feat: make reverse proxy operator-managed
Release / release (push) Failing after 10s

This commit is contained in:
Qiufeng
2026-08-17 16:24:32 +08:00
parent aed561c702
commit 7394c9e7e4
20 changed files with 358 additions and 124 deletions
+1
View File
@@ -91,6 +91,7 @@ cp "$JAR" "$STAGE/app.jar"
cp -R "$ROOT/frontend/dist/." "$STAGE/public/"
printf '%s\n' "$VERSION" > "$STAGE/VERSION"
cp "$ROOT/deploy/update.sh" "$STAGE/ops/update.sh"
# Kept in the archive so Preview.9's updater can complete the one-time transition.
cp "$ROOT/deploy/nginx/kaidi-finance.conf" "$STAGE/ops/kaidi-finance.conf"
cp "$ROOT/deploy/systemd/kaidi-finance.service" "$STAGE/ops/kaidi-finance.service"
cp "$ROOT/deploy/systemd/kaidi-update.service" "$STAGE/ops/kaidi-update.service"
+7
View File
@@ -23,6 +23,10 @@ set -Eeuo pipefail
[ "$KAIDI_RELEASE_API_URL" = 'https://git.example.test/api/v1/repos/TEAM/REPO/releases/latest' ]
[ "$KAIDI_RELEASE_PUBLIC_KEY_SHA256" = 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa' ]
if [ "${EXPECT_PORT:-false}" = true ]; then
[ "$KAIDI_APP_PORT" = '19090' ]
[ "$KAIDI_SERVER_ADDRESS" = '127.0.0.1' ]
fi
if [ "${KAIDI_SETUP_WIZARD:-false}" = true ]; then
[ -z "${KAIDI_DB_URL:-}${KAIDI_DB_USERNAME:-}${KAIDI_DB_PASSWORD:-}" ]
else
@@ -44,9 +48,12 @@ chmod 0600 "$FIXTURE/token"
installer_sha256=$(sha256sum "$FIXTURE/repo/deploy/install.sh" | awk '{print $1}')
PATH="$FIXTURE/bin:$PATH" \
EXPECT_PORT=true \
KAIDI_INSTALLER_SHA256="$installer_sha256" \
KAIDI_RELEASE_API_URL=https://git.example.test/api/v1/repos/TEAM/REPO/releases/latest \
KAIDI_RELEASE_PUBLIC_KEY_SHA256=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \
KAIDI_APP_PORT=19090 \
KAIDI_SERVER_ADDRESS=127.0.0.1 \
KAIDI_DB_URL=jdbc:mysql://DB_HOST:3306/kaidi_finance \
KAIDI_DB_USERNAME=kaidi \
KAIDI_DB_PASSWORD=fixture-password \
+37 -1
View File
@@ -17,6 +17,9 @@ fail() {
sed -n '/^read_existing_env()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^read_setup_env()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^read_reinstall_env()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^port_is_listening()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^valid_app_port()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^configure_app_port()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^is_semver()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^write_env_file_preserving_unknown()/,/^}/p' "$ROOT/deploy/install.sh"
sed -n '/^azul_arch()/,/^}/p' "$ROOT/deploy/install.sh"
@@ -78,6 +81,31 @@ grep -qx 'jdbc:mysql://runtime/kaidi_finance' <(read_reinstall_env DB_URL) \
grep -qx 'runtime-user' <(read_reinstall_env DB_USERNAME) \
|| fail 'reinstall did not prefer the completed setup runtime database user'
for port in 1024 18080 65535; do
valid_app_port "$port" || fail "installer rejected valid application port $port"
done
for port in 0 80 1023 65536 invalid 18080.0; do
! valid_app_port "$port" || fail "installer accepted invalid application port $port"
