mirror of
https://github.com/cs341-illinois/coursebook.git
synced 2026-10-02 08:04:38 +08:00
The coursebook now publishes its wiki again, but nothing tells the website to rebuild, so a change reaches the site only when someone else pushes to it. Restore that trigger with a deploy key (SITE_DEPLOY_KEY) rather than the built-in token: GITHUB_TOKEN is scoped to this repo, and pushes made with it deliberately do not trigger workflows. A deploy key also has no expiry and is exempt from the org's SAML SSO, so it will not silently lapse the way the old credentials did. - point site_deploy.sh at cs341-illinois/cs341-illinois.github.io; it still named illinois-cs241, two renames stale - add IdentitiesOnly so ssh cannot offer some other key - seed known_hosts with ssh-keyscan instead of relying on the runner - skip the site deploy when the secret is absent, so forks still pass
20 lines
667 B
Bash
20 lines
667 B
Bash
#!/bin/bash
|
|
|
|
set -e;
|
|
|
|
# Set up ssh. IdentitiesOnly stops ssh offering any other key it finds.
|
|
git config --global core.sshCommand "ssh -i /tmp/deploy_site -o IdentitiesOnly=yes -F /dev/null"
|
|
export DOCS_SHA=$(git rev-parse --short HEAD)
|
|
|
|
# Clone the site repo. The empty commit below is what triggers its
|
|
# Website Deploy workflow, which pulls the coursebook wiki via the
|
|
# _coursebook submodule and republishes.
|
|
git clone -b develop --depth 1 git@github.com:cs341-illinois/cs341-illinois.github.io.git ${CLONE_DIR}
|
|
cd ${CLONE_DIR}
|
|
|
|
git commit --allow-empty -m "Updating docs to ${DOCS_SHA}"
|
|
git push origin develop
|
|
|
|
# Go back to the build dir
|
|
cd ${GITHUB_WORKSPACE}
|