Compare commits

..

85 Commits

Author SHA1 Message Date
Joshua Piper 60b01ef2bb Merge pull request #26 from JoshPiper/dependabot/docker/alpine-3.20.0
Bump alpine from 3.19.1 to 3.20.0
2024-06-02 18:22:49 +01:00
dependabot[bot] f0190b67ea Bump alpine from 3.19.1 to 3.20.0
Bumps alpine from 3.19.1 to 3.20.0.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-06-01 01:28:41 +00:00
Joshua Piper 3c0d26131e Merge pull request #25 from JoshPiper/dependabot/docker/alpine-3.19.1
Bump alpine from 3.18.5 to 3.19.1
2024-02-05 15:03:36 +00:00
dependabot[bot] 5e08a40917 Bump alpine from 3.18.5 to 3.19.1
Bumps alpine from 3.18.5 to 3.19.1.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-02-01 01:24:56 +00:00
Joshua Piper 6be9b2ad1d Merge pull request #23 from JoshPiper/dependabot/docker/alpine-3.18.5
Bump alpine from 3.18.4 to 3.18.5
2023-12-14 16:00:50 +00:00
dependabot[bot] cc463fa970 Bump alpine from 3.18.4 to 3.18.5
Bumps alpine from 3.18.4 to 3.18.5.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-12-01 01:02:09 +00:00
Joshua Piper c673699aad build(deps): Merge pull request #22 from JoshPiper/dependabot/docker/alpine-3.18.4
Bump alpine from 3.18.3 to 3.18.4
2023-10-02 16:15:22 +01:00
dependabot[bot] 7d0de51603 Bump alpine from 3.18.3 to 3.18.4
Bumps alpine from 3.18.3 to 3.18.4.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-01 01:48:05 +00:00
Joshua Piper b624387060 Merge pull request #21 from JoshPiper/dependabot/docker/alpine-3.18.3
Bump alpine from 3.18.2 to 3.18.3
2023-09-01 17:34:42 +01:00
dependabot[bot] b88e4596cf Bump alpine from 3.18.2 to 3.18.3
Bumps alpine from 3.18.2 to 3.18.3.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-01 01:29:47 +00:00
Joshua Piper 16693f1129 Merge pull request #20 from JoshPiper/dependabot/docker/alpine-3.18.2
Bump alpine from 3.18.0 to 3.18.2
2023-07-01 03:41:14 +01:00
dependabot[bot] 04f80d18ef Bump alpine from 3.18.0 to 3.18.2
Bumps alpine from 3.18.0 to 3.18.2.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-07-01 01:58:58 +00:00
Joshua Piper b1a157e5bd Merge pull request #18 from JoshPiper/dependabot/docker/alpine-3.18.0
Bump alpine from 3.17.3 to 3.18.0
2023-06-04 17:35:54 +01:00
dependabot[bot] 3b1bdb8b97 Bump alpine from 3.17.3 to 3.18.0
Bumps alpine from 3.17.3 to 3.18.0.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-01 01:56:41 +00:00
Joshua Piper 6e71633c53 Merge pull request #17 from JoshPiper/dependabot/docker/alpine-3.17.3
Bump alpine from 3.17.2 to 3.17.3
2023-04-02 00:57:43 +01:00
dependabot[bot] 5dbee44011 Bump alpine from 3.17.2 to 3.17.3
Bumps alpine from 3.17.2 to 3.17.3.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-04-01 01:56:40 +00:00
Joshua Piper b4368abed7 Merge pull request #16 from JoshPiper/dependabot/docker/alpine-3.17.2
Bump alpine from 3.17.1 to 3.17.2
2023-03-03 17:26:25 +00:00
dependabot[bot] 0c35136de4 Bump alpine from 3.17.1 to 3.17.2
Bumps alpine from 3.17.1 to 3.17.2.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-03-01 01:56:58 +00:00
Joshua Piper 0a42ac2737 Merge pull request #15 from JoshPiper/dependabot/docker/alpine-3.17.1
Bump alpine from 3.17.0 to 3.17.1
2023-02-03 15:51:25 +00:00
dependabot[bot] 1c1f030fbd Bump alpine from 3.17.0 to 3.17.1
