Skip to content

ci(deploy): move server identity into secrets - #127

Merged
obchain merged 2 commits into
mainfrom
ci/scrub-server-identity
Jun 22, 2026
Merged

obchain merged 2 commits into
mainfrom
ci/scrub-server-identity

Conversation

@obchain

@obchain obchain commented Jun 22, 2026

Copy link
Copy Markdown
Owner

What

The deploy workflow hard-coded the deploy target in plaintext: the SSH host alias, the login user, and the remote deploy directory. Move all three into repo secrets so they are not baked into the public workflow file.

Changes

  • New secrets consumed: SERVER_SSH_HOST, SERVER_USER, SERVER_DEPLOY_DIR (already set in the repo).
  • Configure SSH step: the generated ~/.ssh/config Host/User now interpolate from $SERVER_SSH_HOST / $SERVER_USER.
  • Ship step: DEPLOY_DIR comes from secrets.SERVER_DEPLOY_DIR; every ssh/scp target uses $SERVER_SSH_HOST.

Behaviour

No functional change — same host, user, and directory, just sourced from secrets (GitHub masks the values in job logs). YAML validated.

Note

This scrubs the current file. The values still exist in older commits in git history; a history rewrite is out of scope here and would force-push over open PR bases.

obchain added 2 commits June 22, 2026 15:23
The deploy workflow hard-coded the SSH host alias, the login user, and the
remote deploy directory in plaintext. Pull them from new repo secrets
(SERVER_SSH_HOST, SERVER_USER, SERVER_DEPLOY_DIR) so the deploy target is
not baked into the public workflow. GitHub masks the values in job logs.
No behavioural change — same host, user, and directory, sourced indirectly.
CI has no path filter, so a docs-only merge to main runs the full pipeline
and, on success, triggers a rebuild + redeploy via the deploy workflow's
workflow_run hook. Add paths-ignore for markdown, docs/, and LICENSE on the
push trigger so documentation edits no longer rebuild images or redeploy the
server. Pull-request runs are unchanged (still validate every PR).
@obchain
obchain merged commit 8278f0a into main Jun 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant