|
|
|
@@ -146,7 +146,7 @@ jobs:
|
|
|
|
|
shell: sh
|
|
|
|
|
env:
|
|
|
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
|
|
|
run: "set +e\nif command -v git >/dev/null 2>&1; then\n if [ ! -d .git ]; then\n git init -q\n git config user.email \"ci@localhost\"\n git config user.name \"CI\"\n git add .\n git commit -q -m \"current\"\n REPO_URL=\"https://x-access-token:${GITHUB_TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git\"\n git remote add origin \"$REPO_URL\"\n fi\n git fetch origin main --depth=1 -q 2>/dev/null || echo \"WARN: cannot fetch main, will check all migrations\"\nelse\n echo \"WARN: git not available, will check all migrations\"\nfi\nexit 0\n"
|
|
|
|
|
run: "set -eu\nif command -v git >/dev/null 2>&1; then\n if [ ! -d .git ]; then\n git init -q\n git config user.email \"ci@localhost\"\n git config user.name \"CI\"\n git add .\n git commit -q -m \"current\"\n REPO_URL=\"https://x-access-token:${GITHUB_TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git\"\n git remote add origin \"$REPO_URL\"\n fi\n git fetch origin main --depth=1 -q 2>/dev/null || echo \"WARN: cannot fetch main, will check all migrations\"\nelse\n echo \"WARN: git not available, will check all migrations\"\nfi\n"
|
|
|
|
|
- name: Check migration safety
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu\nif git rev-parse origin/main >/dev/null 2>&1; then\n python3 scripts/check_migration_safety.py --allow-medium-risk --diff-against origin/main\nelse\n python3 scripts/check_migration_safety.py --allow-medium-risk\nfi\n"
|
|
|
|
@@ -448,20 +448,8 @@ jobs:
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push API image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-api:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/api-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/api.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"API image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
run: "set -eu\nREGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"\nIMAGE_NAME=\"xiaoxia-saas-api\"\nCACHE_REF=\"${REGISTRY}/api-cache:develop\"\n\nCACHE_FROM=\"type=registry,ref=${CACHE_REF},ignore-error=true\"\n\nif [ \"${CACHE_MODE}\" = \"read-write\" ]; then\n CACHE_TO=\"type=registry,ref=${CACHE_REF},mode=max\"\n echo \"Building API image with read-write cache...\"\n docker buildx build --build-arg APP_VERSION=\"${GITHUB_SHA}\" --cache-from \"${CACHE_FROM}\" --cache-to \"${CACHE_TO}\" -f infra/docker/api.Dockerfile -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\" --push .\nelse\n echo \"Building API image with read-only cache...\"\n docker buildx build --build-arg APP_VERSION=\"${GITHUB_SHA}\" --cache-from \"${CACHE_FROM}\" -f infra/docker/api.Dockerfile -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\" --push .\nfi\necho\
|
|
|
|
|
\ \"API image pushed: ${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\"\n"
|
|
|
|
|
- name: Job duration summary
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
@@ -522,20 +510,8 @@ echo \"API image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push Worker image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-worker:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/worker-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/worker.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"WORKER image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
run: "set -eu\nREGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"\nIMAGE_NAME=\"xiaoxia-saas-worker\"\nCACHE_REF=\"${REGISTRY}/worker-cache:develop\"\n\nCACHE_FROM=\"type=registry,ref=${CACHE_REF},ignore-error=true\"\n\nif [ \"${CACHE_MODE}\" = \"read-write\" ]; then\n CACHE_TO=\"type=registry,ref=${CACHE_REF},mode=min\"\n echo \"Building Worker image with read-write cache...\"\n docker buildx build --build-arg APP_VERSION=\"${GITHUB_SHA}\" --cache-from \"${CACHE_FROM}\" --cache-to \"${CACHE_TO}\" -f infra/docker/worker.Dockerfile -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\" --push .\nelse\n echo \"Building Worker image with read-only cache...\"\n docker buildx build --build-arg APP_VERSION=\"${GITHUB_SHA}\" --cache-from \"${CACHE_FROM}\" -f infra/docker/worker.Dockerfile -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\" --push \
|
|
|
|
|
\ .\nfi\necho \"Worker image pushed: ${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\"\n"
|
|
|
|
|
- name: Job duration summary
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
@@ -599,20 +575,8 @@ echo \"WORKER image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push Web image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-web:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/web-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/web.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"WEB image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
run: "set -eu\nREGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"\nIMAGE_NAME=\"xiaoxia-saas-web\"\nCACHE_REF=\"${REGISTRY}/web-cache:develop\"\nNGINX_CONF=\"infra/docker/nginx-staging.conf\"\n\nCACHE_FROM=\"type=registry,ref=${CACHE_REF},ignore-error=true\"\n\nif [ \"${CACHE_MODE}\" = \"read-write\" ]; then\n CACHE_TO=\"type=registry,ref=${CACHE_REF},mode=max\"\n echo \"Building Web image with read-write cache...\"\n docker buildx build --cache-from \"${CACHE_FROM}\" --cache-to \"${CACHE_TO}\" -f infra/docker/web-artifact.Dockerfile --build-arg \"NGINX_CONF=${NGINX_CONF}\" -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\" --push .\nelse\n echo \"Building Web image with read-only cache...\"\n docker buildx build --cache-from \"${CACHE_FROM}\" -f infra/docker/web-artifact.Dockerfile --build-arg \"NGINX_CONF=${NGINX_CONF}\" -t \"${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\"\
|
|
|
|
|
\ --push .\nfi\necho \"Web image pushed: ${REGISTRY}/${IMAGE_NAME}:${GITHUB_SHA}\"\n"
|
|
|
|
|
- name: Job duration summary
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
@@ -861,20 +825,24 @@ echo \"WEB image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push API image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-api:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/api-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
run: 'set -eu
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/api.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
REGISTRY="git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"API image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
IMAGE_NAME="xiaoxia-saas-api"
|
|
|
|
|
|
|
|
|
|
VERSION="${GITHUB_REF_NAME}"
|
|
|
|
|
|
|
|
|
|
CACHE_REF="${REGISTRY}/api-cache:main"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
echo "Building Production API image: ${VERSION}"
|
|
|
|
|
|
|
|
|
|
docker buildx build --build-arg APP_VERSION="${VERSION}" --cache-from "type=registry,ref=${CACHE_REF},ignore-error=true" --cache-to "type=registry,ref=${CACHE_REF},mode=max" -f infra/docker/api.Dockerfile -t "${REGISTRY}/${IMAGE_NAME}:${VERSION}" --push .