done
port_is_listening() { return 1; }
log() { printf '%s\n' "$*" >/dev/null; }
# shellcheck disable=SC2329 # Invoked by the extracted installer helper.
die() { printf '%s\n' "$*" >&2; return 1; }
export APP_PORT=19090 SERVER_ADDRESS=127.0.0.1 HEALTH_URL='' APP_INDEX_URL='' REINSTALL=false
configure_app_port
[ "$HEALTH_URL" = 'http://127.0.0.1:19090/actuator/health' ] \
|| fail 'selected application port did not reach the health URL'
[ "$APP_INDEX_URL" = 'http://127.0.0.1:19090/' ] \
|| fail 'selected application port did not reach the frontend URL'
export APP_PORT=19091 SERVER_ADDRESS=::1 HEALTH_URL='' APP_INDEX_URL=''
configure_app_port
[ "$HEALTH_URL" = 'http://[::1]:19091/actuator/health' ] \
|| fail 'IPv6 bind address did not produce a bracketed health URL'
[ "$APP_INDEX_URL" = 'http://[::1]:19091/' ] \
|| fail 'IPv6 bind address did not produce a bracketed frontend URL'
[ "$PROXY_TARGET" = 'http://[::1]:19091' ] \
|| fail 'IPv6 bind address did not produce a bracketed reverse-proxy target'
for version in 0.0.0 1.2.3-alpha- 1.2.3--alpha 1.2.3-alpha+build.07; do
is_semver "$version" || fail "installer rejected valid SemVer $version"
"$ROOT/scripts/check-semver.sh" "$version" || fail "release workflow rejected valid SemVer $version"
@@ -218,6 +246,14 @@ grep -Fq 'KAIDI_SETUP_WIZARD' "$ROOT/deploy/install.sh" \
|| fail 'installer no longer supports first-run setup mode'
grep -Fq 'FINANCE_SETUP_TOKEN_SHA256' "$ROOT/deploy/install.sh" \
|| fail 'installer no longer writes the one-time setup-code hash'
# shellcheck disable=SC2016 # Match literal installer source.
grep -Fq 'SERVER_PORT "$APP_PORT"' "$ROOT/deploy/install.sh" \
|| fail 'installer does not persist the selected application port'
# shellcheck disable=SC2016 # Match literal installer source.
grep -Fq 'SERVER_ADDRESS "$SERVER_ADDRESS"' "$ROOT/deploy/install.sh" \
|| fail 'installer does not persist the selected bind address'
! grep -Eqi 'nginx|/etc/nginx/' "$ROOT/deploy/install.sh" \
|| fail 'installer must not install, start, or modify Nginx'
grep -Fq 'EnvironmentFile=-/var/lib/kaidi/setup/application.env' \
"$ROOT/deploy/systemd/kaidi-finance.service" \
|| fail 'application service no longer loads the setup-completion environment'
@@ -230,4 +266,4 @@ grep -Fq 'chown root:kaidi "$UPDATE_STATE_ROOT"' "$ROOT/deploy/install.sh" \
grep -Fq 'install.sh | sudo bash' "$ROOT/README.md" \
|| fail 'README does not document the public one-line setup-wizard install path'
printf 'Install configuration, public Gitea, optional private token, i686, setup wizard, and MySQL 8.4 fixtures passed\n'
printf 'Install configuration, custom port, public Gitea, optional private token, i686, setup wizard, and MySQL 8.4 fixtures passed\n'
+6 -16
View File
@@ -55,7 +55,7 @@ esac
if [ -n "$output" ]; then
if [ -n "${MOCK_RELEASE_API_URL:-}" ] && [ "$url" = "$MOCK_RELEASE_API_URL" ]; then
cp "$FIXTURE_RELEASE_ROOT/release-api.json" "$output"
elif [ "$url" = "${KAIDI_PUBLIC_INDEX_URL:-http://127.0.0.1/}" ]; then
elif [ "$url" = "${KAIDI_APP_INDEX_URL:-http://127.0.0.1:18080/}" ]; then