Bumps alpine from 3.17.0 to 3.17.1.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-01 01:00:51 +00:00
Joshua Piper 58cbbf02a2 Merge pull request #14 from JoshPiper/dependabot/docker/alpine-3.17.0
Bump alpine from 3.16.2 to 3.17.0
2022-12-02 17:56:18 +00:00
dependabot[bot] edd99d0461 Bump alpine from 3.16.2 to 3.17.0
Bumps alpine from 3.16.2 to 3.17.0.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-12-01 01:01:08 +00:00
Joshua Piper e53397bf1e Merge pull request #13 from JoshPiper/dependabot/docker/alpine-3.16.2
Bump alpine from 3.16.1 to 3.16.2
2022-09-01 02:18:27 +01:00
dependabot[bot] 24e95accc4 Bump alpine from 3.16.1 to 3.16.2
Bumps alpine from 3.16.1 to 3.16.2.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-09-01 01:04:14 +00:00
Joshua Piper 3c932a0612 Merge pull request #11 from JoshPiper/dependabot/docker/alpine-3.16.1
Bump alpine from 3.16.0 to 3.16.1
2022-08-01 16:06:00 +01:00
dependabot[bot] e9e2d7d1bc Bump alpine from 3.16.0 to 3.16.1
Bumps alpine from 3.16.0 to 3.16.1.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-01 01:32:53 +00:00
Joshua Piper 154ad8a39e Merge pull request #10 from JoshPiper/dependabot/docker/alpine-3.16.0
Bump alpine from 3.15.4 to 3.16.0
2022-07-27 15:09:31 +01:00
dependabot[bot] 1e75577cad Bump alpine from 3.15.4 to 3.16.0
Bumps alpine from 3.15.4 to 3.16.0.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-06-01 01:04:09 +00:00
Joshua Piper 4e35d1ff4c Merge pull request #9 from JoshPiper/dependabot/docker/alpine-3.15.4
Bump alpine from 3.15.3 to 3.15.4
2022-05-04 16:51:47 +01:00
dependabot[bot] 44b4d25884 Bump alpine from 3.15.3 to 3.15.4
Bumps alpine from 3.15.3 to 3.15.4.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-05-01 01:05:38 +00:00
Joshua Piper 60f4ec2b37 Merge pull request #8 from JoshPiper/dependabot/docker/alpine-3.15.3
Bump alpine from 3.15.0 to 3.15.3
2022-04-02 12:09:54 +01:00
dependabot[bot] b0af1ee5f4 Bump alpine from 3.15.0 to 3.15.3
Bumps alpine from 3.15.0 to 3.15.3.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-04-01 01:03:01 +00:00
Joshua Piper e916daeaf4 Merge pull request #7 from JoshPiper/dependabot/docker/alpine-3.15.0
Bump alpine from 3.14.2 to 3.15.0
2021-12-01 13:43:41 +00:00
dependabot[bot] 6b27be47f9 Bump alpine from 3.14.2 to 3.15.0
Bumps alpine from 3.14.2 to 3.15.0.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-12-01 01:02:59 +00:00
Joshua Piper 7deef466aa Merge pull request #6 from JoshPiper/dependabot/docker/alpine-3.14.2
feat: Bump alpine from 3.14.1 to 3.14.2
2021-09-01 11:54:30 +01:00
dependabot[bot] 77bc0d7f9a Bump alpine from 3.14.1 to 3.14.2
Bumps alpine from 3.14.1 to 3.14.2.

---
updated-dependencies:
- dependency-name: alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2021-09-01 01:03:03 +00:00
Joshua Piper daac796c91 Merge pull request #5 from h1dden-da3m0n/chore/update-alpine
feat(deps): update alpine base image
2021-08-12 12:01:29 +01:00
K3rnelPan1c 0b2d66da23 chore: update alpine base image from 3.11 to 3.14.1 2021-08-11 23:25:59 +02:00
Joshua Piper 29021e4048 docs: Update tag information. 2021-08-02 22:03:17 +01:00
Joshua Piper f63e2c405d Merge pull request #3 from Burnett01/feat/support-key-with-passphrase
feat: Add support for SSH keys with passphrases.
