Skip to content

Commit f361921

Browse files
committed
chore(infra): 继承工作设施并适配 Tauri 项目(CI/发布链/git hooks/部署配置)
1 parent 158b3ff commit f361921

31 files changed

Lines changed: 3370 additions & 0 deletions

‎.env.example‎

Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
# ===========================================
2+
# 熵减 (Entropydecrease) 环境变量模板
3+
# ===========================================
4+
# 复制此文件为 .env 并填入实际值
5+
6+
# --- 前端 (client/) ---
7+
8+
# Supabase 认证(在 https://supabase.com 创建项目后获取)
9+
VITE_SUPABASE_URL=https://your-project-id.supabase.co
10+
VITE_SUPABASE_ANON_KEY=your-anon-key
11+
12+
# 后端服务地址
13+
VITE_API_BASE_URL=http://localhost:8080
14+
VITE_AI_GATEWAY_URL=http://localhost:8000
15+
VITE_API_HEALTH_URL=/api/health
16+
VITE_SYNC_SERVER_URL=http://localhost:8080
17+
18+
# --- 后端 (server/) ---
19+
20+
# 应用环境(development/production)
21+
APP_ENV=development
22+
23+
# AI 模型 API Key(在对应平台注册获取)
24+
# 通义千问:https://dashscope.aliyun.com
25+
QWEN_API_KEY=sk-your-qwen-api-key
26+
27+
# DeepSeek:https://platform.deepseek.com
28+
DEEPSEEK_API_KEY=sk-your-deepseek-key
29+
30+
# 智谱 GLM(可选,作为备选模型):https://open.bigmodel.cn
31+
GLM_API_KEY=sk-your-glm-api-key
32+
33+
# Gemini(可选,用于视频分析):https://aistudio.google.com/app/apikey
34+
GEMINI_API_KEY=your-gemini-api-key
35+
36+
# 数据库(Docker Compose 默认值,本地开发无需修改)
37+
DATABASE_URL=postgresql://keban:keban_dev@localhost:5432/keban
38+
REDIS_URL=redis://localhost:6379
39+
40+
# JWT 安全密钥(生产环境必须修改为随机字符串)
41+
JWT_SECRET=change-this-to-a-random-string-in-production
42+
43+
# Supabase JWT 公钥(从 Supabase Dashboard > Settings > API > JWT Settings 获取)
44+
# 用于后端服务验证前端 Supabase Auth 签发的 RS256 JWT
45+
SUPABASE_JWT_SECRET=
46+
47+
# Supabase 项目 URL(用于后端验证 JWT issuer)
48+
SUPABASE_URL=https://your-project-id.supabase.co
49+
50+
# Supabase 服务端密钥(Service Role Key,仅供服务端调用,禁止暴露给前端)
51+
SUPABASE_SERVICE_KEY=your-service-role-key
52+
53+
# Supabase JWT 签名算法(HS256/RS256/ES256)
54+
# SUPABASE_JWT_ALGORITHM=RS256
55+
56+
# 开发者白名单(AI 网关):逗号分隔的 Supabase user_id 或邮箱,
57+
# 命中的账号完全豁免平台配额(不限流/不限费用)并赋予 lifetime 最高身份,
58+
# 仅供开发者自测,切勿在生产环境加入普通用户。
59+
# DEV_USER_IDS=dev@example.com,uuid-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
60+
61+
# 服务端口
62+
SYNC_SERVICE_PORT=8080
63+
AI_GATEWAY_PORT=8000
64+
65+
# AI 网关预算控制(每日 token/费用上限,0=不限制)
66+
# BUDGET_DAILY_TOKEN_LIMIT=100000
67+
# BUDGET_DAILY_COST_LIMIT=10
68+
69+
# AI 网关开发降级模式(生产环境缺密钥时拒绝启动;仅开发环境可显式开启)
70+
# GATEWAY_ALLOW_DEV_AUTH=false
71+
72+
# OpenTelemetry 导出端点(可选,配置后网关上报 trace 到 OTLP Collector)
73+
# OTEL_EXPORTER_OTLP_ENDPOINT=http://localhost:4318
74+
75+
# 付费系统(面包多,可选——未配置时付费功能禁用)
76+
# PAYMENT_PROVIDER=mianbaoduo
77+
# PAYMENT_API_KEY=your-mianbaoduo-api-key
78+
# PAYMENT_API_SECRET=your-mianbaoduo-api-secret
79+
# PAYMENT_WEBHOOK_SECRET=your-webhook-secret
80+
# PAYMENT_API_BASE_URL=https://api.mianbaoduo.com
81+
# PAYMENT_TIMEOUT_MS=5000
82+
# PAYMENT_RETRY_COUNT=3
83+
84+
# --- 生产部署配置 ---
85+
86+
# CORS 允许的前端域名(多个用逗号分隔)
87+
# CORS_ORIGINS=https://entropydecrease.com,https://www.entropydecrease.com
88+
89+
# 前端 API 基础 URL(生产环境设置为后端服务域名)
90+
# VITE_API_BASE_URL=https://api.entropydecrease.com
91+
92+
# 日志级别(DEBUG/INFO/WARNING/ERROR)
93+
# LOG_LEVEL=INFO

