fix: stabilize external-db deployment and updates
Release / release (push) Canceled after 0s

This commit is contained in:
Qiufeng
2026-08-18 22:51:35 +08:00
parent 227c4b0129
commit 8c6c10eb85
22 changed files with 767 additions and 279 deletions
+203 -83
View File
@@ -38,9 +38,125 @@ JAVA_ACTIVATED=false
SERVICE_USER=kaidi
SERVICE_GROUP=kaidi
HOST_ARCH=
LOG_LOCALE=${KAIDI_LOG_LOCALE:-zh-CN}
SERVICE_USER_CREATED=false
SERVICE_GROUP_CREATED=false
CREATED_LAYOUT_PATHS=()
log() { printf '[kaidi-install] %s\n' "$*"; }
die() { printf '[kaidi-install] ERROR: %s\n' "$*" >&2; exit 1; }
localize_message() {
local message=$1
[ "$LOG_LOCALE" = en ] && { printf '%s' "$message"; return; }
case "$message" in
"Unsupported CPU architecture: "*) printf '不支持的 CPU 架构:%s' "${message#Unsupported CPU architecture: }" ;;
"The installer only supports Linux") printf '安装程序仅支持 Linux' ;;
"Custom installation roots"*) printf '打包版 systemd 不支持自定义安装目录' ;;
"systemd is required") printf '需要 systemd' ;;
"systemd-analyze is required") printf '需要 systemd-analyze' ;;
"getconf is required") printf '需要 getconf' ;;
"systemd is not running as PID 1") printf 'systemd 当前不是 PID 1,无法托管服务' ;;
"/etc/systemd/system is missing") printf '缺少 /etc/systemd/system' ;;
"CPU architecture and userspace word size"*) printf 'CPU 架构与用户空间位数不匹配:%s' "${message#*: }" ;;
"32-bit Linux deployment requires glibc"*) printf '32 位 Linux 需要 glibc;当前系统不兼容 i686 Java' ;;
"32-bit Linux deployment requires the glibc loader"*) printf '32 位 Linux 缺少 glibc 加载器 /lib/ld-linux.so.2' ;;
"Set KAIDI_RELEASE_PUBLIC_KEY_SHA256"*) printf '请设置受信任的发布公钥 SHA-256:KAIDI_RELEASE_PUBLIC_KEY_SHA256' ;;
"Run with sudo or as root") printf '请使用 sudo 或 root 运行' ;;
"Set only one of KAIDI_RELEASE_TOKEN"*) printf 'KAIDI_RELEASE_TOKEN 与 KAIDI_RELEASE_TOKEN_FILE 只能设置一个' ;;
"KAIDI_RELEASE_TOKEN_FILE must be a regular file") printf 'KAIDI_RELEASE_TOKEN_FILE 必须是普通文件' ;;
"KAIDI_RELEASE_TOKEN_FILE is too large") printf 'KAIDI_RELEASE_TOKEN_FILE 过大' ;;
"KAIDI_REINSTALL must be true or false") printf 'KAIDI_REINSTALL 只能是 true 或 false' ;;
"KAIDI_SETUP_WIZARD must be true or false") printf 'KAIDI_SETUP_WIZARD 只能是 true 或 false' ;;
"A setup-wizard repair needs"*) printf '安装向导修复需要已有配置文件:%s' "${message#A setup-wizard repair needs the existing }" ;;
"The existing installation is already in production mode"*) printf '现有安装已是正式模式,请执行普通修复重装' ;;
"The setup wizard is already locked"*) printf '安装向导已锁定,请执行普通修复重装' ;;
"Kaidi Finance is already installed"*) printf 'Kaidi 财务系统已安装,请从系统更新页面执行更新或先卸载' ;;
"Set KAIDI_RELEASE_BASE_URL"*) printf '请设置 Gitea Release 源:KAIDI_RELEASE_BASE_URL 或 KAIDI_RELEASE_API_URL' ;;
"KAIDI_RELEASE_TOKEN is invalid") printf 'KAIDI_RELEASE_TOKEN 无效' ;;
"Download failed: "*) printf '下载失败:%s' "${message#Download failed: }" ;;
"Release URLs must use HTTPS") printf '发布地址必须使用 HTTPS' ;;
"Release authentication header is unavailable") printf '发布认证请求头不可用' ;;
