diff --git a/.tangled/workflows/deploy.yaml b/.tangled/workflows/deploy.yaml index 142a49e..f3b8963 100644 --- a/.tangled/workflows/deploy.yaml +++ b/.tangled/workflows/deploy.yaml @@ -1,6 +1,6 @@ -# Builds the image natively (no QEMU: nixery steps run on the spindle host's -# own arch, and the Dockerfile's multi-stage build never cross-compiles), then -# SSH-deploys it to the droplet. Replaces the manual scp+ssh recipe in +# Builds and pushes the image with buildah (the nixery runner has the docker +# CLI but no daemon, so `docker build` can't run) natively on the runner's own +# arch, then SSH-deploys to the droplet. Replaces the manual scp+ssh recipe in # docs/deploy.md. Needs "GHCR_TOKEN", "DEPLOY_SSH_KEY", and "DEPLOY_HOST" set # under this repo's Settings -> Secrets on tangled.sh. when: @@ -11,17 +11,20 @@ engine: nixery dependencies: nixpkgs: - - docker + - buildah - openssh steps: - name: "Build and push image" command: | - echo "$GHCR_TOKEN" | docker login ghcr.io -u nmokkenstorm --password-stdin - docker build -t ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA . - docker tag ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA ghcr.io/nmokkenstorm/at-record:latest - docker push ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA - docker push ghcr.io/nmokkenstorm/at-record:latest + # vfs storage + chroot isolation so buildah works without a daemon or + # user-namespace privileges in the nixery container. + export STORAGE_DRIVER=vfs BUILDAH_ISOLATION=chroot + echo "$GHCR_TOKEN" | buildah login -u nmokkenstorm --password-stdin ghcr.io + buildah build -t ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA . + buildah tag ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA ghcr.io/nmokkenstorm/at-record:latest + buildah push ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA + buildah push ghcr.io/nmokkenstorm/at-record:latest - name: "Deploy to droplet" command: |