www

Unnamed repository; edit this file 'description' to name the repository.
Log | Files | Refs | README

make-travis-key.sh (2245B)


      1 #!/bin/sh
      2 set -e
      3 set +x
      4 
      5 usage() {
      6   echo "Usage: $0 built-repo-url deploy-repo-url"
      7   echo " - The first argument must be the URL for the repository being built"
      8   echo "   with Travis-Ci, e.g."
      9   echo "       git@github.com:built-user/built-repo.git"
     10   echo " - The second argument must be the URL for the repository to which the"
     11   echo "   artifacts will be pushed, e.g."
     12   echo "       git@github.com:deploy-user/deploy-repo.git"
     13   echo ""
     14   echo " It is preferable to create a repository specifically for hosting the"
     15   echo " artifacts, so that if the private key is accidentally leaked, only"
     16   echo " that repository will be affected."
     17   echo ""
     18   echo " Furthermore, it is preferable to only push non-executable artifacts"
     19   echo " (e.g. screenshots), so that if the repository is compromised, an"
     20   echo " attacker may not inject malicious code into what people may consider"
     21   echo " trusted artifacts."
     22 }
     23 
     24 if test "$#" -eq 1 && test "$1" = "-h" -o "$1" = "--help"; then
     25   usage
     26   exit 0
     27 elif test "$#" -ne 2; then
     28   usage
     29   exit 1
     30 fi
     31 
     32 built_repo="$1" # git@github.com:built-user/built-repo.git
     33 deploy_repo="$2" # git@github.com:deploy-user/deploy-repo.git
     34 
     35 if ! which travis > /dev/null; then
     36   gem install travis || echo "Notice: you need the following packages or their equivalent: ruby ruby-dev"
     37 fi
     38 
     39 ssh_dir="$("$(dirname "$0")/mktemp.sh" -d)"
     40 mkdir -m 700 "${ssh_dir}/permissions/"
     41 ssh-keygen -N '' -f "${ssh_dir}/permissions/travis-deploy-key-id_rsa"
     42 
     43 if test "$(git remote get-url origin)" != "${built_repo}"; then
     44     echo "ERROR: The url of the remote \"origin\" in the current repository is"
     45     echo "not the same as the one of the built repository specified on the"
     46     echo "command-line."
     47     echo "origin url:                  $(git remote get-url origin)"
     48     echo "command-line built-repo-url: $built_repo"
     49   exit 1
     50 fi
     51 
     52 travis login
     53 travis encrypt-file "${ssh_dir}/permissions/travis-deploy-key-id_rsa"
     54 git add "travis-deploy-key-id_rsa.enc"
     55 
     56 printf "\033[1;32mNow copy the following public SSH key and add it as a\033[m\n"
     57 printf "\033[1;32mread-write deploy key for the repository \033[1;33m${deploy_repo}\033[1;32m on GitHub.\033[m\n"
     58 cat "${ssh_dir}/permissions/travis-deploy-key-id_rsa.pub"
     59 rm -fr "${ssh_dir}"