Deploy to FTP account root (codedev@codedev.llc is chrooted to the do… #4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy Website | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| env: | |
| FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| # Deploy over EXPLICIT FTPS with curl (--ssl-reqd requires TLS — never plaintext) | |
| # + retries. Same shared host as termpolis.com; it intermittently resets the | |
| # control socket during the FTPS handshake (`read ECONNRESET`), so curl's | |
| # --retry/--retry-all-errors rides out those transient resets. | |
| # | |
| # `-k` (insecure): this shared host serves an FTPS certificate that does NOT | |
| # match FTP_HOST (curl error 60), so strict verification can't pass. The transfer | |
| # stays TLS-ENCRYPTED; -k only skips server-identity verification. | |
| # | |
| # The codedev@codedev.llc FTP account is scoped (chrooted) to codedev.llc's | |
| # document root, so its FTP root IS the web root — we upload tracked web files | |
| # straight to "/" (no subfolder). --ftp-create-dirs creates remote dirs as needed. | |
| # .github/, .gitignore, and README.md aren't web content. | |
| - name: Deploy to codedev.llc (FTPS via curl, retried) | |
| env: | |
| FTP_HOST: ${{ secrets.FTP_HOST }} | |
| FTP_USERNAME: ${{ secrets.FTP_USERNAME }} | |
| FTP_PASSWORD: ${{ secrets.FTP_PASSWORD }} | |
| run: | | |
| set -uo pipefail | |
| if [ -z "${FTP_HOST:-}" ] || [ -z "${FTP_USERNAME:-}" ] || [ -z "${FTP_PASSWORD:-}" ]; then | |
| echo "::notice::FTP secrets not set yet — skipping deploy. Add FTP_HOST, FTP_USERNAME, and FTP_PASSWORD (same values as termpolis-website), then re-run this workflow." | |
| exit 0 | |
| fi | |
| files=$(git ls-files | grep -vE '^(\.github/|\.gitignore$|README\.md$)') | |
| rc=0; n=0; ok=0 | |
| while IFS= read -r f; do | |
| [ -n "$f" ] && [ -f "$f" ] || continue | |
| n=$((n+1)) | |
| if curl --ssl-reqd -k -sS --retry 5 --retry-all-errors --connect-timeout 30 \ | |
| --ftp-create-dirs --user "$FTP_USERNAME:$FTP_PASSWORD" \ | |
| -T "$f" "ftp://$FTP_HOST/${f// /%20}"; then # %20-encode spaces in remote path | |
| ok=$((ok+1)) | |
| else | |
| echo " FAILED: $f"; rc=1 | |
| fi | |
| done <<< "$files" | |
| echo "Uploaded $ok/$n files to the codedev.llc web root." | |
| if [ "$rc" -ne 0 ]; then echo "::error::One or more files failed to upload after retries."; fi | |
| exit $rc |