2021-08-02 18:43:25 +01:00
Steven Agyekum babc7ad0c2 mention new agent-askpass and agent-add behavior 2021-08-02 19:36:36 +02:00
Steven Agyekum 2b8e763f59 correct old typo 2021-08-02 19:18:51 +02:00
Steven Agyekum eb3ddd767e add ssh pass ability to agent-start
* invokes agent-askpass when a passphrase protected key should be added via ssh-add
2021-08-02 19:16:39 +02:00
Steven Agyekum d0cc021e84 add ssh-askpass(1) program 2021-08-02 19:14:48 +02:00
Steven Agyekum a3710d5d3e simplify perms handling 2021-08-02 19:14:10 +02:00
JoshPiper 4b9899c3a0 Create LICENSE 2020-03-18 16:16:38 +00:00
JoshPiper 66d951b0e1 Create README.md 2020-01-03 21:20:58 +00:00
John Internet d9fbddef5e Add arguments to add and autostart. 2020-01-03 15:41:34 +00:00
John Internet 7e8e10f130 Don't allow agent reloads, if it's running already. 2020-01-02 23:08:35 +00:00
John Internet 6cd1d3e4bd That's meant to just be an id. 2020-01-02 22:48:55 +00:00
John Internet 73618b6bfb Add default paths. Shortern full path. 2020-01-02 22:38:02 +00:00
John Internet fa30c8125a Remove the files after we've read them. 2020-01-02 22:28:40 +00:00
John Internet e09a929e60 Add path support, to allow multiple agents to run (ie gitlab) 2020-01-02 22:28:07 +00:00
John Internet d8263c4260 Cat the agent ID? 2020-01-02 22:08:48 +00:00
John Internet 29ed9db523 Redirect ssh-add output. 2020-01-02 21:57:16 +00:00
John Internet dd58c9fa20 Remove line endings, since gitlab seems to mangle them. 2020-01-02 21:50:10 +00:00
John Internet b6a8f25609 Add some debug 2020-01-02 21:38:03 +00:00
John Internet 17bbc35df4 Add an autostart, for autoloading from the "ssh_private_key" env var. 2020-01-02 21:02:22 +00:00
John Internet c9f5dd48ad Don't echo out. 2020-01-02 20:53:50 +00:00
John Internet 162b6de809 Add a fucking comment. 2020-01-02 20:53:37 +00:00
John Internet 505578365f cat. not echo. fuck sake.
source the agent start.
2020-01-02 20:52:12 +00:00
John Internet bbf699c73b Split that to be easier to read. Fix an additional newline. 2020-01-02 20:48:04 +00:00
John Internet 258e2fe50d Why the fuck does docker make me do this? 2020-01-02 20:47:00 +00:00
John Internet 52c97f68f8 Remove c. returns 2020-01-02 19:17:45 +00:00
John Internet d2b9818bec clean up those. 2020-01-02 17:39:55 +00:00
John Internet d331a23e2d Read stdin and pass to ssh agent. 2020-01-02 17:26:36 +00:00
John Internet d9d0f73fda Line endings fix. 2020-01-02 17:06:16 +00:00
John Internet c7327aed5b Move that around a bit. 2020-01-02 16:30:47 +00:00
John Internet 55957604fb Clear the hosts file before use. 2020-01-02 16:29:47 +00:00
John Internet d13aa57813 Remove that comment. 2020-01-02 16:29:00 +00:00
John Internet 7c0a4562df Notify if it's already running. 2020-01-02 16:28:48 +00:00
John Internet 9660fcb269 Make sure permissions are set. 2020-01-02 16:00:19 +00:00
John Internet 9f23357b59 Copy the executables in two layers, not 5.
chmod with grep.
