mirror of
https://github.com/wlixcc/SFTP-Deploy-Action.git
synced 2026-09-23 21:28:32 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c392989cc9 | ||
|
|
bada6e2c24 | ||
|
|
a5ccb9c621 | ||
|
|
b131f3d078 | ||
|
|
a2526c619d | ||
|
|
74f82cb508 | ||
|
|
896dcfc555 | ||
|
|
89e97d73f9 | ||
|
|
675755b272 | ||
|
|
067de34294 | ||
|
|
834e1ad841 | ||
|
|
259119b427 | ||
|
|
f944ea4c67 | ||
|
|
7589349f24 | ||
|
|
da88a4dbe9 | ||
|
|
e57406ff6c | ||
|
|
6596a6c48c | ||
|
|
33436f92f1 | ||
|
|
3586e619fa | ||
|
|
8392b571c7 | ||
|
|
c6e4d76ad9 | ||
|
|
3a6bd36ae1 | ||
|
|
00c712f732 | ||
|
|
28d6168ebf |
@@ -0,0 +1,26 @@
|
||||
name: Continuous Deploy
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: sftp
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: deploy file to server
|
||||
uses: ./ # Uses an action in the root directory
|
||||
with:
|
||||
username: '${{ secrets.USER }}'
|
||||
server: '${{ secrets.SERVER_IP }}'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './*'
|
||||
remote_path: '/tmp/testAction'
|
||||
sftpArgs: '-o ConnectTimeout=5'
|
||||
rsyncArgs: '--exclude *.yml'
|
||||
|
||||
|
||||
# sftp_only: true
|
||||
# password: ${{secrets.SSH_PASSWORD}}
|
||||
# delete_remote_files: true
|
||||
+9
-12
@@ -1,15 +1,12 @@
|
||||
# Container image that runs your code
|
||||
FROM alpine:3.10
|
||||
# Use an up-to-date and secure Alpine version
|
||||
FROM alpine:3.18
|
||||
|
||||
# Copies your code file from your action repository to the filesystem path `/` of the container
|
||||
# Install required packages in one RUN statement to reduce image layers
|
||||
RUN apk update && apk add --no-cache rsync sshpass openssh expect
|
||||
|
||||
# Copy entrypoint script and set correct permissions
|
||||
COPY entrypoint.sh /entrypoint.sh
|
||||
RUN chmod +x /entrypoint.sh
|
||||
|
||||
#Make sure to make you entrypoint.sh file executable:
|
||||
RUN chmod 777 entrypoint.sh
|
||||
|
||||
RUN apk update
|
||||
RUN apk add --no-cache openssh
|
||||
|
||||
|
||||
# Code file to execute when the docker container starts up (`entrypoint.sh`)
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
# Set the entrypoint for the container
|
||||
ENTRYPOINT ["/bin/sh", "/entrypoint.sh"]
|
||||
@@ -1,132 +1,190 @@
|
||||
# SFTP Deploy action
|
||||
|
||||
> Use this action to deploy your files to server using `SSH Private Key`
|
||||
# SFTP Deploy Action
|
||||
|
||||
> 使用此`action`部署你的项目到服务器上,`仅支持密钥对连接`
|
||||
> Use this action to deploy your files to a server using `SSH Private Key`
|
||||
|
||||
> [使用Github Action 部署项目到云服务器](https://zhuanlan.zhihu.com/p/107545396)
|
||||
> 使用此 `action` 部署你的项目到服务器上,中文介绍链接:[使用Github Action 部署项目到云服务器](https://zhuanlan.zhihu.com/p/107545396)
|
||||
|
||||
---
|
||||
|
||||
## 🚀 **1. Inputs**
|
||||
|
||||
| Name | Required | Default | Description |
|
||||
|------------------------|----------|---------|----------------------------------------------------------------------------------------------------------------------|
|
||||
| `username` | yes | | SSH username |
|
||||
| `server` | yes | | Remote host |
|
||||
| `port` | yes | 22 | Remote host port |
|
||||
| `ssh_private_key` | no | | You can copy the private key from your `ssh_private_key` file and save it to `repo/settings/secrets`<br>  |
|
||||
| `local_path` | yes | `./*` | Local path of your project. <br> - Single file: `./myfile` <br> - Directory: `./static/*` <br> Default: `./*` (will put all files in your repo). |
|
||||
