Deploy: Docker Hub registry + inject keeper .env from GitHub secrets - #123
Merged
Merged
Conversation
Push/pull images from Docker Hub (obchain219/volx-*) instead of GHCR: build job
logs in with DOCKER_USERNAME/DOCKER_PASSWORD and tags ${user}/volx-<svc>:latest
+ :sha; deploy.sh does an optional Docker Hub login before pulling. The deploy
job now writes the server .env (SEPOLIA_RPC_URL, PRIVATE_KEY) from GitHub
secrets each run (umask 077), so runtime secrets are managed in one place
instead of placed on the host by hand.
Inject VOLX_REGISTRY into the server .env from the DOCKER_USERNAME secret so the compose default can never drift from what CI pushed, and document that the Docker Hub repos must be public (no server-side login is configured).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two related deploy changes.
Docker Hub instead of GHCR
Images now push/pull from Docker Hub
obchain219/volx-*:docker-compose.prod.yml: image refs default to${VOLX_REGISTRY:-obchain219}/volx-<svc>.deploy.ymlbuild job logs in withDOCKER_USERNAME/DOCKER_PASSWORDand tags<user>/volx-<svc>:latest+:sha. Dropped the GHCRpackages:writepermission.deploy.shdoes an optional Docker Hub login (only needed for private repos) before pulling.Inject keeper .env from secrets (Option B)
The deploy job now writes
~/volx-deploy/.envon the server from GitHub secrets each run (SEPOLIA_RPC_URL,PRIVATE_KEY,umask 077-> 0600). Runtime secrets are managed in one place (GitHub) instead of placed on the host by hand. Values are masked in Actions logs.Secrets (repository)
Already set via API:
SEPOLIA_RPC_URL,PRIVATE_KEY. Still needed for a live run:DOCKER_USERNAME,DOCKER_PASSWORD,SERVER_SSH_KEY(+ optionalSERVER_KNOWN_HOSTS).Compose validated; deploy.sh
bash -nclean; deploy.yml YAML valid.