105 lines
3.4 KiB
YAML
105 lines
3.4 KiB
YAML
name: Plainleaf 自动发布
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: plainleaf-release
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: plainleaf-release
|
|
timeout-minutes: 120
|
|
env:
|
|
REGISTRY_ENDPOINT: 192.168.31.68:8092
|
|
IMAGE_REPOSITORY: 192.168.31.68:8092/wushenghua/plainleaf
|
|
REGISTRY_USERNAME: wushenghua
|
|
steps:
|
|
- name: 检出代码
|
|
run: |
|
|
set -euo pipefail
|
|
gitea_url="${GITHUB_SERVER_URL:-https://gitea.aichickenfarm.cn}"
|
|
repository="${GITHUB_REPOSITORY:-wushenghua/plainleaf}"
|
|
git init .
|
|
git remote add origin "${gitea_url}/${repository}.git"
|
|
git fetch --no-tags --depth=1 origin "${GITHUB_SHA}"
|
|
git checkout --detach FETCH_HEAD
|
|
|
|
- name: 检查发布环境
|
|
run: |
|
|
set -euo pipefail
|
|
docker version
|
|
test -n "${REGISTRY_TOKEN}"
|
|
test -n "${NAS_DEPLOY_KEY}"
|
|
env:
|
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
|
NAS_DEPLOY_KEY: ${{ secrets.NAS_DEPLOY_KEY }}
|
|
|
|
- name: 登录 Gitea 镜像仓库
|
|
run: |
|
|
set -euo pipefail
|
|
printf '%s' "${REGISTRY_TOKEN}" | docker login \
|
|
"${REGISTRY_ENDPOINT}" \
|
|
--username "${REGISTRY_USERNAME}" \
|
|
--password-stdin
|
|
env:
|
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
|
|
|
- name: 构建并推送 amd64 镜像
|
|
run: |
|
|
set -euo pipefail
|
|
push_with_retry() {
|
|
local image="$1"
|
|
local attempt
|
|
for attempt in 1 2 3 4 5; do
|
|
if docker push "$image"; then
|
|
return 0
|
|
fi
|
|
if [[ "$attempt" -eq 5 ]]; then
|
|
echo "镜像推送连续失败 5 次:${image}" >&2
|
|
return 1
|
|
fi
|
|
delay=$((attempt * 10))
|
|
echo "镜像推送失败,${delay} 秒后重试(${attempt}/5):${image}" >&2
|
|
sleep "$delay"
|
|
done
|
|
}
|
|
short_sha="$(printf '%s' "${GITHUB_SHA}" | cut -c1-8)"
|
|
docker build \
|
|
--platform linux/amd64 \
|
|
--build-arg "GITHUB_SHA=${GITHUB_SHA}" \
|
|
--file Dockerfile.nas \
|
|
--tag "${IMAGE_REPOSITORY}:${short_sha}" \
|
|
--tag "${IMAGE_REPOSITORY}:edge" \
|
|
.
|
|
push_with_retry "${IMAGE_REPOSITORY}:${short_sha}"
|
|
push_with_retry "${IMAGE_REPOSITORY}:edge"
|
|
|
|
- name: 安全触发极空间更新
|
|
run: |
|
|
set -euo pipefail
|
|
install -d -m 0700 "${HOME}/.ssh"
|
|
install -m 0600 /dev/null "${HOME}/.ssh/plainleaf_deploy"
|
|
printf '%s\n' "${NAS_DEPLOY_KEY}" > "${HOME}/.ssh/plainleaf_deploy"
|
|
install -m 0600 deploy/nas/plainleaf_known_hosts "${HOME}/.ssh/known_hosts"
|
|
ssh \
|
|
-o BatchMode=yes \
|
|
-o IdentitiesOnly=yes \
|
|
-o StrictHostKeyChecking=yes \
|
|
-i "${HOME}/.ssh/plainleaf_deploy" \
|
|
-p 10000 \
|
|
13616066635@192.168.31.68 \
|
|
"sudo -n /usr/bin/systemctl start plainleaf-update.service"
|
|
env:
|
|
NAS_DEPLOY_KEY: ${{ secrets.NAS_DEPLOY_KEY }}
|
|
|
|
- name: 清理临时凭据
|
|
if: ${{ always() }}
|
|
run: |
|
|
rm -f "${HOME}/.ssh/plainleaf_deploy"
|
|
docker logout "${REGISTRY_ENDPOINT}" || true
|