wip/static-publishing-13-kraftwerk
blog
Hugo source for the LibreTECH blog with the Pickles theme as a pinned submodule.
git clone --recurse-submodules https://git.librete.ch/public/blog.git
hugo server # local preview
Releases
The blog is published as an immutable release, never from a checkout. The
served tree contains only the built site and its release marker: no source,
.git, credentials or links outside the release.
delivery/build.shbuilds the checked-out commit with the pinned Hugo release (verified by SHA-256) and packages it deterministically asdelivery/.build/site.tar.gz. A rebuild of the same commit has the same digest.- Publish blog immutable package (
publish-blog.yml) runs on everymainpush. WithBLOG_PACKAGE_PUBLISH_ENABLED=true, the reviewedpackage_publishgate and theBLOG_PACKAGE_USER/BLOG_PACKAGE_TOKENsecrets, it publishespublic/blog-site/<revision>/to the Gitea package registry and prints thestacks.ymlcoordinate. - A reviewed pull request in
libretech/gitops-sandboxputs that coordinate in theblogrecord. Merging it dispatches Deploy blog immutable package (deploy-blog.yml). - The deploy workflow re-downloads and inspects the package, then streams it
to the site-scoped receiver on Netcup, which activates
/srv/libretech-static/blog/currentatomically and verifieshttps://blog.static.librete.ch/.well-known/release.json. A stale or re-run dispatch older than the live selection ends as superseded and changes nothing.
Rollback is a reviewed stacks.yml change back to an earlier complete
coordinate. See the
operations guide.
delivery/scripts/ is a copy of the receiver modules from
libretech/librete.ch (donatella/scripts/); update them together.
blog.librete.ch itself is still served from the earlier Uberspace in-place
build (publishDir in hugo.toml) until its DNS cut-over; the release
workflows override publishDir and never write there.
Languages
Markdown
100%