#!/usr/bin/env bash set -euo pipefail # DC-056 legal-pages deploy. # # Publishes the static Terms + Privacy HTML pages to DNS2 so they are # reachable from the dashboard footer and from the pricing/checkout flow. # # Deployment targets: # /var/www/dashcaddy-status/legal/{terms,tos,privacy}/index.html # served at https://status.sami/legal/{terms,tos,privacy} # # A separate `legal.dashcaddy.net` subdomain is INTENTIONALLY NOT created # at v1.0 — it would need its own DNS record + Caddy vhost + LE cert, and # the status.sami/legal/... mount covers the launch requirement without # extra infra. Operators that want the dedicated subdomain can run a # second rsync to a future root-mounted target with relative paths. # # Verification curls status.sami/legal/{terms,tos,privacy} — not the # (not-yet-existing) legal.dashcaddy.net — so the post-deploy gate # matches the actually-served routes. DNS2_HOST="${DNS2_HOST:-root@100.121.150.22}" REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" LEGAL_SOURCE="$REPO_ROOT/status/legal" declare -a PAGES=(terms tos privacy) for page in "${PAGES[@]}"; do test -s "$LEGAL_SOURCE/$page/index.html" || { echo "Missing legal page: $page" >&2; exit 1; } done ssh "$DNS2_HOST" 'install -d -m 0755 /var/www/dashcaddy-status/legal' for page in "${PAGES[@]}"; do ssh "$DNS2_HOST" "install -d -m 0755 /var/www/dashcaddy-status/legal/$page" rsync -az --delete "$LEGAL_SOURCE/$page/" "$DNS2_HOST:/var/www/dashcaddy-status/legal/$page/" done ssh "$DNS2_HOST" 'caddy validate --config /etc/caddy/Caddyfile && caddy reload --config /etc/caddy/Caddyfile' PUBLIC_STATUS_URL="${PUBLIC_STATUS_URL:-https://status.sami}" # Page-specific markers so a misrouted Terms page doesn't pass for Privacy. # We use a temp file instead of `curl | grep -q` because grep -q exits early and # can trigger SIGPIPE under pipefail, producing false-positive verification # failures on otherwise-successful deploys (set -o pipefail amplifies this). declare -A PAGE_MARKERS=( [terms]="Terms of Service" [tos]="Terms of Service" # alias page content [privacy]="Privacy Policy" ) TMP_CURL_BODY="$(mktemp)" trap 'rm -f "$TMP_CURL_BODY"' EXIT for path in "${PAGES[@]}"; do marker="${PAGE_MARKERS[$path]}" if ! curl --fail --silent --show-error --location "${PUBLIC_STATUS_URL}/legal/${path}" -o "$TMP_CURL_BODY"; then echo "Post-deploy verification failed: ${PUBLIC_STATUS_URL}/legal/${path} (HTTP error)" >&2 exit 1 fi if ! grep -qF "${marker}" "$TMP_CURL_BODY"; then echo "Post-deploy verification failed: ${PUBLIC_STATUS_URL}/legal/${path} (expected '${marker}')" >&2 exit 1 fi done printf 'Legal pages deployed to status.sami/legal.\n'