This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
SPRING_PROFILES_ACTIVE=production
|
||||
SERVER_PORT=18080
|
||||
SERVER_ADDRESS=127.0.0.1
|
||||
SESSION_COOKIE_SECURE=false
|
||||
|
||||
DB_URL=jdbc:mysql://127.0.0.1:3307/kaidi_finance?useUnicode=true&characterEncoding=utf8&connectionTimeZone=UTC&serverTimezone=UTC
|
||||
|
||||
@@ -5,7 +5,7 @@ umask 077
|
||||
|
||||
ROOT=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)
|
||||
INSTALLER="$ROOT/deploy/install.sh"
|
||||
INSTALLER_SHA256=${KAIDI_INSTALLER_SHA256:-faf52cc902abbc2bd48571caee3f4207de50ce339b82ce88fe23f9c4ce8f89ef}
|
||||
INSTALLER_SHA256=${KAIDI_INSTALLER_SHA256:-cc9ae48fc3e36fbeb13b0660b0d91e59bd099a1386d49df699f214285c1afc0a}
|
||||
RELEASE_API_URL=${KAIDI_RELEASE_API_URL:-https://git.awaioi.com/api/v1/repos/ERP-Team/kaidi/releases/latest}
|
||||
PUBLIC_KEY_SHA256=${KAIDI_RELEASE_PUBLIC_KEY_SHA256:-807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9}
|
||||
TOKEN_FILE=${KAIDI_RELEASE_TOKEN_FILE:-}
|
||||
@@ -44,6 +44,8 @@ fi
|
||||
|
||||
KAIDI_REINSTALL=${KAIDI_REINSTALL:-}
|
||||
KAIDI_SETUP_WIZARD=${KAIDI_SETUP_WIZARD:-}
|
||||
KAIDI_APP_PORT=${KAIDI_APP_PORT:-}
|
||||
KAIDI_SERVER_ADDRESS=${KAIDI_SERVER_ADDRESS:-}
|
||||
KAIDI_DB_URL=${KAIDI_DB_URL:-}
|
||||
KAIDI_DB_USERNAME=${KAIDI_DB_USERNAME:-}
|
||||
KAIDI_DB_PASSWORD=${KAIDI_DB_PASSWORD:-}
|
||||
@@ -54,7 +56,8 @@ KAIDI_DB_CONTAINER=${KAIDI_DB_CONTAINER:-}
|
||||
KAIDI_SESSION_COOKIE_SECURE=${KAIDI_SESSION_COOKIE_SECURE:-}
|
||||
KAIDI_FILE_SCANNER_ENABLED=${KAIDI_FILE_SCANNER_ENABLED:-}
|
||||
|
||||
for name in KAIDI_REINSTALL KAIDI_SETUP_WIZARD KAIDI_DB_URL KAIDI_DB_USERNAME KAIDI_DB_PASSWORD \
|
||||
for name in KAIDI_REINSTALL KAIDI_SETUP_WIZARD KAIDI_APP_PORT KAIDI_SERVER_ADDRESS \
|
||||
KAIDI_DB_URL KAIDI_DB_USERNAME KAIDI_DB_PASSWORD \
|
||||
KAIDI_DB_HOST KAIDI_DB_PORT KAIDI_DB_NAME KAIDI_DB_CONTAINER \
|
||||
KAIDI_SESSION_COOKIE_SECURE KAIDI_FILE_SCANNER_ENABLED; do
|
||||
value=${!name}
|
||||
|
||||
+90
-26
@@ -11,7 +11,11 @@ RELEASE_BASE_URL=${KAIDI_RELEASE_BASE_URL:-}
|
||||
RELEASE_API_URL=${KAIDI_RELEASE_API_URL:-https://git.awaioi.com/api/v1/repos/ERP-Team/kaidi/releases/latest}
|
||||
RELEASE_TOKEN=${KAIDI_RELEASE_TOKEN:-}
|
||||
RELEASE_TOKEN_FILE=${KAIDI_RELEASE_TOKEN_FILE:-}
|
||||
HEALTH_URL=${KAIDI_HEALTH_URL:-http://127.0.0.1:18080/actuator/health}
|
||||
HEALTH_URL=${KAIDI_HEALTH_URL:-}
|
||||
APP_INDEX_URL=${KAIDI_APP_INDEX_URL:-}
|
||||
APP_PORT=${KAIDI_APP_PORT:-}
|
||||
SERVER_ADDRESS=${KAIDI_SERVER_ADDRESS:-127.0.0.1}
|
||||
PROXY_TARGET=
|
||||
TRUSTED_PUBLIC_KEY_SHA256=${KAIDI_RELEASE_PUBLIC_KEY_SHA256:-807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9}
