release: harden plugin deployment and recovery
Business Plugins CI / check (plugin-admin) (push) Successful in 1m37s
Business Plugins CI / check (subscription-admin) (push) Successful in 1m31s

This commit is contained in:
Qiufeng
2026-08-30 13:14:22 +08:00
parent ada4ab3c21
commit d3ff9be315
16 changed files with 259 additions and 50 deletions
+13 -1
View File
@@ -3,7 +3,7 @@ set -Eeuo pipefail
REPO_URL=${PLUGIN_REPO_URL:-https://git.awaioi.com/awaioi/sub2api-add.git}
SOURCE_DIR=${PLUGIN_SOURCE_DIR:-/opt/sub2api-add}
REF=${PLUGIN_REF:-v1.1.0}
REF=${PLUGIN_REF:-v1.1.1}
EXPECTED_SHA=${PLUGIN_COMMIT_SHA:-}
ALLOW_MUTABLE_REF=${PLUGIN_ALLOW_MUTABLE_REF:-false}
DEPLOY_ENV=${PLUGIN_ENV:-production}
@@ -22,10 +22,18 @@ validate_path_components() {
[[ "$component" != "." && "$component" != ".." ]] || die "$label 不能包含 . 或 .. 路径组件"
current="$current/$component"
[[ ! -L "$current" ]] || die "$label 的路径组件不能是符号链接:$current"
[[ ! -e "$current" || -d "$current" ]] || die "$label 的路径组件不是目录:$current"
done
}
ensure_real_parent() {
local path=$1 label=$2 parent
parent=$(dirname -- "$path")
[[ -d "$parent" && ! -L "$parent" ]] || die "$label 的父目录必须是已存在的真实目录:$parent"
}
validate_path_components "$SOURCE_DIR" PLUGIN_SOURCE_DIR
ensure_real_parent "$SOURCE_DIR" PLUGIN_SOURCE_DIR
if [[ "$SOURCE_DIR" != */sub2api-add && "${PLUGIN_ALLOW_CUSTOM_PATHS:-false}" != "true" ]]; then
die "PLUGIN_SOURCE_DIR 必须以 sub2api-add 结尾;如确需自定义路径请显式设置 PLUGIN_ALLOW_CUSTOM_PATHS=true"
fi
@@ -57,6 +65,10 @@ if [[ -e "$SOURCE_DIR" && ! -d "$SOURCE_DIR/.git" ]]; then
die "$SOURCE_DIR 已存在但不是本插件仓库;请设置 PLUGIN_SOURCE_DIR"
fi
if [[ ! -e "$SOURCE_DIR" ]]; then
ensure_real_parent "$SOURCE_DIR" PLUGIN_SOURCE_DIR
fi
if [[ -d "$SOURCE_DIR/.git" ]]; then
if [[ -n "$(git -C "$SOURCE_DIR" status --porcelain)" ]]; then
die "$SOURCE_DIR 有未提交修改,先清理后再升级"