2020-01-02 15:57:38 +00:00
John Internet 8a8eb3a7f3 Remove .sh ext 2020-01-02 15:57:06 +00:00
John Internet 539d248dc2 Add agent stop. 2020-01-02 14:59:58 +00:00
John Internet 014b3ffccb Fully remove the ca certs, not required. 2020-01-02 14:37:57 +00:00
John Internet cfa21ae7a4 Fixed bin/bin 2020-01-02 14:32:36 +00:00
JoshPiper 5a8e0148aa Update Dockerfile 2020-01-02 14:26:07 +00:00
JoshPiper 1228d21283 Update Dockerfile 2020-01-02 13:56:37 +00:00
JoshPiper b79ca6ec6b Update Dockerfile 2020-01-02 13:11:11 +00:00
JoshPiper bbac77b3df Remove the extension? 2020-01-02 13:04:19 +00:00
JoshPiper e859f6f655 Update Dockerfile 2020-01-02 12:58:28 +00:00
JoshPiper 8d2928e3f8 Update Dockerfile 2020-01-02 12:43:08 +00:00
JoshPiper 4b1ab34958 Make sure the ssh dir exists. 2020-01-02 12:23:40 +00:00
JoshPiper 8e3c58b325 Create Dockerfile 2020-01-02 12:03:53 +00:00
16 changed files with 169 additions and 417 deletions
-6
View File
@@ -1,6 +0,0 @@
version: 2
updates:
- package-ecosystem: docker
directory: /
schedule:
interval: monthly
-76
View File
@@ -1,76 +0,0 @@
# Contributor Covenant Code of Conduct
## Our Pledge
In the interest of fostering an open and welcoming environment, we as
contributors and maintainers pledge to making participation in our project and
our community a harassment-free experience for everyone, regardless of age, body
size, disability, ethnicity, sex characteristics, gender identity and expression,
level of experience, education, socio-economic status, nationality, personal
appearance, race, religion, or sexual identity and orientation.
## Our Standards
Examples of behavior that contributes to creating a positive environment
include:
* Using welcoming and inclusive language
* Being respectful of differing viewpoints and experiences
* Gracefully accepting constructive criticism
* Focusing on what is best for the community
* Showing empathy towards other community members
Examples of unacceptable behavior by participants include:
* The use of sexualized language or imagery and unwelcome sexual attention or
advances
* Trolling, insulting/derogatory comments, and personal or political attacks
* Public or private harassment
* Publishing others' private information, such as a physical or electronic
address, without explicit permission
* Other conduct which could reasonably be considered inappropriate in a
professional setting
## Our Responsibilities
Project maintainers are responsible for clarifying the standards of acceptable
behavior and are expected to take appropriate and fair corrective action in
response to any instances of unacceptable behavior.
Project maintainers have the right and responsibility to remove, edit, or
reject comments, commits, code, wiki edits, issues, and other contributions
that are not aligned to this Code of Conduct, or to ban temporarily or
permanently any contributor for other behaviors that they deem inappropriate,
threatening, offensive, or harmful.
## Scope
This Code of Conduct applies both within project spaces and in public spaces
when an individual is representing the project or its community. Examples of
representing a project or community include using an official project e-mail
address, posting via an official social media account, or acting as an appointed
representative at an online or offline event. Representation of a project may be
further defined and clarified by project maintainers.
## Enforcement
Instances of abusive, harassing, or otherwise unacceptable behavior may be
reported by contacting the project team via issues. All
complaints will be reviewed and investigated and will result in a response that
is deemed necessary and appropriate to the circumstances. The project team is
obligated to maintain confidentiality with regard to the reporter of an incident.
Further details of specific enforcement policies may be posted separately.
Project maintainers who do not follow or enforce the Code of Conduct in good
faith may face temporary or permanent repercussions as determined by other
members of the project's leadership.
## Attribution
This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4,
available at https://www.contributor-covenant.org/version/1/4/code-of-conduct.html
[homepage]: https://www.contributor-covenant.org
For answers to common questions about this code of conduct, see
https://www.contributor-covenant.org/faq
-1
View File
@@ -1 +0,0 @@
Feel free to contribute to this project.
+14 -5
View File
@@ -1,7 +1,16 @@
FROM drinternet/rsync:v1.4.4
FROM alpine:3.20.0
MAINTAINER Dr Internet <internet@limelightgaming.net>
# Copy entrypoint
COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
# Install RSync and Open SSH.
RUN apk update && apk add --no-cache rsync openssh-client
RUN rm -rf /var/cache/apk/*
ENTRYPOINT ["/entrypoint.sh"]
# Prepare SSH dir.
RUN mkdir ~/.ssh
# Copy in our executables.
COPY agent-* hosts-* /bin/
RUN chmod +x /bin/agent-* /bin/hosts-*
# Prepare for known hosts.
RUN hosts-clear
+1 -2
View File
@@ -1,7 +1,6 @@
MIT License
Copyright (c) 2019-2022 Contention
Copyright (c) 2019-2022 Burnett01
Copyright (c) 2020 Joshua Piper
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
+79 -238
View File
@@ -1,252 +1,93 @@
# rsync deployments
# rsync docker image.
This GitHub Action (amd64) deploys files in `GITHUB_WORKSPACE` to a remote folder via rsync over ssh.
