diff --git a/.gitea/workflows/plainleaf-release.yml b/.gitea/workflows/plainleaf-release.yml index b65342d5..6f35cfbd 100644 --- a/.gitea/workflows/plainleaf-release.yml +++ b/.gitea/workflows/plainleaf-release.yml @@ -1,11 +1,14 @@ name: Plainleaf 自动发布 on: + push: + branches: + - main workflow_dispatch: concurrency: group: plainleaf-release - cancel-in-progress: true + cancel-in-progress: false jobs: release: diff --git a/deploy/nas/README.md b/deploy/nas/README.md index f771ec2c..fc9faaf6 100644 --- a/deploy/nas/README.md +++ b/deploy/nas/README.md @@ -1,7 +1,7 @@ # Plainleaf 极空间部署 -Plainleaf 使用 Gitea Actions 自动发布。首次安装和验收期间从 Gitea Actions 页面 -手动触发;验收完成后,代码推送到指定分支即可触发。NAS 上的专用 Runner 在隔离 +Plainleaf 使用 Gitea Actions 自动发布。代码推送到 `main` 分支后会自动触发构建和 +部署;也可以从 Gitea Actions 页面手动触发,用于发布失败后的重试。NAS 上的专用 Runner 在隔离 的 rootless Docker 中构建镜像,推送 `edge` 到 Gitea Registry,然后通过受限 SSH 密钥触发更新服务。不运行定时器,也不会轮询 Registry。 只有镜像 ID 变化时才会重建 `plainleaf` 容器,不会执行 `compose down`、Docker diff --git a/deploy/nas/deployment.test.ts b/deploy/nas/deployment.test.ts index 0cb75e43..a45a5db6 100644 --- a/deploy/nas/deployment.test.ts +++ b/deploy/nas/deployment.test.ts @@ -155,10 +155,13 @@ test("dedicated Actions runner is isolated from the NAS Docker daemon", () => { ); }); -test("release workflow never runs for pull requests or a generic runner label", () => { +test("release workflow runs for main pushes and manual retries only", () => { expect(releaseWorkflow).not.toContain("pull_request:"); - expect(releaseWorkflow).not.toContain("push:"); + expect(releaseWorkflow).toContain("push:"); + expect(releaseWorkflow).toContain("branches:"); + expect(releaseWorkflow).toContain("- main"); expect(releaseWorkflow).not.toContain("runs-on: ubuntu-latest"); expect(releaseWorkflow).toContain("workflow_dispatch:"); + expect(releaseWorkflow).toContain("cancel-in-progress: false"); expect(releaseWorkflow).not.toMatch(/GITEA_RUNNER_REGISTRATION_TOKEN:\s*\S+/); }); diff --git a/deploy/runner/README.md b/deploy/runner/README.md index c68973a9..8b4cecc5 100644 --- a/deploy/runner/README.md +++ b/deploy/runner/README.md @@ -54,6 +54,5 @@ sudo ./install-runner.sh 工作流不会输出 Secret。镜像推送完成后,它使用固定 SSH host key 触发 NAS 上的 `plainleaf-update.service`;该服务只拉取并重建 Plainleaf,失败时自动回滚。 -首次安装和验收完成前,发布工作流只允许在 Gitea Actions 页面手动触发。确认 -Runner、Registry、NAS 更新服务和回滚流程均正常后,再启用指定分支的 `push` -触发。 +当前发布工作流会在代码推送到 `main` 分支时自动运行。Gitea Actions 页面仍保留 +手动触发入口,用于发布失败后的重试。