|
|
|
|
|
|
|
|
|
|
echo "Production API image pushed: ${REGISTRY}/${IMAGE_NAME}:${VERSION}"
|
|
|
|
|
|
|
|
|
|
'
|
|
|
|
|
- name: Job duration summary
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
@@ -932,20 +900,24 @@ echo \"API image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push Worker image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-worker:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/worker-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
run: 'set -eu
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/worker.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
REGISTRY="git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"WORKER image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
IMAGE_NAME="xiaoxia-saas-worker"
|
|
|
|
|
|
|
|
|
|
VERSION="${GITHUB_REF_NAME}"
|
|
|
|
|
|
|
|
|
|
CACHE_REF="${REGISTRY}/worker-cache:main"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
echo "Building Production Worker image: ${VERSION}"
|
|
|
|
|
|
|
|
|
|
docker buildx build --build-arg APP_VERSION="${VERSION}" --cache-from "type=registry,ref=${CACHE_REF},ignore-error=true" --cache-to "type=registry,ref=${CACHE_REF},mode=min" -f infra/docker/worker.Dockerfile -t "${REGISTRY}/${IMAGE_NAME}:${VERSION}" --push .
|
|
|
|
|
|
|
|
|
|
echo "Production Worker image pushed: ${REGISTRY}/${IMAGE_NAME}:${VERSION}"
|
|
|
|
|
|
|
|
|
|
'
|
|
|
|
|
- name: Job duration summary
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
@@ -1006,20 +978,26 @@ echo \"WORKER image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
run: "set -eu\n# 确保使用 docker-container driver 以支持 cache export 功能\nif ! docker buildx inspect ci-builder > /dev/null 2>&1; then\n docker buildx create --use --name ci-builder --driver docker-container\n echo \"Created ci-builder (docker-container driver)\"\nelse\n docker buildx use ci-builder\n echo \"Using existing ci-builder\"\nfi\ndocker buildx inspect --bootstrap\n"
|
|
|
|
|
- name: Build and push Web image (buildx cache)
|
|
|
|
|
shell: sh
|
|
|
|
|
run: "set -eu
|
|
|
|
|
REGISTRY=\"git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas\"
|
|
|
|
|
IMAGE_TAG=\"${REGISTRY}/xiaoxia-saas-web:${GITHUB_SHA}\"
|
|
|
|
|
CACHE_REF=\"${REGISTRY}/web-cache:${GITHUB_REF_NAME}\"
|
|
|
|
|
run: 'set -eu
|
|
|
|
|
|
|
|
|
|
bash scripts/ci/docker_build_push.sh \
|
|
|
|
|
infra/docker/web.Dockerfile \
|
|
|
|
|
\"${IMAGE_TAG}\" \
|
|
|
|
|
\"${CACHE_REF}\" \
|
|
|
|
|
APP_VERSION=\"${GITHUB_SHA}\"
|
|
|
|
|
REGISTRY="git.xiaoxiajianji.com/xiaoxia/xiaoxia-saas"
|
|
|
|
|
|
|
|
|
|
echo
|
|
|
|
|
echo \"WEB image pushed: ${IMAGE_TAG}\"
|
|
|
|
|
"
|
|
|
|
|
IMAGE_NAME="xiaoxia-saas-web"
|
|
|
|
|
|
|
|
|
|
VERSION="${GITHUB_REF_NAME}"
|
|
|
|
|
|
|
|
|
|
CACHE_REF="${REGISTRY}/web-cache:main"
|
|
|
|
|
|
|
|
|
|
NGINX_CONF="infra/docker/nginx-production.conf"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
echo "Building Production Web image: ${VERSION}"
|
|
|
|
|
|
|
|
|
|
docker buildx build --cache-from "type=registry,ref=${CACHE_REF},ignore-error=true" --cache-to "type=registry,ref=${CACHE_REF},mode=max" -f infra/docker/web-artifact.Dockerfile --build-arg "NGINX_CONF=${NGINX_CONF}" -t "${REGISTRY}/${IMAGE_NAME}:${VERSION}" --push .
|
|
|
|
|
|
|
|
|
|
echo "Production Web image pushed: ${REGISTRY}/${IMAGE_NAME}:${VERSION}"
|
|
|
|
|
|
|
|
|
|
'
|
|
|
|
|
- name: Cleanup old Docker images
|
|
|
|
|
if: always()
|
|
|
|
|
shell: sh
|
|
|
|
|