feat: make reverse proxy operator-managed
Release / release (push) Failing after 10s

This commit is contained in:
Qiufeng
2026-08-17 16:24:32 +08:00
parent aed561c702
commit 7394c9e7e4
20 changed files with 358 additions and 124 deletions
+9 -23
View File
@@ -19,13 +19,11 @@ RELEASE_TOKEN=${UPDATE_RELEASE_TOKEN:-}
CACHE_ROOT=${KAIDI_UPDATE_CACHE_ROOT:-$STATE_ROOT/cache}
SERVICE_NAME=${KAIDI_SERVICE_NAME:-kaidi-finance.service}
HEALTH_URL=${KAIDI_HEALTH_URL:-http://127.0.0.1:18080/actuator/health}
PUBLIC_HEALTH_URL=${KAIDI_PUBLIC_HEALTH_URL:-http://127.0.0.1/actuator/health}
PUBLIC_INDEX_URL=${KAIDI_PUBLIC_INDEX_URL:-http://127.0.0.1/}
APP_INDEX_URL=${KAIDI_APP_INDEX_URL:-http://127.0.0.1:18080/}
LOCK_FILE=$STATE_ROOT/update.lock
BACKUP_ROOT=${KAIDI_BACKUP_ROOT:-$STATE_ROOT/backups}
UPDATER_PATH=${KAIDI_UPDATER_PATH:-$APP_ROOT/bin/update.sh}
SYSTEMD_ROOT=${KAIDI_SYSTEMD_ROOT:-/etc/systemd/system}
NGINX_CONFIG=${KAIDI_NGINX_CONFIG:-/etc/nginx/conf.d/kaidi-finance.conf}
LOG_ROOT=${KAIDI_LOG_ROOT:-/var/log/kaidi}
HEALTH_ATTEMPTS=${KAIDI_UPDATE_HEALTH_ATTEMPTS:-60}
HEALTH_INTERVAL_SECONDS=${KAIDI_UPDATE_HEALTH_INTERVAL_SECONDS:-2}
@@ -161,10 +159,10 @@ wait_for_health() {
return 1
}
verify_public_surface() {
wait_for_health "$PUBLIC_HEALTH_URL" || return 1
verify_app_surface() {
wait_for_health "$HEALTH_URL" || return 1
index_file=$(mktemp "$STATE_ROOT/work/public-index.XXXXXX")
if curl -fsS "$PUBLIC_INDEX_URL" -o "$index_file" \
if curl -fsS "$APP_INDEX_URL" -o "$index_file" \
&& grep -Eiq '<!doctype|<html' "$index_file"; then
rm -f "$index_file"
return 0
@@ -266,8 +264,7 @@ backup_operations() {
backup_managed_file "$UPDATER_PATH" update.sh \
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-finance.service" kaidi-finance.service \
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.service" kaidi-update.service \
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path \
&& backup_managed_file "$NGINX_CONFIG" kaidi-finance.conf
&& backup_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path
}
apply_operations() {
@@ -278,9 +275,7 @@ apply_operations() {
"$SYSTEMD_ROOT/kaidi-update.service" 0644 \
&& atomic_install "$RELEASE_DIR/ops/kaidi-update.path" \
"$SYSTEMD_ROOT/kaidi-update.path" 0644 \
&& atomic_install "$RELEASE_DIR/ops/kaidi-finance.conf" "$NGINX_CONFIG" 0644 \
&& systemctl daemon-reload \
&& nginx -t
&& systemctl daemon-reload
}
restore_operations() {
@@ -289,13 +284,7 @@ restore_operations() {
restore_managed_file "$SYSTEMD_ROOT/kaidi-finance.service" kaidi-finance.service || restore_failed=1
restore_managed_file "$SYSTEMD_ROOT/kaidi-update.service" kaidi-update.service || restore_failed=1
restore_managed_file "$SYSTEMD_ROOT/kaidi-update.path" kaidi-update.path || restore_failed=1
restore_managed_file "$NGINX_CONFIG" kaidi-finance.conf || restore_failed=1
systemctl daemon-reload || restore_failed=1
if nginx -t; then
systemctl reload nginx || restore_failed=1
else
restore_failed=1
fi
[ "$restore_failed" -eq 0 ]
}
@@ -338,7 +327,7 @@ rollback_active_transaction() {
fi
restore_operations || rollback_ok=false
systemctl start "$SERVICE_NAME" || rollback_ok=false
if [ "$rollback_ok" = true ] && wait_for_health "$HEALTH_URL" && verify_public_surface; then
if [ "$rollback_ok" = true ] && verify_app_surface; then
remove_failed_release "$failed_release"
rm -rf "$ACTIVE_TRANSACTION"
fail "$reason; previous release was restored and verified"
@@ -499,7 +488,6 @@ fi
[ -s "$WORK_DIR/extracted/ops/kaidi-finance.service" ] || fail "Release application unit is missing"
[ -s "$WORK_DIR/extracted/ops/kaidi-update.service" ] || fail "Release updater unit is missing"
[ -s "$WORK_DIR/extracted/ops/kaidi-update.path" ] || fail "Release updater path unit is missing"
[ -s "$WORK_DIR/extracted/ops/kaidi-finance.conf" ] || fail "Release Nginx configuration is missing"
validate_release_operations || fail "Release operations validation failed"
if [ "$REQUEST_ACTION" = DOWNLOAD ]; then
@@ -562,10 +550,8 @@ write_transaction_value phase APP_SWITCHED
status RUNNING "Starting and verifying release $TARGET_VERSION" "$TARGET_VERSION"
write_transaction_value phase HEALTH_CHECKING
if systemctl start "$SERVICE_NAME" \
&& wait_for_health "$HEALTH_URL" \
&& systemctl reload nginx \
&& systemctl is-active --quiet kaidi-update.path \
&& verify_public_surface; then
&& verify_app_surface; then
write_transaction_value phase COMMITTED
status SUCCEEDED "Release $TARGET_VERSION is running" "$TARGET_VERSION"
TERMINAL_STATUS_WRITTEN=true
@@ -574,4 +560,4 @@ if systemctl start "$SERVICE_NAME" \
exit 0
fi
rollback_active_transaction "Release health or public-surface verification failed"
rollback_active_transaction "Release health or application-surface verification failed"