diff --git a/README.md b/README.md index aff0e31..7b765c9 100644 --- a/README.md +++ b/README.md @@ -59,14 +59,14 @@ PostgreSQL 18。PostgreSQL 兼容开发已冻结,不属于本次 Preview.12 ### 直接 curl 安装 ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh | sudo bash +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh | sudo bash ``` 这条命令会提示填写 Java 应用端口,直接回车使用 `18080`;随后安装最新签名 Release,并默认进入 `/setup` 安装向导。Java 默认只监听 `127.0.0.1:所选端口`,前端页面、API 和健康检查均由同一端口提供。无人值守安装可直接指定: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh \ +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh \ | sudo env KAIDI_APP_PORT=19090 bash ``` @@ -74,8 +74,8 @@ curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-previe 时才设置 `KAIDI_SERVER_ADDRESS=0.0.0.0`,通常应保持默认回环绑定并由本机反向代理访问。需要在执行前独立校验安装脚本时使用: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh -o /tmp/kaidi-install.sh -printf '%s %s\n' 824ec6eb5b8bad97485d5c8beb3af93352fd12b1ee631b15a5b9bee38fcb5e67 /tmp/kaidi-install.sh | sha256sum -c - +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh -o /tmp/kaidi-install.sh +printf '%s %s\n' 8a75ee99a1c2f426c11ea18c8ef65f4f4ac3f8d52321c358f3ff645baa6ad99c /tmp/kaidi-install.sh | sha256sum -c - sudo bash /tmp/kaidi-install.sh rm -f /tmp/kaidi-install.sh ``` @@ -86,7 +86,7 @@ rm -f /tmp/kaidi-install.sh 包装器会在 `sudo` 前校验 `deploy/install.sh` 的固定 SHA-256,再按同一公钥信任链安装最新签名 Release。 ```bash -git clone --branch v1.0.0-preview.14 --depth 1 https://git.awaioi.com/ERP-Team/kaidi.git kaidi-preview +git clone --branch v1.0.0-preview.15 --depth 1 https://git.awaioi.com/ERP-Team/kaidi.git kaidi-preview cd kaidi-preview ./deploy/install-from-git.sh ``` @@ -141,7 +141,7 @@ sudo cat /root/kaidi-first-login.txt 32 位服务端镜像,因此 32 位主机需要预先连接一台 MySQL 8.4 数据库,之后仍然只执行一个安装命令: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh | sudo bash +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh | sudo bash ``` 无论主机架构如何,安装器都不会安装 MySQL、数据库客户端或创建数据库容器。在打开向导前,需要预先创建 `kaidi_finance`,并授予安装账号该库的 @@ -161,7 +161,7 @@ GRANT ALL PRIVILEGES ON kaidi_finance.* TO 'kaidi'@'KAIDI_SERVER_IP'; 管理员数据和运维人员新增的环境变量: ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh \ +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh \ | sudo env KAIDI_REINSTALL=true KAIDI_SETUP_WIZARD=false bash ``` @@ -171,7 +171,7 @@ curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-previe 如果安装器已完成但向导尚未提交,可执行下面的命令重新生成一次性安装码;该恢复路径只接受仍处于向导模式且未锁定的安装,正式模式不会被覆盖。 ```bash -curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.14/install.sh \ +curl -fsSL https://git.awaioi.com/ERP-Team/kaidi/releases/download/v1.0.0-preview.15/install.sh \ | sudo env KAIDI_REINSTALL=true bash ``` @@ -207,8 +207,8 @@ act_runner 提供 `ubuntu-24.04` 标签,并在 tag 发布时执行后端、前 Preview 属性由 SemVer 版本名表达。之后推送 tag 即会构建、测试、签名并发布: ```bash -git tag v1.0.0-preview.14 -git push origin v1.0.0-preview.14 +git tag v1.0.0-preview.15 +git push origin v1.0.0-preview.15 ``` 在线更新使用独立的 TDesign 页面:隔离的系统管理员进入“系统治理 → 系统更新”。权限与配置页只管理用户、角色、数据范围、表单模板和参数版本,不配置系统名称或域名。 @@ -260,7 +260,7 @@ cat /var/lib/kaidi-update/status.json ```bash KAIDI_RELEASE_SIGNING_KEY=/secure/release-signing-private.pem \ KAIDI_TRUSTED_RELEASE_PUBLIC_KEY_SHA256=807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9 \ - ./scripts/package-release.sh 1.0.0-preview.14 + ./scripts/package-release.sh 1.0.0-preview.15 KAIDI_TRUSTED_RELEASE_PUBLIC_KEY_SHA256=807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9 \ ./scripts/verify-release.sh dist/release ``` diff --git a/deploy/install-from-git.sh b/deploy/install-from-git.sh index e730481..d91443c 100755 --- a/deploy/install-from-git.sh +++ b/deploy/install-from-git.sh @@ -5,7 +5,7 @@ umask 077 