From d2807fa62a8af778abf92f6a86ca7079cbdfe7da Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9s=20Ignacio=20Torres?= Date: Fri, 15 May 2026 23:10:33 -0700 Subject: [PATCH] chore: sync github and tangled repos --- .github/workflows/sync.yml | 53 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 .github/workflows/sync.yml diff --git a/.github/workflows/sync.yml b/.github/workflows/sync.yml new file mode 100644 index 0000000..770b4c3 --- /dev/null +++ b/.github/workflows/sync.yml @@ -0,0 +1,53 @@ +name: Sync + +on: + push: + branches: + - main + +jobs: + sync: + name: Sync to tangled.sh repo + runs-on: ubuntu-latest + if: github.repository == 'aitorres/pds' + timeout-minutes: 5 + steps: + - name: Checkout + uses: actions/checkout@v6 + with: + persist-credentials: false + + - name: Sync to tangled.sh repo + env: + TANGLED_REPO_URL: ${{ secrets.TANGLED_REPO_URL }} + TANGLED_SSH_PRIVATE_KEY: ${{ secrets.TANGLED_SSH_PRIVATE_KEY }} + run: | + set -euo pipefail + + if [[ -z "$TANGLED_REPO_URL" || -z "$TANGLED_SSH_PRIVATE_KEY" ]]; then + echo "Required secrets are missing" + exit 1 + fi + + case "$TANGLED_REPO_URL" in + git@*:* ) + ssh_host="${TANGLED_REPO_URL#git@}" + ssh_host="${ssh_host%%:*}" + ;; + * ) + echo "TANGLED_REPO_URL must be an SSH Git remote" + exit 1 + ;; + esac + + install -m 700 -d ~/.ssh + printf '%s' "$TANGLED_SSH_PRIVATE_KEY" > ~/.ssh/id_rsa + chmod 600 ~/.ssh/id_rsa + ssh-keyscan -H "$ssh_host" >> ~/.ssh/known_hosts + chmod 644 ~/.ssh/known_hosts + + git remote add tangled "$TANGLED_REPO_URL" 2>/dev/null || \ + git remote set-url tangled "$TANGLED_REPO_URL" + + GIT_SSH_COMMAND='ssh -i ~/.ssh/id_rsa -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes' \ + git push tangled HEAD:refs/heads/main -- 2.51.2