145bf06ff8
2026-07-04 二维码 IP 事故复盘:env 不随发版同步(by design,密钥走 render-env 手动通道),但 render-env 还停在 EC2 时代且割接后没跑过, 线上 env 的 STORAGE_*/CORS 一直是割接临时 IP。三处修复: - deploy/render-env.sh:目标改 ssh 别名 ali(可 JIU_DEPLOY_SSH 覆盖)、 SECRET_KEYS 补 PAY_SECRET(旧模板缺此行,直接 deploy 会删掉线上支付 密钥)、健康检查改 :8081、覆盖前先备份线上 env - deploy/production.env.template:SERVER_PORT 8080→8081(对齐 ali nginx 反代口径)、补 PAY_SECRET 占位 - scripts/ci/deploy-server.sh(ali 分支):部署后比对模板与线上 env 的 非密钥项,漂移只告警不覆盖——手改线上配置不再长期无人发现 线上 env 已手工修正(STORAGE_BASE_URL/STORAGE_PUBLIC_URL/SERVER_CORS_ORIGIN → https://jiu.51yanmei.com,退役 LICENSE_* 三行清除,改前有备份) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
167 lines
6.0 KiB
Bash
167 lines
6.0 KiB
Bash
#!/usr/bin/env bash
|
|
# deploy-server.sh <tag> — deploy the backend binary + nginx config.
|
|
# Two source modes: uses dist/ built in the same job, or downloads the release
|
|
# assets by tag (manual rollback). Does NOT touch the web app, marketing site,
|
|
# or version.yaml.
|
|
#
|
|
# Targets (post-cutover 2026-07-02: Ali is the live primary; the EC2 jiu stack
|
|
# is decommissioned — deploying there would resurrect a backend against a stale
|
|
# database, so the workflow no longer calls the ec2 branch):
|
|
# - ali: stop jiu → swap binary → start jiu → health check (:8081) →
|
|
# reload the host nginx (443 ssl jiu.51yanmei.com, 备案回切 2026-07-03).
|
|
# - ec2 (legacy default, kept for manual rollback of pre-cutover tags only):
|
|
# stop jiu → swap binary → start jiu → health check → reload nginx
|
|
# inside the pangolin-edge container.
|
|
set -euo pipefail
|
|
|
|
# shellcheck source=scripts/ci/lib-forgejo.sh
|
|
. "$(dirname "$0")/lib-forgejo.sh"
|
|
|
|
TAG="$1"
|
|
DEPLOY_TARGET="${DEPLOY_TARGET:-ec2}"
|
|
TARGET_HOST="${DEPLOY_HOST:-$EC2_HOST}"
|
|
TARGET_USER="${DEPLOY_USER:-$EC2_USER}"
|
|
echo "==> deploy-server: tag=${TAG} target=${DEPLOY_TARGET} host=${TARGET_HOST}"
|
|
|
|
if [ ! -f dist/jiu-server ] || [ ! -f dist/configs.tar.gz ]; then
|
|
download_release_assets "$TAG"
|
|
fi
|
|
|
|
echo "==> deploy-server: dist/ contents:"
|
|
ls -lh dist/
|
|
|
|
rm -rf /tmp/jiu-configs
|
|
mkdir -p /tmp/jiu-configs
|
|
tar -xzf dist/configs.tar.gz -C /tmp/jiu-configs
|
|
|
|
# Pick the nginx config matching the target's reverse-proxy topology.
|
|
if [ "$DEPLOY_TARGET" = "ali" ]; then
|
|
NGINX_SRC=/tmp/jiu-configs/deploy/nginx-jiu-ali.conf
|
|
else
|
|
NGINX_SRC=/tmp/jiu-configs/deploy/nginx-jiu.conf
|
|
fi
|
|
|
|
setup_ssh
|
|
echo "==> deploy-server: uploading files to ${TARGET_HOST}"
|
|
${SCP} dist/jiu-server "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-server"
|
|
${SCP} "${NGINX_SRC}" "${TARGET_USER}@${TARGET_HOST}:/tmp/nginx-jiu.conf"
|
|
|
|
# Platform code-minting CLI + wrapper (absent when rolling back to a pre-gencode
|
|
# release — upload only when present).
|
|
if [ -f dist/jiu-gencode ]; then
|
|
${SCP} dist/jiu-gencode "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-gencode"
|
|
${SCP} /tmp/jiu-configs/deploy/jiu-gencode.sh "${TARGET_USER}@${TARGET_HOST}:/tmp/jiu-gencode.sh"
|
|
fi
|
|
|
|
if [ "$DEPLOY_TARGET" = "ali" ]; then
|
|
# --- Alibaba Cloud (live primary since the 2026-07-02 cutover) ---
|
|
# Full swap-and-restart: jiu.service runs against the promoted local primary
|
|
# DB on :8081; nginx serves 443 ssl (jiu.51yanmei.com, 备案回切 2026-07-03).
|
|
${SSH} "${TARGET_USER}@${TARGET_HOST}" << 'ENDSSH'
|
|
set -e
|
|
|
|
systemctl stop jiu
|
|
cp /tmp/jiu-server /opt/jiu/backend/jiu-server
|
|
chmod +x /opt/jiu/backend/jiu-server
|
|
|
|
if [ -f /tmp/jiu-gencode ]; then
|
|
cp /tmp/jiu-gencode /opt/jiu/backend/jiu-gencode
|
|
chmod +x /opt/jiu/backend/jiu-gencode
|
|
if [ -f /tmp/jiu-gencode.sh ]; then
|
|
cp /tmp/jiu-gencode.sh /opt/jiu/backend/jiu-gencode.sh
|
|
chmod +x /opt/jiu/backend/jiu-gencode.sh
|
|
fi
|
|
fi
|
|
|
|
systemctl start jiu
|
|
echo "Waiting for health check..."
