diff --git a/infra/build-server/hands/install-hands.sh b/infra/build-server/hands/install-hands.sh index d48fc3675..6211dab67 100755 --- a/infra/build-server/hands/install-hands.sh +++ b/infra/build-server/hands/install-hands.sh @@ -68,14 +68,34 @@ IFS=',' read -r -a peers <<< "${PEERS:-}"; for p in "${peers[@]}"; do [ -n "$p" [ -n "${EXTRA_ARGS_OBSERVER:-}" ] && args+=($EXTRA_ARGS_OBSERVER) exec "$IGNEUMD" "${args[@]}" RUN +# the read-only deploy key (main, 7 October 2026): made HERE as user build, the private half never leaves this box and is never +# printed; the project lead adds the public half as a read-only deploy key on github.com/igneum-network/igneum (steps in +# docs/plans/build-server.md, "Deploy key"). Until GitHub accepts it, observer-sync.sh follows the mirror. +install -d -m 700 -o $U -g $U $O/.ssh +if [ ! -f $O/.ssh/deploy_igneum ]; then su - $U -c "ssh-keygen -q -t ed25519 -N '' -C 'igneum-build-1 observer read-only' -f $O/.ssh/deploy_igneum"; log "deploy key created at $O/.ssh/deploy_igneum (public half: $O/.ssh/deploy_igneum.pub)"; else log "deploy key ok"; fi +chmod 600 $O/.ssh/deploy_igneum; chmod 644 $O/.ssh/deploy_igneum.pub +install -d -m 700 -o $U -g $U /home/$U/.ssh +if ! grep -q '^Host github-igneum-observer' /home/$U/.ssh/config 2>/dev/null; then + printf 'Host github-igneum-observer\n HostName github.com\n User git\n IdentityFile %s/.ssh/deploy_igneum\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$O" >> /home/$U/.ssh/config + chown $U:$U /home/$U/.ssh/config; chmod 600 /home/$U/.ssh/config; log "ssh alias github-igneum-observer written" +fi + cat > $H/bin/observer-sync.sh <<'RUN' #!/usr/bin/env bash -# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum from the mirror /srv/igneum.git (fed by every -# build-remote.sh and run-from-mac.sh push from the Mac), restart igneum-observer when tools/observer or site/lib changed. +# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum, then restart igneum-observer when tools/observer or +# site/lib changed. Source: GitHub through the read-only deploy key (ssh alias github-igneum-observer, remote `github`) once +# the project lead has added the public half; until then, or when GitHub refuses, the mirror /srv/igneum.git (fed by every build-remote.sh +# and run-from-mac.sh push from the Mac). One line says which. set -uo pipefail cd /srv/observer/igneum || exit 1 before=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ') -su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2 +if su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 | grep -q "successfully authenticated"; then + su - build -c "git -C /srv/observer/igneum remote get-url github >/dev/null 2>&1 || git -C /srv/observer/igneum remote add github git@github-igneum-observer:igneum-network/igneum.git" + if su - build -c "git -C /srv/observer/igneum pull -q --ff-only github master" 2>&1 | head -2; then echo "source: github (deploy key accepted)"; else echo "source: github refused the pull, mirror next"; su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2; fi +else + echo "source: mirror (the deploy key is not accepted by GitHub yet: docs/plans/build-server.md, Deploy key)" + su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2 +fi after=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ') if [ "$before" != "$after" ]; then echo "observer files changed ($(git rev-parse --short HEAD)); restarting igneum-observer"; systemctl restart igneum-observer; else echo "observer up to date at $(git rev-parse --short HEAD)"; fi RUN