A simple alpine based docker image for rsync and ssh deployments.
Use this action in a CD workflow which leaves deployable code in `GITHUB_WORKSPACE`.
## Using this image
This image has two primary uses. Firstly, as a deployment image for GitLab CI runs. Secondly, as a base image for other images.
The base-image [drinternet/rsync](https://github.com/JoshPiper/rsync-docker/) of this action is very small and is based on Alpine 3.19.1 (no cache) which results in fast deployments.
### gitlab-ci.yml
```yml
image: drinternet/rsync:1.0.1
...
before_script:
- source agent-autostart "$CI_PROJECT_ID-$CI_PIPELINE_ID-$_CI_CONCURRENT_ID"
- hosts-add "$SSH_KNOWN_HOSTS"
---
## Inputs
- `switches`* - The first is for any initial/required rsync flags, eg: `-avzr --delete`
- `rsh` - Remote shell commands
- `legacy_allow_rsa_hostkeys` - Enables support for legacy RSA host keys on OpenSSH 8.8+. ("true" / "false")
- `path` - The source path. Defaults to GITHUB_WORKSPACE and is relative to it
- `remote_path`* - The deployment target path
- `remote_host`* - The remote host
- `remote_port` - The remote port. Defaults to 22
- `remote_user`* - The remote user
- `remote_key`* - The remote ssh key
- `remote_key_pass` - The remote ssh key passphrase (if any)
``* = Required``
## Required secret(s)
This action needs secret variables for the ssh private key of your key pair. The public key part should be added to the authorized_keys file on the server that receives the deployment. The secret variable should be set in the Github secrets section of your org/repo and then referenced as the `remote_key` input.
> Always use secrets when dealing with sensitive inputs!
For simplicity, we are using `DEPLOY_*` as the secret variables throughout the examples.
## Example usage
Simple:
```
name: DEPLOY
on:
push:
branches:
- master
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: rsync deployments
uses: burnett01/rsync-deployments@7.0.0
with:
switches: -avzr --delete
path: src/
remote_path: /var/www/html/
remote_host: example.com
remote_user: debian
remote_key: ${{ secrets.DEPLOY_KEY }}
after_script:
- agent-stop "$CI_PROJECT_ID-$CI_PIPELINE_ID-$_CI_CONCURRENT_ID"
```
Advanced:
```
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: rsync deployments
uses: burnett01/rsync-deployments@7.0.0
with:
switches: -avzr --delete --exclude="" --include="" --filter=""
path: src/
remote_path: /var/www/html/
remote_host: example.com
remote_port: 5555
remote_user: debian
remote_key: ${{ secrets.DEPLOY_KEY }}
### Base image in a `Dockerfile
```dockerfile
FROM drinternet/rsync:1.0.1
COPY some/file or/whatever
```
For better **security**, I suggest you create additional secrets for remote_host, remote_port, remote_user and remote_path inputs.
## Inbuilt commands.
```
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: rsync deployments
uses: burnett01/rsync-deployments@7.0.0
with:
switches: -avzr --delete
path: src/
remote_path: ${{ secrets.DEPLOY_PATH }}
remote_host: ${{ secrets.DEPLOY_HOST }}
remote_port: ${{ secrets.DEPLOY_PORT }}
remote_user: ${{ secrets.DEPLOY_USER }}
remote_key: ${{ secrets.DEPLOY_KEY }}
This base image also includes a few shell scripts, to help with managing SSH agents and known hosts files.
### SSH Agent Management
#### agent-start
This command starts the SSH agent, if it isn't already started (SSH_AGENT_PID set or ssh agent ID file found).
It takes one optional argument, for the name of the agent to be started. Defaults to "default".
This program needs to be source'd to work correctly.
`source agent-start "default"`
#### agent-stop
This command stops the SSH agent, if it is started (SSH_AGENT_PID set or ssh agent ID file found).
It takes one optional argument, for the name of the agent to be stopped. Defaults to "default".
`agent-stop "my-agent-name"`
#### agent-add
This command adds a key to the currently running SSH agent. The key is taken from stdin, and the agent used is that in SSH_AGENT_PID.
