Files
feedc0de 01185ad0bc
Validate and deploy Anubis / Validate manifests (push) Successful in 12s
Validate and deploy Anubis / Deploy to Kubernetes (push) Successful in 35s
Add existing anubis deployment and add CI/CD
2026-09-04 10:43:09 +02:00

23 lines
859 B
Bash
Executable File

#!/bin/sh
set -eu
project_dir=$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)
namespace=default
secret_name=gitea-anubis-key
if ! kubectl --namespace "$namespace" get secret "$secret_name" >/dev/null 2>&1; then
anubis_signing_key=$(openssl rand -hex 32)
kubectl --namespace "$namespace" create secret generic "$secret_name" \
--from-literal="ED25519_PRIVATE_KEY_HEX=${anubis_signing_key}"
fi
kubectl apply --dry-run=server --validate=false \
--filename "${project_dir}/anubis.yaml"
kubectl apply --filename "${project_dir}/anubis.yaml"
# ConfigMap volume updates do not restart Anubis, and the policy is read at
# process startup. Restart explicitly so policy-only changes take effect.
kubectl --namespace "$namespace" rollout restart deployment/gitea-anubis
kubectl --namespace "$namespace" rollout status deployment/gitea-anubis \
--timeout=5m