|
||||
REINSTALL=${KAIDI_REINSTALL:-false}
|
||||
SETUP_WIZARD=${KAIDI_SETUP_WIZARD:-true}
|
||||
@@ -36,7 +40,7 @@ preflight_host() {
|
||||
[ "$(uname -s)" = Linux ] || die "The installer only supports Linux"
|
||||
[ "$APP_ROOT" = /opt/kaidi ] && [ "$STATE_ROOT" = /var/lib/kaidi ] \
|
||||
&& [ "$UPDATE_STATE_ROOT" = /var/lib/kaidi-update ] && [ "$CONFIG_ROOT" = /etc/kaidi ] \
|
||||
|| die "Custom installation roots are not supported by the packaged systemd and Nginx configuration"
|
||||
|| die "Custom installation roots are not supported by the packaged systemd configuration"
|
||||
command -v systemctl >/dev/null 2>&1 || die "systemd is required"
|
||||
[ -d /run/systemd/system ] || die "systemd is not running as PID 1"
|
||||
[ -d /etc/systemd/system ] || die "/etc/systemd/system is missing"
|
||||
@@ -148,11 +152,11 @@ install_packages() {
|
||||
if command -v apt-get >/dev/null 2>&1; then
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
apt-get update -qq
|
||||
apt-get install -y -qq ca-certificates coreutils curl findutils gzip jq openssl tar nginx util-linux default-mysql-client
|
||||
apt-get install -y -qq ca-certificates coreutils curl findutils gzip jq openssl tar util-linux default-mysql-client
|
||||
elif command -v dnf >/dev/null 2>&1; then
|
||||
dnf install -y ca-certificates coreutils curl findutils gzip jq openssl tar nginx util-linux mysql
|
||||
dnf install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux mysql
|
||||
elif command -v yum >/dev/null 2>&1; then
|
||||
yum install -y ca-certificates coreutils curl findutils gzip jq openssl tar nginx util-linux mysql
|
||||
yum install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux mysql
|
||||
else
|
||||
die "Supported package managers are apt, dnf, and yum"
|
||||
fi
|
||||
@@ -264,6 +268,72 @@ read_reinstall_env() {
|
||||
fi
|
||||
}
|
||||
|
||||
port_is_listening() {
|
||||
local port_hex files=(/proc/net/tcp)
|
||||
port_hex=$(printf '%04X' "$APP_PORT")
|
||||
[ -r /proc/net/tcp ] || return 1
|
||||
[ ! -r /proc/net/tcp6 ] || files+=(/proc/net/tcp6)
|
||||
awk -v port="$port_hex" '
|
||||
toupper($2) ~ (":" port "$") && $4 == "0A" { found=1 }
|
||||
END { exit(found ? 0 : 1) }
|
||||
' "${files[@]}" 2>/dev/null
|
||||
}
|
||||
|
||||
valid_app_port() {
|
||||
[[ "$1" =~ ^[0-9]{1,5}$ ]] && [ "$1" -ge 1024 ] && [ "$1" -le 65535 ]
|
||||
}
|
||||
|
||||
configure_app_port() {
|
||||
local default_port=18080 existing_port entered probe_host probe_authority
|
||||
if [ -z "$APP_PORT" ]; then
|
||||
default_port=$(read_reinstall_env SERVER_PORT || true)
|
||||
[[ "$default_port" =~ ^[0-9]{1,5}$ ]] || default_port=18080