"Release asset "*" is missing") printf '缺少发布资产:%s' "${message#Release asset }" ;;
"Gitea Release tag is invalid") printf 'Gitea Release 标签无效' ;;
"KAIDI_RELEASE_API_URL must be a Gitea"*) printf 'KAIDI_RELEASE_API_URL 必须是 Gitea Release API 地址' ;;
"Required command is missing"*) printf '依赖命令缺失:%s' "${message#*: }" ;;
"Supported package managers"*) printf '仅支持 apt、dnf 或 yum' ;;
"Using existing Java"*) printf '使用现有 Java:%s' "${message#Using existing Java 17+ runtime at }" ;;
"Local Java verified: "*) printf '本机 Java 校验通过:%s' "${message#Local Java verified: }" ;;
"No local Java"*) printf '未找到可用 Java 17,正在下载 Azul Java 17 运行时' ;;
"Java 17 runtime download URL"*) printf 'Java 17 运行时下载地址无效' ;;
"Downloaded Java verified: "*) printf '下载的 Java 校验通过:%s' "${message#Downloaded Java verified: }" ;;
"The existing Java runtime cannot start"*) printf '现有 Java 运行时无法启动,请检查架构和权限' ;;
"No Java 17 runtime is published"*) printf '当前 Linux 架构没有可用的 Java 17 运行时' ;;
"Java 17 runtime SHA-256 verification failed") printf 'Java 17 运行时 SHA-256 校验失败' ;;
"Downloaded Java runtime architecture"*) printf '下载的 Java 运行时架构与主机不匹配' ;;
"The downloaded Java runtime cannot start"*) printf '下载的 Java 运行时无法启动,请检查 glibc 和主机架构' ;;
"Java 17 runtime SHA-256 is unavailable") printf 'Java 17 运行时缺少 SHA-256 摘要' ;;
"Existing user "*" has unexpected home directory "*) printf '现有用户目录不符合 Kaidi 约定:%s' "${message#Existing user }" ;;
"Service-user filesystem and Java access checks passed") printf '服务用户文件系统与 Java 访问检查通过' ;;
*" cannot traverse or read the active release") printf '服务用户无法进入或读取当前发布目录' ;;
"The selected Java runtime is unavailable"*) printf '选定的 Java 运行时不可用:%s' "${message#The selected Java runtime is unavailable at }" ;;
"The selected Java runtime cannot execute"*) printf '服务用户无法执行选定的 Java 运行时' ;;
*" cannot execute the selected Java runtime") printf '服务用户无法执行选定的 Java 运行时' ;;
*" cannot execute as "*) printf '服务用户无法启动 Java 运行时' ;;
*" cannot write the file-storage directory") printf '服务用户无法写入文件存储目录' ;;
*" cannot write the update inbox") printf '服务用户无法写入更新请求目录' ;;
"SELinux context restoration reported"*) printf 'SELinux 上下文恢复有提示,将继续进行服务访问检查' ;;
"No interactive terminal detected"*) printf '未检测到交互终端,使用应用端口 %s' "${message##*port }" ;;
"Application port "*" is already held"*) printf '应用端口已由现有 Kaidi 服务占用:%s' "${message#Application port }" ;;
"Application port "*" is already in use"*) printf '应用端口已被占用,请使用 KAIDI_APP_PORT 更换端口' ;;
"Application will bind "*) printf '应用监听地址:%s' "${message#Application will bind }" ;;
"Reverse proxy target: "*) printf '反向代理目标:%s' "${message#Reverse proxy target: }" ;;
"KAIDI_SERVER_ADDRESS contains"*) printf 'KAIDI_SERVER_ADDRESS 含有不支持的字符' ;;
"KAIDI_APP_PORT must be an integer"*) printf 'KAIDI_APP_PORT 必须是 1024 到 65535 的整数' ;;
"Do not pass database credentials"*) printf '向导模式不要在命令行传数据库账号密码,请在浏览器向导中填写' ;;
"KAIDI_DB_USERNAME and KAIDI_DB_PASSWORD"*) printf '设置 KAIDI_DB_URL 时必须同时提供数据库用户名和密码' ;;
