# Deploy this stack onto the host it runs on. A push that changes the # compose file, a Dockerfile or a rendered config pulls and brings the # stack up; a portal or gdo upgrade is a commit that bumps the version in # .env.example and, on the host, in .env. # # Runs on kasse's host runner. It is not root: it may run one script, # /usr/local/bin/deploy-tomtervel, which pulls this repo under # /srv/tomtervel and runs `podman compose up -d --build` and nothing # else. The .env on the host - the NATS password, the OAuth2 secret, the # Kanidm token - is never in this repo and is not touched by a deploy. name: deploy on: push: branches: [main] paths: - compose.yml - Caddyfile - portal/** - gdo/** - kanidm/server.toml.tpl - nats/nats.conf.tpl - .gitea/workflows/deploy.yml workflow_dispatch: jobs: deploy: runs-on: fish steps: - name: Pull and bring the stack up run: sudo /usr/local/bin/deploy-tomtervel