|
||||
if [ -t 1 ] && [ -r /dev/tty ]; then
|
||||
printf '[kaidi-install] Application port [%s]: ' "$default_port" > /dev/tty
|
||||
if IFS= read -r entered < /dev/tty; then
|
||||
APP_PORT=${entered:-$default_port}
|
||||
else
|
||||
APP_PORT=$default_port
|
||||
fi
|
||||
else
|
||||
APP_PORT=$default_port
|
||||
log "No interactive terminal detected; using application port $APP_PORT"
|
||||
fi
|
||||
fi
|
||||
valid_app_port "$APP_PORT" \
|
||||
|| die "KAIDI_APP_PORT must be an integer between 1024 and 65535"
|
||||
case "$SERVER_ADDRESS" in
|
||||
''|*[!A-Za-z0-9_.:-]*) die "KAIDI_SERVER_ADDRESS contains unsupported characters" ;;
|
||||
esac
|
||||
if port_is_listening; then
|
||||
existing_port=$(read_existing_env SERVER_PORT || true)
|
||||
if [ "$REINSTALL" = true ] && [ "$existing_port" = "$APP_PORT" ] \
|
||||
&& systemctl is-active --quiet kaidi-finance.service; then
|
||||
log "Application port $APP_PORT is already held by the existing Kaidi service"
|
||||
else
|
||||
die "Application port $APP_PORT is already in use; choose another port with KAIDI_APP_PORT"
|
||||
fi
|
||||
fi
|
||||
probe_host=${KAIDI_HEALTH_HOST:-$SERVER_ADDRESS}
|
||||
case "$probe_host" in
|
||||
0.0.0.0) probe_host=127.0.0.1 ;;
|
||||
::) probe_host=::1 ;;
|
||||
esac
|
||||
case "$probe_host" in
|
||||
*:*) probe_authority="[$probe_host]" ;;
|
||||
*) probe_authority="$probe_host" ;;
|
||||
esac
|
||||
if [ -z "$HEALTH_URL" ]; then
|
||||
HEALTH_URL="http://${probe_authority}:${APP_PORT}/actuator/health"
|
||||
fi
|
||||
if [ -z "$APP_INDEX_URL" ]; then
|
||||
APP_INDEX_URL="http://${probe_authority}:${APP_PORT}/"
|
||||
fi
|
||||
PROXY_TARGET="http://${probe_authority}:${APP_PORT}"
|
||||
log "Application will bind ${SERVER_ADDRESS}:${APP_PORT}"
|
||||
log "Reverse proxy target: $PROXY_TARGET"
|
||||
}
|
||||
|
||||
is_semver() {
|
||||
[ "${#1}" -le 128 ] \
|
||||
&& LC_ALL=C grep -Eq '^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-(0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*)(\.(0|[1-9][0-9]*|[0-9]*[A-Za-z-][0-9A-Za-z-]*))*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$' \
|
||||
@@ -454,8 +524,6 @@ backup_managed_state() {
|
||||
/etc/systemd/system/kaidi-finance.service
|
||||
/etc/systemd/system/kaidi-update.service
|
||||
/etc/systemd/system/kaidi-update.path
|
||||
/etc/nginx/conf.d/kaidi-finance.conf
|
||||
/etc/nginx/sites-enabled/default
|
||||
)
|
||||
BACKUP_DIR="$WORK_DIR/rollback"
|
||||
mkdir -p "$BACKUP_DIR/files"
|
||||
@@ -470,8 +538,6 @@ backup_managed_state() {
|
||||
systemctl is-enabled --quiet kaidi-finance.service && PREVIOUS_APP_ENABLED=true || PREVIOUS_APP_ENABLED=false
|
||||