| `remote_path` | yes | | The target folder on the remote server. |
|
||||
| `sftp_only` | no | | If your port only accepts the sftp protocol, set this option to `true`. However, when set to `true`, the remote folder won't be automatically created. |
|
||||
| `sftpArgs` | no | | Extra arguments you want to pass to `sftp`, for example: `-o ConnectTimeout=5` |
|
||||
| `delete_remote_files` | no | false | Set to `true` to delete the remote path folder and all files in it **before** uploading. |
|
||||
| `password` | no | | SSH password. If a password is set, `ssh_private_key` and `ssh_passphrase` is ignored. *(for @v1.2.4 and greater)* |
|
||||
| `rsyncArgs` | no | | Additional arguments for the `rsync` command. You can customize file synchronization behavior, such as excluding files or directories. Example: `--exclude=node_modules --exclude=.git --exclude=*.log`. *(for @v1.2.5 and greater)* |
|
||||
| `ssh_passphrase` | no | | The passphrase for encrypted ssh private-key |
|
||||
|
||||
> ⚠️ **Warning:**
|
||||
> Be careful when using `delete_remote_files`. This will **permanently delete** the remote path folder and all files in it **before** uploading.
|
||||
|
||||
---
|
||||
|
||||
## 📦 **2. Action Examples**
|
||||
|
||||
### **🔹 Basic Example**
|
||||
|
||||
```yaml
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: Deploy Files
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Deploy to Server
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
|
||||
with:
|
||||
username: 'root'
|
||||
server: 'your server ip'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './static/*'
|
||||
remote_path: '/var/www/app'
|
||||
sftpArgs: '-o ConnectTimeout=5'
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### **🔹 Example with rsyncArgs**
|
||||
|
||||
```yaml
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: Deploy with rsync exclude
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Deploy with Exclude Patterns
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
|
||||
with:
|
||||
username: 'root'
|
||||
server: 'your server ip'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './'
|
||||
remote_path: '/var/www/app'
|
||||
rsyncArgs: '--exclude=node_modules --exclude=.git --exclude=*.log'
|
||||
sftpArgs: '-o ConnectTimeout=5'
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### **🔹 Example with Password Authentication**
|
||||
|
||||
```yaml
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: Deploy with Password
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Deploy with Password
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
|
||||
with:
|
||||
username: ${{ secrets.FTP_USERNAME }}
|
||||
server: ${{ secrets.FTP_SERVER }}
|
||||
port: ${{ secrets.FTP_PORT }}
|
||||
local_path: './static/*'
|
||||
remote_path: '/var/www/app'
|
||||
sftp_only: true
|
||||
password: ${{ secrets.FTP_PASSWORD }}
|
||||
```
|
||||
|
||||
|
||||
## Inputs
|
||||
### **🔹 Example with Encrypted Private Key Authentication**
|
||||
```yaml
|
||||
on: [push]
|
||||
|
||||
### `username`
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: Deploy with encrypted private key
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
**Required** sftp username.
|
||||
- name: Deploy with encrypted private key
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
|
||||
with:
|
||||
username: ${{ secrets.FTP_USERNAME }}
|
||||
server: ${{ secrets.FTP_SERVER }}
|
||||
port: ${{ secrets.FTP_PORT }}
|
||||
local_path: './static/*'
|
||||
remote_path: '/var/www/app'