ROOT=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd) INSTALLER="$ROOT/deploy/install.sh" -INSTALLER_SHA256=${KAIDI_INSTALLER_SHA256:-824ec6eb5b8bad97485d5c8beb3af93352fd12b1ee631b15a5b9bee38fcb5e67} +INSTALLER_SHA256=${KAIDI_INSTALLER_SHA256:-8a75ee99a1c2f426c11ea18c8ef65f4f4ac3f8d52321c358f3ff645baa6ad99c} RELEASE_API_URL=${KAIDI_RELEASE_API_URL:-https://git.awaioi.com/api/v1/repos/ERP-Team/kaidi/releases/latest} PUBLIC_KEY_SHA256=${KAIDI_RELEASE_PUBLIC_KEY_SHA256:-807c6aec1dc3f7ce494db16aa9d763c66f292033c38f328afd0390d2715a8cd9} TOKEN_FILE=${KAIDI_RELEASE_TOKEN_FILE:-} diff --git a/deploy/install.sh b/deploy/install.sh index e8bb372..78d3e70 100755 --- a/deploy/install.sh +++ b/deploy/install.sh @@ -538,12 +538,25 @@ write_env_file_preserving_unknown() { } wait_for_health() { - local attempts=0 + local attempts=0 active_state restart_count + log "Waiting for application startup at $HEALTH_URL" while [ "$attempts" -lt 60 ]; do - if curl -fsS "$HEALTH_URL" | jq -e '.status == "UP"' >/dev/null 2>&1; then + if curl --fail --silent --connect-timeout 1 --max-time 2 "$HEALTH_URL" 2>/dev/null \ + | jq -e '.status == "UP"' >/dev/null 2>&1; then + log "Application health check is UP" return 0 fi + active_state=$(systemctl show kaidi-finance.service --property=ActiveState --value 2>/dev/null || printf unknown) + restart_count=$(systemctl show kaidi-finance.service --property=NRestarts --value 2>/dev/null || printf 0) + [[ "$restart_count" =~ ^[0-9]+$ ]] || restart_count=0 + if [ "$active_state" = failed ] || [ "$restart_count" -ge 3 ]; then + journalctl -u kaidi-finance.service -n 80 --no-pager >&2 || true + die "Application service failed during startup (state=$active_state, restarts=$restart_count)" + fi attempts=$((attempts + 1)) + if [ $((attempts % 5)) -eq 0 ]; then + log "Application is still starting (state=$active_state, elapsed=$((attempts * 2))s)" + fi sleep 2 done journalctl -u kaidi-finance.service -n 80 --no-pager >&2 || true @@ -573,10 +586,14 @@ backup_managed_state() { fi index=$((index + 1)) done - systemctl is-active --quiet kaidi-finance.service && PREVIOUS_APP_ACTIVE=true || PREVIOUS_APP_ACTIVE=false - systemctl is-enabled --quiet kaidi-finance.service && PREVIOUS_APP_ENABLED=true || PREVIOUS_APP_ENABLED=false - systemctl is-active --quiet kaidi-update.path && PREVIOUS_UPDATE_ACTIVE=true || PREVIOUS_UPDATE_ACTIVE=false - systemctl is-enabled --quiet kaidi-update.path && PREVIOUS_UPDATE_ENABLED=true || PREVIOUS_UPDATE_ENABLED=false + systemctl is-active --quiet kaidi-finance.service >/dev/null 2>&1 \ + && PREVIOUS_APP_ACTIVE=true || PREVIOUS_APP_ACTIVE=false + systemctl is-enabled --quiet kaidi-finance.service >/dev/null 2>&1 \ + && PREVIOUS_APP_ENABLED=true || PREVIOUS_APP_ENABLED=false + systemctl is-active --quiet kaidi-update.path >/dev/null 2>&1 \ + && PREVIOUS_UPDATE_ACTIVE=true || PREVIOUS_UPDATE_ACTIVE=false + systemctl is-enabled --quiet kaidi-update.path >/dev/null 2>&1 \ + && PREVIOUS_UPDATE_ENABLED=true || PREVIOUS_UPDATE_ENABLED=false INSTALL_TRANSACTION_ARMED=true } diff --git a/scripts/test-install-fixture.sh b/scripts/test-install-fixture.sh index 28a6813..172d399 100755 --- a/scripts/test-install-fixture.sh +++ b/scripts/test-install-fixture.sh @@ -239,6 +239,11 @@ grep -Fq 'java_sha256=$(jq -er' "$ROOT/deploy/install.sh" \ || fail 'installer no longer obtains the Java runtime SHA-256' grep -Fq 'Using existing Java 17 runtime' "$ROOT/deploy/install.sh" \ || fail 'installer no longer reuses a local Java 17 runtime' +# shellcheck disable=SC2016 # Match the literal installer command. +grep -Fq -- '--connect-timeout 1 --max-time 2 "$HEALTH_URL" 2>/dev/null' "$ROOT/deploy/install.sh" \ + || fail 'installer no longer performs a quiet bounded health check' +grep -Fq 'restart_count" -ge 3' "$ROOT/deploy/install.sh" \ + || fail 'installer no longer stops early after repeated service restarts' # shellcheck disable=SC2016 # Match literal installer source. grep -Fq '[ "$actual_sha256" = "$java_sha256" ]' "$ROOT/deploy/install.sh" \ || fail 'installer no longer verifies the Java runtime SHA-256'