diff --git a/.gitea/workflows/deploy-infrastructure.yml b/.gitea/workflows/deploy-infrastructure.yml index db7df59..85d1723 100644 --- a/.gitea/workflows/deploy-infrastructure.yml +++ b/.gitea/workflows/deploy-infrastructure.yml @@ -39,13 +39,27 @@ jobs: - name: Setup OpenTofu uses: opentofu/setup-opentofu@v1 - - name: Configure Git Auth for Private Modules + - name: Configure and Debug Authentication run: | - # Strip the protocol (https:// or http://) from the server URL - GITEA_HOST=$(echo "${{ gitea.server_url }}" | sed -e 's|^[^/]*//||') + echo "=== Debug: Variable Check ===" + echo "Raw Server URL: ${{ gitea.server_url }}" - # Tell Git to use the actor and token for any request matching your server - git config --global url."https://${{ gitea.actor }}:${{ secrets.GITEA_TOKEN }}@$GITEA_HOST/".insteadOf "${{ gitea.server_url }}/" + # Extract just the hostname (e.g., git.itlab-ffeks.dnu.edu.ua) + GITEA_HOST=$(echo "${{ gitea.server_url }}" | awk -F/ '{print $3}') + echo "Extracted Hostname: $GITEA_HOST" + + # Write it to .netrc (Git and cURL use this automatically for auth) + echo "machine $GITEA_HOST login ${{ gitea.actor }} password ${{ secrets.GITEA_TOKEN }}" > ~/.netrc + chmod 600 ~/.netrc + + echo "=== Debug: .netrc Check ===" + ls -la ~/.netrc + # Print the file contents but mask the password to avoid leaking it in logs + cat ~/.netrc | sed 's/password .*/password ****/' + + echo "=== Debug: Testing Git Connection directly ===" + # Try to reach the module repo directly using Git to see if auth works + git ls-remote "https://$GITEA_HOST/infrastructure/proxmox-vm.git" HEAD || echo "Git test failed, but continuing to see Tofu output..." - name: OpenTofu Init & Apply run: |