Files
caddy-conf/scripts/webhook/caddy-deploy-webhook.service
Claudio b6dec2a894 Add deploy.sh + webhook receiver
deploy.sh runs on LXC 121: git pull, caddy validate, systemctl reload.
webhook.py is a small HTTP receiver on :9797/deploy that verifies the
gitea HMAC-SHA256 signature and triggers deploy.sh.
install.sh provisions /etc/caddy-deploy/secret and the systemd unit.
2026-04-20 17:10:15 +02:00

18 lines
321 B
Desktop File

[Unit]
Description=Caddy-conf deploy webhook
After=network.target caddy.service
[Service]
Type=simple
ExecStart=/usr/bin/python3 /etc/caddy/scripts/webhook/webhook.py
Restart=on-failure
RestartSec=2
User=root
ProtectSystem=full
ProtectHome=true
NoNewPrivileges=true
PrivateTmp=true
[Install]
WantedBy=multi-user.target