#!/usr/bin/env bash # Source this to configure git to push to the tangled knot as the lgtm.shop release bot. # Requires the KNOT_DEPLOY_KEY secret: an SSH private key whose public half is registered # on the lgtm.shop account (see RELEASING.md → "Release-PR automation"). # # Usage: source scripts/ci/knot-ssh-env.sh set -euo pipefail : "${KNOT_DEPLOY_KEY:?KNOT_DEPLOY_KEY is required to push to the knot}" install -d -m 700 "$HOME/.ssh" printf '%s\n' "$KNOT_DEPLOY_KEY" > "$HOME/.ssh/id_ed25519" chmod 600 "$HOME/.ssh/id_ed25519" export GIT_SSH_COMMAND="ssh -i $HOME/.ssh/id_ed25519 -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new" # Author release commits as the lgtm.shop account (email tangled maps to the account, so its # avatar shows on the commit). git config --global user.name "lgtm.shop" git config --global user.email "nate@lgtm.shop" # The Spindle checkout may lack an ssh origin; pin it so pushes reach the knot. git remote set-url origin git@tangled.org:lgtm.shop/commerce 2>/dev/null \ || git remote add origin git@tangled.org:lgtm.shop/commerce