diff --git a/.tangled/workflows/deploy.yaml b/.tangled/workflows/deploy.yaml index a80d8ba..a4518b7 100644 --- a/.tangled/workflows/deploy.yaml +++ b/.tangled/workflows/deploy.yaml @@ -1,8 +1,8 @@ -# Builds and pushes the image with buildah (the nixery runner has the docker -# CLI but no daemon, so `docker build` can't run) natively on the runner's own -# arch, then SSH-deploys to the droplet. Replaces the manual scp+ssh recipe in -# docs/deploy.md. Needs "GHCR_TOKEN", "DEPLOY_SSH_KEY", and "DEPLOY_HOST" set -# under this repo's Settings -> Secrets on tangled.sh. +# Builds and pushes the image with kaniko (the nixery runner has no docker +# daemon and forbids the user namespaces buildah/podman need); kaniko builds the +# Dockerfile in userspace and pushes to GHCR, then we SSH-deploy to the droplet. +# Replaces the manual scp+ssh recipe in docs/deploy.md. Needs "GHCR_TOKEN", +# "DEPLOY_SSH_KEY", and "DEPLOY_HOST" set under Settings -> Secrets. when: - event: ["push"] branch: ["main"] @@ -11,23 +11,26 @@ engine: nixery dependencies: nixpkgs: - - buildah + - kaniko + - coreutils - openssh steps: - name: "Build and push image" command: | - # The nixery container runs as uid 0 with no /etc/passwd entry, so - # buildah's user lookup fails ("unknown userid 0"); give root one. vfs + - # chroot let it build without a daemon or user-namespace privileges. - export HOME=/root STORAGE_DRIVER=vfs BUILDAH_ISOLATION=chroot - mkdir -p /root + # --force runs kaniko outside its own container. HOME + passwd entry are + # for the uid-0/no-/etc/passwd env; the config.json is kaniko's GHCR auth. + export HOME=/root DOCKER_CONFIG=/root/.docker + mkdir -p /root/.docker grep -q '^root:' /etc/passwd 2>/dev/null || echo 'root:x:0:0:root:/root:/bin/sh' >> /etc/passwd - echo "$GHCR_TOKEN" | buildah login -u nmokkenstorm --password-stdin ghcr.io - buildah build -t ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA . - buildah tag ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA ghcr.io/nmokkenstorm/at-record:latest - buildah push ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA - buildah push ghcr.io/nmokkenstorm/at-record:latest + printf '{"auths":{"ghcr.io":{"auth":"%s"}}}' \ + "$(printf 'nmokkenstorm:%s' "$GHCR_TOKEN" | base64 -w0)" > /root/.docker/config.json + executor \ + --context="dir://$PWD" \ + --dockerfile=Dockerfile \ + --destination="ghcr.io/nmokkenstorm/at-record:$TANGLED_SHA" \ + --destination="ghcr.io/nmokkenstorm/at-record:latest" \ + --force - name: "Deploy to droplet" command: |