|
||||
sftp_only: true
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
ssh_passphrase: ${{ secrets.SSH_PASSPHRASE }}
|
||||
```
|
||||
---
|
||||
|
||||
### `server`
|
||||
## 🌐 **3. [Deploy React App Example](https://github.com/wlixcc/React-Deploy)**
|
||||
|
||||
**Required** sftp server address.
|
||||
```yaml
|
||||
on: [push]
|
||||
|
||||
### `port`
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: Build & Deploy React App
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
sftp srever port , default `22`
|
||||
- name: Install Dependencies
|
||||
run: yarn
|
||||
|
||||
### `ssh_private_key`
|
||||
- name: Build
|
||||
run: yarn build
|
||||
|
||||
**Required** you can copy private_key from your `ssh_private_key.pem file`, keep format, and save at`repo/settings/secrets`
|
||||
- name: Deploy Build Folder
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.2.6
|
||||
with:
|
||||
username: 'root'
|
||||
server: '${{ secrets.SERVER_IP }}'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './build/*'
|
||||
remote_path: '/var/www/react-app'
|
||||
rsyncArgs: '--exclude=*.map'
|
||||
sftpArgs: '-o ConnectTimeout=5'
|
||||
```
|
||||
|
||||

|
||||
|
||||
---
|
||||
|
||||
## 🛡️ **4. Invalid format? You need to keep the format**
|
||||
|
||||
If you use the **Ed25519** algorithm to generate an SSH key pair:
|
||||
|
||||
```sh
|
||||
ssh-keygen -t ed25519 -C "your_email@example.com"
|
||||
```
|
||||
|
||||
⚠️ **Important:**
|
||||
The last line of the private key **must remain a blank line** when adding it to **Repository Secrets**.
|
||||
If you remove it, you might encounter an `invalid format` error.
|
||||
|
||||

|
||||
|
||||
---
|
||||
|
||||
|
||||

|
||||
|
||||
### `local_path`
|
||||
|
||||
**Required** `local_path` of you project, if you want put single file:use path like `./myfile`, if you want put directory: use path like `./static/*`, it will put all files under `static` directory. Default to `./*`(will put all files in your repo).
|
||||
|
||||
### `remote_path`
|
||||
**Required** remote_path
|
||||
|
||||
### `args`
|
||||
args of sftp cmd, E.g.`-o ConnectTimeout=5`
|
||||
|
||||
|
||||
## Action Example
|
||||
|
||||
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: deploy
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
- name: deploy file
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.0
|
||||
with:
|
||||
username: 'root'
|
||||
server: 'your server ip'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './static/*'
|
||||
remote_path: '/var/www/app'
|
||||
args: '-o ConnectTimeout=5'
|
||||
|
||||
## 1. [Deploy React App Example](https://github.com/wlixcc/React-Deploy)
|
||||
|
||||
> If you use nginx, all you need to do is upload the static files to the server after the project is built
|
||||
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: build&deploy
|
||||
steps:
|
||||
# To use this repository's private action, you must check out the repository
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Install Dependencies
|
||||
run: yarn
|
||||
- name: Build
|
||||
run: yarn build
|
||||
|
||||
- name: deploy file to server
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.0
|
||||
with:
|
||||
username: 'root'
|
||||
server: '${{ secrets.SERVER_IP }}'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './build/*'
|
||||
remote_path: '/var/www/react-app'
|
||||
args: '-o ConnectTimeout=5'
|
||||
|
||||

|
||||
|
||||
## 2.Deploy Umi App Example (Ant Design Pro)
|
||||
|
||||
name: continuous deployment
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
deploy_job:
|
||||
runs-on: ubuntu-latest
|
||||
name: build&deploy
|
||||
steps:
|
||||
# To use this repository's private action, you must check out the repository
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Install umi
|
||||
run: yarn global add umi
|
||||
|
||||
- name: Install Dependencies
|
||||
run: yarn
|
||||
- name: Build
|
||||
run: yarn build
|
||||
|
||||
- name: deploy file to server
|
||||
uses: wlixcc/SFTP-Deploy-Action@v1.0
|
||||
with:
|
||||
username: 'root'
|
||||
server: '${{ secrets.SERVER_IP }}'
|
||||
ssh_private_key: ${{ secrets.SSH_PRIVATE_KEY }}
|
||||
local_path: './dist/*'
|
||||
remote_path: '/var/www/umiapp'
|
||||
args: '-o ConnectTimeout=5'
|
||||

|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
+30
-6
@@ -14,7 +14,7 @@ inputs:
|
||||
default: "22"
|
||||
ssh_private_key:
|
||||
description: 'you can copy private_key from your *.pem file, keep format'
|
||||
required: true
|
||||
required: false
|
||||
local_path:
|
||||
description: 'will put all file under this path'
|
||||
required: true
|
||||
@@ -22,12 +22,30 @@ inputs:
|
||||
remote_path:
|
||||
description: 'files will copy to under remote_path'
|
||||
required: true
|
||||
default: /
|
||||
|
||||
args:
|
||||
sftp_only:
|
||||
description: 'connection via sftp protocol only'
|
||||
required: false
|
||||
default: false
|
||||
sftpArgs:
|
||||
description: 'sftp args'
|
||||
required: false
|
||||
|
||||
delete_remote_files:
|
||||
description: 'This operation will delete all files in the remote path before upload. Please be careful set this to true'
|
||||
required: false
|
||||
default: false
|
||||
password:
|
||||
description: "SSH passsword,If a password is set, the secret key pair is ignored"
|
||||
required: false
|
||||
rsyncArgs:
|
||||
description: "Additional arguments for the rsync command.