#### agent-autostart
This command starts the SSH agent and loads the private key from the "SSH_PRIVATE_KEY" environment var. The command takes one optional argument, for the name of the agent to be started. Defaults to "default".
As with agent-start, this command needs to be sourced.
#### agent-askpass
This command is called by ssh-add when the [SSH_ASKPASS](https://man.openbsd.org/ssh-add.1#ENVIRONMENT) variable is set active. The command returns the SSH_PASS to [ssh-askpass(1)](https://man.openbsd.org/ssh-askpass.1).
This command is ignored by ssh-add if the key does not require a passphrase.
### known_hosts management
#### hosts-clear
This command truncates the known_hosts file and sets its permissions.
#### hosts-add
This command adds an entry to the known hosts file, and ensures its permissions are correct. It takes one argument, which is the new key to add.
## Tags
Both the repository and Docker Hub images follow the [semantic versioning](https://semver.org/) standard.
Docker Hub image versions are prefixed with v, and contain the full version, version sub patch number and version sub minor and patch.
For example, the repository tag 1.2.3, creates the Hub tags v1.2.3, v1.2 and v1, to allow for binding to a specific version, specific minor version or specific major version.
## Example gitlab-ci.yml
```yml
image: drinternet/rsync:1.0.1
stages:
- deploy
before_script:
- source agent-autostart "$CI_PROJECT_ID-$CI_PIPELINE_ID-$_CI_CONCURRENT_ID"
- hosts-add "$SSH_KNOWN_HOSTS"
after_script:
- agent-stop "$CI_PROJECT_ID-$CI_PIPELINE_ID-$_CI_CONCURRENT_ID"
deploy:
stage: deploy
script:
- rsync -zrSlhaO --chmod=D2775,F664 --delete-after . $FTP_USER@$FTP_HOST:/var/www/deployment/
```
If your private key is passphrase protected you should use:
## Using with passphrase protected key
You can supply a passphrase with ``SSH_PASS`` to ``agent-add``, ``agent-start`` or ``agent-autostart``.
```
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: rsync deployments
uses: burnett01/rsync-deployments@7.0.0
with:
switches: -avzr --delete
path: src/
remote_path: ${{ secrets.DEPLOY_PATH }}
remote_host: ${{ secrets.DEPLOY_HOST }}
remote_port: ${{ secrets.DEPLOY_PORT }}
remote_user: ${{ secrets.DEPLOY_USER }}
remote_key: ${{ secrets.DEPLOY_KEY }}
remote_key_pass: ${{ secrets.DEPLOY_KEY_PASS }}
SSH_PASS="THE_PASSPHRASE" agent-add
```
---
#### Legacy RSA Hostkeys support for OpenSSH Servers >= 8.8+
If your remote OpenSSH Server still uses RSA hostkeys, then you have to
manually enable legacy support for this by using ``legacy_allow_rsa_hostkeys: "true"``.
```
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: rsync deployments
uses: burnett01/rsync-deployments@7.0.0
with:
switches: -avzr --delete
legacy_allow_rsa_hostkeys: "true"
path: src/
remote_path: ${{ secrets.DEPLOY_PATH }}
remote_host: ${{ secrets.DEPLOY_HOST }}
remote_port: ${{ secrets.DEPLOY_PORT }}
remote_user: ${{ secrets.DEPLOY_USER }}
remote_key: ${{ secrets.DEPLOY_KEY }}
```
See [#49](https://github.com/Burnett01/rsync-deployments/issues/49) and [#24](https://github.com/Burnett01/rsync-deployments/issues/24) for more information.
---
## Version 6.0 (MAINTENANCE)
Check here:
- https://github.com/Burnett01/rsync-deployments/tree/6.0 (alpine 3.17.2)
---
## Version 5.0, 5.1 & 5.2 & 5.x (DEPRECATED)
Check here:
- https://github.com/Burnett01/rsync-deployments/tree/5.0 (alpine 3.11.x)
- https://github.com/Burnett01/rsync-deployments/tree/5.1 (alpine 3.14.1)
- https://github.com/Burnett01/rsync-deployments/tree/5.2 (alpine 3.15.0)
- https://github.com/Burnett01/rsync-deployments/tree/5.2.1 (alpine 3.16.1)
- https://github.com/Burnett01/rsync-deployments/tree/5.2.2 (alpine 3.17.2)
---
## Version 4.0 & 4.1 (EOL)
Check here:
- https://github.com/Burnett01/rsync-deployments/tree/4.0
- https://github.com/Burnett01/rsync-deployments/tree/4.1
Version 4.0 & 4.1 use the ``drinternet/rsync:1.0.1`` base-image.