"An external MySQL 8.4 database is required"*) printf '需要连接用户预先准备的 MySQL 8.4 数据库:请设置 KAIDI_DB_URL、KAIDI_DB_USERNAME、KAIDI_DB_PASSWORD' ;;
"KAIDI_REINSTALL needs"*) printf 'KAIDI_REINSTALL 需要读取已有安装配置或提供数据库配置' ;;
"The database host is empty") printf '数据库主机不能为空' ;;
"The database port is invalid") printf '数据库端口无效' ;;
"The database name is invalid") printf '数据库名无效,只能包含字母、数字、下划线和美元符号' ;;
"KAIDI_DB_URL must start with jdbc:mysql://") printf 'KAIDI_DB_URL 必须以 jdbc:mysql:// 开头' ;;
"KAIDI_DB_USERNAME is empty") printf 'KAIDI_DB_USERNAME 不能为空' ;;
"KAIDI_DB_PASSWORD is empty") printf 'KAIDI_DB_PASSWORD 不能为空' ;;
"KAIDI_DB_BACKUP_MODE must be skip or mysqldump") printf 'KAIDI_DB_BACKUP_MODE 只能是 skip 或 mysqldump' ;;
"Waiting for application startup"*) printf '正在等待应用启动:%s' "${message#Waiting for application startup at }" ;;
"Application health check is UP") printf '应用健康检查通过(UP)' ;;
"Application is still starting"*) printf '应用仍在启动:%s' "${message#Application is still starting }" ;;
"Application service failed"*) printf '应用服务启动失败:%s' "${message#Application service failed during startup }" ;;
"Application health check did not become UP") printf '应用健康检查未变为 UP,请查看服务日志' ;;
"Application frontend entry point is unavailable") printf '应用前端入口不可访问,请检查服务和端口' ;;
"Installation failed; restoring"*) printf '安装失败,正在恢复原有运行状态' ;;
"ERROR: rollback was incomplete"*) printf '错误:回滚未完成,请检查 systemd 状态' ;;
*" contains a line break") printf '配置项包含换行符,已拒绝:%s' "${message%% contains a line break*}" ;;
"Kaidi Finance "*" is installed") printf 'Kaidi 财务系统 %s 已安装' "${message#Kaidi Finance }" ;;
"Configure your reverse proxy"*) printf '请将反向代理指向:%s' "${message#Configure your reverse proxy to }" ;;
"Open /setup"*) printf '请通过反向代理域名打开 /setup,完成首次安装向导' ;;
"Setup code: "*) printf '安装码位置:%s' "${message#Setup code: }" ;;
"Open the reverse-proxy domain"*) printf '请打开反向代理域名并使用管理员账号登录' ;;
"Temporary credentials: "*) printf '临时凭据位置:%s' "${message#Temporary credentials: }" ;;
"Change the temporary password"*) printf '首次登录后请立即修改临时密码' ;;
"Release public-key SHA-256 does not match"*) printf '发布公钥 SHA-256 与受信指纹不一致' ;;
"Release manifest signature verification failed") printf '发布清单签名校验失败' ;;
"Release version is invalid") printf '发布版本无效' ;;
"Release artifact name is invalid") printf '发布包文件名无效' ;;
"Release SHA-256 is invalid") printf '发布包 SHA-256 无效' ;;
"Release artifact SHA-256 verification failed") printf '发布包 SHA-256 校验失败' ;;
"Release archive contains an unsafe path") printf '发布归档包含不安全路径,已拒绝' ;;
"Release archive must not contain symbolic links") printf '发布归档不能包含符号链接,已拒绝' ;;
"Release app.jar is missing") printf '发布包缺少 app.jar' ;;
"Release frontend is missing") printf '发布包缺少前端文件' ;;
"Release version mismatch") printf '发布包版本与清单不一致' ;;
"Release updater is missing") printf '发布包缺少更新脚本' ;;
"Baota Spring Boot launcher is missing") printf '发布包缺少宝塔启动脚本' ;;
"Baota Spring Boot launcher is invalid") printf '宝塔启动脚本语法无效' ;;
"The existing FIELD_ENCRYPTION_KEY is missing") printf '已有安装缺少 FIELD_ENCRYPTION_KEY' ;;
