fix: support panel-managed deployment safely
Release / release (push) Canceled after 0s

This commit is contained in:
Qiufeng
2026-08-18 00:02:45 +08:00
parent c35ef3d383
commit 2c73ad7eb0
13 changed files with 265 additions and 22 deletions
+9 -7
View File
@@ -102,7 +102,7 @@ secure_release_tree() {
chown -R root:"$SERVICE_GROUP" "$release_dir" || return 1
find "$release_dir" -type d -exec chmod 0750 {} + || return 1
find "$release_dir" -type f -exec chmod 0640 {} + || return 1
chmod 0750 "$release_dir/ops/update.sh"
chmod 0750 "$release_dir/ops/update.sh" "$release_dir/ops/baota-start.sh"
}
verify_release_access() {
@@ -379,7 +379,6 @@ rollback_active_transaction() {
link_restored=true
operations_restored=true
systemctl stop "$SERVICE_NAME" || true
if [ -n "$previous_target" ] && [ -d "$previous_target" ]; then
if ! ln -sfn "$previous_target" "$APP_ROOT/current.next" \
|| ! mv -Tf "$APP_ROOT/current.next" "$APP_ROOT/current"; then
@@ -390,7 +389,7 @@ rollback_active_transaction() {
fi
restore_operations || operations_restored=false
systemctl reset-failed "$SERVICE_NAME" >/dev/null 2>&1 || true
systemctl start "$SERVICE_NAME" || true
systemctl restart "$SERVICE_NAME" || systemctl start "$SERVICE_NAME" || true
if [ "$link_restored" = true ] && verify_app_surface; then
remove_failed_release "$failed_release"
rm -rf "$ACTIVE_TRANSACTION"
@@ -400,8 +399,11 @@ rollback_active_transaction() {
fail "$reason; previous release is running, but operations restoration requires manual review"
fi
TERMINAL_STATUS_WRITTEN=true
status FAILED "$reason; rollback is incomplete and will be retried" "${TARGET_VERSION:-}"
printf '%s\n' "$reason; rollback is incomplete and will be retried" >&2
status FAILED "$reason; rollback is incomplete and manual recovery is required" "${TARGET_VERSION:-}"
if ! archive_processing_request; then
printf '%s\n' "Update request could not be archived after an incomplete rollback" >&2
fi
printf '%s\n' "$reason; rollback is incomplete and manual recovery is required" >&2
exit 1
}
@@ -427,6 +429,7 @@ recover_interrupted_transaction() {
validate_release_operations() {
sh -n "$WORK_DIR/extracted/ops/update.sh" || return 1
bash -n "$WORK_DIR/extracted/ops/baota-start.sh" || return 1
command -v systemd-analyze >/dev/null 2>&1 || return 1
systemd-analyze verify \
"$WORK_DIR/extracted/ops/kaidi-finance.service" \
@@ -613,7 +616,6 @@ apply_operations || rollback_active_transaction "Release operations files could
write_transaction_value phase OPS_APPLIED
write_transaction_value phase APP_SWITCHING
systemctl stop "$SERVICE_NAME" || rollback_active_transaction "Application service could not be stopped"
if ! ln -sfn "$RELEASE_DIR" "$APP_ROOT/current.next" \
|| ! mv -Tf "$APP_ROOT/current.next" "$APP_ROOT/current"; then
rollback_active_transaction "Release application link could not be activated"
@@ -623,7 +625,7 @@ write_transaction_value phase APP_SWITCHED
status RUNNING "Starting and verifying release $TARGET_VERSION" "$TARGET_VERSION"
write_transaction_value phase HEALTH_CHECKING
systemctl reset-failed "$SERVICE_NAME" >/dev/null 2>&1 || true
systemctl start "$SERVICE_NAME" || true
systemctl restart "$SERVICE_NAME" || systemctl start "$SERVICE_NAME" || true
if verify_app_surface; then
success_message="Release $TARGET_VERSION is running"
if ! systemctl start "$UPDATE_PATH_NAME" >/dev/null 2>&1; then