systemctl is-active --quiet kaidi-update.path && PREVIOUS_UPDATE_ACTIVE=true || PREVIOUS_UPDATE_ACTIVE=false
|
||||
systemctl is-enabled --quiet kaidi-update.path && PREVIOUS_UPDATE_ENABLED=true || PREVIOUS_UPDATE_ENABLED=false
|
||||
systemctl is-active --quiet nginx && PREVIOUS_NGINX_ACTIVE=true || PREVIOUS_NGINX_ACTIVE=false
|
||||
systemctl is-enabled --quiet nginx && PREVIOUS_NGINX_ENABLED=true || PREVIOUS_NGINX_ENABLED=false
|
||||
INSTALL_TRANSACTION_ARMED=true
|
||||
}
|
||||
|
||||
@@ -529,10 +595,6 @@ rollback_install() {
|
||||
|| rollback_failed=true
|
||||
restore_unit_state kaidi-update.path "$PREVIOUS_UPDATE_ENABLED" "$PREVIOUS_UPDATE_ACTIVE" \
|
||||
|| rollback_failed=true
|
||||
restore_unit_state nginx "$PREVIOUS_NGINX_ENABLED" "$PREVIOUS_NGINX_ACTIVE" || rollback_failed=true
|
||||
if [ "$PREVIOUS_NGINX_ACTIVE" = true ]; then
|
||||
nginx -t >/dev/null 2>&1 && systemctl reload nginx >/dev/null 2>&1 || rollback_failed=true
|
||||
fi
|
||||
set -e
|
||||
[ "$rollback_failed" = false ]
|
||||
}
|
||||
@@ -542,7 +604,7 @@ cleanup() {
|
||||
trap - EXIT
|
||||
if [ "$result" -ne 0 ] && [ "$INSTALL_TRANSACTION_ARMED" = true ] \
|
||||
&& [ "$INSTALL_COMMITTED" != true ]; then
|
||||
rollback_install || log "ERROR: rollback was incomplete; inspect systemd and Nginx state"
|
||||
rollback_install || log "ERROR: rollback was incomplete; inspect the managed systemd state"
|
||||
fi
|
||||
[ -z "$WORK_DIR" ] || rm -rf "$WORK_DIR"
|
||||
exit "$result"
|
||||
@@ -550,6 +612,7 @@ cleanup() {
|
||||
|
||||
trap cleanup EXIT
|
||||
|
||||
configure_app_port
|
||||
preflight_host
|
||||
install_packages
|
||||
|
||||
@@ -655,7 +718,8 @@ if [ "$SETUP_WIZARD" = true ]; then
|
||||
fi
|
||||
write_env_file_preserving_unknown "$CONFIG_ROOT/kaidi.env" \
|
||||
SPRING_PROFILES_ACTIVE production \
|
||||
SERVER_PORT 18080 \
|
||||
SERVER_PORT "$APP_PORT" \
|
||||
SERVER_ADDRESS "$SERVER_ADDRESS" \
|
||||
SESSION_COOKIE_SECURE "$SESSION_COOKIE_SECURE" \
|
||||
DB_URL "$DB_URL" \
|
||||
DB_USERNAME "$DB_USERNAME" \
|
||||
@@ -692,6 +756,7 @@ write_env_file "$CONFIG_ROOT/update.env" \
|
||||
KAIDI_UPDATE_STATE_ROOT "$UPDATE_STATE_ROOT" \
|
||||
KAIDI_SERVICE_NAME kaidi-finance.service \
|
||||
KAIDI_HEALTH_URL "$HEALTH_URL" \
|
||||
KAIDI_APP_INDEX_URL "$APP_INDEX_URL" \
|
||||
KAIDI_DB_CONTAINER "${KAIDI_DB_CONTAINER:-}" \
|
||||
KAIDI_DB_HOST "$(database_host)" \
|
||||
KAIDI_DB_PORT "$(database_port)" \
|
||||
@@ -703,17 +768,12 @@ chmod 0600 "$CONFIG_ROOT/update.env"
|
||||
install -m 0644 "$RELEASE_DIR/ops/kaidi-finance.service" /etc/systemd/system/kaidi-finance.service
|
||||
install -m 0644 "$RELEASE_DIR/ops/kaidi-update.service" /etc/systemd/system/kaidi-update.service