"Installed systemd units failed validation") printf '已安装的 systemd 单元校验失败' ;;
"Environment verified: "*) printf '环境检查通过:%s' "${message#Environment verified: }" ;;
*) printf '%s' "$message" ;;
esac
}
log() { printf '[kaidi-install] %s\n' "$(localize_message "$*")"; }
die() { printf '[kaidi-install] 错误:%s\n' "$(localize_message "$*")" >&2; exit 1; }
sha256_file() {
sha256sum "$1" | awk '{print $1}'
@@ -208,15 +324,23 @@ download_release_asset() {
install_packages() {
if command -v apt-get >/dev/null 2>&1; then
export DEBIAN_FRONTEND=noninteractive
apt-get update -qq
apt-get install -y -qq ca-certificates coreutils curl findutils gzip jq openssl tar util-linux
apt-get update -qq >/dev/null 2>&1 \
|| die "系统软件源更新失败,请检查网络和 apt 配置"
apt-get install -y -qq ca-certificates coreutils curl findutils gzip jq openssl tar util-linux \
>/dev/null 2>&1 \
|| die "系统依赖安装失败;安装器不会安装 MySQL 或 Docker"
elif command -v dnf >/dev/null 2>&1; then
dnf install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux
dnf install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux \
>/dev/null 2>&1 \
|| die "系统依赖安装失败;安装器不会安装 MySQL 或 Docker"
elif command -v yum >/dev/null 2>&1; then
yum install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux
yum install -y ca-certificates coreutils curl findutils gzip jq openssl tar util-linux \
>/dev/null 2>&1 \
|| die "系统依赖安装失败;安装器不会安装 MySQL 或 Docker"
else
die "Supported package managers are apt, dnf, and yum"
fi
log "系统依赖检查完成(未安装 MySQL、MariaDB、Docker)"
}
preflight_runtime_commands() {
@@ -230,31 +354,6 @@ preflight_runtime_commands() {
done
}
mysql_client_bin() {
local candidate
if [ -n "${KAIDI_MYSQL_CLIENT:-}" ]; then
case "$KAIDI_MYSQL_CLIENT" in
*/*) [ -x "$KAIDI_MYSQL_CLIENT" ] && printf '%s\n' "$KAIDI_MYSQL_CLIENT" && return 0 ;;
*) candidate=$(command -v "$KAIDI_MYSQL_CLIENT" 2>/dev/null || true); [ -n "$candidate" ] && printf '%s\n' "$candidate" && return 0 ;;
esac
return 1
fi
candidate=$(command -v mysql 2>/dev/null || command -v mariadb 2>/dev/null || true)
if [ -n "$candidate" ]; then
printf '%s\n' "$candidate"
return 0
fi
for candidate in \
/www/server/mysql/bin/mysql /www/server/mysql/bin/mariadb \
/usr/bin/mysql /usr/bin/mariadb /usr/local/mysql/bin/mysql /opt/mysql/bin/mysql; do
if [ -x "$candidate" ]; then
printf '%s\n' "$candidate"
return 0
fi
done
return 1
}
azul_arch() {
case "${HOST_ARCH:-$(normalized_host_arch)}" in
x86_64) printf x86 ;;
@@ -327,15 +426,15 @@ system_java_home() {
}
prepare_java() {
local api java_metadata package_metadata package_uuid java_url java_sha256 actual_sha256 system_home java_line
local api java_metadata package_metadata package_uuid java_url java_sha256 actual_sha256 system_home java_line java_version
JAVA_BIN=
JAVA_STAGED_DIR=
if system_home=$(system_java_home); then
JAVA_BIN="$system_home/bin/java"
java_line=$("$JAVA_BIN" -version 2>&1 | head -n 1) \
|| die "The existing Java runtime cannot start on this host"
