fix(ci): 修复部署流水线配置

- 使用 Git commit hash 作为镜像标签
- 修复 Docker 网络配置(先连接 traefik-public,再附加 mysql 网络)
- 增加健康检查超时到 120 秒
- 添加镜像清理阶段(保留 7 天)
- 修复 Gitea Actions: github.sha → gitea.sha
- 添加 Docker Registry 认证
- kubectl 版本修正为 v1.30.0
- JDK 安装添加 sudo 权限
- 添加部署失败自动回滚机制

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-19 19:09:22 +08:00
parent 73fdaf82e7
commit b70d90d18a
2 changed files with 44 additions and 26 deletions
Vendored
+27 -19
View File
@@ -1,7 +1,7 @@
pipeline {
agent none // 全局不指定,局部自己声明
agent none
environment {
IMAGE_NAME = 'lpt-prod:0.0'
IMAGE_NAME = "lpt-prod:${env.GIT_COMMIT?.take(8) ?: '0.0'}"
CONTAINER_NAME = 'LPT-prod'
CONTAINER_PORT = '8888'
}
@@ -31,23 +31,24 @@ pipeline {
sh '''
docker network create traefik-public || true
docker rm -f $CONTAINER_NAME || true
docker run -d --name $CONTAINER_NAME --network mysql-prod_mysql-prod \\
--restart=always \\
-e SPRING_PROFILES_ACTIVE=prod \\
--label "traefik.enable=true" \\
--label "traefik.docker.network=traefik-public" \\
--label 'traefik.http.routers.lpt-api.rule=Host(`lpt.cat-shark.xyz`) && PathPrefix(`/api`)' \\
--label "traefik.http.routers.lpt-api.entrypoints=websecure" \\
--label "traefik.http.routers.lpt-api.tls.certresolver=le" \\
--label "traefik.http.routers.lpt-api.priority=100" \\
--label "traefik.http.routers.lpt-api.service=lpt-api" \\
--label "traefik.http.routers.lpt-api.middlewares=lpt-api-strip" \\
--label "traefik.http.middlewares.lpt-api-strip.stripprefix.prefixes=/api" \\
--label "traefik.http.services.lpt-api.loadbalancer.server.port=$CONTAINER_PORT" \\
--log-driver=loki \\
--log-opt loki-url="http://192.168.123.199:3100/loki/api/v1/push" \\
docker run -d --name $CONTAINER_NAME \
--network traefik-public \
--restart=always \
-e SPRING_PROFILES_ACTIVE=prod \
--label "traefik.enable=true" \
--label "traefik.docker.network=traefik-public" \
--label 'traefik.http.routers.lpt-api.rule=Host(`lpt.cat-shark.xyz`) && PathPrefix(`/api`)' \
--label "traefik.http.routers.lpt-api.entrypoints=websecure" \
--label "traefik.http.routers.lpt-api.tls.certresolver=le" \
--label "traefik.http.routers.lpt-api.priority=100" \
--label "traefik.http.routers.lpt-api.service=lpt-api" \
--label "traefik.http.routers.lpt-api.middlewares=lpt-api-strip" \
--label "traefik.http.middlewares.lpt-api-strip.stripprefix.prefixes=/api" \
--label "traefik.http.services.lpt-api.loadbalancer.server.port=$CONTAINER_PORT" \
--log-driver=loki \
--log-opt loki-url="http://192.168.123.199:3100/loki/api/v1/push" \
$IMAGE_NAME
docker network connect traefik-public $CONTAINER_NAME || true
docker network connect mysql-prod_mysql-prod $CONTAINER_NAME || true
'''
}
}
@@ -57,7 +58,7 @@ pipeline {
steps {
script {
def lastStatus = ''
timeout(time: 60, unit: 'SECONDS') {
timeout(time: 120, unit: 'SECONDS') {
waitUntil {
def status = sh(
script: "docker inspect -f '{{.State.Health.Status}}' $CONTAINER_NAME || echo 'unhealthy'",
@@ -74,5 +75,12 @@ pipeline {
}
}
}
stage('清理旧镜像') {
agent any
steps {
sh 'docker image prune -af --filter "until=168h" || true'
}
}
}
}