|
||||
install -m 0644 "$RELEASE_DIR/ops/kaidi-update.path" /etc/systemd/system/kaidi-update.path
|
||||
install -m 0644 "$RELEASE_DIR/ops/kaidi-finance.conf" /etc/nginx/conf.d/kaidi-finance.conf
|
||||
rm -f /etc/nginx/sites-enabled/default
|
||||
nginx -t
|
||||
systemctl daemon-reload
|
||||
systemctl enable kaidi-finance.service
|
||||
systemctl restart kaidi-finance.service
|
||||
wait_for_health
|
||||
systemctl enable --now nginx
|
||||
systemctl reload nginx
|
||||
curl -fsS http://127.0.0.1/actuator/health | jq -e '.status == "UP"' >/dev/null \
|
||||
|| die "Nginx proxy health check failed"
|
||||
curl -fsS "$APP_INDEX_URL" | grep -Eiq '<!doctype|<html' \
|
||||
|| die "Application frontend entry point is unavailable"
|
||||
|
||||
if [ "$SETUP_WIZARD" != true ]; then
|
||||
sed -i 's/^FINANCE_BOOTSTRAP_ENABLED="true"$/FINANCE_BOOTSTRAP_ENABLED="false"/' "$CONFIG_ROOT/kaidi.env"
|
||||
@@ -727,14 +787,16 @@ systemctl enable --now kaidi-update.path
|
||||
|
||||
if [ "$SETUP_WIZARD" = true ]; then
|
||||
cat > /root/kaidi-first-login.txt <<EOF
|
||||
URL: http://SERVER_IP/setup
|
||||
URL after reverse proxy: http://SERVER_IP/setup
|
||||
Reverse proxy target: $PROXY_TARGET
|
||||
Setup code: $SETUP_CODE
|
||||
Version: $VERSION
|
||||
EOF
|
||||
chmod 0600 /root/kaidi-first-login.txt
|
||||
elif [ "$REINSTALL" != true ]; then
|
||||
cat > /root/kaidi-first-login.txt <<EOF
|
||||
URL: http://SERVER_IP/
|
||||
URL after reverse proxy: http://SERVER_IP/
|
||||
Reverse proxy target: $PROXY_TARGET
|
||||
Username: admin
|
||||
Temporary password: $ADMIN_PASSWORD
|
||||
Version: $VERSION
|
||||
@@ -746,10 +808,12 @@ INSTALL_TRANSACTION_ARMED=false
|
||||
|
||||
log "Kaidi Finance $VERSION is installed"
|
||||
if [ "$SETUP_WIZARD" = true ]; then
|
||||
log "Open http://SERVER_IP/setup and complete the first-run wizard"
|
||||
log "Configure your reverse proxy to $PROXY_TARGET"
|
||||
log "Open /setup through your reverse-proxy domain and complete the first-run wizard"
|
||||
log "Setup code: /root/kaidi-first-login.txt"
|
||||
else
|
||||
log "Open http://SERVER_IP/ and sign in as admin"
|
||||
log "Configure your reverse proxy to $PROXY_TARGET"
|
||||
log "Open the reverse-proxy domain and sign in as admin"
|
||||
fi
|
||||
if [ "$REINSTALL" != true ] && [ "$SETUP_WIZARD" != true ]; then
|
||||
log "Temporary credentials: /root/kaidi-first-login.txt"
|
||||
|
||||
@@ -2,12 +2,11 @@ server {
|
||||
listen 80 default_server;
|
||||
listen [::]:80 default_server;
|
||||
server_name _;
|
||||
|
||||
root /opt/kaidi/current/public;
|
||||
index index.html;
|
||||
client_max_body_size 500m;
