diff --git a/.gitea/workflows/cd.yml b/.gitea/workflows/cd.yml index 5f3a59a..5cf6d5c 100644 --- a/.gitea/workflows/cd.yml +++ b/.gitea/workflows/cd.yml @@ -52,9 +52,19 @@ jobs: # (that only worked when act_runner ran on koala's bare host network; # from inside the containerized runner's own pod netns, loopback # never reaches the host — "Connection refused", found 2026-07-27). - printf 'Host git.d-ma.be\n HostName gitea-ssh-nodeport.gitea.svc.cluster.local\n Port 22\n StrictHostKeyChecking no\n' >> ~/.ssh/config - - GIT_SSH_COMMAND="ssh -i ~/.ssh/infra_deploy_key -o IdentitiesOnly=yes" \ + # + # Pass as -o overrides on the ssh invocation itself, NOT appended to + # ~/.ssh/config: $HOME (/data) is a PVC that persists across job + # runs on this runner (same "workspace not ephemeral" class as + # brain: act-runner-host-executor-tmp-persists), so an appended + # line here would pile up duplicate `Host git.d-ma.be` blocks + # across every run — ssh_config is first-match-wins, so a stale + # entry from an earlier failed run would silently shadow this + # fix forever (exactly what happened once already: this fix's + # own first attempt got appended AFTER an already-stale entry + # and lost). CLI -o options always win regardless of file state, + # so this step is safe to re-run any number of times. + GIT_SSH_COMMAND="ssh -i ~/.ssh/infra_deploy_key -o IdentitiesOnly=yes -o HostName=gitea-ssh-nodeport.gitea.svc.cluster.local -o Port=22 -o StrictHostKeyChecking=no" \ git clone "${INFRA_REPO}" /tmp/infra-update cd /tmp/infra-update