‎.github/dependabot.yml‎

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# Dependabot 自动安全更新配置
2+
# 定期扫描项目各模块的依赖漏洞,自动发起 Pull Request 升级受影响的依赖版本。
3+
# 详见:https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
4+
5+
version: 2
6+
updates:
7+
# ─── 客户端 npm 依赖 ───
8+
# Electron + React 桌面客户端,依赖数量最多,每周扫描安全漏洞
9+
- package-ecosystem: "npm"
10+
directory: "/client"
11+
schedule:
12+
interval: "weekly" # 每周检查一次更新
13+
open-pull-requests-limit: 10 # 最多同时保持 10 个 PR,避免维护负担过重
14+
15+
# ─── 官网 npm 依赖 ───
16+
# Next.js 静态官网,依赖相对较少
17+
- package-ecosystem: "npm"
18+
directory: "/website"
19+
schedule:
20+
interval: "weekly"
21+
open-pull-requests-limit: 5
22+
23+
# ─── AI 网关 pip 依赖 ───
24+
# Python FastAPI 后端,负责多模型路由与 AI 调度
25+
- package-ecosystem: "pip"
26+
directory: "/server/ai-gateway"
27+
schedule:
28+
interval: "weekly"
29+
open-pull-requests-limit: 5
30+
31+
# ─── 同步服务 Go 依赖 ───
32+
# Go Gin 后端,负责数据同步与 WebSocket 通道
33+
- package-ecosystem: "gomod"
34+
directory: "/server/sync-service"
35+
schedule:
36+
interval: "weekly"
37+
open-pull-requests-limit: 5
38+
39+
# ─── GitHub Actions 依赖 ───
40+
# CI/CD 流水线中使用的第三方 Action 插件
41+
- package-ecosystem: "github-actions"
42+
directory: "/"
43+
schedule:
44+
interval: "weekly"
45+
open-pull-requests-limit: 5

‎.github/workflows/pr-check.yml‎

Lines changed: 102 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,102 @@
1+
name: PR Quality Check
2+
3+
on:
4+
pull_request:
5+
branches: [main, dev]
6+
push:
7+
branches: [dev]
8+
9+
jobs:
10+
# ===========================================================================
11+
# 路径变更检测 —— 决定哪些子项目需要执行检查
12+
# ===========================================================================
13+
changes:
14+
runs-on: ubuntu-latest
15+
timeout-minutes: 10
16+
permissions:
17+
contents: read
18+
pull-requests: read
19+
outputs:
20+
app-frontend: ${{ steps.filter.outputs.app-frontend }}
21+
app-rust: ${{ steps.filter.outputs.app-rust }}
22+
docs: ${{ steps.filter.outputs.docs }}
23+
steps:
24+
- uses: actions/checkout@v4
25+
- uses: dorny/paths-filter@v3
26+
id: filter
27+
with:
28+
filters: |
29+
app-frontend:
30+
- 'app/src/**'
31+
- 'app/package.json'
32+
- 'app/package-lock.json'
33+
- 'app/index.html'
34+
- 'app/vite.config.ts'
35+
- 'app/tsconfig*.json'
36+
app-rust:
37+
- 'app/src-tauri/**'
38+
- 'app/src-tauri/Cargo.lock'
39+
docs:
40+
- 'docs/**'
41+
- 'scripts/docs-check.mjs'
42+
- '.docscheckignore'
43+
44+
# ===========================================================================
45+
# App 前端 —— React + Vite + TypeScript
46+
# ===========================================================================
47+
app-frontend:
48+
needs: changes
49+
if: needs.changes.outputs.app-frontend == 'true'
50+
runs-on: ubuntu-latest
51+
timeout-minutes: 15
52+
steps:
53+
- uses: actions/checkout@v4
54+
- uses: actions/setup-node@v4
55+
with:
56+
node-version: 20
57+
cache: 'npm'
58+
cache-dependency-path: app/package-lock.json
59+
- run: cd app && npm ci
60+
- name: Typecheck
61+
run: cd app && npx tsc --noEmit
62+
- name: Build
63+
run: cd app && npm run build
64+
65+
# ===========================================================================
66+
# App Rust 后端 —— Tauri 主进程(含单测与 lint)
67+
# ===========================================================================
68+
app-rust:
69+
needs: changes
70+
if: needs.changes.outputs.app-rust == 'true'
71+
runs-on: ubuntu-latest
72+
timeout-minutes: 60
73+
steps:
74+
- uses: actions/checkout@v4
75+
- uses: dtolnay/rust-toolchain@stable
76+
with:
77+
components: clippy
78+
# sherpa-onnx 等 crate 编译耗时较长,启用 sccache 加速重复构建
79+
- name: Cache cargo registry
80+
uses: Swatinem/rust-cache@v2
81+
with:
82+
workspaces: app/src-tauri
83+
- name: Test
84+
run: cd app/src-tauri && cargo test
85+
- name: Lint (clippy)
86+
run: cd app/src-tauri && cargo clippy -- -D warnings
87+
88+
# ===========================================================================
89+
# Docs —— 文档体系一致性检查(链接/索引/命名)
90+
# ===========================================================================
91+
docs:
92+
needs: changes
93+
if: needs.changes.outputs.docs == 'true'
94+
runs-on: ubuntu-latest
95+
timeout-minutes: 10
96+
steps:
97+
- uses: actions/checkout@v4
98+
- uses: actions/setup-node@v4
99+
with:
100+
node-version: 20
101+
- name: Docs check
102+
run: node scripts/docs-check.mjs

0 commit comments

Comments
 (0)