- Add SSH key verification step with ssh-add -l - Properly configure known_hosts with ssh-keyscan - Add SSH connection test before rsync - Remove StrictHostKeyChecking=no from rsync and remote commands - Follow webfactory/ssh-agent best practices Resolves SSH key authentication failures during deployment 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
44 lines
1.2 KiB
YAML
44 lines
1.2 KiB
YAML
name: Deploy to NAS (rsync)
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
jobs:
|
|
deploy:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup SSH key
|
|
uses: webfactory/ssh-agent@v0.9.0
|
|
with:
|
|
ssh-private-key: ${{ secrets.NAS_SSH_KEY_ADMIN }}
|
|
|
|
- name: Check SSH key loaded
|
|
run: ssh-add -l
|
|
|
|
- name: Add NAS host to known_hosts
|
|
run: |
|
|
mkdir -p ~/.ssh
|
|
ssh-keyscan -p ${{ secrets.NAS_PORT }} ${{ secrets.NAS_HOST }} >> ~/.ssh/known_hosts
|
|
|
|
- name: Test SSH connection
|
|
run: |
|
|
ssh -o StrictHostKeyChecking=no -p ${{ secrets.NAS_PORT }} \
|
|
${{ secrets.NAS_USER }}@${{ secrets.NAS_HOST }} echo "SSH connection successful"
|
|
|
|
- name: Rsync to NAS
|
|
run: |
|
|
rsync -avz -e "ssh -p ${{ secrets.NAS_PORT }}" ./ \
|
|
${{ secrets.NAS_USER }}@${{ secrets.NAS_HOST }}:/volume1/homes/admin/nginx-infra/
|
|
|
|
- name: Remote docker-compose up
|
|
run: |
|
|
ssh -p ${{ secrets.NAS_PORT }} ${{ secrets.NAS_USER }}@${{ secrets.NAS_HOST }} << 'EOF'
|
|
cd /volume1/homes/admin/nginx-infra
|
|
docker-compose up -d --build
|
|
EOF |