|
||||
|
||||
location /api/v1/ {
|
||||
# Optional example. The installer does not install or modify Nginx.
|
||||
# Replace 18080 with the KAIDI_APP_PORT selected during installation.
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:18080;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
@@ -17,24 +16,4 @@ server {
|
||||
proxy_connect_timeout 10s;
|
||||
proxy_read_timeout 120s;
|
||||
}
|
||||
|
||||
location = /actuator/health {
|
||||
proxy_pass http://127.0.0.1:18080;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
location / {
|
||||
try_files $uri $uri/ /index.html;
|
||||
add_header X-Content-Type-Options nosniff always;
|
||||
add_header Referrer-Policy same-origin always;
|
||||
add_header X-Frame-Options SAMEORIGIN always;
|
||||
}
|
||||
|
||||
location ~* \.(?:js|css|woff2?|png|jpe?g|gif|svg|ico)$ {
|
||||
try_files $uri =404;
|
||||
expires 7d;
|
||||
add_header Cache-Control "public, immutable";
|
||||
add_header X-Content-Type-Options nosniff always;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,5 +20,5 @@ IOSchedulingPriority=6
|
||||
PrivateTmp=true
|
||||
ProtectHome=true
|
||||
ProtectSystem=full
|
||||
ReadWritePaths=/opt/kaidi /var/lib/kaidi /var/lib/kaidi-update /var/log/kaidi /etc/systemd/system /etc/nginx/conf.d
|
||||
ReadWritePaths=/opt/kaidi /var/lib/kaidi /var/lib/kaidi-update /var/log/kaidi /etc/systemd/system
|
||||
UMask=0077
|
||||
|
||||
+9
-23
@@ -19,13 +19,11 @@ RELEASE_TOKEN=${UPDATE_RELEASE_TOKEN:-}
|
||||
CACHE_ROOT=${KAIDI_UPDATE_CACHE_ROOT:-$STATE_ROOT/cache}
|
||||
SERVICE_NAME=${KAIDI_SERVICE_NAME:-kaidi-finance.service}
|
||||
HEALTH_URL=${KAIDI_HEALTH_URL:-http://127.0.0.1:18080/actuator/health}
|
||||
PUBLIC_HEALTH_URL=${KAIDI_PUBLIC_HEALTH_URL:-http://127.0.0.1/actuator/health}
|
||||
PUBLIC_INDEX_URL=${KAIDI_PUBLIC_INDEX_URL:-http://127.0.0.1/}
|
||||
APP_INDEX_URL=${KAIDI_APP_INDEX_URL:-http://127.0.0.1:18080/}
|
||||
LOCK_FILE=$STATE_ROOT/update.lock
|
||||
BACKUP_ROOT=${KAIDI_BACKUP_ROOT:-$STATE_ROOT/backups}
|
||||
UPDATER_PATH=${KAIDI_UPDATER_PATH:-$APP_ROOT/bin/update.sh}
|
||||
SYSTEMD_ROOT=${KAIDI_SYSTEMD_ROOT:-/etc/systemd/system}
|
||||
NGINX_CONFIG=${KAIDI_NGINX_CONFIG:-/etc/nginx/conf.d/kaidi-finance.conf}
|
||||
LOG_ROOT=${KAIDI_LOG_ROOT:-/var/log/kaidi}
|
||||
HEALTH_ATTEMPTS=${KAIDI_UPDATE_HEALTH_ATTEMPTS:-60}
|
||||
HEALTH_INTERVAL_SECONDS=${KAIDI_UPDATE_HEALTH_INTERVAL_SECONDS:-2}
|
||||
@@ -161,10 +159,10 @@ wait_for_health() {
|
||||
return 1
|
||||
}
|
||||
|
||||
verify_public_surface() {
|
||||
wait_for_health "$PUBLIC_HEALTH_URL" || return 1
|
||||
verify_app_surface() {
|
||||
wait_for_health "$HEALTH_URL" || return 1
|
||||
index_file=$(mktemp "$STATE_ROOT/work/public-index.XXXXXX")
|
||||
if curl -fsS "$PUBLIC_INDEX_URL" -o "$index_file" \
|
||||
if curl -fsS "$APP_INDEX_URL" -o "$index_file" \
|
||||
&& grep -Eiq '<!doctype|<html' "$index_file"; then
|
||||
rm -f "$index_file"
|
||||
return 0
|
||||
@@ -266,8 +264,7 @@ backup_operations() {
|
||||
backup_managed_file "$UPDATER_PATH" update.sh \
|
||||
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-finance.service" kaidi-finance.service \
|
||||
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.service" kaidi-update.service \
|
||||
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path \
