ci: 启用 main 分支自动发布
Plainleaf 自动发布 / release (push) Successful in 3m34s

Co-Authored-By: Codex <noreply@anthropic.com>
This commit is contained in:
2026-08-13 12:19:33 +08:00
co-authored by Codex
parent ad30966904
commit 87def9b8a6
4 changed files with 13 additions and 8 deletions
+4 -1
View File
@@ -1,11 +1,14 @@
name: Plainleaf 自动发布
on:
push:
branches:
- main
workflow_dispatch:
concurrency:
group: plainleaf-release
cancel-in-progress: true
cancel-in-progress: false
jobs:
release:
+2 -2
View File
@@ -1,7 +1,7 @@
# Plainleaf 极空间部署
Plainleaf 使用 Gitea Actions 自动发布。首次安装和验收期间从 Gitea Actions 页面
手动触发;验收完成后,代码推送到指定分支即可触发。NAS 上的专用 Runner 在隔离
Plainleaf 使用 Gitea Actions 自动发布。代码推送到 `main` 分支后会自动触发构建和
部署;也可以从 Gitea Actions 页面手动触发,用于发布失败后的重试。NAS 上的专用 Runner 在隔离
的 rootless Docker 中构建镜像,推送 `edge` 到 Gitea Registry,然后通过受限
SSH 密钥触发更新服务。不运行定时器,也不会轮询 Registry。
只有镜像 ID 变化时才会重建 `plainleaf` 容器,不会执行 `compose down`、Docker
+5 -2
View File
@@ -155,10 +155,13 @@ test("dedicated Actions runner is isolated from the NAS Docker daemon", () => {
);
});
test("release workflow never runs for pull requests or a generic runner label", () => {
test("release workflow runs for main pushes and manual retries only", () => {
expect(releaseWorkflow).not.toContain("pull_request:");
expect(releaseWorkflow).not.toContain("push:");
expect(releaseWorkflow).toContain("push:");
expect(releaseWorkflow).toContain("branches:");
expect(releaseWorkflow).toContain("- main");
expect(releaseWorkflow).not.toContain("runs-on: ubuntu-latest");
expect(releaseWorkflow).toContain("workflow_dispatch:");
expect(releaseWorkflow).toContain("cancel-in-progress: false");
expect(releaseWorkflow).not.toMatch(/GITEA_RUNNER_REGISTRATION_TOKEN:\s*\S+/);
});
+2 -3
View File
@@ -54,6 +54,5 @@ sudo ./install-runner.sh
工作流不会输出 Secret。镜像推送完成后,它使用固定 SSH host key 触发 NAS 上的
`plainleaf-update.service`;该服务只拉取并重建 Plainleaf,失败时自动回滚。
首次安装和验收完成前,发布工作流只允许在 Gitea Actions 页面手动触发。确认
Runner、Registry、NAS 更新服务和回滚流程均正常后,再启用指定分支的 `push`
触发。
当前发布工作流会在代码推送到 `main` 分支时自动运行。Gitea Actions 页面仍保留
手动触发入口,用于发布失败后的重试。