log "Using existing Java 17+ runtime at $system_home"
log "Local Java verified: $java_line"
java_version=$(printf '%s\n' "$java_line" | sed -n 's/.*version "\([0-9][0-9.]*\).*/\1/p')
log "使用现有 Java 运行时:$system_home(版本 ${java_version:-未知})"
return 0
fi
log "No local Java 17 runtime found; downloading the official Azul Java 17 runtime"
@@ -362,7 +461,8 @@ prepare_java() {
java_line=$("$JAVA_STAGED_DIR/bin/java" -version 2>&1 | head -n 1) \
|| die "The downloaded Java runtime cannot start; verify glibc and the host architecture"
JAVA_BIN="$APP_ROOT/runtime/java/bin/java"
log "Downloaded Java verified: $java_line"
java_version=$(printf '%s\n' "$java_line" | sed -n 's/.*version "\([0-9][0-9.]*\).*/\1/p')
log "下载的 Java 运行时校验通过(版本 ${java_version:-未知})"
}
activate_java() {
@@ -383,6 +483,7 @@ ensure_service_identity() {
command -v getent >/dev/null 2>&1 || die "getent is required"
if ! getent group "$SERVICE_GROUP" >/dev/null 2>&1; then
groupadd --system "$SERVICE_GROUP"
SERVICE_GROUP_CREATED=true
fi
if id "$SERVICE_USER" >/dev/null 2>&1; then
existing_home=$(getent passwd "$SERVICE_USER" | awk -F: '{print $6}')
@@ -397,10 +498,27 @@ ensure_service_identity() {
[ -n "$nologin_path" ] || nologin_path=/usr/sbin/nologin
[ -x "$nologin_path" ] || die "A nologin shell is required"
useradd --system --gid "$SERVICE_GROUP" --home-dir "$STATE_ROOT" --shell "$nologin_path" "$SERVICE_USER"
SERVICE_USER_CREATED=true
}
record_layout_path() {
[ -e "$1" ] || [ -L "$1" ] || CREATED_LAYOUT_PATHS+=("$1")
}
prepare_managed_layout() {
command -v runuser >/dev/null 2>&1 || die "runuser is required"
record_layout_path "$APP_ROOT"
record_layout_path "$APP_ROOT/releases"
record_layout_path "$APP_ROOT/runtime"
record_layout_path "$APP_ROOT/bin"
record_layout_path "$STATE_ROOT"
record_layout_path "$STATE_ROOT/files"
record_layout_path "$STATE_ROOT/tmp"
record_layout_path /var/log/kaidi
record_layout_path "$STATE_ROOT/setup"
record_layout_path "$UPDATE_STATE_ROOT"
record_layout_path "$UPDATE_STATE_ROOT/inbox"
record_layout_path "$CONFIG_ROOT"
install -d -o root -g "$SERVICE_GROUP" -m 0750 \
"$APP_ROOT" "$APP_ROOT/releases" "$APP_ROOT/runtime" "$APP_ROOT/bin"
install -d -o "$SERVICE_USER" -g "$SERVICE_GROUP" -m 0750 \
@@ -529,7 +647,7 @@ configure_app_port() {
default_port=$(read_reinstall_env SERVER_PORT || true)
[[ "$default_port" =~ ^[0-9]{1,5}$ ]] || default_port=18080
if [ -t 1 ] && [ -r /dev/tty ]; then
printf '[kaidi-install] Application port [%s]: ' "$default_port" > /dev/tty
printf '[kaidi-install] 应用端口 [%s]:' "$default_port" > /dev/tty
if IFS= read -r entered < /dev/tty; then
APP_PORT=${entered:-$default_port}
else
@@ -640,48 +758,36 @@ database_name() {
printf '%s' "${KAIDI_DB_NAME:-$name}"
}
preflight_database() {
local client host port name version table
validate_database_configuration() {
[ "$SETUP_WIZARD" != true ] || return 0
case "$DB_URL" in
jdbc:mysql://*) ;;