|
||||
&& backup_managed_file "$NGINX_CONFIG" kaidi-finance.conf
|
||||
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path
|
||||
}
|
||||
|
||||
apply_operations() {
|
||||
@@ -278,9 +275,7 @@ apply_operations() {
|
||||
"$SYSTEMD_ROOT/kaidi-update.service" 0644 \
|
||||
&& atomic_install "$RELEASE_DIR/ops/kaidi-update.path" \
|
||||
"$SYSTEMD_ROOT/kaidi-update.path" 0644 \
|
||||
&& atomic_install "$RELEASE_DIR/ops/kaidi-finance.conf" "$NGINX_CONFIG" 0644 \
|
||||
&& systemctl daemon-reload \
|
||||
&& nginx -t
|
||||
&& systemctl daemon-reload
|
||||
}
|
||||
|
||||
restore_operations() {
|
||||
@@ -289,13 +284,7 @@ restore_operations() {
|
||||
restore_managed_file "$SYSTEMD_ROOT/kaidi-finance.service" kaidi-finance.service || restore_failed=1
|
||||
restore_managed_file "$SYSTEMD_ROOT/kaidi-update.service" kaidi-update.service || restore_failed=1
|
||||
restore_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path || restore_failed=1
|
||||
restore_managed_file "$NGINX_CONFIG" kaidi-finance.conf || restore_failed=1
|
||||
systemctl daemon-reload || restore_failed=1
|
||||
if nginx -t; then
|
||||
systemctl reload nginx || restore_failed=1
|
||||
else
|
||||
restore_failed=1
|
||||
fi
|
||||
[ "$restore_failed" -eq 0 ]
|
||||
}
|
||||
|
||||
@@ -338,7 +327,7 @@ rollback_active_transaction() {
|
||||
fi
|
||||
restore_operations || rollback_ok=false
|
||||
systemctl start "$SERVICE_NAME" || rollback_ok=false
|
||||
if [ "$rollback_ok" = true ] && wait_for_health "$HEALTH_URL" && verify_public_surface; then
|
||||
if [ "$rollback_ok" = true ] && verify_app_surface; then
|
||||
remove_failed_release "$failed_release"
|
||||
rm -rf "$ACTIVE_TRANSACTION"
|
||||
fail "$reason; previous release was restored and verified"
|
||||
@@ -499,7 +488,6 @@ fi
|
||||
[ -s "$WORK_DIR/extracted/ops/kaidi-finance.service" ] || fail "Release application unit is missing"
|
||||
[ -s "$WORK_DIR/extracted/ops/kaidi-update.service" ] || fail "Release updater unit is missing"
|
||||
[ -s "$WORK_DIR/extracted/ops/kaidi-update.path" ] || fail "Release updater path unit is missing"
|
||||
[ -s "$WORK_DIR/extracted/ops/kaidi-finance.conf" ] || fail "Release Nginx configuration is missing"
|
||||
validate_release_operations || fail "Release operations validation failed"
|
||||
|
||||
if [ "$REQUEST_ACTION" = DOWNLOAD ]; then
|
||||
@@ -562,10 +550,8 @@ write_transaction_value phase APP_SWITCHED
|
||||
status RUNNING "Starting and verifying release $TARGET_VERSION" "$TARGET_VERSION"
|
||||
write_transaction_value phase HEALTH_CHECKING
|
||||
if systemctl start "$SERVICE_NAME" \
|
||||
&& wait_for_health "$HEALTH_URL" \
|
||||
&& systemctl reload nginx \
|
||||
&& systemctl is-active --quiet kaidi-update.path \
|
||||
&& verify_public_surface; then
|
||||
&& verify_app_surface; then
|
||||
write_transaction_value phase COMMITTED
|
||||
status SUCCEEDED "Release $TARGET_VERSION is running" "$TARGET_VERSION"
|
||||
TERMINAL_STATUS_WRITTEN=true
|
||||
@@ -574,4 +560,4 @@ if systemctl start "$SERVICE_NAME" \
|
||||
exit 0
|
||||
fi
|
||||
|
||||
rollback_active_transaction "Release health or public-surface verification failed"
|
||||
rollback_active_transaction "Release health or application-surface verification failed"
|
||||
|
||||
Reference in New Issue
Block a user