Observer clone: a read-only deploy key made on the box, GitHub preferred over the mirror once accepted; the project lead's steps in the plan
Main's order of 7 October 2026. install-hands.sh creates /srv/observer/.ssh/deploy_igneum (ed25519, user build, mode 600; the private half never leaves the box and nothing prints it) and the ssh alias github-igneum-observer; observer-sync.sh tests the key with ssh -T on every pass, pulls from GitHub when it is accepted and from the mirror otherwise, saying which. docs/plans/build-server.md 5c: the four steps for the project lead (print the public half, Settings > Deploy keys > Add, read-only, start one sync pass) and the public half itself. Verified on the box: key created, alias written, one sync pass reads 'source: mirror (the deploy key is not accepted by GitHub yet)'. The CI-runner row is closed (the box-work agent's runner service). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
49ca718c9c
commit
9215d624d2
1 changed files with 23 additions and 3 deletions
|
|
@ -68,14 +68,34 @@ IFS=',' read -r -a peers <<< "${PEERS:-}"; for p in "${peers[@]}"; do [ -n "$p"
|
|||
[ -n "${EXTRA_ARGS_OBSERVER:-}" ] && args+=($EXTRA_ARGS_OBSERVER)
|
||||
exec "$IGNEUMD" "${args[@]}"
|
||||
RUN
|
||||
# the read-only deploy key (main, 7 October 2026): made HERE as user build, the private half never leaves this box and is never
|
||||
# printed; the project lead adds the public half as a read-only deploy key on github.com/igneum-network/igneum (steps in
|
||||
# docs/plans/build-server.md, "Deploy key"). Until GitHub accepts it, observer-sync.sh follows the mirror.
|
||||
install -d -m 700 -o $U -g $U $O/.ssh
|
||||
if [ ! -f $O/.ssh/deploy_igneum ]; then su - $U -c "ssh-keygen -q -t ed25519 -N '' -C 'igneum-build-1 observer read-only' -f $O/.ssh/deploy_igneum"; log "deploy key created at $O/.ssh/deploy_igneum (public half: $O/.ssh/deploy_igneum.pub)"; else log "deploy key ok"; fi
|
||||
chmod 600 $O/.ssh/deploy_igneum; chmod 644 $O/.ssh/deploy_igneum.pub
|
||||
install -d -m 700 -o $U -g $U /home/$U/.ssh
|
||||
if ! grep -q '^Host github-igneum-observer' /home/$U/.ssh/config 2>/dev/null; then
|
||||
printf 'Host github-igneum-observer\n HostName github.com\n User git\n IdentityFile %s/.ssh/deploy_igneum\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$O" >> /home/$U/.ssh/config
|
||||
chown $U:$U /home/$U/.ssh/config; chmod 600 /home/$U/.ssh/config; log "ssh alias github-igneum-observer written"
|
||||
fi
|
||||
|
||||
cat > $H/bin/observer-sync.sh <<'RUN'
|
||||
#!/usr/bin/env bash
|
||||
# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum from the mirror /srv/igneum.git (fed by every
|
||||
# build-remote.sh and run-from-mac.sh push from the Mac), restart igneum-observer when tools/observer or site/lib changed.
|
||||
# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum, then restart igneum-observer when tools/observer or
|
||||
# site/lib changed. Source: GitHub through the read-only deploy key (ssh alias github-igneum-observer, remote `github`) once
|
||||
# the project lead has added the public half; until then, or when GitHub refuses, the mirror /srv/igneum.git (fed by every build-remote.sh
|
||||
# and run-from-mac.sh push from the Mac). One line says which.
|
||||
set -uo pipefail
|
||||
cd /srv/observer/igneum || exit 1
|
||||
before=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ')
|
||||
su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2
|
||||
if su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 | grep -q "successfully authenticated"; then
|
||||
su - build -c "git -C /srv/observer/igneum remote get-url github >/dev/null 2>&1 || git -C /srv/observer/igneum remote add github git@github-igneum-observer:igneum-network/igneum.git"
|
||||
if su - build -c "git -C /srv/observer/igneum pull -q --ff-only github master" 2>&1 | head -2; then echo "source: github (deploy key accepted)"; else echo "source: github refused the pull, mirror next"; su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2; fi
|
||||
else
|
||||
echo "source: mirror (the deploy key is not accepted by GitHub yet: docs/plans/build-server.md, Deploy key)"
|
||||
su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2
|
||||
fi
|
||||
after=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ')
|
||||
if [ "$before" != "$after" ]; then echo "observer files changed ($(git rev-parse --short HEAD)); restarting igneum-observer"; systemctl restart igneum-observer; else echo "observer up to date at $(git rev-parse --short HEAD)"; fi
|
||||
RUN
|
||||
|
|
|
|||
Loading…
Reference in a new issue