mirror of
https://github.com/jakejarvis/jarv.is.git
synced 2026-09-04 11:15:32 -04:00
Start switch to GitHub Pages and separate sub-repos
This commit is contained in:
@@ -1,50 +0,0 @@
|
|||||||
name: Deploy
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@master
|
|
||||||
with:
|
|
||||||
fetch-depth: 1
|
|
||||||
lfs: false
|
|
||||||
- uses: jakejarvis/hugo-build-action@develop-v0.53-DEV
|
|
||||||
- uses: actions/upload-artifact@master
|
|
||||||
with:
|
|
||||||
name: public
|
|
||||||
path: './public'
|
|
||||||
- uses: jakejarvis/s3-sync-action@master
|
|
||||||
with:
|
|
||||||
args: --acl public-read --delete --follow-symlinks
|
|
||||||
env:
|
|
||||||
SOURCE_DIR: './public'
|
|
||||||
AWS_REGION: 'us-east-1'
|
|
||||||
AWS_S3_BUCKET: 'jarv.is'
|
|
||||||
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
|
||||||
- uses: jakejarvis/cloudflare-serverless-action@master
|
|
||||||
env:
|
|
||||||
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
|
||||||
CLOUDFLARE_AUTH_EMAIL: ${{ secrets.CLOUDFLARE_EMAIL }}
|
|
||||||
CLOUDFLARE_AUTH_KEY: ${{ secrets.CLOUDFLARE_KEY }}
|
|
||||||
CLOUDFLARE_ZONE_ID: ${{ secrets.CLOUDFLARE_ZONE }}
|
|
||||||
CLOUDFLARE_WORKER_NAME: 'jarv-is'
|
|
||||||
CLOUDFLARE_SCRIPT_NAME: 'worker'
|
|
||||||
- uses: jakejarvis/cloudflare-purge-action@master
|
|
||||||
env:
|
|
||||||
CLOUDFLARE_ZONE: ${{ secrets.CLOUDFLARE_ZONE }}
|
|
||||||
CLOUDFLARE_EMAIL: ${{ secrets.CLOUDFLARE_EMAIL }}
|
|
||||||
CLOUDFLARE_KEY: ${{ secrets.CLOUDFLARE_KEY }}
|
|
||||||
- run: sleep 30s
|
|
||||||
- uses: jakejarvis/lighthouse-action@master
|
|
||||||
with:
|
|
||||||
url: 'https://jarv.is/'
|
|
||||||
- uses: actions/upload-artifact@master
|
|
||||||
with:
|
|
||||||
name: report
|
|
||||||
path: './report'
|
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
name: GitHub Pages
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@master
|
||||||
|
with:
|
||||||
|
fetch-depth: 1
|
||||||
|
lfs: false
|
||||||
|
- uses: jakejarvis/hugo-build-action@develop-v0.53-DEV
|
||||||
|
- uses: jakejarvis/github-pages-deploy-action@master
|
||||||
|
env:
|
||||||
|
PAGES_TOKEN: ${{ secrets.GITHUB_ACCESS_TOKEN }}
|
||||||
|
PAGES_CNAME: 'jarv.is'
|
||||||
|
PAGES_SOURCE_FOLDER: 'public'
|
||||||
|
PAGES_SOURCE_BRANCH: 'master'
|
||||||
|
PAGES_TARGET_BRANCH: 'master'
|
||||||
|
PAGES_TARGET_REPO: 'jakejarvis.github.io'
|
||||||
@@ -1,13 +1,12 @@
|
|||||||
# 🏡 [jarv.is](https://jarv.is/)
|
# 🏡 [jarv.is](https://jarv.is/)
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Personal website of [@jakejarvis](https://github.com/jakejarvis), created and deployed using the following:
|
Personal website of [@jakejarvis](https://github.com/jakejarvis), created and deployed using the following:
|
||||||
|
|
||||||
- [Hugo](https://github.com/gohugoio/hugo)
|
- [Hugo](https://github.com/gohugoio/hugo)
|
||||||
- [GitHub Actions](.github/workflows/deploy.yml)
|
- [GitHub Actions](.github/workflows)
|
||||||
- [Amazon S3](https://aws.amazon.com/s3/)
|
- [GitHub Pages](https://pages.github.com/)
|
||||||
- [Cloudflare Workers](worker.js)
|
|
||||||
- [Matomo Analytics](https://matomo.org/)
|
- [Matomo Analytics](https://matomo.org/)
|
||||||
|
|
||||||
I keep an ongoing list of [blog post ideas](https://github.com/jakejarvis/jarv.is/issues/1) as an issue in this repo.
