fix(ci): 修复部署流水线配置

- 使用 Git commit hash 作为镜像标签
- 修复 Docker 网络配置(先连接 traefik-public,再附加 mysql 网络)
- 增加健康检查超时到 120 秒
- 添加镜像清理阶段(保留 7 天)
- 修复 Gitea Actions: github.sha → gitea.sha
- 添加 Docker Registry 认证
- kubectl 版本修正为 v1.30.0
- JDK 安装添加 sudo 权限
- 添加部署失败自动回滚机制

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-19 19:09:22 +08:00
parent 73fdaf82e7
commit b70d90d18a
2 changed files with 44 additions and 26 deletions
+17 -7
View File
@@ -23,28 +23,32 @@ jobs:
- name: Checkout code
run: |
git clone $REPO_URL .
git checkout ${{ github.sha }}
git checkout ${{ gitea.sha }}
- name: Set up JDK 17
run: |
apt-get update -qq
apt-get install -y -qq openjdk-17-jdk
sudo apt-get update -qq
sudo apt-get install -y -qq openjdk-17-jdk
java -version
- name: Build with Maven
run: ./mvnw package -DskipTests -B
- name: Login to Docker Registry
run: |
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login $REGISTRY -u "${{ secrets.REGISTRY_USERNAME }}" --password-stdin
- name: Build & Push Docker image
run: |
apt-get install -y -qq docker.io
TAG=${{ github.sha }}
TAG=${{ gitea.sha }}
docker build -t $REGISTRY/$APP:$TAG -t $REGISTRY/$APP:${{ inputs.environment }} .
docker push $REGISTRY/$APP:$TAG
docker push $REGISTRY/$APP:${{ inputs.environment }}
- name: Setup kubectl
run: |
curl -sLO "https://dl.k8s.io/release/v1.36.0/bin/linux/amd64/kubectl"
curl -sLO "https://dl.k8s.io/release/v1.30.0/bin/linux/amd64/kubectl"
chmod +x kubectl
mv kubectl /usr/local/bin/
mkdir -p ~/.kube
@@ -52,6 +56,12 @@ jobs:
- name: Deploy to K8s
run: |
TAG=${{ github.sha }}
kubectl set image deployment/$APP $APP=$REGISTRY/$APP:$TAG -n lpt-${{ inputs.environment }}
TAG=${{ gitea.sha }}
kubectl set image deployment/$APP $APP=$REGISTRY/$APP:$TAG -n lpt-${{ inputs.environment }} --record
kubectl rollout status deployment/$APP -n lpt-${{ inputs.environment }} --timeout=5m
- name: Rollback on failure
if: failure()
run: |
kubectl rollout undo deployment/$APP -n lpt-${{ inputs.environment }}
kubectl rollout status deployment/$APP -n lpt-${{ inputs.environment }}