---
## Version 3.0 (EOL)
Check here: https://github.com/Burnett01/rsync-deployments/tree/3.0
Version 3.0 uses the ``alpine:latest`` base-image directly.<br>
Consider upgrading to 4.0 that uses a docker-image ``drinternet/rsync:1.0.1`` that is<br>
based on ``alpine:latest``and heavily optimized for rsync.
## Version 2.0 (EOL)
Check here: https://github.com/Burnett01/rsync-deployments/tree/2.0
Version 2.0 uses a larger base-image (``ubuntu:latest``).<br>
Consider upgrading to 3.0 for even faster deployments.
## Version 1.0 (EOL)
Check here: https://github.com/Burnett01/rsync-deployments/tree/1.0
Please note that version 1.0 has reached end of life state.
---
## Acknowledgements
+ This project is a fork of [Contention/rsync-deployments](https://github.com/Contention/rsync-deployments)
+ Base image [JoshPiper/rsync-docker](https://github.com/JoshPiper/rsync-docker)
---
## Media
This action was featured in multiple blogs across the globe:
> Disclaimer: The author & co-authors are not responsible for the content of the site-links below.
- https://leobrack.co.uk/blog/2020-02-15-automatically-push-changes-to-your-live-site-with-github-actions
- https://blog.maniak.co/ci-cd-for-wordpress/
- https://elijahverdoorn.com/2020/04/14/automating-deployment-with-github-actions/
- https://www.vektor-inc.co.jp/post/github-actions-deploy/
- https://ews.ink/tech/blog-deploy-2/
- https://webpick.info/automatiser-avec-github-actions/
- https://matthias-andrasch.eu/blog/2021/tutorial-webseite-mittels-github-actions-deployment-zu-uberspace-uebertragen-rsync/
- https://mikael.koutero.me/posts/hugo-github-actions-deploy-rsync/
- https://cdmana.com/2021/02/20210208122400688I.html
- https://jishuin.proginn.com/p/763bfbd38928
- https://cloud.tencent.com/developer/article/1786522
- http://www.ningco.cn/github_action_deploy_blog/
- https://qdmana.com/2021/01/20210127094413405u.html
-19
View File
@@ -1,19 +0,0 @@
# Security Policy
## Supported Versions
The following versions are currently being supported with security updates:
| Version | Supported |
| ------- | ------------------ |
| 7.x | :white_check_mark: |
| 6.x | :information_source: MAINTENANCE |
| 5.x | :warning: DEPRECATED |
| 4.x | :x: EOL |
| 3.0 | :x: EOL |
| 2.0 | :x: EOL |
| 1.0 | :x: EOL |
## Reporting a Vulnerability
You can report a vulnerability by creating an issue.
-45
View File
@@ -1,45 +0,0 @@
name: 'Rsync Deployments Action'
description: 'GitHub Action for deploying code via rsync over ssh'
author: 'Burnett01'
inputs:
switches:
description: 'The switches'
required: true
rsh:
description: 'The remote shell argument'
required: false
default: ''
legacy_allow_rsa_hostkeys:
description: 'Enables support for legacy RSA host keys on OpenSSH 8.8+'
required: false
default: 'false'
path:
description: 'The local path'
required: false
default: ''
remote_path:
description: 'The remote path'
required: true
remote_host:
description: 'The remote host'
required: true
remote_port:
description: 'The remote port'
required: false
default: 22
remote_user:
description: 'The remote user'
required: true
remote_key:
description: 'The remote key'
required: true
remote_key_pass:
description: 'The remote key passphrase'
required: false
default: ''
runs:
using: 'docker'
image: 'Dockerfile'
branding:
icon: 'send'
color: 'gray-dark'
+4
View File
@@ -0,0 +1,4 @@
#!/bin/sh
source agent-start "${1:-default}"
cat - | tr -d '\r' | DISPLAY=1 SSH_ASKPASS=agent-askpass ssh-add - >/dev/null
+2
View File
@@ -0,0 +1,2 @@
#!/bin/sh
echo "$SSH_PASS"
+4
View File
@@ -0,0 +1,4 @@
#!/bin/sh
source agent-start "${1:-default}"
echo "$SSH_PRIVATE_KEY" | agent-add
+22
View File
@@ -0,0 +1,22 @@
#!/bin/sh
FOLDER=${1:-default}
STORE_PATH="/tmp/ssh-agent/$FOLDER"
mkdir -p "$STORE_PATH"
