Observer clone: a read-only deploy key made on the box, GitHub preferred over the mirror once accepted; Josh's steps in the plan

Main's order of 7 October 2026. install-hands.sh creates /srv/observer/.ssh/deploy_igneum (ed25519, user build, mode 600; the private
half never leaves the box and nothing prints it) and the ssh alias github-igneum-observer; observer-sync.sh tests the key with
ssh -T on every pass, pulls from GitHub when it is accepted and from the mirror otherwise, saying which. docs/plans/build-server.md
5c: the four steps for Josh (print the public half, Settings > Deploy keys > Add, read-only, start one sync pass) and the public
half itself. Verified on the box: key created, alias written, one sync pass reads 'source: mirror (the deploy key is not accepted by
GitHub yet)'. The CI-runner row is closed (the box-work agent's runner service).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-josh 2026-10-07 00:47:10 +01:00
parent e8cfbead82
commit d468ac74f4

View file

@ -68,14 +68,34 @@ IFS=',' read -r -a peers <<< "${PEERS:-}"; for p in "${peers[@]}"; do [ -n "$p"
[ -n "${EXTRA_ARGS_OBSERVER:-}" ] && args+=($EXTRA_ARGS_OBSERVER)
exec "$IGNEUMD" "${args[@]}"
RUN
# the read-only deploy key (main, 7 October 2026): made HERE as user build, the private half never leaves this box and is never
# printed; Josh adds the public half as a read-only deploy key on github.com/igneum-network/igneum (steps in
# docs/plans/build-server.md, "Deploy key"). Until GitHub accepts it, observer-sync.sh follows the mirror.
install -d -m 700 -o $U -g $U $O/.ssh
if [ ! -f $O/.ssh/deploy_igneum ]; then su - $U -c "ssh-keygen -q -t ed25519 -N '' -C 'igneum-build-1 observer read-only' -f $O/.ssh/deploy_igneum"; log "deploy key created at $O/.ssh/deploy_igneum (public half: $O/.ssh/deploy_igneum.pub)"; else log "deploy key ok"; fi
chmod 600 $O/.ssh/deploy_igneum; chmod 644 $O/.ssh/deploy_igneum.pub
install -d -m 700 -o $U -g $U /home/$U/.ssh
if ! grep -q '^Host github-igneum-observer' /home/$U/.ssh/config 2>/dev/null; then
printf 'Host github-igneum-observer\n HostName github.com\n User git\n IdentityFile %s/.ssh/deploy_igneum\n IdentitiesOnly yes\n StrictHostKeyChecking accept-new\n' "$O" >> /home/$U/.ssh/config
chown $U:$U /home/$U/.ssh/config; chmod 600 /home/$U/.ssh/config; log "ssh alias github-igneum-observer written"
fi
cat > $H/bin/observer-sync.sh <<'RUN'
#!/usr/bin/env bash
# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum from the mirror /srv/igneum.git (fed by every
# build-remote.sh and run-from-mac.sh push from the Mac), restart igneum-observer when tools/observer or site/lib changed.
# the box's tools/observer/autosync.sh: fast-forward /srv/observer/igneum, then restart igneum-observer when tools/observer or
# site/lib changed. Source: GitHub through the read-only deploy key (ssh alias github-igneum-observer, remote `github`) once
# Josh has added the public half; until then, or when GitHub refuses, the mirror /srv/igneum.git (fed by every build-remote.sh
# and run-from-mac.sh push from the Mac). One line says which.
set -uo pipefail
cd /srv/observer/igneum || exit 1
before=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ')
su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2
if su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 | grep -q "successfully authenticated"; then
su - build -c "git -C /srv/observer/igneum remote get-url github >/dev/null 2>&1 || git -C /srv/observer/igneum remote add github git@github-igneum-observer:igneum-network/igneum.git"
if su - build -c "git -C /srv/observer/igneum pull -q --ff-only github master" 2>&1 | head -2; then echo "source: github (deploy key accepted)"; else echo "source: github refused the pull, mirror next"; su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2; fi
else
echo "source: mirror (the deploy key is not accepted by GitHub yet: docs/plans/build-server.md, Deploy key)"
su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2
fi
after=$(git rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ')
if [ "$before" != "$after" ]; then echo "observer files changed ($(git rev-parse --short HEAD)); restarting igneum-observer"; systemctl restart igneum-observer; else echo "observer up to date at $(git rev-parse --short HEAD)"; fi
RUN