No description
- Dockerfile 73.4%
- Makefile 26.6%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
Build & publish the deploy image / build (push) Successful in 2m19s
Reviewed-on: #2 |
||
| .forgejo/workflows | ||
| Dockerfile | ||
| Makefile | ||
| README.md | ||
ci-deploy — deploy image for the Semaphore EE pipelines
git.botyglot.tech/botyglot-public/ci-deploy:<ruby>-<build> — the container the
kamal deploy jobs of our Kamal apps run in on the EE plane (infra-00035).
Sibling of ci-ruby (tests); same conventions, smaller.
| Baked in | Why |
|---|---|
lastpass-cli 1.3.7 (bookworm) |
.kamal/lpass-env reads the deploy secrets from LastPass, which stays the single source of truth |
kamal 2.12.0 |
pinned to the version running on the VPSes (kamal-proxy MINIMUM_VERSION) |
docker-ce-cli + docker-buildx-plugin |
Kamal drives the remote builder on the VPS (builder.remote) — the job needs the client, never a daemon |
lego 5.4.1 + awscli |
forge renews its wildcard certificate with lego over Gandi DNS and syncs the ACME state with Object Storage (scripts/kamal/renew_cert.sh runs them natively here, no Docker daemon in the job — infra-00036) |
| Semaphore toolbox | checkout and friends |
forge host keys (:22 passthrough and :222) |
no ssh host-key prompt in a bare container |
user semaphore (uid 1000) + sudo |
EE secret files are injected under /home/semaphore/… |
Pulled anonymously (the org is public); pushes need a PAT with package write.
Release
make print # what would be published
make release # buildx linux/amd64 → push :<tag> and :latest
Bump BUILD in the Makefile on every change — agent nodes pull pinned tags
IfNotPresent, so a republished tag would silently serve the old image. The
Forgejo Actions workflow does the same on every push to main (repo secrets
REGISTRY_USER / REGISTRY_TOKEN).
Using it in a pipeline
agent:
machine:
type: s1-botykube
containers:
- name: main
image: git.botyglot.tech/botyglot-public/ci-deploy:3.4.9-1
Then, in the job: checkout, chmod 0600 the injected SSH key, ssh-add it,
lpass login, .kamal/check-secrets, kamal deploy, lpass logout --force
in the epilogue — see sentinel's .semaphore/deploy/production.yml.