diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 012de80..2d9d0eb 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -50,3 +50,13 @@ jobs: - id: deployment uses: actions/deploy-pages@v4 + + - name: HTTP must redirect to HTTPS + run: | + for attempt in 1 2 3 4 5 6; do + location=$(curl -sI http://opentaberna.de/ | tr -d '\r' | awk 'tolower($1)=="location:"{print $2}') + [ "$location" = "https://opentaberna.de/" ] && exit 0 + sleep 10 + done + echo "http://opentaberna.de/ redirects to '${location}', expected https://opentaberna.de/" + exit 1 diff --git a/README.md b/README.md index 5401347..a03df3c 100644 --- a/README.md +++ b/README.md @@ -22,7 +22,8 @@ project-specific structural checks. Pushes to `main` run `.github/workflows/deploy.yml`. The workflow verifies the site before it uploads and deploys the GitHub Pages artifact. Pages must use **GitHub Actions** as its source, with the custom domain `opentaberna.de` and -**Enforce HTTPS** enabled. +**Enforce HTTPS** enabled. After each deploy the workflow checks that +`http://opentaberna.de/` redirects to HTTPS and fails if it does not. The repository's `CNAME` file is in place. The apex and `www` DNS records can therefore be added as documented in the project issue; the `wiki` subdomain is