From 1a2d472b5c6375d0e76a24851fa5ea9439ed69e9 Mon Sep 17 00:00:00 2001 From: Qiufeng Date: Tue, 18 Aug 2026 20:14:45 +0800 Subject: [PATCH] fix deployment setup and release contract --- .gitea/workflows/release.yml | 6 +++--- README.md | 18 +++++++++--------- deploy/baota-init.sh | 4 ++-- deploy/env.production.example | 2 +- scripts/test-install-fixture.sh | 7 +++++-- 5 files changed, 20 insertions(+), 17 deletions(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 0f2f064..60fd383 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -10,9 +10,9 @@ permissions: jobs: release: - # Production releases use the repository's standard Linux runner label. - # A self-hosted act_runner must advertise ubuntu-latest before tagging. - runs-on: ubuntu-latest + # The release runner is an explicitly registered host label. Keeping the + # label stable avoids silently queueing when the server has no ubuntu VM. + runs-on: kaidi-release steps: - uses: actions/checkout@v4 with: diff --git a/README.md b/README.md index edef881..fd6c1fc 100644 --- a/README.md +++ b/README.md @@ -75,7 +75,7 @@ PostgreSQL 18 兼容工作继续冻结。 先在宝塔面板停止并删除当前错误的 Java 项目,再执行: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.40/install.sh | sudo env KAIDI_APP_PORT=18080 bash +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.41/install.sh | sudo env KAIDI_APP_PORT=18080 bash ``` 该命令只安装程序运行所需的 systemd 单元,自动创建 `kaidi` 用户并检测现有 Java 17(包括 @@ -88,9 +88,9 @@ curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-previe 随后执行一键清理: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.40/purge.sh \ +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.41/purge.sh \ -o /tmp/kaidi-purge.sh \ - && curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.40/SHA256SUMS \ + && curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.41/SHA256SUMS \ -o /tmp/kaidi-SHA256SUMS \ && (cd /tmp && grep ' purge.sh$' kaidi-SHA256SUMS | sha256sum -c -) \ && sudo env KAIDI_PURGE_CONFIRM=DELETE_LOCAL_KAIDI_INSTALLATION bash /tmp/kaidi-purge.sh \ @@ -110,9 +110,9 @@ Spring Boot 项目。数据库、JDK、Nginx 和宝塔本身都由运维人员 下载地址: -`https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.40/kaidi-finance-1.0.0-preview.40.tar.gz` +`https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.41/kaidi-finance-1.0.0-preview.41.tar.gz` -校验文件:`https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.40/SHA256SUMS` +校验文件:`https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.41/SHA256SUMS` 服务器要求:Linux + systemd、Java 17(宝塔项目选择 JDK 17)、可访问外部 MySQL 8.4.x;32 位 Linux 需要宿主机 已经提供可运行的 32 位 Java 17。程序只连接已有数据库,不安装数据库客户端或数据库服务。初始化只需要 @@ -127,7 +127,7 @@ Spring Boot 项目。数据库、JDK、Nginx 和宝塔本身都由运维人员 必须直接位于 `RELEASE_ROOT`,不能再嵌套一层目录。 ```bash -VERSION=1.0.0-preview.40 +VERSION=1.0.0-preview.41 APP_ROOT=/www/wwwroot/kaidi RELEASE_ROOT="$APP_ROOT/releases/$VERSION" sudo install -d -m 0755 "$RELEASE_ROOT" @@ -261,8 +261,8 @@ Actions 页面显示 “No matching online runner”,先启动并注册该标 Preview 属性由 SemVer 版本名表达。之后推送 tag 即会构建、测试、签名并发布: ```bash -git tag v1.0.0-preview.40 -git push origin v1.0.0-preview.40 +git tag v1.0.0-preview.41 +git push origin v1.0.0-preview.41 ``` 在线更新仍使用独立的 TDesign 页面:系统管理员进入“系统治理 → 系统更新”。更新源由 root 在 @@ -314,7 +314,7 @@ cat /var/lib/kaidi-update/status.json ```bash KAIDI_RELEASE_SIGNING_KEY=/secure/release-signing-private.pem \ KAIDI_TRUSTED_RELEASE_PUBLIC_KEY_SHA256=807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9 \ - ./scripts/package-release.sh 1.0.0-preview.40 + ./scripts/package-release.sh 1.0.0-preview.41 KAIDI_TRUSTED_RELEASE_PUBLIC_KEY_SHA256=807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9 \ ./scripts/verify-release.sh dist/release ``` diff --git a/deploy/baota-init.sh b/deploy/baota-init.sh index c1cd378..79175a4 100755 --- a/deploy/baota-init.sh +++ b/deploy/baota-init.sh @@ -157,13 +157,13 @@ main() { # The Baota process manager does not own a restartable application unit. # Keep its updater files for diagnostics, but do not expose online update # actions until the panel lifecycle is integrated with the transaction state machine. + # The setup context has no datasource. Empty values avoid Baota treating + # a development placeholder as a real local MySQL dependency. write_env_file "$CONFIG_ROOT/kaidi.env" \ SPRING_PROFILES_ACTIVE production \ SERVER_ADDRESS 127.0.0.1 \ SERVER_PORT "$app_port" \ SESSION_COOKIE_SECURE false \ - # The setup context has no datasource. Empty values avoid Baota treating - # a development placeholder as a real local MySQL dependency. DB_URL '' \ DB_USERNAME '' \ DB_PASSWORD '' \ diff --git a/deploy/env.production.example b/deploy/env.production.example index 1053397..33210f4 100644 --- a/deploy/env.production.example +++ b/deploy/env.production.example @@ -15,7 +15,7 @@ FILE_SCANNER_ENABLED=true FINANCE_BOOTSTRAP_ENABLED=false FINANCE_BOOTSTRAP_PASSWORD= -APP_VERSION=1.0.0-preview.34 +APP_VERSION=1.0.0-preview.41 UPDATE_CURRENT_VERSION_FILE=/opt/kaidi/current/VERSION FINANCE_UPDATE_ENABLED=true # Use either a stable direct asset base URL or the public Gitea latest-release API. diff --git a/scripts/test-install-fixture.sh b/scripts/test-install-fixture.sh index a987286..1bf61b7 100755 --- a/scripts/test-install-fixture.sh +++ b/scripts/test-install-fixture.sh @@ -447,8 +447,11 @@ grep -Fq 'load_runtime_database_env' "$ROOT/deploy/update.sh" \ # shellcheck disable=SC2016 # Match literal installer source. grep -Fq 'install -d -o root -g "$SERVICE_GROUP" -m 0750 "$UPDATE_STATE_ROOT"' "$ROOT/deploy/install.sh" \ || fail 'update state parent is not group-accessible to the application user' -grep -Fq 'kaidi-finance-1.0.0-preview.34.tar.gz' "$ROOT/README.md" \ - || fail 'README does not document the public manual-deployment artifact' +manual_version=$(sed -n 's/^VERSION=\(1\.0\.0-preview\.[0-9][0-9]*\)$/\1/p' "$ROOT/README.md" | sed -n '1p') +[ -n "$manual_version" ] \ + || fail 'README does not declare a preview version for the public manual-deployment artifact' +grep -Fq "kaidi-finance-$manual_version.tar.gz" "$ROOT/README.md" \ + || fail 'README does not document the public manual-deployment artifact for its declared version' grep -Fq 'ops/baota-init.sh' "$ROOT/README.md" \ || fail 'README does not document the local Baota initialization command' grep -Fq 'FINANCE_UPDATE_ENABLED false' "$ROOT/deploy/baota-init.sh" \