#!/usr/bin/env bash # usage: ssh-run.sh # Runs one deploy-lib.sh stage on the workstation over SSH. set -euo pipefail : "${DEPLOY_HOST:?missing DEPLOY_HOST}" : "${DEPLOY_USER:?missing DEPLOY_USER}" : "${DEPLOY_KEY:?missing DEPLOY_SSH_KEY}" deploy_port="${DEPLOY_PORT:-22}" deploy_path="${DEPLOY_PATH:-/srv/homelab}" deploy_path="$(printf '%s' "$deploy_path" | tr -d '\"' | tr -d '\r' | xargs)" # The private key is written to a per-run directory that is removed on exit, so a # failed or cancelled job cannot leave deploy credentials in the runner's temp # directory. Do not use a fixed path: apply-k8s and apply-compose run in parallel. key_dir="$(mktemp -d "${RUNNER_TEMP:-/tmp}/homelab-deploy-key.XXXXXXXX")" trap 'rm -rf "$key_dir"' EXIT INT TERM ssh_key="$key_dir/deploy_key" printf '%s\n' "$DEPLOY_KEY" > "$ssh_key" chmod 600 "$ssh_key" ssh -i "$ssh_key" -p "$deploy_port" \ -o BatchMode=yes -o StrictHostKeyChecking=accept-new \ "${DEPLOY_USER}@${DEPLOY_HOST}" \ "REPO=$deploy_path APPLY_PRUNE=${APPLY_PRUNE:-false} DEPLOY_SHA=${DEPLOY_SHA:-} DEPLOY_SNAPSHOT_DIR=${DEPLOY_SNAPSHOT_DIR:-} STAGE=$1 bash -se" <<'EOF' source "$REPO/.gitea/workflows/deploy-lib.sh" run_stage "$STAGE" EOF