#!/usr/bin/env bash # deploy-docker.sh — build + deploy jayrup.me. Versioned in the repo so the # post-receive hook always uses the deploy logic that matches the pushed tree. # # Designed to run ON MERU (docker-only machine) from a git archive snapshot: # git archive HEAD | tar -x -C "$BUILD_DIR" && bash "$BUILD_DIR/deploy-docker.sh" "$BUILD_DIR" # Quarto runs inside the pinned devxygmbh/alpine-quarto container; rsync ships # public/ to nandi (jayrup.me). # # Usage: deploy-docker.sh set -euo pipefail BUILD_DIR="${1:?usage: deploy-docker.sh }" SHORT_SHA="${2:?missing short sha}" cd "$BUILD_DIR" # Pinned digest — update deliberately (docker pull devxygmbh/alpine-quarto:latest # then replace the sha256:). QUARTO_IMAGE="${QUARTO_IMAGE:-devxygmbh/alpine-quarto@sha256:0c0d785139b467ab75c053bc24463d2450cbf928ca8ece8d9a20dedba9568fa9}" # Fallback if meru can't reach jayrup.me (IPv6): DEPLOY_HOST=jayrup@100.94.131.98 DEPLOY_HOST="${DEPLOY_HOST:-jayrup.me}" RUN_UID="$(id -u)" RUN_GID="$(id -g)" # Render script runs INSIDE the container (one container spin, both passes). # HOME=/tmp so quarto's cache is writable by the unprivileged uid. # Written into the private build dir (not /tmp) per review finding. cat > "$BUILD_DIR/homepage-render.sh" <<'RENDER_EOF' #!/usr/bin/env bash set -euo pipefail cd /site rm -rf public quarto render --to html find . -name "*.qmd" -not -path "./.*" -not -path "./public/*" | while read -r file; do rel_dir=$(dirname "${file#./}") base_name=$(basename "$file" .qmd) quarto render "$file" --to plain --output "${base_name}.txt" --output-dir "public/$rel_dir" done RENDER_EOF chmod +x "$BUILD_DIR/homepage-render.sh" echo ">> rendering with $QUARTO_IMAGE (commit $SHORT_SHA)" # --entrypoint /bin/bash overrides whatever entrypoint the image declares docker run --rm \ --entrypoint /bin/bash \ -u "$RUN_UID:$RUN_GID" \ -e HOME=/tmp \ -v "$BUILD_DIR":/site \ -v "$BUILD_DIR/homepage-render.sh":/render.sh:ro \ -w /site \ "$QUARTO_IMAGE" /render.sh # Static assets bundled in the repo mkdir -p public/cv cp cv/index.pdf public/cv.pdf cp cv/index.txt public/cv.txt cp assets/dissertation.pdf public/dissertation.pdf cp assets/public_key public/public_key # Deploy status marker — site-visible proof of the last successful deploy printf 'deployed %s commit %s\n' "$(date -u +%Y-%m-%dT%H:%M:%SZ)" "$SHORT_SHA" > public/last-deploy.txt echo ">> pushing to $DEPLOY_HOST" rsync -avz --delete public/ "$DEPLOY_HOST":~/homepage/public/ echo ">> deploy OK ($SHORT_SHA)"