|
||||
You can use this parameter to customize the rsync behavior, such as excluding files or directories.
|
||||
Example: '--exclude=node_modules --exclude=.git --exclude=*.log'.
|
||||
If set, these arguments will be passed directly to the rsync command."
|
||||
required: false
|
||||
default: ""
|
||||
ssh_passphrase:
|
||||
description: "Passphrase for ssh encrypted private-key. If the private-key is not encrypted, this parameter is not required."
|
||||
required: false
|
||||
|
||||
runs:
|
||||
using: 'docker'
|
||||
@@ -39,7 +57,13 @@ runs:
|
||||
- ${{ inputs.ssh_private_key }}
|
||||
- ${{ inputs.local_path }}
|
||||
- ${{ inputs.remote_path }}
|
||||
- ${{ inputs.args }}
|
||||
- ${{ inputs.sftp_only }}
|
||||
- ${{ inputs.sftpArgs }}
|
||||
- ${{ inputs.delete_remote_files }}
|
||||
- ${{ inputs.password }}
|
||||
- ${{ inputs.rsyncArgs }}
|
||||
- ${{ inputs.ssh_passphrase }}
|
||||
|
||||
|
||||
branding:
|
||||
icon: 'upload-cloud'
|
||||
|
||||
+93
-9
@@ -3,28 +3,112 @@
|
||||
#set -e at the top of your script will make the script exit with an error whenever an error occurs (and is not explicitly handled)
|
||||
set -eu
|
||||
|
||||
|
||||
TEMP_SSH_PRIVATE_KEY_FILE='../private_key.pem'
|
||||
TEMP_SFTP_FILE='../sftp'
|
||||
|
||||
# 定义一个本地临时目录,用于 rsync 过滤后存放文件
|
||||
RSYNC_LOCAL_DEST="../filtered_upload"
|
||||
|
||||
RSYNC_ARGS="${11}"
|
||||
|
||||
# 如果用户“未”设置 exclude(EXCLUDE_PATTERNS 为空),则直接进入原逻辑
|
||||
if [ -z "$RSYNC_ARGS" ]; then
|
||||
echo "===> No rsync args provided, skip rsync filtering..."
|
||||
else
|
||||
echo "===> rsync args detected, start rsync filtering..."
|
||||
|
||||
# 先清理并创建该临时目录
|
||||
rm -rf "$RSYNC_LOCAL_DEST"
|
||||
mkdir -p "$RSYNC_LOCAL_DEST"
|
||||
|
||||
# 6) 打印完整的 rsync 命令,方便调试
|
||||
echo "===> rsync command: rsync -av $RSYNC_ARGS $5 $RSYNC_LOCAL_DEST/"
|
||||
|
||||
# 执行 rsync 命令
|
||||
rsync -av $RSYNC_ARGS $5 $RSYNC_LOCAL_DEST/
|
||||
|
||||
# 将 $5 替换为过滤后的目录下的所有文件,这样后面原脚本里 put -r $5 $6 就无需改动其他地方
|
||||
set -- "$1" "$2" "$3" "$4" "$RSYNC_LOCAL_DEST/*" "$6" "$7" "$8" "$9" "${10}"
|
||||
|
||||
echo "===> Done rsync filtering. Continue original script..."
