summaryrefslogtreecommitdiff
path: root/deploy-docker.sh
blob: 69ccdce121cefaf3c3227542811dc869afcf2f01 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
#!/usr/bin/env bash
# deploy-docker.sh — build + deploy jayrup.me. Versioned in the repo so the
# post-receive hook always uses the deploy logic that matches the pushed tree.
#
# Designed to run ON MERU (docker-only machine) from a git archive snapshot:
#   git archive HEAD | tar -x -C "$BUILD_DIR" && bash "$BUILD_DIR/deploy-docker.sh" "$BUILD_DIR" <sha>
# Quarto runs inside the pinned devxygmbh/alpine-quarto container; rsync ships
# public/ to nandi (jayrup.me).
#
# Usage: deploy-docker.sh <build-dir> <short-sha>
set -euo pipefail

BUILD_DIR="${1:?usage: deploy-docker.sh <build-dir> <short-sha>}"
SHORT_SHA="${2:?missing short sha}"
cd "$BUILD_DIR"

# Pinned digest — update deliberately (docker pull devxygmbh/alpine-quarto:latest
# then replace the sha256:).
QUARTO_IMAGE="${QUARTO_IMAGE:-devxygmbh/alpine-quarto@sha256:0c0d785139b467ab75c053bc24463d2450cbf928ca8ece8d9a20dedba9568fa9}"
# Fallback if meru can't reach jayrup.me (IPv6): DEPLOY_HOST=jayrup@100.94.131.98
DEPLOY_HOST="${DEPLOY_HOST:-jayrup.me}"
RUN_UID="$(id -u)"
RUN_GID="$(id -g)"

# Render script runs INSIDE the container (one container spin, both passes).
# HOME=/tmp so quarto's cache is writable by the unprivileged uid.
# Written into the private build dir (not /tmp) per review finding.
cat > "$BUILD_DIR/homepage-render.sh" <<'RENDER_EOF'
#!/usr/bin/env bash
set -euo pipefail
cd /site
rm -rf public
quarto render --to html
find . -name "*.qmd" -not -path "./.*" -not -path "./public/*" | while read -r file; do
    rel_dir=$(dirname "${file#./}")
    base_name=$(basename "$file" .qmd)
    quarto render "$file" --to plain --output "${base_name}.txt" --output-dir "public/$rel_dir"
done
RENDER_EOF
chmod +x "$BUILD_DIR/homepage-render.sh"

echo ">> rendering with $QUARTO_IMAGE (commit $SHORT_SHA)"
# --entrypoint /bin/bash overrides whatever entrypoint the image declares
docker run --rm \
    --entrypoint /bin/bash \
    -u "$RUN_UID:$RUN_GID" \
    -e HOME=/tmp \
    -v "$BUILD_DIR":/site \
    -v "$BUILD_DIR/homepage-render.sh":/render.sh:ro \
    -w /site \
    "$QUARTO_IMAGE" /render.sh

# Static assets bundled in the repo
mkdir -p public/cv
cp cv/index.pdf public/cv.pdf
cp cv/index.txt public/cv.txt
cp assets/dissertation.pdf public/dissertation.pdf
cp assets/public_key public/public_key

# Deploy status marker — site-visible proof of the last successful deploy
printf 'deployed %s commit %s\n' "$(date -u +%Y-%m-%dT%H:%M:%SZ)" "$SHORT_SHA" > public/last-deploy.txt

echo ">> pushing to $DEPLOY_HOST"
rsync -avz --delete public/ "$DEPLOY_HOST":~/homepage/public/
echo ">> deploy OK ($SHORT_SHA)"