Co-Authored-By: Codex <noreply@anthropic.com>
This commit is contained in:
@@ -1,11 +1,14 @@
|
|||||||
name: Plainleaf 自动发布
|
name: Plainleaf 自动发布
|
||||||
|
|
||||||
on:
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: plainleaf-release
|
group: plainleaf-release
|
||||||
cancel-in-progress: true
|
cancel-in-progress: false
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Plainleaf 极空间部署
|
# Plainleaf 极空间部署
|
||||||
|
|
||||||
Plainleaf 使用 Gitea Actions 自动发布。首次安装和验收期间从 Gitea Actions 页面
|
Plainleaf 使用 Gitea Actions 自动发布。代码推送到 `main` 分支后会自动触发构建和
|
||||||
手动触发;验收完成后,代码推送到指定分支即可触发。NAS 上的专用 Runner 在隔离
|
部署;也可以从 Gitea Actions 页面手动触发,用于发布失败后的重试。NAS 上的专用 Runner 在隔离
|
||||||
的 rootless Docker 中构建镜像,推送 `edge` 到 Gitea Registry,然后通过受限
|
的 rootless Docker 中构建镜像,推送 `edge` 到 Gitea Registry,然后通过受限
|
||||||
SSH 密钥触发更新服务。不运行定时器,也不会轮询 Registry。
|
SSH 密钥触发更新服务。不运行定时器,也不会轮询 Registry。
|
||||||
只有镜像 ID 变化时才会重建 `plainleaf` 容器,不会执行 `compose down`、Docker
|
只有镜像 ID 变化时才会重建 `plainleaf` 容器,不会执行 `compose down`、Docker
|
||||||
|
|||||||
@@ -155,10 +155,13 @@ test("dedicated Actions runner is isolated from the NAS Docker daemon", () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("release workflow never runs for pull requests or a generic runner label", () => {
|
test("release workflow runs for main pushes and manual retries only", () => {
|
||||||
expect(releaseWorkflow).not.toContain("pull_request:");
|
expect(releaseWorkflow).not.toContain("pull_request:");
|
||||||
expect(releaseWorkflow).not.toContain("push:");
|
expect(releaseWorkflow).toContain("push:");
|
||||||
|
expect(releaseWorkflow).toContain("branches:");
|
||||||
|
expect(releaseWorkflow).toContain("- main");
|
||||||
expect(releaseWorkflow).not.toContain("runs-on: ubuntu-latest");
|
expect(releaseWorkflow).not.toContain("runs-on: ubuntu-latest");
|
||||||
expect(releaseWorkflow).toContain("workflow_dispatch:");
|
expect(releaseWorkflow).toContain("workflow_dispatch:");
|
||||||
|
expect(releaseWorkflow).toContain("cancel-in-progress: false");
|
||||||
expect(releaseWorkflow).not.toMatch(/GITEA_RUNNER_REGISTRATION_TOKEN:\s*\S+/);
|
expect(releaseWorkflow).not.toMatch(/GITEA_RUNNER_REGISTRATION_TOKEN:\s*\S+/);
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -54,6 +54,5 @@ sudo ./install-runner.sh
|
|||||||
工作流不会输出 Secret。镜像推送完成后,它使用固定 SSH host key 触发 NAS 上的
|
工作流不会输出 Secret。镜像推送完成后,它使用固定 SSH host key 触发 NAS 上的
|
||||||
`plainleaf-update.service`;该服务只拉取并重建 Plainleaf,失败时自动回滚。
|
`plainleaf-update.service`;该服务只拉取并重建 Plainleaf,失败时自动回滚。
|
||||||
|
|
||||||
首次安装和验收完成前,发布工作流只允许在 Gitea Actions 页面手动触发。确认
|
当前发布工作流会在代码推送到 `main` 分支时自动运行。Gitea Actions 页面仍保留
|
||||||
Runner、Registry、NAS 更新服务和回滚流程均正常后,再启用指定分支的 `push`
|
手动触发入口,用于发布失败后的重试。
|
||||||
触发。
|
|
||||||
|
|||||||
Reference in New Issue
Block a user