|
I keep an ongoing list of [blog post ideas](https://github.com/jakejarvis/jarv.is/issues/1) as an issue in this repo.
|
||||||
|
|||||||
+1
-2
@@ -30,9 +30,8 @@
|
|||||||
# TECHNOLOGY
|
# TECHNOLOGY
|
||||||
|
|
||||||
Hugo
|
Hugo
|
||||||
Amazon S3
|
|
||||||
GitHub Actions
|
GitHub Actions
|
||||||
Cloudflare Workers
|
GitHub Pages
|
||||||
Matomo Analytics
|
Matomo Analytics
|
||||||
|
|
||||||
# VIEW SOURCE
|
# VIEW SOURCE
|
||||||
|
|||||||
@@ -1,117 +0,0 @@
|
|||||||
/**
|
|
||||||
* Cloudflare Worker to add security headers and remove S3 headers.
|
|
||||||
* https://jarv.is/notes/security-headers-cloudflare-workers/
|
|
||||||
*/
|
|
||||||
|
|
||||||
let addHeaders = {
|
|
||||||
"Content-Security-Policy": "default-src 'self'; script-src 'self' 'unsafe-inline' stats.jarv.is comments.jarv.is buttons.github.io platform.twitter.com cdn.syndication.twimg.com; style-src 'self' 'unsafe-inline' comments.jarv.is platform.twitter.com; img-src 'self' data: https:; font-src 'self' comments.jarv.is; object-src 'self'; media-src 'self'; base-uri 'self'; form-action 'self' platform.twitter.com syndication.twitter.com; frame-src 'self' www.youtube.com www.youtube-nocookie.com platform.twitter.com syndication.twitter.com buttons.github.io codepen.io; frame-ancestors 'self'; worker-src 'none'; connect-src 'self' csp.jarv.is jarvis.report-uri.com stats.jarv.is comments.jarv.is api.github.com syndication.twitter.com; upgrade-insecure-requests; report-uri https://csp.jarv.is/r/d/csp/enforce; report-to default",
|
|
||||||
"Report-To": "{\"group\":\"default\",\"max_age\":604800,\"endpoints\":[{\"url\":\"https://csp.jarv.is/a/d/g\"}]}",
|
|
||||||
"NEL": "{\"report_to\":\"default\",\"max_age\":604800}",
|
|
||||||
// "Strict-Transport-Security" : "max-age=1000",
|
|
||||||
"X-XSS-Protection": "1; mode=block; report=https://csp.jarv.is/r/d/xss/enforce",
|
|
||||||
"X-Frame-Options": "SAMEORIGIN",
|
|
||||||
"X-Content-Type-Options": "nosniff",
|
|
||||||
"Referrer-Policy": "same-origin",
|
|
||||||
"X-DNS-Prefetch-Control": "off",
|
|
||||||
"X-UA-Compatible": "IE=edge",
|
|
||||||
"X-Permitted-Cross-Domain-Policies": "none",
|
|
||||||
"Feature-Policy": "accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; sync-xhr 'none'; payment 'none'; usb 'none'; vr 'none'",
|
|
||||||
"X-Humans": "https://jarv.is/humans.txt",
|
|
||||||
"X-View-Source": "https://github.com/jakejarvis/jarv.is"
|
|
||||||
}
|
|
||||||
|
|
||||||
let removeHeaders = [
|
|
||||||
"Last-Modified",
|
|
||||||
"Expires",
|
|
||||||
"Public-Key-Pins",
|
|
||||||
"X-Powered-By",
|
|
||||||
"x-amz-request-id",
|
|
||||||
"x-amz-id-2",
|
|
||||||
"x-amz-bucket",
|
|
||||||
"x-amz-bucket-region",
|
|
||||||
"x-amz-error-code",
|
|
||||||
"x-amz-error-message",
|
|
||||||
"x-amz-error-detail-key",
|
|
||||||
"x-amz-version-id"
|
|
||||||
]
|
|
||||||
|
|
||||||
addEventListener("fetch", event => {
|
|
||||||
event.respondWith(fetchAndApply(event.request))
|
|
||||||
})
|
|
||||||
|
|
||||||
async function fetchAndApply(request) {
|
|
||||||
// Ignore POST and PUT HTTP requests.
