# Woodpecker CI: translate → build → deploy # # Triggered by the Gitea push webhook. The translate step replaces the old # synchronous WordPress save_post hook: publishing in Decap is one git commit, # translation happens here, asynchronously, and every generated sibling lands # as a reviewable bot commit. # # Translation is self-hosted — OPUS-MT runs on CPU inside the image, so there # is no API key and no third-party request. Before the first run, on the server: # bash scripts/fetch-models.sh # -> /srv/mt-models # docker build -t vienalatina/translate:2 docker/translate # # The models are mounted rather than baked in, so swapping them later does not # mean rebuilding the image. The repo must be marked "trusted" in Woodpecker # for this mount, which it already is for the deploy step. # # Secrets to configure in Woodpecker (repo settings → secrets): # gitea_push_token — Gitea token for the translations bot user # (translations@vienalatina.com) with repo write access # # The deploy step writes to the Caddy web root via a host mount, which # requires the repo to be marked "trusted" in Woodpecker. when: - event: push branch: main steps: translate: image: vienalatina/translate:2 pull: false # built locally on the server, never fetched from a registry volumes: - /srv/mt-models:/opt/mt/models:ro environment: GITEA_PUSH_TOKEN: from_secret: gitea_push_token commands: - python scripts/translate.py build: image: hugomods/hugo:0.135.0 commands: # Bundle Decap locally so the /admin page makes zero third-party requests. - wget -q -O static/admin/decap-cms.js https://unpkg.com/decap-cms@^3.0.0/dist/decap-cms.js # --printPathWarnings makes Hugo report two pages resolving to one output # path; --panicOnWarning turns that report into a failed build. Without # both, Hugo writes both documents into the same index.html and the site # ships a page that renders as the article followed by a second copy of # the whole site — with nothing in the CMS, the pipeline or the logs # saying a word about it. Better a red build than a corrupted page. - hugo --minify --printPathWarnings --panicOnWarning deploy: image: alpine:3.20 volumes: - /var/www/vienalatina.com:/deploy-target commands: - apk add --no-cache rsync - rsync -a --delete public/ /deploy-target/