*) die "KAIDI_DB_URL must start with jdbc:mysql://" ;;
esac
client=$(mysql_client_bin || true)
[ -n "$client" ] || die "A MySQL command-line client is required; set KAIDI_MYSQL_CLIENT or add mysql/mariadb to PATH"
host=$(database_host)
port=$(database_port)
name=$(database_name)
[ -n "$host" ] || die "The database host is empty"
[[ "$port" =~ ^[0-9]{1,5}$ ]] && [ "$port" -ge 1 ] && [ "$port" -le 65535 ] \
[ -n "$DB_USERNAME" ] || die "KAIDI_DB_USERNAME is empty"
[ -n "$DB_PASSWORD" ] || die "KAIDI_DB_PASSWORD is empty"
[ -n "$(database_host)" ] || die "The database host is empty"
[[ "$(database_port)" =~ ^[0-9]{1,5}$ ]] \
&& [ "$(database_port)" -ge 1 ] && [ "$(database_port)" -le 65535 ] \
|| die "The database port is invalid"
[[ "$name" =~ ^[A-Za-z0-9_$]+$ ]] || die "The database name is invalid"
[[ "$(database_name)" =~ ^[A-Za-z0-9_$]+$ ]] || die "The database name is invalid"
# The installer deliberately does not invoke mysql/mariadb and does not
# execute DDL/DML. The application performs Flyway migrations only after
# it has connected to the operator-provided schema.
log "已记录外部 MySQL 连接配置;安装器不安装 MySQL、不连接数据库、不执行 SQL"
}
version=$(MYSQL_PWD="$DB_PASSWORD" "$client" --protocol=TCP --connect-timeout=10 \
-h "$host" -P "$port" -u "$DB_USERNAME" "$name" --batch --skip-column-names \
-e 'SELECT VERSION()' 2>/dev/null) || die "Cannot connect to the configured MySQL database"
case "$version" in
8.4.*) ;;
*) die "MySQL 8.4.x is required; server reported $version" ;;
# Kept as a compatibility name for older local fixtures and wrappers. It is
# now a pure configuration check and has no database side effects.
preflight_database() {
validate_database_configuration
}
validate_database_backup_mode() {
case "${KAIDI_DB_BACKUP_MODE:-skip}" in
skip|mysqldump) ;;
*) die "KAIDI_DB_BACKUP_MODE must be skip or mysqldump" ;;
esac
table="kaidi_install_preflight_$$"
if ! MYSQL_PWD="$DB_PASSWORD" "$client" --protocol=TCP --connect-timeout=10 \
-h "$host" -P "$port" -u "$DB_USERNAME" "$name" >/dev/null <<SQL
DROP TABLE IF EXISTS $table;
CREATE TABLE $table (id INT NOT NULL PRIMARY KEY);
INSERT INTO $table (id) VALUES (1);
UPDATE $table SET id = 2 WHERE id = 1;
DELETE FROM $table WHERE id = 2;
DROP TABLE $table;
SQL
then
MYSQL_PWD="$DB_PASSWORD" "$client" --protocol=TCP --connect-timeout=10 \
-h "$host" -P "$port" -u "$DB_USERNAME" "$name" \
-e "DROP TABLE IF EXISTS $table" >/dev/null 2>&1 || true
die "The database account needs DDL and DML permissions on $name"
fi
log "MySQL $version connectivity and DDL/DML permissions verified"
}
write_env_file() {
@@ -840,7 +946,7 @@ restore_managed_path() {
}
rollback_install() {
local index=0 path rollback_failed=false
local index=0 path rollback_failed=false layout_path service_uid
set +e
log "Installation failed; restoring the previous managed state"
systemctl stop kaidi-update.path kaidi-finance.service >/dev/null 2>&1 || true
@@ -858,6 +964,19 @@ rollback_install() {