|
|
||||||
// https://github.com/cloudflare/worker-examples/blob/master/examples/security/ingore-post-and-put.js
|
|
||||||
if (request.method === 'POST' || request.method === 'PUT') {
|
|
||||||
return new Response('Sorry, that method isn\'t allowed here.',
|
|
||||||
{ status: 403, statusText: 'Forbidden' })
|
|
||||||
}
|
|
||||||
|
|
||||||
// Fetch the original page from the origin
|
|
||||||
let response = await fetch(request)
|
|
||||||
|
|
||||||
// Make response headers mutable
|
|
||||||
response = new Response(response.body, response)
|
|
||||||
|
|
||||||
// Content-Type and Cache-Control headers based on file extension...
|
|
||||||
// ...because S3 sucks at guessing.
|
|
||||||
if(response.status === 200) {
|
|
||||||
let url = new URL(request.url)
|
|
||||||
|
|
||||||
// Content-Type
|
|
||||||
if (new RegExp(`\\.ico$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "image/x-icon")
|
|
||||||
else if (new RegExp(`\\.svg$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "image/svg+xml")
|
|
||||||
else if (new RegExp(`\\.ttf$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "font/ttf")
|
|
||||||
else if (new RegExp(`\\.otf$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "font/otf")
|
|
||||||
else if (new RegExp(`\\.eot$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "application/vnd.ms-fontobject")
|
|
||||||
else if (new RegExp(`\\.woff$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "font/woff")
|
|
||||||
else if (new RegExp(`\\.woff2$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "font/woff2")
|
|
||||||
else if (new RegExp(`\\.xml$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "text/xml")
|
|
||||||
else if (new RegExp(`\\.mp4$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "video/mp4")
|
|
||||||
else if (new RegExp(`\\.webm$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "video/webm")
|
|
||||||
else if (new RegExp(`\\.vtt$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "text/vtt")
|
|
||||||
else if (new RegExp(`\\.docx$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "application/vnd.openxmlformats-officedocument.wordprocessingml.document")
|
|
||||||
else if (new RegExp(`\\.pdf$`).test(url.pathname))
|
|
||||||
response.headers.set("Content-Type", "application/pdf")
|
|
||||||
|
|
||||||
// Cache-Control
|
|
||||||
if (new RegExp(`\\.(css|js|jpg|png|gif|svg|ico|mp4|webm|vtt|pdf)$`).test(url.pathname))
|
|
||||||
response.headers.set("Cache-Control", "max-age=604800, public")
|
|
||||||
else if (new RegExp(`\\.(ttf|otf|eot|woff|woff2)$`).test(url.pathname))
|
|
||||||
response.headers.set("Cache-Control", "max-age=2628000, public")
|
|
||||||
else
|
|
||||||
response.headers.set("Cache-Control", "max-age=3600, public")
|
|
||||||
|
|
||||||
// .asc exception
|
|
||||||
if (new RegExp(`\\.asc$`).test(url.pathname)) {
|
|
||||||
response.headers.set("Content-Type", "text/plain; charset=utf-8")
|
|
||||||
response.headers.set("Cache-Control", "max-age=0, no-store, no-cache, must-revalidate")
|
|
||||||
response.headers.set("Content-Disposition", "inline; filename=\"jarvis.asc\"")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Set each header in addHeaders
|
|
||||||
Object.keys(addHeaders).map(function(name, index) {
|
|
||||||
response.headers.set(name, addHeaders[name])
|
|
||||||
})
|
|
||||||
|
|
||||||
// Delete each header in removeHeaders
|
|
||||||
removeHeaders.forEach(function(name){
|
|
||||||
response.headers.delete(name)
|
|
||||||
})
|
|
||||||
|
|
||||||
// Return the new mutated page
|
|
||||||
return response
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user