cp "$MOCK_APP_ROOT/current/public/index.html" "$output"
else
[ "${MOCK_DOWNLOAD_FAILURE:-}" != "${url##*/}" ] || exit 22
@@ -75,12 +75,6 @@ SH
#!/bin/sh
printf '%s\n' "$*" >> "$MOCK_SYSTEMCTL_LOG"
exit 0
SH
cat > "$mock_bin/nginx" <<'SH'
#!/bin/sh
printf '%s\n' "$*" >> "$MOCK_NGINX_LOG"
exit 0
SH
cat > "$mock_bin/flock" <<'SH'
@@ -138,7 +132,7 @@ build_release() {
printf '%s\n' "$version" > "$stage/VERSION"
printf '#!/bin/sh\nprintf "new updater\\n"\n' > "$stage/ops/update.sh"
chmod 0755 "$stage/ops/update.sh"
for name in kaidi-finance.service kaidi-update.service kaidi-update.path kaidi-finance.conf; do
for name in kaidi-finance.service kaidi-update.service kaidi-update.path; do
printf 'new %s\n' "$name" > "$stage/ops/$name"
done
@@ -174,7 +168,7 @@ prepare_installation() {
local fixture=$1
local version=$2
mkdir -p "$fixture/app/releases/1.0.0-preview.1/public" "$fixture/app/bin" \
"$fixture/state/inbox" "$fixture/systemd" "$fixture/nginx" "$fixture/log"
"$fixture/state/inbox" "$fixture/systemd" "$fixture/log"
printf 'old application\n' > "$fixture/app/releases/1.0.0-preview.1/app.jar"
printf '<!doctype html><title>old</title>\n' > "$fixture/app/releases/1.0.0-preview.1/public/index.html"
printf '1.0.0-preview.1\n' > "$fixture/app/releases/1.0.0-preview.1/VERSION"
@@ -184,7 +178,6 @@ prepare_installation() {
for name in kaidi-finance.service kaidi-update.service kaidi-update.path; do
printf 'old %s\n' "$name" > "$fixture/systemd/$name"
done
printf 'old kaidi-finance.conf\n' > "$fixture/nginx/kaidi-finance.conf"
write_request "$fixture" "$version" DOWNLOAD
}
@@ -227,12 +220,10 @@ run_update() {
MOCK_RELEASE_ORIGIN="${FIXTURE_RELEASE_ORIGIN:-https://release.fixture.invalid}" \
MOCK_EXPECT_RELEASE_TOKEN="${FIXTURE_RELEASE_TOKEN-}" \
MOCK_SYSTEMCTL_LOG="$fixture/systemctl.log" \
MOCK_NGINX_LOG="$fixture/nginx.log" \
KAIDI_APP_ROOT="$fixture/app" \
KAIDI_UPDATE_STATE_ROOT="$fixture/state" \
KAIDI_LOG_ROOT="$fixture/log" \
KAIDI_SYSTEMD_ROOT="$fixture/systemd" \
KAIDI_NGINX_CONFIG="$fixture/nginx/kaidi-finance.conf" \
KAIDI_UPDATER_PATH="$fixture/app/bin/update.sh" \
KAIDI_SKIP_DB_BACKUP="$skip_backup" \
KAIDI_UPDATE_HEALTH_ATTEMPTS=1 \
@@ -243,9 +234,8 @@ run_update() {
UPDATE_PUBLIC_KEY="$fixture/release-public.pem" \
UPDATE_REQUEST_FILE="$fixture/state/inbox/request.json" \
UPDATE_STATUS_FILE="$fixture/state/status.json" \
KAIDI_HEALTH_URL=http://127.0.0.1:18080/actuator/health \
KAIDI_PUBLIC_HEALTH_URL=http://127.0.0.1/actuator/health \
KAIDI_PUBLIC_INDEX_URL=http://127.0.0.1/ \
KAIDI_HEALTH_URL=http://127.0.0.1:19090/actuator/health \
KAIDI_APP_INDEX_URL=http://127.0.0.1:19090/ \
"$ROOT/deploy/update.sh"
}
@@ -319,7 +309,7 @@ assert_success_case() {
[ ! -e "$fixture/state/processing/request.json" ] \
|| fail 'success case left a claimed request behind'
grep -qx 'daemon-reload' "$fixture/systemctl.log" || fail 'systemd units were not reloaded'
grep -qx 'reload nginx' "$fixture/systemctl.log" || fail 'Nginx was not reloaded'
! grep -qi nginx "$fixture/systemctl.log" || fail 'updater unexpectedly managed Nginx'
}
assert_rollback_case() {