From 3b182a07989b09a39cbf44fa8ed7817360c803db Mon Sep 17 00:00:00 2001 From: Frank Schwenk Date: Sun, 5 Jul 2026 16:26:38 +0200 Subject: [PATCH] fix: deploy hook git pull without writable global config Use git -c safe.directory instead of git config --global in the container; set HOME=/tmp for deploy-hook. Co-authored-by: Cursor --- compose.yml | 1 + hooks/deploy.sh | 11 +++++++---- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/compose.yml b/compose.yml index 74f58a8..f157ecf 100644 --- a/compose.yml +++ b/compose.yml @@ -24,6 +24,7 @@ services: - .:/repo - ./hooks:/etc/webhook:ro environment: + - HOME=/tmp - WEBHOOK_SECRET=${WEBHOOK_SECRET} - DEPLOY_GIT_TOKEN=${DEPLOY_GIT_TOKEN:-} - DEPLOY_BRANCH=${DEPLOY_BRANCH:-main} diff --git a/hooks/deploy.sh b/hooks/deploy.sh index 754e131..a4ffd5f 100755 --- a/hooks/deploy.sh +++ b/hooks/deploy.sh @@ -3,21 +3,24 @@ set -euo pipefail REPO_DIR="/repo" BRANCH="${DEPLOY_BRANCH:-main}" -REMOTE_URL="${DEPLOY_GIT_URL:-https://gitea.schwenk.online/froxxxy/playground.git}" if [ ! -d "${REPO_DIR}/.git" ]; then echo "Error: ${REPO_DIR} is not a git repository" exit 1 fi -git config --global --add safe.directory "${REPO_DIR}" cd "${REPO_DIR}" +# Container has no writable $HOME — avoid git config --global (//.gitconfig) +git_cmd() { + git -c "safe.directory=${REPO_DIR}" "$@" +} + if [ -n "${DEPLOY_GIT_TOKEN:-}" ]; then auth_url="https://oauth2:${DEPLOY_GIT_TOKEN}@gitea.schwenk.online/froxxxy/playground.git" - git pull "${auth_url}" "${BRANCH}" + git_cmd pull "${auth_url}" "${BRANCH}" else - git pull origin "${BRANCH}" + git_cmd pull origin "${BRANCH}" fi echo "Deploy pull completed for ${BRANCH}"