# Start the SSH agent if it isn't already.
if [ -z "$SSH_AGENT_PID" ]; then
if [ -f "$STORE_PATH/id" ]; then
# Our auth agent is already running.
# Reload the vars, and export them.
SSH_AGENT_PID=$(cat "$STORE_PATH/id")
export SSH_AGENT_PID
SSH_AUTH_SOCK=$(cat "$STORE_PATH/sock")
export SSH_AUTH_SOCK
else
eval "$(ssh-agent)" > /dev/null
echo "$SSH_AGENT_PID" > "$STORE_PATH"/id
echo "$SSH_AUTH_SOCK" > "$STORE_PATH"/sock
fi
fi
+35
View File
@@ -0,0 +1,35 @@
#!/bin/sh
if [ ! -z "$SSH_AGENT_PID" ]; then
# Here, the environment is set already, just kill the script.
eval $(ssh-agent -k) >/dev/null
exit $?
else
# The env isn't set, construct the file path.
FOLDER=${1:-default}
STORE_PATH="/tmp/ssh-agent/$FOLDER"
if [ ! -d "$STORE_PATH" ]; then
echo "Store Path $STORE_PATH doesn't exist!" >&2
exit 1
fi
# And check our files exist.
if [ -f "$STORE_PATH/id" ]; then
# Grab our PID and socket.
SSH_AGENT_PID=$(cat "$STORE_PATH/id")
export SSH_AGENT_PID
rm "$STORE_PATH/id"
SSH_AUTH_SOCK=$(cat "$STORE_PATH/sock")
export SSH_AUTH_SOCK
rm "$STORE_PATH/sock"
rmdir "$STORE_PATH"
eval $(ssh-agent -k) >/dev/null
exit $?
else
echo "SSH_AGENT_PID not set, $STORE_PATH/id doesn't exist!" >&2
exit 1
fi
fi
-25
View File
@@ -1,25 +0,0 @@
#!/bin/sh
if [ -z "$(echo "$INPUT_REMOTE_PATH" | awk '{$1=$1};1')" ]; then
echo "The remote_path can not be empty. see: github.com/Burnett01/rsync-deployments/issues/44"
exit 1
fi
# Start the SSH agent and load key.
source agent-start "$GITHUB_ACTION"
echo "$INPUT_REMOTE_KEY" | SSH_PASS="$INPUT_REMOTE_KEY_PASS" agent-add
# Add strict errors.
set -eu
# Variables.
LEGACY_RSA_HOSTKEYS="-o HostKeyAlgorithms=+ssh-rsa -o PubkeyAcceptedKeyTypes=+ssh-rsa"
LEGACY_RSA_HOSTKEYS=$([ "$INPUT_LEGACY_ALLOW_RSA_HOSTKEYS" = "true" ] && echo "$LEGACY_RSA_HOSTKEYS" || echo "")
SWITCHES="$INPUT_SWITCHES"
RSH="ssh -o StrictHostKeyChecking=no $LEGACY_RSA_HOSTKEYS -p $INPUT_REMOTE_PORT $INPUT_RSH"
LOCAL_PATH="$GITHUB_WORKSPACE/$INPUT_PATH"
DSN="$INPUT_REMOTE_USER@$INPUT_REMOTE_HOST"
# Deploy.
sh -c "rsync $SWITCHES -e '$RSH' $LOCAL_PATH $DSN:$INPUT_REMOTE_PATH"
+4
View File
@@ -0,0 +1,4 @@
#!/bin/sh
echo "$@" >> ~/.ssh/known_hosts
chmod 0664 ~/.ssh/known_hosts
+4
View File
@@ -0,0 +1,4 @@
#!/bin/sh
truncate -s 0 ~/.ssh/known_hosts
chmod 0664 ~/.ssh/known_hosts