|
|
for i in $(seq 1 30); do
|
|
if curl -f http://localhost:8081/health > /dev/null 2>&1; then
|
|
echo "Health check passed"
|
|
break
|
|
fi
|
|
sleep 2
|
|
done
|
|
curl -f http://localhost:8081/health > /dev/null || { echo "Health check failed!"; exit 1; }
|
|
|
|
cp /tmp/nginx-jiu.conf /etc/nginx/conf.d/jiu.conf
|
|
nginx -t && systemctl reload nginx
|
|
|
|
echo "Ali server deploy complete!"
|
|
ENDSSH
|
|
|
|
# --- 配置漂移检查(只告警不覆盖)---
|
|
# production.env 不随发版同步(密钥走 deploy/render-env.sh 手动通道);
|
|
# 这里比对模板与线上 env 的非密钥项,漂移时在 CI 日志醒目提示,防止
|
|
# 「割接手改 env 后长期无人发现」(2026-07-04 二维码 IP 事故复盘)。
|
|
TEMPLATE=/tmp/jiu-configs/deploy/production.env.template
|
|
if [ -f "$TEMPLATE" ]; then
|
|
${SSH} "${TARGET_USER}@${TARGET_HOST}" \
|
|
"grep -v '^#' /opt/jiu/config/production.env | grep -v '^$'" \
|
|
> /tmp/jiu-env-remote.txt 2>/dev/null || true
|
|
DRIFT=0
|
|
while IFS= read -r line; do
|
|
case "$line" in ''|\#*) continue;; esac
|
|
key="${line%%=*}"
|
|
case " DATABASE_DSN JWT_SECRET DB_PASSWORD PAY_SECRET " in
|
|
*" $key "*) continue;; # 密钥行不比值
|
|
esac
|
|
remote_line="$(grep "^${key}=" /tmp/jiu-env-remote.txt || true)"
|
|
if [ -n "$remote_line" ] && [ "$remote_line" != "$line" ]; then
|
|
echo "⚠️ env 漂移: 线上 [$remote_line] ≠ 模板 [$line]"
|
|
DRIFT=1
|
|
fi
|
|
done < "$TEMPLATE"
|
|
rm -f /tmp/jiu-env-remote.txt
|
|
if [ "$DRIFT" = "1" ]; then
|
|
echo "⚠️ production.env 与模板存在非密钥项漂移——确认线上口径后同步模板,或跑 deploy/render-env.sh --deploy 覆盖线上"
|
|
else
|
|
echo "==> env drift check: 非密钥项与模板一致 ✓"
|
|
fi
|
|
fi
|
|
else
|
|
# --- EC2 (live primary) ---
|
|
${SSH} "${TARGET_USER}@${TARGET_HOST}" << 'ENDSSH'
|
|
set -e
|
|
|
|
# Replace backend binary
|
|
sudo systemctl stop jiu
|
|
cp /tmp/jiu-server /opt/jiu/backend/jiu-server
|
|
chmod +x /opt/jiu/backend/jiu-server
|
|
|
|
# Refresh the code-minting CLI if shipped in this release (skip gracefully on
|
|
# rollback to a pre-gencode release). Not a service — just a host-side binary.
|
|
if [ -f /tmp/jiu-gencode ]; then
|
|
cp /tmp/jiu-gencode /opt/jiu/backend/jiu-gencode
|
|
chmod +x /opt/jiu/backend/jiu-gencode
|
|
if [ -f /tmp/jiu-gencode.sh ]; then
|
|
cp /tmp/jiu-gencode.sh /opt/jiu/backend/jiu-gencode.sh
|
|
chmod +x /opt/jiu/backend/jiu-gencode.sh
|
|
fi
|
|
fi
|
|
|
|
# Start and health check
|
|
sudo systemctl start jiu
|
|
echo "Waiting for health check..."
|
|
for i in $(seq 1 30); do
|
|
if curl -f http://localhost:8080/health > /dev/null 2>&1; then
|
|
echo "Health check passed"
|
|
break
|
|
fi
|
|
sleep 2
|
|
done
|
|
curl -f http://localhost:8080/health > /dev/null || { echo "Health check failed!"; exit 1; }
|
|
|
|
# Update jiu nginx config in the pangolin-edge reverse proxy (host-bind-mounted
|
|
# conf.d; reload nginx inside the container).
|
|
cp /tmp/nginx-jiu.conf /home/ec2-user/pangolin/edge/conf.d/jiu.conf
|
|
docker exec pangolin-edge nginx -t && docker exec pangolin-edge nginx -s reload
|
|
|
|
echo "Server deploy complete!"
|
|
ENDSSH
|
|
fi
|
|
|
|
teardown_ssh
|
|
rm -rf /tmp/jiu-configs
|
|
echo "==> deploy-server: done (target=${DEPLOY_TARGET})"
|