ssh/deploy_key
|
||||||
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ secrets.DEPLOY_HOST }} deploy-timothykim.net
|
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ vars.DEPLOY_HOST }} deploy-timothykim.net
|
||||||
|
|||||||
@@ -84,9 +84,12 @@ After running the script:
|
|||||||
Nginx Proxy Manager certs and Let's Encrypt account keys are encrypted with
|
Nginx Proxy Manager certs and Let's Encrypt account keys are encrypted with
|
||||||
git-crypt (see `.gitattributes`). You need the git-crypt key to unlock them.
|
git-crypt (see `.gitattributes`). You need the git-crypt key to unlock them.
|
||||||
|
|
||||||
The following secrets must be configured in the `hantim` Gitea org settings
|
The following must be configured in the `hantim` Gitea org settings and are
|
||||||
(Settings > Actions > Secrets) and are shared across all repos:
|
shared across all repos:
|
||||||
|
|
||||||
|
Variables (Settings > Actions > Variables):
|
||||||
- `DEPLOY_HOST` -- the server's IP or hostname
|
- `DEPLOY_HOST` -- the server's IP or hostname
|
||||||
|
|
||||||
|
Secrets (Settings > Actions > Secrets):
|
||||||
- `DEPLOY_SSH_KEY` -- the SSH private key for the `deploy` user
|
- `DEPLOY_SSH_KEY` -- the SSH private key for the `deploy` user
|
||||||
- `REGISTRY_TOKEN` -- Gitea personal access token for Docker registry login
|
- `REGISTRY_TOKEN` -- Gitea personal access token for Docker registry login
|
||||||
|
|||||||
+1
-1
@@ -56,7 +56,7 @@ jobs:
|
|||||||
mkdir -p ~/.ssh
|
mkdir -p ~/.ssh
|
||||||
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
|
||||||
chmod 600 ~/.ssh/deploy_key
|
chmod 600 ~/.ssh/deploy_key
|
||||||
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ secrets.DEPLOY_HOST }} deploy-APP_PLACEHOLDER
|
ssh -o StrictHostKeyChecking=accept-new -i ~/.ssh/deploy_key deploy@${{ vars.DEPLOY_HOST }} deploy-APP_PLACEHOLDER
|
||||||
OUTER
|
OUTER
|
||||||
sed -i "s/APP_PLACEHOLDER/$APP/g" "$REPO_ROOT/.gitea/workflows/deploy-$APP.yml"
|
sed -i "s/APP_PLACEHOLDER/$APP/g" "$REPO_ROOT/.gitea/workflows/deploy-$APP.yml"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user