elif [ "$JAVA_ACTIVATED" = true ]; then
rm -rf -- "$APP_ROOT/runtime/java" || rollback_failed=true
fi
if [ "$SERVICE_USER_CREATED" = true ]; then
service_uid=$(id -u "$SERVICE_USER" 2>/dev/null || true)
if [ -n "$service_uid" ]; then
userdel --force "$SERVICE_USER" >/dev/null 2>&1 || rollback_failed=true
fi
fi
if [ "$SERVICE_GROUP_CREATED" = true ] && getent group "$SERVICE_GROUP" >/dev/null 2>&1; then
groupdel "$SERVICE_GROUP" >/dev/null 2>&1 || rollback_failed=true
fi
for ((index=${#CREATED_LAYOUT_PATHS[@]} - 1; index >= 0; index--)); do
layout_path=${CREATED_LAYOUT_PATHS[$index]}
rmdir -- "$layout_path" >/dev/null 2>&1 || true
done
systemctl daemon-reload >/dev/null 2>&1 || rollback_failed=true
restore_unit_state kaidi-finance.service "$PREVIOUS_APP_ENABLED" "$PREVIOUS_APP_ACTIVE" \
|| rollback_failed=true
@@ -882,6 +1001,7 @@ main() {
trap cleanup EXIT
validate_inputs
validate_database_backup_mode
configure_app_port
preflight_host
install_packages
@@ -1025,13 +1145,13 @@ write_env_file "$CONFIG_ROOT/update.env" \
KAIDI_JAVA_BIN "$JAVA_BIN" \
KAIDI_HEALTH_URL "$HEALTH_URL" \
KAIDI_APP_INDEX_URL "$APP_INDEX_URL" \
KAIDI_DB_CONTAINER "${KAIDI_DB_CONTAINER:-}" \
KAIDI_DB_HOST "$(database_host)" \
KAIDI_DB_PORT "$(database_port)" \
KAIDI_DB_NAME "$(database_name)" \
KAIDI_DB_USERNAME "$DB_USERNAME" \
KAIDI_DB_PASSWORD "$DB_PASSWORD" \
KAIDI_MYSQLDUMP_BIN "${KAIDI_MYSQLDUMP_BIN:-}"
KAIDI_MYSQLDUMP_BIN "${KAIDI_MYSQLDUMP_BIN:-}" \
KAIDI_DB_BACKUP_MODE "${KAIDI_DB_BACKUP_MODE:-skip}"
chmod 0600 "$CONFIG_ROOT/update.env"
install -m 0644 "$RELEASE_DIR/ops/kaidi-finance.service" /etc/systemd/system/kaidi-finance.service
@@ -1057,26 +1177,26 @@ if [ "$SETUP_WIZARD" != true ]; then
sed -i 's/^FINANCE_BOOTSTRAP_PASSWORD=.*$/FINANCE_BOOTSTRAP_PASSWORD=""/' "$CONFIG_ROOT/kaidi.env"
fi
jq -n --arg version "$VERSION" --arg updatedAt "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
'{state:"CURRENT",message:"Initial release is running",targetVersion:$version,updatedAt:$updatedAt}' \
'{state:"CURRENT",message:"初始版本正在运行",targetVersion:$version,updatedAt:$updatedAt}' \
> "$UPDATE_STATE_ROOT/status.json"
chmod 0644 "$UPDATE_STATE_ROOT/status.json"
systemctl enable --now kaidi-update.path
if [ "$SETUP_WIZARD" = true ]; then
cat > /root/kaidi-first-login.txt <<EOF
URL after reverse proxy: http://SERVER_IP/setup
Reverse proxy target: $PROXY_TARGET
Setup code: $SETUP_CODE
Version: $VERSION
反向代理访问地址:http://SERVER_IP/setup
反向代理目标:$PROXY_TARGET
安装码:$SETUP_CODE
版本:$VERSION
EOF
chmod 0600 /root/kaidi-first-login.txt
elif [ "$REINSTALL" != true ]; then
cat > /root/kaidi-first-login.txt <<EOF
URL after reverse proxy: http://SERVER_IP/
Reverse proxy target: $PROXY_TARGET
Username: admin
Temporary password: $ADMIN_PASSWORD
Version: $VERSION
反向代理访问地址:http://SERVER_IP/
反向代理目标:$PROXY_TARGET
管理员账号:admin
临时密码:$ADMIN_PASSWORD
版本:$VERSION
EOF
chmod 0600 /root/kaidi-first-login.txt
fi