name: Deploy instance # This content repo owns its portal instance: which portal version runs # on kasse. uhhm/portal only publishes versioned release artifacts; # PORTAL_RELEASE below pins the one this site runs, so every rollout is # a commit - auditable, and revertable by reverting it. # # Content-only changes never come through here: lint-and-reload # hot-swaps those into the running instance over NATS. # # Runs on the host runner, because a deploy has to touch this host's # filesystem and its units. It is allowed exactly one root action: # /usr/local/bin/deploy-portal-instance, which checks the instance # against a fixed list and the tag against a release-tag shape before # it touches anything, and health-checks the site afterwards without a # forwarded header - a check that sends the header Caddy would send # cannot tell you the site is broken for everything that is not Caddy. on: workflow_dispatch: push: branches: [main] paths: - .gitea/workflows/deploy.yml env: PORTAL_RELEASE: v0.5.2 INSTANCE: tomtervel-portal jobs: deploy: runs-on: fish steps: - name: Ship the pinned release and restart run: sudo /usr/local/bin/deploy-portal-instance "$INSTANCE" "$PORTAL_RELEASE"