irongit

Git hosting and a container registry in one Rust binary (axum + Astro)

41 lines1.5 KB
1#!/bin/sh
2# Deploys to production with ./deploy.sh when main is pushed to git.hygo.ai,
3# before the push goes out: if the deploy fails, the push is stopped, so the
4# repository never claims something production is not running.
5#
6# Enabled per clone with: git config core.hooksPath .githooks
7# Skip once with: git push --no-verify (or SKIP_DEPLOY=1 git push)
8set -eu
9
10url="$2"
11[ "${SKIP_DEPLOY:-}" = 1 ] && exit 0
12case "$url" in
13 *git.hygo.ai/huncholane/irongit*) ;;
14 *) exit 0 ;;
15esac
16
17zero=0000000000000000000000000000000000000000
18deploy=0
19while read -r local_ref local_sha remote_ref remote_sha; do
20 [ "$remote_ref" = refs/heads/main ] || continue
21 [ "$local_sha" = "$zero" ] && continue # deleting main is not a deploy
22 if [ "$local_sha" != "$(git rev-parse HEAD)" ]; then
23 echo "pre-push: main is $(git rev-parse --short "$local_sha") but you have $(git rev-parse --short HEAD) checked out." >&2
24 echo "pre-push: check out main to deploy it, or push with --no-verify." >&2
25 exit 1
26 fi
27 deploy=1
28done
29[ "$deploy" = 1 ] || exit 0
30
31# The image is built from this folder, not the commit: refuse anything that
32# is not committed (untracked files included) so prod matches main exactly.
33if [ -n "$(git status --porcelain)" ]; then
34 echo "pre-push: uncommitted or untracked files would be deployed:" >&2
35 git status --short >&2
36 echo "pre-push: commit or stash them, or push with --no-verify to skip the deploy." >&2
37 exit 1
38fi
39
40echo "pre-push: deploying $(git rev-parse --short HEAD) to production before pushing main"
41./deploy.sh </dev/null