Repository navigation
chore(merge): 合并 v0.41.0 发布提交 #30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy AI Gateway | |
| on: | |
| push: | |
| branches: [main] | |
| paths: ['server/**'] | |
| # 手动触发入口:用于部署链路验证与紧急重部署(不依赖路径变更) | |
| workflow_dispatch: | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # 部署前门禁(2026-08 审计 #11):server 变更直接部署前先跑完整测试, | |
| # 防止未验证代码上线(pr-check 只在 PR 流程生效,main 直推会绕过) | |
| - name: Gate - AI Gateway tests | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Run AI Gateway tests | |
| run: | | |
| cd server/ai-gateway | |
| pip install -r requirements.txt | |
| pip install ruff pytest pytest-asyncio httpx | |
| ruff check . | |
| pytest tests/ -q | |
| - name: Gate - Sync service tests | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: '1.25' | |
| - name: Run Sync service tests | |
| run: | | |
| cd server/sync-service | |
| go build ./... && go vet ./... && go test ./... -count=1 | |
| # 上传 server/ 源码到服务器(服务器非 git 仓库,代码由 CI 同步) | |
| # 注意:rm 必须为 false —— 服务器上的 .env.production 为真实生产密钥, | |
| # 不在仓库内(被 gitignore),删除目标目录会导致密钥永久丢失。 | |
| - name: Upload server sources | |
| uses: appleboy/scp-action@v0.1.7 | |
| with: | |
| host: ${{ secrets.SERVER_HOST }} | |
| username: ${{ secrets.SERVER_USER }} | |
| key: ${{ secrets.SSH_PRIVATE_KEY }} | |
| source: server/* | |
| target: /opt/Entropydecrease | |
| rm: false | |
| - name: Rebuild and restart services | |
| uses: appleboy/ssh-action@v1 | |
| with: | |
| host: ${{ secrets.SERVER_HOST }} | |
| username: ${{ secrets.SERVER_USER }} | |
| key: ${{ secrets.SSH_PRIVATE_KEY }} | |
| script: | | |
| set -e | |
| cd /opt/Entropydecrease/server | |
| # .env.production 含生产密钥,必须显式传入,否则 DB_PASSWORD 等会被解析为空串 | |
| COMPOSE="docker compose -f docker-compose.prod.yml --env-file .env.production" | |
| # 拉取第三方镜像(postgres/redis/nginx),自建服务由 --build 重新构建 | |
| $COMPOSE pull --ignore-buildable || true | |
| $COMPOSE up -d --build --force-recreate | |
| # 健康检查:失败时输出日志便于定位(docker compose 无 rollback 子命令, | |
| # 回滚由 revert 提交重新触发部署完成) | |
| sleep 15 | |
| if ! curl -fsS http://127.0.0.1:8000/health; then | |
| echo "::error::ai-gateway 健康检查失败,最近日志:" | |
| $COMPOSE logs --tail=60 ai-gateway | |
| exit 1 | |
| fi | |
| if ! curl -fsS http://127.0.0.1:8080/health; then | |
| echo "::error::sync-service 健康检查失败,最近日志:" | |
| $COMPOSE logs --tail=60 sync-service | |
| exit 1 | |
| fi | |
| echo "部署成功:ai-gateway 与 sync-service 健康检查通过" |