No description
  • Dockerfile 73.4%
  • Makefile 26.6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-22 07:55:55 +00:00
.forgejo/workflows feat: deploy image for the Semaphore EE pipelines (infra-00035) 2026-09-17 17:23:03 +02:00
Dockerfile feat: lego and the AWS CLI in the deploy image, build 3.4.9-2 (infra-00036) 2026-09-22 09:51:08 +02:00
Makefile feat: lego and the AWS CLI in the deploy image, build 3.4.9-2 (infra-00036) 2026-09-22 09:51:08 +02:00
README.md feat: lego and the AWS CLI in the deploy image, build 3.4.9-2 (infra-00036) 2026-09-22 09:51:08 +02:00

ci-deploy — deploy image for the Semaphore EE pipelines

git.botyglot.tech/botyglot-public/ci-deploy:<ruby>-<build> — the container the kamal deploy jobs of our Kamal apps run in on the EE plane (infra-00035). Sibling of ci-ruby (tests); same conventions, smaller.

Baked in Why
lastpass-cli 1.3.7 (bookworm) .kamal/lpass-env reads the deploy secrets from LastPass, which stays the single source of truth
kamal 2.12.0 pinned to the version running on the VPSes (kamal-proxy MINIMUM_VERSION)
docker-ce-cli + docker-buildx-plugin Kamal drives the remote builder on the VPS (builder.remote) — the job needs the client, never a daemon
lego 5.4.1 + awscli forge renews its wildcard certificate with lego over Gandi DNS and syncs the ACME state with Object Storage (scripts/kamal/renew_cert.sh runs them natively here, no Docker daemon in the job — infra-00036)
Semaphore toolbox checkout and friends
forge host keys (:22 passthrough and :222) no ssh host-key prompt in a bare container
user semaphore (uid 1000) + sudo EE secret files are injected under /home/semaphore/…

Pulled anonymously (the org is public); pushes need a PAT with package write.

Release

make print            # what would be published
make release          # buildx linux/amd64 → push :<tag> and :latest

Bump BUILD in the Makefile on every change — agent nodes pull pinned tags IfNotPresent, so a republished tag would silently serve the old image. The Forgejo Actions workflow does the same on every push to main (repo secrets REGISTRY_USER / REGISTRY_TOKEN).

Using it in a pipeline

agent:
  machine:
    type: s1-botykube
  containers:
    - name: main
      image: git.botyglot.tech/botyglot-public/ci-deploy:3.4.9-1

Then, in the job: checkout, chmod 0600 the injected SSH key, ssh-add it, lpass login, .kamal/check-secrets, kamal deploy, lpass logout --force in the epilogue — see sentinel's .semaphore/deploy/production.yml.