|
||||
fi
|
||||
|
||||
# make sure remote path is not empty
|
||||
if [ -z "$6" ]; then
|
||||
echo 'remote_path is empty'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# use password
|
||||
if [ -n "${10}" ]; then
|
||||
echo 'use sshpass'
|
||||
|
||||
if test $9 == "true";then
|
||||
echo 'Start delete remote files'
|
||||
sshpass -p ${10} ssh -o StrictHostKeyChecking=no -p $3 $1@$2 rm -rf $6
|
||||
fi
|
||||
if test $7 = "true"; then
|
||||
echo "Connection via sftp protocol only, skip the command to create a directory"
|
||||
else
|
||||
echo 'Create directory if needed'
|
||||
sshpass -p ${10} ssh -o StrictHostKeyChecking=no -p $3 $1@$2 mkdir -p $6
|
||||
fi
|
||||
|
||||
echo 'SFTP Start'
|
||||
# create a temporary file containing sftp commands
|
||||
printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
|
||||
#-o StrictHostKeyChecking=no avoid Host key verification failed.
|
||||
SSHPASS=${10} sshpass -e sftp -oBatchMode=no -b $TEMP_SFTP_FILE -P $3 $8 -o StrictHostKeyChecking=no $1@$2
|
||||
|
||||
echo 'Deploy Success'
|
||||
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# keep string format
|
||||
printf "%s" "$4" >$TEMP_SSH_PRIVATE_KEY_FILE
|
||||
# avoid Permissions too open
|
||||
chmod 600 $TEMP_SSH_PRIVATE_KEY_FILE
|
||||
|
||||
echo 'ssh start'
|
||||
# delete remote files if needed
|
||||
if test $9 == "true";then
|
||||
echo 'Start delete remote files'
|
||||
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2 rm -rf $6
|
||||
fi
|
||||
|
||||
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
|
||||
if test $7 = "true"; then
|
||||
echo "Connection via sftp protocol only, skip the command to create a directory"
|
||||
else
|
||||
echo 'Create directory if needed'
|
||||
ssh -o StrictHostKeyChecking=no -p $3 -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2 mkdir -p $6
|
||||
fi
|
||||
|
||||
# create directory if needed
|
||||
mkdir -p $6
|
||||
# check if passphrase is set, if yes decrypt the private key
|
||||
if [ -n "${12:-}" ]; then
|
||||
echo 'Use ssh-agent to decrypt private key with passphrase'
|
||||
# start ssh agent
|
||||
eval $(ssh-agent -s)
|
||||
# use expect for ssh passphrase encryption
|
||||
expect <<EOF
|
||||
spawn ssh-add $TEMP_SSH_PRIVATE_KEY_FILE
|
||||
expect "Enter passphrase"
|
||||
send "${12}\r"
|
||||
expect eof
|
||||
EOF
|
||||
fi
|
||||
|
||||
echo 'sftp start'
|
||||
echo 'SFTP Start'
|
||||
# create a temporary file containing sftp commands
|
||||
printf "%s" "put -r $5 $6" >$TEMP_SFTP_FILE
|
||||
#-o StrictHostKeyChecking=no avoid Host key verification failed.
|
||||
sftp -b $TEMP_SFTP_FILE -P $3 $7 -o StrictHostKeyChecking=no -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
|
||||
sftp -b $TEMP_SFTP_FILE -P $3 $8 -o StrictHostKeyChecking=no -i $TEMP_SSH_PRIVATE_KEY_FILE $1@$2
|
||||
|
||||
echo 'Deploy Success'
|
||||
# if passphrase is set stop ssh-agent after sftp connection
|
||||
if [ -n "${12:-}" ]; then
|
||||
echo 'Clear keys from ssh-agent'
|
||||
# delete all keys from RAM
|
||||
ssh-add -D
|
||||
fi
|
||||
|
||||
echo 'deploy success'
|
||||
exit 0
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 54 KiB |
Reference in New Issue
Block a user